Identity and access
In progressEntra ID, RBAC, least privilege, and AZ-104 identity objectives are active study areas.
Theme
A mock Microsoft Defender / Azure security blade for the portfolio itself: what is protected, what is planned, and what the project proves.
Mock score, but the story behind it is real: privacy-by-default content sync now, backend guardrails before the AI goes live.
Entra ID, RBAC, least privilege, and AZ-104 identity objectives are active study areas.
Public-safe content allowlist, phone-number scrub requirement, and explicit vault denylist.
Phase 3 keeps Azure OpenAI secrets server-side in Azure Functions, then moves toward managed identity.
Future Cloudflare Web Analytics or Azure-native telemetry with no invasive tracking.
Ingest Entra sign-in logs, write KQL detections for impossible-travel and MFA fatigue, and surface them on a workbook.
Stand up a set of CA policies, then try to break in from a non-compliant device to prove each one actually blocks.
Move admin roles to just-in-time activation and run access reviews to show least privilege holding over time.
Deploy a deliberately misconfigured workload, then remediate the findings and track the secure score climbing.
Pull every secret out of app config into Key Vault, authenticate with managed identity, and rotate keys with zero downtime.
Expose a decoy box from the VM blade and wire an alert that fires on first unauthorized touch. Ties the labs together.
Switching directory
Loading selected view
Choose directory
You can switch later from the profile menu in the top-right, just like changing directories in Azure Portal.