Practical resource
Secure Cloud Control Matrix
Twenty questions to expose gaps in access, privileged identity, workload trust and recurring control evidence across a Microsoft Cloud environment.
Control domain
Identity & authentication
Know which identities can begin a path to critical resources and under which conditions.
- 01
Which human, guest and emergency identities can reach each critical resource?
Evidence example: Named identity inventory linked to resource ownership
- 02
Is phishing-resistant authentication required for privileged and high-risk access?
Evidence example: Authentication method policy and sign-in evidence
- 03
Do Conditional Access policies cover every relevant access path without unmanaged exclusions?
Evidence example: Policy map, exclusions and tested scenarios
- 04
Are legacy authentication and unmanaged access paths blocked or explicitly risk-accepted?
Evidence example: Protocol settings, exceptions and owner approval
- 05
Can the team explain how device trust affects access to sensitive workloads and data?
Evidence example: Compliance policy, device state and access test
Control domain
Privileged access
Reduce standing privilege and make elevation deliberate, time-bound and reviewable.
- 06
Which privileged roles are permanent, eligible, unused or assigned outside the expected process?
Evidence example: Role export, PIM status and last-used evidence
- 07
Does privilege activation require justification, approval and strong authentication where appropriate?
Evidence example: PIM configuration and activation history
- 08
Are administrative duties separated from everyday user accounts and endpoints?
Evidence example: Admin account model and privileged workstation controls
- 09
Are emergency access accounts protected, monitored and tested without weakening normal controls?
Evidence example: Break-glass procedure and last test evidence
- 10
Who reviews privileged access, how often and what happens when ownership is unclear?
Evidence example: Review schedule, decisions and removal record
Control domain
Workloads & data
Make non-human access and data dependencies visible before they become hidden risk.
- 11
Which service principals, managed identities and applications can reach critical resources?
Evidence example: Workload identity inventory and permission graph
- 12
Does every high-impact application permission have a business and technical owner?
Evidence example: Owner register and consent rationale
- 13
Are secrets, certificates and keys inventoried with expiry and rotation responsibilities?
Evidence example: Key and certificate inventory with lifecycle data
- 14
Can cryptographic dependencies be replaced without redesigning the dependent service?
Evidence example: Crypto-agility assessment and dependency map
- 15
Are critical data paths logged well enough to investigate misuse or control failure?
Evidence example: Logging coverage, retention and test query
Control domain
Evidence & continuous governance
Keep controls effective as configuration, people and operational exceptions change.
- 16
Which controls are material enough to validate every month or quarter?
Evidence example: Approved control baseline and validation cadence
- 17
Can each control produce evidence without a manual reconstruction exercise?
Evidence example: Repeatable query, report or validation procedure
- 18
Who owns failed checks, exceptions and remediation deadlines?
Evidence example: Named owner, due date and escalation path
- 19
How is drift from the approved baseline detected and risk-ranked?
Evidence example: Configuration comparison and risk criteria
- 20
Can management see control status, open risk and remediation progress in one concise view?
Evidence example: Current evidence pack and prioritized backlog
Next step
Several uncertain answers usually indicate an evidence or ownership gap
Enki Tech can turn the matrix into a scoped trust-path assessment, prioritized remediation plan and repeatable governance baseline.
