Microsoft Cybersecurity Architect (SC-100)Design a Zero Trust strategy and architectureHard

A software-as-a-service (SaaS) provider is building a multi-tenant application on Azure Kubernetes Service (AKS). Each tenant's data and application components must be logically isolated from other tenants to meet strict compliance and security requirements. The Zero Trust architecture mandates that communication between pods belonging to different tenants, even within the same AKS cluster, must be strictly controlled and denied by default. Access decisions must be based on the identity of the tenant and the specific application components.

  1. AUse a shared Kubernetes namespace for all tenants and rely on application-level authorization.
  2. BImplement network security groups (NSGs) at the Azure Virtual Network subnet level.
  3. CDeploy each tenant's application into a separate, dedicated AKS cluster.
  4. DUtilize network policies within AKS combined with identity-based micro-segmentation.
Show answer & explanation

Correct answer: D. Utilize network policies within AKS combined with identity-based micro-segmentation.

For multi-tenant AKS, deploying network policies is crucial for micro-segmentation, allowing granular control over pod-to-pod communication within the cluster. Combining this with identity-based segmentation (e.g., using AAD Pod Identity or workload identities to enforce policies based on tenant identity) ensures that access decisions are tied to the tenant and application components, fulfilling the 'denied by default' and strict isolation requirements.

Why the other options are wrong

  • A. Using a shared namespace with only application-level authorization is highly insecure and does not provide the required logical isolation or 'denied by default' network control at the infrastructure level.
  • B. NSGs operate at the subnet level and are too coarse-grained for pod-to-pod isolation within an AKS cluster; they cannot enforce policies based on tenant identity or specific application components.
  • C. Dedicated AKS clusters per tenant provide strong isolation but are cost-prohibitive and complex to manage for a large number of tenants, not ideal for a SaaS provider.

Identity-Based Micro-segmentation (AKS Multi-tenant)

Applying granular network and access policies within an AKS cluster, tied to the identity of specific tenants or workloads, to achieve logical isolation in multi-tenant environments.

  • Uses Kubernetes Network Policies to control pod-to-pod communication.
  • Integrates with identity systems (e.g., Azure AD) to define policy rules.
  • Enforces 'deny by default' for cross-tenant communication within the cluster.
  • Critical for compliance and security in multi-tenant SaaS architectures on AKS.

Memory trick: AKS Network Policies + Identity: Isolate Kube System Securely.

More Design a Zero Trust strategy and architecture questions