Start here! Get your feet wet with the Microsoft cloud and begin your journey to earning your Microsoft Certified: Azure Fundamentals certification!
Prepare and test your skills

Prepare and test your skills

Worked example. The correct answer is already marked and every option is explained below, so there is nothing to select here. To answer questions yourself, start the free trial.
An organization is evaluating its migration strategy to Microsoft Azure and reviewing how operational and security responsibilities change across different cloud service types.
The IT leadership team needs to ensure governance, data protection, and user access policies remain compliant across all adopted services, whether using Infrastructure as a Service (IaaS), Platform as a Service (PaaS), or Software as a Service (SaaS).
Under the shared responsibility model, which responsibility is always retained entirely by the customer regardless of the cloud service model chosen?
Keep the momentum going with these hand-picked practice scenarios
Want more questions like this?
Get a free certification question every week.
Identity and access management (IAM) and data governance encompass the policies, tools, and processes used to secure data, authenticate users, and authorize access to cloud resources. In Microsoft Azure, identity is centralized using Microsoft Entra ID and governed via Azure role-based access control (Azure RBAC).
Under the shared responsibility model, certain operational and security duties remain 100% the customer's responsibility across every cloud delivery model:
Whether utilizing IaaS, PaaS, or SaaS, Microsoft provides the tools to manage access and protect data, but configuring, assigning, and enforcing access rules remains the customer's exclusive duty.
Cloud providers manage underlying physical assets and infrastructure, but they cannot determine which specific employees or systems inside an enterprise require access to corporate data. Retaining full customer accountability for identity and data ensures business-level security policies are maintained across IaaS, PaaS, and SaaS deployments.