☁️ Azure Identity & Governance Engineering
Practical implementation of Azure identity, access governance, secure storage, and network security controls
📌 Overview
This repository demonstrates practical Azure implementations with a focus on identity, access governance, and secure cloud administration.
The projects showcase real-world administrative and engineering scenarios, including identity lifecycle management, role-based access control, policy-driven governance, secure storage configuration, and controlled network architecture.
The work reflects enterprise-level considerations such as least privilege access, defence in depth, secure access boundaries, and operational governance.
🏗️ Project Overview
| Project | Focus Area | Key Concepts | IAM / Security Relevance | Status |
|---|---|---|---|---|
| Identity & Access Governance | Identity Management | Entra ID, RBAC, Azure Policy, PowerShell | Identity lifecycle, role design, access governance | Completed / In Progress |
| Data Protection & Secure Storage | Data Security | Storage Accounts, Azure Files, Access Controls, ACI | Data protection, secure access, compliance controls | Completed / In Progress |
| Network Security & Traffic Control | Network Architecture | Hub-Spoke, VNet Peering, NSGs, UDR | Segmentation, controlled traffic flow, access boundaries | Completed / In Progress |
🔐 Identity, Security & Governance Focus
Identity & Access
- Managing identities and groups within Microsoft Entra ID
- Implementing Role-Based Access Control (RBAC) aligned to least privilege
- Supporting identity lifecycle and access governance processes
- Using PowerShell to support repeatable administrative tasks
Governance & Compliance
- Authoring and applying Azure Policies to enforce standards
- Implementing controls to reduce misconfiguration risk
- Aligning governance with operational and security accountability
- Demonstrating practical understanding of access control and policy enforcement
Storage & Data Protection
- Configuring secure storage access controls
- Applying data protection principles to Azure Storage services
- Supporting secure file access and controlled resource exposure
- Considering compliance-focused controls such as retention and restricted access
Network & Infrastructure Security
- Designing segmented networks to reduce lateral movement risk
- Controlling inbound and outbound traffic using NSGs and routing
- Implementing hub-spoke network design principles
- Applying defence-in-depth across infrastructure layers
🧠 Core Capabilities Demonstrated
- Identity and access governance in Azure environments
- Secure infrastructure design aligned to Zero Trust principles
- RBAC implementation and least privilege access control
- Policy-driven governance and compliance enforcement
- Secure storage configuration and data protection
- Network segmentation and controlled traffic flow
- Practical Azure administration using portal and scripting workflows
🎯 Purpose
This repository demonstrates capability in:
- Identity and Access Management
- Access Governance
- Cloud Security Engineering
- Azure Administration
- Secure Infrastructure Design
with a focus on secure, scalable, and well-governed Azure environments.
🎓 Certification Context
Aligned with Microsoft Azure Administrator (AZ-104), with emphasis on practical implementation rather than exam-focused coverage.
🧭 Project Status
Projects 1–3 are the current focus of this repository.
Additional projects may be added later, but this repository currently prioritises:
- Identity and access governance
- Secure storage and data protection
- Network security and traffic control
Maintained by Jacob Adedoyin