Protego field desk
Infrastructure Security Architecture / 25-30% of exam

L12.SaaS, PaaS, IaaS, Containers & AI Services

Course outlineLesson 12 of 18

Specify workload security baselines according to the shared-responsibility model, with dedicated controls for web apps, containers, orchestration, IoT workloads, and Azure AI services.

Start with the service model

Shared responsibility changes across SaaS, PaaS, and IaaS. The provider takes on more platform operation as the service becomes more managed, but the customer still owns data, identities, access, configuration, and appropriate monitoring.

Define workload baselines

For IaaS, include image governance, patching, endpoint protection, disk encryption, network controls, and privileged administration. For PaaS and web workloads, focus on identity, private access, TLS, application controls, configuration, secrets, logging, and data protection. SaaS designs emphasize tenant configuration, identity, data governance, integrations, and audit.

Secure containers and orchestration

Protect the software supply chain, registry, images, runtime, secrets, admission policy, service identities, network paths, and orchestration control plane. Use minimal images, scan dependencies, sign artifacts, restrict privileged containers, and separate workloads by risk.

Evaluate Azure AI services

Apply managed identity, network isolation where required, approved model and data use, content and prompt protections, logging, rate limits, output handling, and responsible AI governance. Agent tool access needs its own authorization boundary. Decision rule: Select controls based on what the customer can configure and what business impact remains, not on an assumption that a managed service is automatically secure.

Exam Focus Points
  • Customer responsibility always includes data, identity, access, and configuration
  • Workload baselines differ across SaaS, PaaS, and IaaS
  • Container security spans source, image, registry, admission, runtime, and control plane
  • Azure AI security includes identity, network, data, model, output, and tool controls
Knowledge Check

1. Which responsibility remains with the customer when moving from IaaS to SaaS?