Independent DPDP educationBrowser-only workspace · no accounts, analytics or submissions

Cloud infrastructureSystem guide · implementation aid

Microsoft Azure: follow the evidence.

Map tenants, subscriptions, resources, data planes, logs, backups and privileged identities.

00 What usually flows through Microsoft Azure

A working data journey, not a legal conclusion.

Application data, databases, storage, logs, backups, identities, support events and cross-tenant transfers. Replace this editorial model with the systems, data and roles your organisation can actually evidence.

Typical Microsoft Azure data journeySix stages show information moving from collection through operational systems, evidence and an end-of-lifecycle decision.010203040506
  1. 01ApplicationAPI · event · upload
  2. 02ResourcesDB · storage · queue
  3. 03AccessEntra · RBAC · identity
  4. 04Copieslog · replica · pipeline
  5. 05Evidenceactivity · resource · alert
  6. 06Endsoft delete · backup · restore
Illustrative operating model. Verify actual fields, destinations, contracts, regions, retention and access.

01

Accountability

Role map

Roles depend on who decides purpose and means, who acts on instructions, and what each party actually does. Record the conclusion and its evidence; do not infer it from the vendor label.

  • Name tenant, subscription, workload, platform, security and data owners.
  • Separate Entra directory roles, Azure RBAC roles, managed identities and data-plane permissions.
  • Record Microsoft and managed-service roles from current agreements and architecture.

02

Collection surfaces

Collection and notice touchpoints

Walk each entry path as a real user. Save the notice, fields, choices, time and destination rather than relying on a policy page alone.

  • Application endpoints, databases, storage, messaging and analytics.
  • Developer operations, support, monitoring and diagnostic logs.
  • Backups, geo-replication, data factories and cross-tenant access.

03

Purpose discipline

Purpose and data minimisation checks

Every field and copy should have a named operating reason, accountable owner and review event.

  • Map data classes to necessary resources, regions and diagnostic fields.
  • Avoid personal data in resource names, tags and verbose logs.
  • Limit test copies, shared keys and analytics duplication.

04

Choice evidence

Consent and preference evidence

When consent is relied on, preserve the affirmative action and withdrawal path. Where another legal route is assessed, record that analysis instead of manufacturing a consent record.

  • Carry collection and purpose evidence from the application.
  • Do not treat RBAC as the individual’s consent.
  • Confirm downstream analytics and AI uses match the recorded purpose.

05

Least privilege

Access control and privileged roles

Test ordinary view, sensitive fields, bulk action, export, configuration and integration access separately.

  • Review Entra roles, Azure RBAC, managed identities, service principals and shared keys.
  • Separate management-plane and resource data-plane access.
  • Exercise role removal, secret rotation and privileged activation review.

06

Lifecycle

Retention, deletion, backup and export behaviour

A delete button is not a lifecycle rule. Record the start event, end event, exception, system action, residual copy and accountable approver.

  • Define deletion for live resources, soft delete, versions, replicas and backups.
  • Test restore paths and record resource-specific retention.
  • Document region and diagnostic-log retention decisions.

07

Service chain

Processor, sub-processor and contract checks

Use the current contract and actual architecture. A product page cannot establish the complete role allocation for your organisation.

  • Retrieve current Microsoft terms, DPA and sub-processor information.
  • Inventory marketplace, managed-service, support and cross-tenant parties.
  • Record assistance, exit, deletion and incident expectations.
Open the processor-register guide

08

Detection + response

Logs, monitoring and breach evidence

Coverage, event types, retention and exportability vary. Preserve an evidence timeline without claiming that one log proves the complete event.

  • Confirm Activity Log, resource-log and Entra-log coverage separately.
  • Create diagnostic settings where longer or data-plane evidence is required.
  • Protect exports and connect alerts to investigation evidence.

09

Request workflow

Rights-request search, export, correction and erasure workflow

  1. 01

    Translate verified person identifiers into application and storage keys.

  2. 02

    Search live resources, analytics stores and owned pipelines.

  3. 03

    Apply exceptions and execute correction or deletion through the application.

  4. 04

    Track soft-delete, versions, replicas, backups and downstream confirmations.

10

Bounded configuration

Configuration checklist

RBAC and identity

Directory, resource and data-plane access are reviewed separately.

Admin path
Verify in the current admin console
Evidence to save
Role assignments, app identities and exceptions.
Activity and resource logs

Control- and data-plane evidence have deliberate coverage and retention.

Admin path
Verify in the current admin console
Evidence to save
Diagnostic settings and sample events.
Backup lifecycle

Soft-delete, versions, replicas and restore paths follow owned rules.

Admin path
Verify in the current admin console
Evidence to save
Resource lifecycle map and test.

No menu-path fiction: open the current vendor documentation and your live console together. Feature names, paths and entitlements can change.

11

Retrievable proof

Evidence to save

Tenant, subscription and resource map

Directory/RBAC/data-plane access review

Activity Log and diagnostic-setting record

Managed identity and secret review

Backup/soft-delete lifecycle

Rights-search and restore exercise

Save redacted configuration evidence in an approved internal location. This private preview does not accept uploads or store these records.

12

Do not overclaim

Known limitations and questions for the vendor

Known limitations

  • Azure Activity Log generally covers control-plane operations, not every data-plane action.
  • Resource logs require service-specific diagnostic configuration.
  • Default retention and available features change by log and subscription.

Questions to resolve

  1. Which tenants, subscriptions and regions are in scope?
  2. Which principals have data-plane access?
  3. Which diagnostic settings are enabled?
  4. What can restore a deleted record?

13

Traceable record

Official vendor sources, DPDP sources and corrections

Vendor documentation supports configuration questions only. DPDP statements are mapped separately to official Indian sources and phased commencement records.

Editorial status

Reviewed · not counsel-reviewed · educational implementation guidance, not legal advice, certification or a legal conclusion.

Report or inspect a correction

Microsoft Azure and Microsoft Entra are trademarks of Microsoft Corporation. References are nominative and do not imply endorsement. No affiliation or endorsement is implied.

14 Continue the workspace

Turn this system review into owned gaps.

The browser-only readiness map can capture what is evidenced, partial, unknown or missing. It does not produce a pass, certificate or legal conclusion.

Answer the linked readiness itemTrace SEC-02 to evidence Read: Cross-border processing
Related system guides

Amazon Web ServicesCloud infrastructure

All system guidesSearch the complete stack