---
title: Nuances of Azure’s Shared Responsibility Security Model
description: As you move workloads to Azure, don’t assume they are automatically protected. It’s all detailed in Microsoft’s Shared Responsibility Security Model. Understanding where the Shared Responsibility model starts and stops is critical to ensuring your data is secure. Here are some key considerations.
image: https://www.daymarksi.com/hubfs/blog-images/shared-responsibility.jpg
---

- [MICROSOFT SERVICE OFFERINGS](https://www.daymarksi.com/microsoft-service-offerings)
- [CONTACT](https://www.daymarksi.com/location-for-our-new-england-office-massachusetts)
- [SUPPORT](https://www.daymarksi.com/support)

[![DM_LogoTag_white-20yr](https://www.daymarksi.com/hubfs/brand-assets/DM_LogoTag_white-20yr.png "DM_LogoTag_white-20yr")](https://www.daymarksi.com)

- [About](https://www.daymarksi.com/about-daymark) 
    - [Why Daymark](https://www.daymarksi.com/why-daymark)
    - [Leadership](https://www.daymarksi.com/leadership)
    - [Industry Awards](https://www.daymarksi.com/industry-awards)
    - [Daymark Solutions Charitable Trust](https://www.daymarksi.com/charitable-trust)
    - [Customers](https://www.daymarksi.com/customers)
    - [Testimonials](https://www.daymarksi.com/testimonials)
    - [Technical Certifications](https://www.daymarksi.com/technical-certifications)
    - [Careers](https://www.daymarksi.com/careers)
    - [Locations](https://www.daymarksi.com/location-for-our-new-england-office-massachusetts)
- [Solutions](https://www.daymarksi.com/solutions) 
    - [Cloud Solutions](https://www.daymarksi.com/cloud)
    - [CMMC Compliance](https://www.daymarksi.com/understanding-the-cybersecurity-maturity-model-certification)
    - [Data Center Infrastructure](https://www.daymarksi.com/solutions/data-center-infrastructure-for-storage-networking-compute-security)
    - [Data Protection](https://www.daymarksi.com/solutions/data-protection-backups-recovery-restore)
    - [Networking](https://www.daymarksi.com/solutions/networking-and-security)
    - [Security](https://www.daymarksi.com/solutions/networking-and-security)
    - [Virtualization](https://www.daymarksi.com/solutions/virtualization)
    - [All Technology Partners](https://www.daymarksi.com/partners)
- Cloud 
    - [Microsoft Azure](https://www.daymarksi.com/microsoftazure)
    - [Microsoft Azure Government](https://www.daymarksi.com/protecting-government-data-for-the-defense-industrial-base)
    - [Microsoft 365](https://www.daymarksi.com/microsoft-365)
    - [Copilot for Microsoft 365](https://www.daymarksi.com/copilot-for-microsoft-365)
    - [Microsoft 365 GCC High](https://www.daymarksi.com/microsoft-gcc-high-for-defense-contractors)
    - [Mimecast](https://www.daymarksi.com/cloud)
    - [Okta](https://www.daymarksi.com/cloud)
    - [All Cloud Partners](https://www.daymarksi.com/cloud-partners)
- [Services](https://www.daymarksi.com/services) 
    - [Microsoft Service Offerings](https://www.daymarksi.com/microsoft-service-offerings)
    - [Assessment & Health Checks](https://www.daymarksi.com/services/assessment-and-health-checks)
    - [Cloud Architecture](https://www.daymarksi.com/services/custom-cloud-computing-implementations-and-services-in-new-england)
    - [CMMC Compliance Readiness](https://www.daymarksi.com/understanding-the-cybersecurity-maturity-model-certification)
    - [Contract & Maintenance Management](https://www.daymarksi.com/services/contract-maintenance-management)
    - [Documentation & Knowledge Transfer](https://www.daymarksi.com/services/documentation)
    - [Government Community Cloud](https://www.daymarksi.com/microsoft-gcc-high-for-defense-contractors)
    - [Identity Mangement](https://www.daymarksi.com/microsoft-entra-id-workshop)
    - [Implementations](https://www.daymarksi.com/services/it-project-implementation-on-budget-on-time-on-scope)
    - [Proof of Concepts](https://www.daymarksi.com/services/proof-of-concept-for-information-technology-initiatives)
    - [Solution Architecture](https://www.daymarksi.com/services/it-solution-architecture-for-complex-storage-network-and-computer-solutions)
    - [Staging & Integration](https://www.daymarksi.com/services/staging-and-integration)
- [MyDaymark](https://www.daymarksi.com/mydaymark/) 
    - [Advanced Support](https://www.daymarksi.com/mydaymark/advanced-support)
    - [Premier Support](https://www.daymarksi.com/mydaymark/premier-support)
    - [Managed Services](https://www.daymarksi.com/mydaymark/managed-services)
    - [Management Platform](https://www.daymarksi.com/mydaymark/management-platform)
    - [Security & Compliance](https://www.daymarksi.com/mydaymark/security-compliance)
- Industries 
    - [Energy & Utilities](https://www.daymarksi.com/new-england-it-project-management-and-implementation-for-energy-and-utilities-industry)
    - [Financial Services](https://www.daymarksi.com/new-england-it-project-implementation-for-financial-services-companies)
    - [Defense Industrial Base](https://www.daymarksi.com/protecting-government-data-for-the-defense-industrial-base)
    - [Healthcare](https://www.daymarksi.com/healthcare-information-technology-development-and-implementation)
    - [Life Sciences](https://www.daymarksi.com/new-england-it-initiative-implementation-for-life-sciences-companies)
- [Resources](https://www.daymarksi.com/information-technolocy-resources) 
    - [Case Studies](https://www.daymarksi.com/information-technolocy-resources?types=casestudy)
    - [Data Sheets](https://www.daymarksi.com/information-technolocy-resources?types=datasheet)
    - [Partner Resources](https://www.daymarksi.com/information-technolocy-resources?types=partnerresources)
    - [Workshops](https://www.daymarksi.com/information-technolocy-resources?types=workshop)
- [News & Events](https://www.daymarksi.com/news-events)
- Blog 
    - [Daymark IT Insights](https://www.daymarksi.com/blog)
    - [Cole Tramp's Microsoft Insights](https://www.daymarksi.com/blog/topic/cole-tramps-microsoft-insights)

