Microsoft 365 FundamentalsDescribe core Microsoft 365 services and conceptsMedium
A Microsoft 365 administrator is preparing for a potential disaster recovery scenario. They need to understand the shared responsibility model for Microsoft 365 services to correctly allocate responsibilities between the organization and Microsoft. Which of the following is a responsibility of Microsoft in this model?
- AAccount and access management
- BData classification and sensitivity labeling
- CDevice and application management
- DPhysical security of the data centers
Show answer & explanationAnswer & explanation
Correct answer: D. Physical security of the data centers
In the shared responsibility model, Microsoft is responsible for the 'security of the cloud,' which includes the physical security of the data centers, the underlying infrastructure, and the global network. The customer is responsible for 'security in the cloud,' such as data classification, device management, and identity management.
Why the other options are wrong
- A. Account and access management (identity) is a shared responsibility, but the configuration and enforcement are primarily customer responsibilities.
- B. Data classification and sensitivity labeling are responsibilities of the customer (security in the cloud).
- C. Device and application management are responsibilities of the customer (security in the cloud).
Shared Responsibility Model
A framework outlining security responsibilities between a cloud provider (Microsoft) and the customer.
- Microsoft: 'Security of the cloud' (physical infrastructure, network, host OS)
- Customer: 'Security in the cloud' (data, identities, devices, applications)
- Responsibilities vary by cloud service model (IaaS, PaaS, SaaS)
- For SaaS (Microsoft 365), Microsoft manages more, but customer still owns data and access.
Memory trick: Microsoft secures the 'cloud itself', customer secures 'within the cloud'.