Secure Azure Platform With Azure AD
Budget: $30 – $250 AUD
I already run an Azure App Service, an Azure Database for PostgreSQL, Wasabi object storage and Azure Key Vault. My immediate focus is Authentication and Authorization, and I want it done right from day one.
Here’s what I need:
• Integrate Azure AD so that all three user groups—internal employees, external partners and customers—can sign in through both OAuth2 and OpenID Connect flows.
• Apply fine-grained RBAC across App Service, PostgreSQL and the Wasabi storage gateway, leaning on Managed Identities to eliminate embedded credentials.
• Store all secrets, keys and connection strings exclusively in Key Vault and wire them back into the workloads with reference syntax.
• Enforce full network isolation: land every resource inside its own VNet, expose only private endpoints, and tighten traffic with NSGs.
• Produce an audit-ready environment that maps clearly to SOC 2 controls, including policy definitions, activity logging and evidence collection procedures.
Deliverables will include the configuration (ARM/Bicep/Terraform templates or scripts if you prefer), a concise hand-off document and a short walkthrough call so I can keep everything compliant going forward. If this sounds like your wheelhouse, let’s talk timelines and get started.
Here’s what I need:
• Integrate Azure AD so that all three user groups—internal employees, external partners and customers—can sign in through both OAuth2 and OpenID Connect flows.
• Apply fine-grained RBAC across App Service, PostgreSQL and the Wasabi storage gateway, leaning on Managed Identities to eliminate embedded credentials.
• Store all secrets, keys and connection strings exclusively in Key Vault and wire them back into the workloads with reference syntax.
• Enforce full network isolation: land every resource inside its own VNet, expose only private endpoints, and tighten traffic with NSGs.
• Produce an audit-ready environment that maps clearly to SOC 2 controls, including policy definitions, activity logging and evidence collection procedures.
Deliverables will include the configuration (ARM/Bicep/Terraform templates or scripts if you prefer), a concise hand-off document and a short walkthrough call so I can keep everything compliant going forward. If this sounds like your wheelhouse, let’s talk timelines and get started.
Related categories:
Cloud Computing
Azure
Amazon Web Services
Windows Server
Cloud Security
DevOps
Data Protection
Terraform