Sample Architectures (LOTs here):
CyberSecurity Reference Architecture
https://docs.microsoft.com/en-us/security/cybersecurity-reference-architecture/mcra
Cloud for IT Architect Illustrations
https://docs.microsoft.com/en-us/microsoft-365/solutions/cloud-architecture-models?view=o365-worldwide#identity-and-device-protection-for-office-365
Steps on moving to a ‘modern’, Zero Trust architecture
- Moving away from VPN by publishing the apps via Azure AD App Proxy (per-app vpn)
- Modernize the app by moving the data/process to SaaS products
- Isolate the app/data by implementing Windows Virtual Desktop (running in Azure) – useful for when you don’t own the endpoint
- Isolate the data using DLP on Windows, Office, MCAS, and anywhere else (MIP integration)
- Monitor all user app/data access via Azure AD Auth with MCAS session controls (includes AWS, SaaS, etc)
Microsoft Well Architected Framework
https://www.microsoft.com/azure/partners/well-architected
https://www.microsoft.com/en-us/us-partner-blog/2021/04/23/azures-well-architected-framework-pillar-5-security/
Well Architected Assessment Tool