![banner-why-daymark.jpg](https://www.daymarksi.com/hs-fs/hub/30865/file-2671640025-jpg/2015_Images/Banner_Images/banner-why-daymark.jpg?width=1400&name=banner-why-daymark.jpg "banner-why-daymark.jpg")

##### **Daymark IT Insights**

Enterprise IT, cloud, security, and AI guidance from Daymark’s technology experts.

# [Nuances of Azure’s Shared Responsibility Security Model](https://www.daymarksi.com/blog/nuances-of-azures-shared-responsibility-security-model)

Posted by [Joe Correia](https://www.daymarksi.com/blog/author/joe-correia)

 Wed, Feb 27, 2019

- [Tweet](https://twitter.com/share)

![shared-responsibility](https://www.daymarksi.com/hs-fs/hubfs/blog-images/shared-responsibility.jpg?width=780&name=shared-responsibility.jpg)

The benefits of migrating applications to Microsoft’s Azure cloud make a very compelling business case – agility, scalability, a pay for what you use cost model, etc. But as you move workloads to Azure, don’t assume they are automatically protected, because while Azure does ensure a secure infrastructure, you are responsible for ensuring protection of your data – not Microsoft.

It’s all detailed in Microsoft’s Shared Responsibility Security Model. Understanding where the Shared Responsibility model starts and stops is critical to ensuring your data is secure and compliant. Here are some key considerations:

**Division of Responsibility**

Azure infrastructure complies with many industry standards like NIST and ISO/IEC 27001:2013 providing 24x7 continuity from inside geographically dispersed datacenters. In compliance with these standards, Microsoft provides security for physical assets, network infrastructure, availability, SQL database, monitoring and operations. The shared responsibility model is used to show where the division of responsibility is when a customer moves their workloads into the cloud. Within Azure, Microsoft assumes responsibility for general datacenter components such as compute hosts, datacenter assets, and the networks that connect them. However, the division can vary when you look at the many service offerings available in the cloud from the operating systems and applications to directory services and account management. Ultimately customers continue to be solely responsible for their user accounts, system endpoints, permissions/access controls and most importantly their data.

Customer data availability and integrity comes with the package when leveraging cloud, however retention, compliance, and rights management are the responsibility of the customer. Microsoft provides many features and tools to help with these challenges, but it is up to the customer to architect and implement the necessary policies and controls for their data.

**Identity and Access Management**

Identity management is leveraged heavily in controlling and protecting customer data in a cloud solution. Typically, when customers move to the cloud additional identity and access management features such as conditional access, single sign-on, multi-factor authentication (MFA), and mobile device management (MDM) are layered onto the legacy on-premises authentication and access methods.

Application control and permissions can be a shared model between the cloud service provider (CSP) and its customer when considering web services, IoT, and media services to reduce responsibility on the customer side. In an IaaS deployment the customer must manage operating systems, applications and data security, and the CSP will tackle everything from the infrastructure layer down, including physical security, platform patching, compliance, etc.

