Microsoft Certified: DevOps Engineer ExpertDevelop a security and compliance planHard

A global software company is building a multi-tenant SaaS application on Azure. They need to ensure strict isolation between tenants' data and resources. Furthermore, they must comply with data residency requirements, meaning customer data for specific regions must remain within those regions. Which Azure architectural pattern and service combination is most suitable for achieving both tenant isolation and data residency?

  1. ADeployment Stamps with dedicated resource groups and geo-redundant storage
  2. BSingle-tenant deployment model with Azure App Service
  3. CDeployment Stamps with dedicated resource groups per tenant and region-specific Azure services
  4. DMulti-tenant deployment model with Azure SQL Database elasticity pools
Show answer & explanation

Correct answer: C. Deployment Stamps with dedicated resource groups per tenant and region-specific Azure services

Deployment Stamps (also known as Scale Units or Deployment Units) are an architectural pattern where independent, identical deployments of the application are created for specific tenants or regions. Combining this with dedicated resource groups per tenant within each stamp ensures strong isolation. Using region-specific Azure services within each stamp directly addresses data residency requirements by deploying all tenant resources and data within the required geographical bounds.

Why the other options are wrong

  • A. Deployment Stamps with dedicated resource groups per tenant is good for isolation, but 'geo-redundant storage' (GRS) replicates data across regions, which violates data residency requirements if not managed carefully to only use locally redundant storage (LRS) or zone-redundant storage (ZRS) within the stamp's region.
  • B. A single-tenant deployment model is for one customer per deployment, which provides isolation but scales poorly for a multi-tenant SaaS and doesn't inherently address data residency without further regional duplication.
  • D. Multi-tenant models with shared resources like elasticity pools offer efficiency but inherently less isolation than dedicated resources. They don't directly enforce data residency without careful partitioning.

Deployment Stamps (Scale Units)

An architectural pattern where multiple independent, identical deployments of an application are created, often to serve different tenants, regions, or scale requirements, providing strong isolation and supporting data residency.

  • Provides strong tenant isolation.
  • Supports data residency by deploying instances in specific regions.
  • Scales horizontally by adding more stamps rather than scaling up a single deployment.

Memory trick: Deployment Stamps are like 'Separate Houses in Each Country' for tenants.

More Develop a security and compliance plan questions