Reference architecture · v0.1

High-Assurance Cloud Access

Map a privileged access path from identity and managed device to workload, sensitive data, logging and evidence—then show how each control is prevented, detected and proven.

Assess your access path
  1. 01Privileged identity
  2. 02Managed device
  3. 03Strong authentication
  4. 04Conditional Access
  5. 05JIT / PIM
  6. 06Workload boundary
  7. 07Sensitive data
  8. 08Logging & detection
  9. 09Assurance evidence

Assurance objective

Prove that the control exists, works and remains governed

This is a reusable discussion and assessment pattern for Microsoft Cloud environments. It helps technical teams, assurance stakeholders and delivery partners agree what should prevent a failure, what should detect it and which evidence supports the conclusion.

01

Trace the complete path

Start with a critical resource and follow every human and workload route that can reach it.

02

Test control effectiveness

Record how each preventive and detective control is validated—not only how it is intended to work.

03

Keep evidence operational

Give every failed check, exception and remediation action an owner, decision and review date.

Control model

Threat → preventive control → detective control → evidence

Tailor the pattern to the actual resource, identity model, risk tolerance and evidence sources. Each row should ultimately have a named owner and validation cadence.

Access stage
Threat
Preventive control
Detective control
Evidence
01Privileged identity
Shared, stale or weakly governed administrative identity.
Named admin accounts, role separation and lifecycle ownership.
Inactive-account and privileged-assignment review.
Identity inventory, role owner and last-use report.
02Managed device
Privileged access from an unmanaged or compromised endpoint.
Compliant device requirement and privileged workstation pattern.
Device compliance, risk and sign-in correlation.
Compliance state, device record and access test.
03Strong authentication
Credential theft, phishing or authentication downgrade.
Phishing-resistant MFA and authentication-strength policy.
Risky sign-in and authentication-method monitoring.
Method registration, policy result and sign-in logs.
04Conditional Access
Bypass through exclusions, legacy protocols or policy gaps.
Scoped deny-by-default controls with governed exceptions.
Policy coverage, exclusion and report-only review.
Policy map, exception register and tested scenarios.
05JIT / PIM
Permanent, excessive or unapproved privilege.
Eligible roles, time-bound activation and approval where needed.
Standing-role scan and unusual activation review.
Assignment report, activation history and approval record.
06Workload boundary
Over-privileged service principals or unmanaged application access.
Least-privilege application permissions and managed identities.
Permission drift, credential expiry and anomalous-use review.
Workload inventory, permission graph and named owner.
07Sensitive data
Unauthorised access, extraction or misuse of critical information.
Resource-level RBAC, segmentation and data-protection controls.
Access analytics, alerting and data-activity review.
Access list, protection policy and activity record.
08Logging & detection
A control fails without timely visibility or investigation context.
Required telemetry, retention and protected log destinations.
Use-case validation, alert review and ingestion monitoring.
Coverage map, test event, alert and investigation trail.
09Assurance evidence
Controls exist in design but cannot be proven or maintained.
Named control owner, validation cadence and acceptance criteria.
Failed-check, exception, drift and overdue-action review.
Control status, exception decision and remediation backlog.

Important boundary

A reference pattern is not certification or accreditation

This architecture does not claim compliance with a specific defence, classified, national or sector framework. Real assurance requires environment-specific scope, evidence, threat context and validation by the responsible authority.

Enki Tech can apply the pattern as a secure-cloud assessment or as a specialist work package inside a partner-led engagement.