Start here! Get your feet wet with the Microsoft cloud and begin your journey to earning your Microsoft Certified: Azure Fundamentals certification!
Prepare and test your skills

Prepare and test your skills

Worked example. The correct answer is already marked and every option is explained below, so there is nothing to select here. To answer questions yourself, start the free trial.
An organization is migrating several enterprise workloads to Microsoft Azure using a mix of Infrastructure as a Service (IaaS), Platform as a Service (PaaS), and Software as a Service (SaaS) offerings. The chief information security officer (CISO) requires a clear division of operational tasks to ensure compliance and security standards are maintained.
Which responsibility always remains solely with the customer across all cloud deployment models?
Keep the momentum going with these hand-picked practice scenarios
Want more questions like this?
Get a free certification question every week.
In cloud computing, the shared responsibility model defines which security, operational, and maintenance tasks are handled by the cloud provider (Microsoft Azure) and which tasks belong to the customer. While responsibilities for physical infrastructure, operating systems, and middleware shift depending on whether a service is categorized as IaaS, PaaS, or SaaS, certain foundational assets are universally owned by the customer.
Across all cloud deployment models—from raw compute infrastructure to turnkey SaaS applications—the classification, protection, and governance of data and the administration of user identities and access privileges remain exclusively with the customer. Microsoft provides built-in tools such as Azure Role-Based Access Control (Azure RBAC), Microsoft Entra ID, and data encryption options, but configuring these controls and defining access policies is strictly an organization-level obligation.
Recognizing that data and identity governance never transfer to the cloud provider prevents critical compliance gaps. It ensures security teams prioritize data classification, key management, and robust access controls rather than mistakenly assuming cloud hosting automatically secures sensitive corporate data.