**Recommendations:**

Having helped customer navigate the nuances of this shared responsibility model, here are some important considerations:

- Implement a data backup solution that integrates with Office 365 to protect against human error, hackers, malicious activity, and ransomware. There are a variety of options available, including Skykick, Mimecast, Veeam and Spanning depending upon your specific deployment and requirements. Office 365 also includes some retention across deleted items (14-30 days) that can help, but may fall short of what you need for a recovery point.
- Design and configure a compliance solution that encompasses data classification, retention, and loss prevention. Policy driven classification can help control not only access but data retention to protect against both unintentional and malicious data destruction. Start with a default retention policy, set to the corporate minimum period, that can be applied to important company data across major services and fine tune up from there.

The bottom line: Going to the cloud does not remove the need for good IT practices.  IT Admins must still apply policies and process to cloud resources the same as they would on-premises.

Need help protecting your data in the cloud? Daymark is a Microsoft Tier 1 Cloud Service Provider. Our consultants have extensive experience with [Azure migrations](https://www.daymarksi.com/microsoftazure) and would be happy to map out your migration strategy. We can get you started with our [Azure Everywhere Workshop](https://www.daymarksi.com/hubfs/collateral-2018/Azure_Everywhere_Workshop.pdf) – A 2-day on-site workshop at your location where Daymark cloud consultants will conduct a thorough assessment of your environment and make recommendations on workloads best suited for the Azure platform. [Contact us](https://www.daymarksi.com/locations-for-our-new-england-offices-connecticut-new-hampshire-massachusetts) today to get started.

 

 

### Subscribe to Daymark Insights

### Latest Posts

### Browse by Tag

- [Microsoft (88)](https://www.daymarksi.com/blog/topic/microsoft)
- [Cloud (70)](https://www.daymarksi.com/blog/topic/cloud)
- [Cole Tramp's Microsoft Insights (58)](https://www.daymarksi.com/blog/topic/cole-tramps-microsoft-insights)
- [Azure (55)](https://www.daymarksi.com/blog/topic/azure)
- [Security (49)](https://www.daymarksi.com/blog/topic/security)
- [Data Protection (43)](https://www.daymarksi.com/blog/topic/data-protection)
- [Microsoft Fabric (41)](https://www.daymarksi.com/blog/topic/microsoft-fabric)
- [Data Governance (38)](https://www.daymarksi.com/blog/topic/data-governance)
- [AI (35)](https://www.daymarksi.com/blog/topic/ai)
- [Partners (33)](https://www.daymarksi.com/blog/topic/partners)
- [Compliance (31)](https://www.daymarksi.com/blog/topic/compliance)
- [Data Center (30)](https://www.daymarksi.com/blog/topic/data-center)
- [CMMC (27)](https://www.daymarksi.com/blog/topic/cmmc)
- [Backup (26)](https://www.daymarksi.com/blog/topic/backup)
- [Daymark News (23)](https://www.daymarksi.com/blog/topic/daymark-news)
- [Storage (22)](https://www.daymarksi.com/blog/topic/storage)
- [GCC High (19)](https://www.daymarksi.com/blog/topic/gcc-high)
- [Veritas (18)](https://www.daymarksi.com/blog/topic/veritas)
- [Virtualization (18)](https://www.daymarksi.com/blog/topic/virtualization)
- [Cybersecurity (17)](https://www.daymarksi.com/blog/topic/cybersecurity)
- [Azure AI Foundry (16)](https://www.daymarksi.com/blog/topic/azure-ai-foundry)
- [Featured Gov (16)](https://www.daymarksi.com/blog/topic/featured-gov)
- [Government Cloud (16)](https://www.daymarksi.com/blog/topic/government-cloud)
- [Disaster Recovery (15)](https://www.daymarksi.com/blog/topic/disaster-recovery)
- [Cloud Backup (14)](https://www.daymarksi.com/blog/topic/cloud-backup)
- [Managed Services (13)](https://www.daymarksi.com/blog/topic/managed-services)
- [Copilot (11)](https://www.daymarksi.com/blog/topic/copilot)
- [Industry Expertise (9)](https://www.daymarksi.com/blog/topic/industry-expertise)
- [NIST SP 800-171 (7)](https://www.daymarksi.com/blog/topic/nist-sp-800-171)
- [Hybrid Cloud (6)](https://www.daymarksi.com/blog/topic/hybrid-cloud)
- [Networking (6)](https://www.daymarksi.com/blog/topic/networking)
- [Power BI (6)](https://www.daymarksi.com/blog/topic/power-bi)
- [Pure Storage (4)](https://www.daymarksi.com/blog/topic/pure-storage)
- [Reporting (3)](https://www.daymarksi.com/blog/topic/reporting)
- [Services (3)](https://www.daymarksi.com/blog/topic/services)
- [AI for Defense (2)](https://www.daymarksi.com/blog/topic/ai-for-defense)
- [Cloud Security (2)](https://www.daymarksi.com/blog/topic/cloud-security)
- [Everpure (2)](https://www.daymarksi.com/blog/topic/everpure)
- [GDPR (2)](https://www.daymarksi.com/blog/topic/gdpr)
- [Microsoft Purview (2)](https://www.daymarksi.com/blog/topic/microsoft-purview)
- [Apple (1)](https://www.daymarksi.com/blog/topic/apple)
- [CMMC 2.0 Requirements (1)](https://www.daymarksi.com/blog/topic/cmmc-2-0-requirements)
- [FedRamp AI (1)](https://www.daymarksi.com/blog/topic/fedramp-ai)
- [Mobile (1)](https://www.daymarksi.com/blog/topic/mobile)
- [Power Automate (1)](https://www.daymarksi.com/blog/topic/power-automate)

