Who Is Responsible for Security in Azure IaaS?
A company deploys a web application on Azure virtual machines (VMs) in an Infrastructure-as-a-Service (IaaS) model. The company is responsible for managing the guest operating system, the application code, and the data stored on the VMs. According to the shared responsibility model, which of the following security responsibilities does Microsoft retain in this scenario?
Quick Answer
The answer is that Microsoft retains responsibility for protecting the physical datacenter and the underlying hardware. This is correct because in the shared responsibility model for IaaS, the cloud provider manages the physical layer up to the hypervisor, including servers, storage, networking, and physical security, while the customer manages everything above the hypervisor, such as the guest OS, application code, and data. On the SC-900 exam, this distinction tests your understanding of how responsibilities shift across service models; a common trap is assuming Microsoft handles the guest OS in IaaS, when in fact that is the customer’s job. A helpful memory tip is to think of IaaS as “Infrastructure as a Service”—Microsoft secures the infrastructure (the building and the racks), while you secure everything you install inside.
⚠ Common exam trap
A common mix-up: candidates confuse 'security of the cloud' (Microsoft's responsibility for the physical infrastructure) with 'security in the cloud' (the customer's responsibility for their own configurations, applications, and data), leading them to incorrectly assign guest OS or application-level tasks to Microsoft.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Protecting the physical datacenter and the underlying hardware
In an IaaS model, Microsoft retains responsibility for the physical datacenter, including physical security, the network infrastructure, and the underlying hardware (servers, storage, networking). This is because the customer manages the guest OS, application, and data, while Microsoft manages the physical layer up to the hypervisor. Option A correctly identifies this retained responsibility.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Protecting the physical datacenter and the underlying hardware
Why this is correct
Microsoft retains responsibility for the physical security of datacenters, servers, storage, and networking hardware in all cloud models, including IaaS.
- ✗
Configuring the operating system firewall on each VM
Why it's wrong here
Configuring the OS-level firewall is a customer responsibility, as the customer manages the guest OS.
When this WOULD be correct
In a Platform-as-a-Service (PaaS) scenario where the customer deploys a web app using Azure App Service, Microsoft manages the underlying OS and its firewall, so configuring the OS firewall would be Microsoft's responsibility.
- ✗
Installing and patching the application software
Why it's wrong here
The customer is responsible for managing and patching application software deployed on IaaS VMs.
When this WOULD be correct
In a Platform-as-a-Service (PaaS) model where the customer deploys a web app using Azure App Service, Microsoft manages the runtime environment, including installing and patching the application platform software (e.g., .NET framework).
- ✗
Managing user access to the application
Why it's wrong here
Identity and access management for the application is the customer's responsibility.
When this WOULD be correct
In a SaaS model, such as Microsoft 365, the provider manages the application, and the customer is responsible for managing user access to the application. A question asking about customer responsibilities in a SaaS deployment would make this option correct.
Option-by-option analysis
Why each answer is right or wrong
Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The SC-900 exam frequently reuses these exact scenarios with slightly different constraints.
✓Protecting the physical datacenter and the underlying hardwareCorrect answer▾
Why this is correct
Microsoft retains responsibility for the physical security of datacenters, servers, storage, and networking hardware in all cloud models, including IaaS.
✗Configuring the operating system firewall on each VMWrong answer — click to see why▾
Why this is wrong here
In the IaaS model, Microsoft is responsible for the physical infrastructure, not for guest OS configuration. Configuring the OS firewall is the customer's responsibility.
★ When this WOULD be the correct answer
In a Platform-as-a-Service (PaaS) scenario where the customer deploys a web app using Azure App Service, Microsoft manages the underlying OS and its firewall, so configuring the OS firewall would be Microsoft's responsibility.
Why candidates choose this
Candidates may confuse the shared responsibility model boundaries, thinking that since Microsoft provides the VM, they also manage its OS-level security settings like the firewall.
✗Installing and patching the application softwareWrong answer — click to see why▾
Why this is wrong here
In an IaaS model, the customer is responsible for managing the guest OS, application code, and data, including installing and patching application software. Microsoft does not manage the application layer.
★ When this WOULD be the correct answer
In a Platform-as-a-Service (PaaS) model where the customer deploys a web app using Azure App Service, Microsoft manages the runtime environment, including installing and patching the application platform software (e.g., .NET framework).
Why candidates choose this
Candidates may confuse IaaS with PaaS or SaaS, assuming Microsoft handles all software patching, or they may overestimate Microsoft's responsibility in the shared responsibility model.
✗Managing user access to the applicationWrong answer — click to see why▾
Why this is wrong here
In an IaaS model, Microsoft retains responsibility for the physical infrastructure, not for managing user access to applications. User access management is the customer's responsibility.
★ When this WOULD be the correct answer
In a SaaS model, such as Microsoft 365, the provider manages the application, and the customer is responsible for managing user access to the application. A question asking about customer responsibilities in a SaaS deployment would make this option correct.
Why candidates choose this
Candidates may confuse shared responsibility boundaries, thinking that since Microsoft provides the platform, they also manage access control, but in IaaS, access management is entirely the customer's duty.
Analysis generated from the official SC-900blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”
Go deeper
Related to this question
Learn chapter
Core Security Concepts
Key term
Shared responsibility
Shared responsibility is a cloud security model where the cloud provider and the customer each own distinct parts of security and compliance duties.
Key term
Security
Security in IT is the practice of protecting systems, networks, and data from unauthorized access, damage, or theft.
About these practice questions
This SC-900 question is part of Courseiva's 1,250-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on SC-900
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. A company hosts a line-of-business application on an Azure virtual machine. The IT team is responsible for configuring the operating system, installing security updates, and managing the application code. An auditor asks who is responsible for the physical security of the data center where the virtual machine runs. According to the shared responsibility model for cloud services, who is responsible?
hard- A.The customer
- ✓ B.Microsoft
- C.Both the customer and Microsoft equally
- D.Neither – physical security is no longer needed in the cloud
Why B: Under the shared responsibility model, Microsoft is responsible for the physical security of its Azure data centers, including access controls, surveillance, and environmental safeguards. The customer is responsible for securing the virtual machine's operating system, applications, and data, but not the physical infrastructure. Therefore, Microsoft retains responsibility for physical security even when the customer manages the guest OS and application.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.