This chapter covers security and governance as cloud computing benefits — how the cloud supports protecting resources and enforcing organizational policy. AZ-900 tests this under objective 1.5, and it connects closely to the Shared Responsibility Model covered earlier.
Jump to a section
A simple way to picture Security and Governance in the Cloud
Security is like the locks on a building's doors — the mechanisms that actually keep unauthorized people out. Governance is like the policy deciding who gets a key in the first place, under what conditions, and how that's tracked and audited over time. A building can have strong locks (security) but a poorly managed key policy (governance) — say, keys handed out freely with no record of who has one — and still end up compromised. Cloud security and governance work the same way: security is the technical protection itself, while governance is the set of policies and processes that decide how that protection is applied, managed, and monitored across an organization.
Security in the cloud
Cloud providers invest heavily in securing their infrastructure — physical data center security, network protections, and built-in security features for the services they offer. Per the Shared Responsibility Model, the customer remains responsible for configuring and using those features correctly, and for securing what they build on top of the platform.
Governance in the cloud
Governance refers to the policies, processes, and tools an organization uses to manage and control how its cloud resources are used — ensuring resources comply with organizational standards, regulatory requirements, and cost expectations. Azure provides governance tools (covered in more depth in later chapters, like Azure Policy and resource locks) that help enforce these rules automatically rather than relying purely on manual oversight.
Why cloud can improve both
Because cloud platforms centralize infrastructure and offer built-in tools for access control, monitoring, and policy enforcement, organizations often gain more consistent security and governance capability than they could easily build and maintain entirely on their own — though realizing this benefit still requires the organization to actively configure and use those tools.
The tradeoff
Centralizing infrastructure with a cloud provider also means trusting that provider's security practices for the parts of the stack they manage — which is why understanding the Shared Responsibility Model matters when evaluating what a customer still needs to actively manage themselves.
Understand what the provider secures
The cloud provider secures the physical infrastructure and, depending on the service model, some or all of the underlying platform — but not the customer's own data, identities, or application-level configuration.
Apply governance policies
Organizations use governance tools to define and enforce rules about how resources can be created, configured, and used — helping maintain consistency and compliance across potentially many resources and teams.
Monitor for compliance
Ongoing monitoring helps confirm that resources continue to comply with organizational policy over time, rather than assuming a one-time setup remains correct indefinitely.
Combine security and governance
Strong security features are most effective when paired with governance processes that ensure they're actually configured and used correctly and consistently across the organization.
An organization uses Azure's built-in identity and access management features to control who can access specific resources — a security concern — while also using governance tools to enforce a policy that all resources must be tagged with a department and cost center for tracking purposes — a governance concern.
A common real-world gap: an organization has strong security tools available but hasn't configured governance policies to ensure those tools are actually used consistently across every team, leading to some resources being well-protected and others being overlooked — illustrating why security capability alone isn't enough without governance to ensure it's applied consistently.
Objective 1.5 expects a general understanding of how cloud computing supports security and governance, connecting back to the Shared Responsibility Model.
A common wrong answer is assuming the cloud provider's security investment means the customer has no security responsibilities — per the Shared Responsibility Model, the customer always retains responsibility for their own data and access management. Another common trap is treating "security" and "governance" as interchangeable — security is the technical protection itself, governance is the policy and process layer that decides how that protection is applied and enforced.
Stable terms: security, governance, Shared Responsibility Model. This chapter connects directly to the shared-responsibility chapter — expect the exam to test both together.
Memory trick: security = the technical protection. Governance = the policies and processes that decide how that protection is applied and enforced consistently.
Cloud providers invest heavily in security, but per the Shared Responsibility Model, the customer always retains responsibility for their own data and access.
Governance refers to the policies and processes an organization uses to manage and control how cloud resources are used.
Security is the technical protection itself; governance is the layer that ensures that protection is applied consistently.
Both work best together — strong security tools are most effective when paired with governance processes ensuring consistent use.
These come up on the exam all the time. Here's how to tell them apart.
Security
The technical protections themselves
Examples: identity and access management, network protections
Answers: 'How is this resource protected?'
Governance
The policies and processes controlling resource use
Examples: tagging policies, resource restrictions, compliance monitoring
Answers: 'How do we ensure protection is applied consistently?'
Mistake
Using a cloud provider means the customer has no security responsibilities.
Correct
Per the Shared Responsibility Model, the customer always retains responsibility for their own data, identities, and access management, regardless of provider.
Mistake
Security and governance are the same thing.
Correct
Security refers to the technical protections themselves; governance refers to the policies and processes that determine how those protections are applied and enforced across an organization.
Mistake
Having security tools available automatically means an organization is secure.
Correct
Tools need to be actively configured, applied consistently, and monitored — governance processes are what ensure that happens, not just the tools' existence.
Security refers to the technical protections in place — things like access controls and network protections. Governance refers to the policies and processes an organization uses to ensure those protections, and overall resource use, comply with organizational standards consistently. They work together but aren't the same thing.
No. Azure secures the underlying infrastructure and offers built-in security features, but per the Shared Responsibility Model, the customer is always responsible for their own data, identity management, and correctly configuring the security features available to them.
Security tools only help if they're consistently configured and applied. Governance processes — policies, monitoring, and enforcement — are what ensure security tools are actually used correctly across an entire organization, not just in isolated cases.
You've just covered Security and Governance in the Cloud — now see how well it sticks with free AZ-900 practice questions. Full explanations included, no account needed.
Done with this chapter?