[see all](https://www.daymarksi.com/blog/nuances-of-azures-shared-responsibility-security-model#)

### How Can We Help?  [![Speak With An Expert](https://no-cache.hubspot.com/cta/default/30865/5de282fd-640c-49b2-bf45-603dbee66842.png)](https://cta-redirect.hubspot.com/cta/redirect/30865/5de282fd-640c-49b2-bf45-603dbee66842)

#### About

Daymark Solutions is an experienced technology integration and solutions provider that helps organizations effectively architect, implement, and deploy customized solutions to help their customers grow and scale their IT infrastructure. Specializing in AI, cloud and modern data center solutions, Daymark’s unique combination of in-depth technical knowledge, extensive experience, and proven methodologies enable its customers to successfully address even the most difficult technology challenges.

#### Connect

<https://twitter.com/daymarksi>     <https://twitter.com/daymarksi><https://www.linkedin.com/company/daymark-solutions-inc./>

#### Links

- [About](https://www.daymarksi.com/about-daymark)
- [Industry Expertise](https://www.daymarksi.com/industry-experience-in-finance-healthcare-energy-utilities-and-life-sciences)
- [Solutions](https://www.daymarksi.com/solutions)
- [Services](https://www.daymarksi.com/services)
- [Cloud](https://www.daymarksi.com/services/custom-cloud-computing-implementations-and-services-in-new-england)
- [Resources](https://www.daymarksi.com/whitepapers-videos-analyst-reports-and-case-studies-on-information-technologies)
- [News & Events](https://www.daymarksi.com/news-events)
- [Blog](https://www.daymarksi.com/blog)

#### Contact

**Corporate Headquarters**  
Daymark Solutions  
131 Middlesex Turnpike  
Burlington, MA 01803

**Corporate:** [+1 781-359-3000](tel:17813593000)

**Email:** [info@daymarksi.com](mailto:info@daymarksi.com)

![DM_LogoTag_white.png](https://www.daymarksi.com/hs-fs/hubfs/Daymarksi-2017/Image/DM_LogoTag_white.png?width=176&name=DM_LogoTag_white.png "DM_LogoTag_white.png")

© 2026 Daymark Solutions, Inc. All rights reserved.  |  [Daymark Privacy Policy](https://www.daymarksi.com/hubfs/Daymark%20-%20Privacy%20Policy.pdf)

```json
{
  "@context" : "https://schema.org",
  "@type" : "BlogPosting",
  "author" : {
    "@type" : "Person",
    "name" : "Joe Correia",
    "url" : "https://www.daymarksi.com/blog/author/joe-correia"
  },
  "dateModified" : "2019-02-27T20:44:17.283Z",
  "datePublished" : "2019-02-27T20:41:57.000Z",
  "headline" : "Nuances of Azure’s Shared Responsibility Security Model",
  "image" : [ "https://www.daymarksi.com/hubfs/blog-images/shared-responsibility.jpg" ],
  "mainEntityOfPage" : {
    "@id" : "https://www.daymarksi.com/blog/nuances-of-azures-shared-responsibility-security-model",
    "@type" : "WebPage"
  },
  "publisher" : {
    "@type" : "Organization",
    "logo" : {
      "@type" : "ImageObject",
      "url" : "https://www.daymarksi.com/hubfs/v2/images/daymark-logo.png"
    },
    "name" : "Daymark Solutions, Inc."
  }
}
```