Compliance builds on the security foundation. While security protects resources, compliance ensures you're meeting regulatory and organizational requirements for data governance.
Chapter 01: Identity Chapter 02: Security Chapter 03: Compliance
───────────────────── ────────────────────── ─────────────────────────
"Who are you?" "How do we protect?" "Are we following rules?"
Entra ID Defender for Cloud Purview
Conditional Access → Zero Trust → Data Classification
Governance Network Security DLP Policies
Information Protection
| AWS Service | Azure Equivalent | Key Difference |
|---|---|---|
| Macie | Purview Data Map | Purview is broader data governance |
| Config Rules | Azure Policy | Policy has more effects (deny, modify) |
| Audit Manager | Purview Compliance Manager | Integrated compliance scoring |
| Lake Formation | Purview Data Catalog | Unified data governance |
| Security Hub (compliance) | Defender for Cloud + Purview | Split between security and data |
| CloudTrail | Activity Log + Purview Audit | Audit spans M365 + Azure |
┌─────────────────────────────────────────────────────────────────────────────┐
│ MICROSOFT PURVIEW │
│ (Unified Data Governance) │
├─────────────────────────────────────────────────────────────────────────────┤
│ │
│ DATA SECURITY DATA GOVERNANCE │
│ ───────────── ─────────────── │
│ ┌─────────────────────────┐ ┌─────────────────────────┐ │
│ │ Information Protection │ │ Data Catalog │ │
│ │ • Sensitivity labels │ │ • Asset discovery │ │
│ │ • Encryption │ │ • Business glossary │ │
│ │ • Rights management │ │ • Data lineage │ │
│ └─────────────────────────┘ └─────────────────────────┘ │
│ ┌─────────────────────────┐ ┌─────────────────────────┐ │
│ │ Data Loss Prevention │ │ Data Map │ │
│ │ • Policy enforcement │ │ • Automated scanning │ │
│ │ • Block/warn/audit │ │ • Classification │ │
│ │ • Endpoint DLP │ │ • Sensitive data types │ │
│ └─────────────────────────┘ └─────────────────────────┘ │
│ ┌─────────────────────────┐ ┌─────────────────────────┐ │
│ │ Insider Risk Management │ │ Data Estate Insights │ │
│ │ • Behavior analytics │ │ • Health scores │ │
│ │ • Policy violations │ │ • Data quality │ │
│ └─────────────────────────┘ └─────────────────────────┘ │
│ │
│ RISK & COMPLIANCE │
│ ───────────────── │
│ ┌─────────────────────────┐ ┌─────────────────────────┐ │
│ │ Compliance Manager │ │ Audit │ │
│ │ • Assessment templates │ │ • Search & investigate │ │
│ │ • Compliance score │ │ • Retention policies │ │
│ │ • Improvement actions │ │ • eDiscovery │ │
│ └─────────────────────────┘ └─────────────────────────┘ │
│ │
└─────────────────────────────────────────────────────────────────────────────┘
| Document | Purpose | Time |
|---|---|---|
| Quick Reference | Compliance cheat sheet | 5 min |
| 01 - Purview Overview | Data governance platform | 25 min |
| 02 - DLP Policies | Data Loss Prevention | 25 min |
| 03 - Information Protection | Labels and encryption | 25 min |
| Case Studies | Compliance scenarios | 20 min |
This chapter addresses these essential Cloud Architect skills:
✅ Security + Compliance (Defender/Purview)
- Configure data classification
- Implement DLP policies
- Design information protection strategy
✅ Data Governance
- Understand data estate
- Implement data lineage
- Meet regulatory requirements
Start with: Quick Reference
Author: Michel Abboud | AI-Assisted Content | APACHE 2.0 License