Azure breaches almost always start at Entra ID (formerly Azure AD), not at a VM or storage account. Get identity right and the rest gets dramatically easier:
- Conditional Access — require compliant device + phishing-resistant MFA for any privileged role.
- Privileged Identity Management (PIM) — make Global Admin and Owner roles just-in-time, with approval and time-bound activation.
- Workload identities — replace client secrets with Federated Identity Credentials (OIDC) wherever possible.
- Break-glass accounts — at least two, with FIDO2 keys stored physically, monitored aggressively.