Service Offerings

Explore tailored services designed to solve business challenges and support growth

Industries

Discover industry-focused expertise built to meet unique business needs

Partners

Meet our service partners who strengthen delivery and support client success

Meet our service partners who enhance our capabilities, strengthen service delivery, and help drive successful outcomes for our clients.

Learn how to modernize data foundations to enable trusted, scalable AI.

Global supply chain leader in apparel embarks on unified analytics strategy with Microsoft Fabric

See how a unified data strategy built faster insights and scaled analytics.

Products

Explore our digital products built to streamline work and drive growth every day

Partners

Meet our product partners who enhance our solutions and expand client value

AI-powered automated
 regression testing: Your
kickstart for 2026

Explore a better way to speed up testing and improve release quality.

Resources

Access blogs, case studies, events, and insights that support smarter decisions.

Latest Resources

CASE STUDY

HamiltonJet transforms regression testing on Infor CloudSuite with Fortest

NEWS

Fortude earns Microsoft Azure Infrastructure Solutions designation

Our People

Discover a culture where you can grow and shape what’s next

Everyone can grow at Fortude

We believe in creating a global workplace where everyone can grow. This is amplified by our teams, who say the best thing about Fortude is our culture, one that is brought to life by a diverse team that spans across continents.

Latest

Fortude builds momentum for women in tech with all-female Ignite 2.0 tech internship

Aug 22, 2025

Pioneering innovation and inculcating learning in the age of AI

Aug 01, 2024

About Us

Learn who we are, what we do, and the values that drive our growth

News & Events

Stay updated with Fortude news, events, stories, and company highlights.

Contact Us

Get in touch with our team to ask questions or start a conversation

Your nearest office- Sri Lanka

Fortude (Pvt) Ltd
146 Kynsey Road, Colombo 7, Sri Lanka

Email – talk-to-us@fortude.co
Phone – +94 11 453 1531

What defines us goes beyond what we do

Every day, we bring together diverse perspectives, strong leadership and responsible thinking to build a business that creates lasting value for our clients, people and communities.

Fortude disrupts ERP delivery with agentic AI across the Infor CloudSuite lifecycle

Office locations

Data & AI

Cloud migration security: What to get right before moving workloads to Azure

7 min read

July 31, 2026

Share

 
  • Identity, access, governance and compliance controls should be ready before migration.
  • Lift-and-shift can carry legacy weaknesses into Azure.
  • A secure landing zone provides repeatable guardrails for every workload.
  • Cloud migration security must continue through monitoring, reviews and optimization.

While many may assume moving a workload to Azure automatically makes it secure, this is far from the truth. Microsoft reported that identity-based attacks rose by 32% in the beginning of last year, while more than 97% of identity attacks were password-based. This is evidence that identity cannot be treated as a post-migration configuration task. 

Effective cloud migration security requires organizations to identify risks, assign responsibilities and implement baseline controls before data, applications or infrastructure leave the on-premises environment.

What changes when workloads move to Azure?

Cloud migration security operates through a shared responsibility model. Microsoft protects the underlying cloud infrastructure, while customers remain accountable for areas including data, identities, access and workload configuration.

The exact division depends on the service model. With Infrastructure as a Service (IaaS), such as Azure Virtual Machines, the customer retains more responsibility for operating systems, applications and network controls. Microsoft assumes more operational responsibility when organizations use managed Platform as a Service (PaaS) or Software as a Service (SaaS) offerings.

Microsoft’s migration guidance highlights shared responsibility, hybrid visibility and unified threat detection as core security considerations. Microsoft also recommends using cloud capabilities to strengthen detection and response rather than transferring on-premises practices unchanged.

Diagram of Azure’s shared responsibility model

Where do Azure migrations create security gaps?

  • Identity and privileged access: Dormant accounts, standing administrator privileges and weak authentication can become cloud attack paths.
  • Governance: Missing subscription structures, ownership rules, naming standards and Azure Policy assignments lead to inconsistent security controls, policy violations, unmanaged resources, and configuration drift.
  • Data protection: Unclassified data may be moved to the wrong region, storage tier or access model.
  • Compliance: Retention, audit logging, data residency and reporting requirements may change across Azure regions.
  • Legacy systems: Unsupported operating systems and tightly coupled applications can remain exposed within a hybrid estate.

What should a cloud migration security assessment examine?

A cloud migration security assessment should establish what is moving, what it depends on, what must protect it and who owns each control.

Assessment area

Questions to answer before migration

Workload inventory

Which applications, databases, APIs and servers are in scope?

 

Dependencies

What identities, integrations, ports and scheduled processes are required?

Data

What is sensitive, regulated or subject to residency requirements?

Identity

Are Multi-Factor Authentication (MFA), conditional access, and least-privilege roles defined?

Recovery

Are recovery time and recovery point objectives agreed on and tested?

Compliance

Which logging, retention and evidence requirements apply?

Ownership

Who approves access, remediates alerts and manages exceptions?

Two widely followed assessments are the Microsoft Cloud Adoption Security Assessment (CASA) and Zero Trust Assessment which help identify security weaknesses that could increase risk during or after migration. We recommend a broader assessment that provides additional benefits. The readiness assessment determines how individual workloads should move. It combines security-focused assessments with a comprehensive readiness review, which helps determine not only whether workloads are secure to migrate, but also how they should be migrated, governed and operated in Azure.

Which controls should be ready before migration?

Cloud migration security is strongest when minimum controls are built into the Azure environment before the first production workload arrives.

Control

Practical baseline

Identity

Microsoft Entra ID, MFA and Conditional Access

Privileged access

Azure RBAC, least privilege and time-bound administration

Governance

Management groups, subscriptions, Azure Policy, tags and ownership

Network

Segmentation, restricted public access and approved connectivity paths

Data

Encryption, key ownership, classification and retention policies

Monitoring

Central logging, alert ownership and incident-response procedures

Resilience

Azure backup, recovery testing and protected backup access

Posture management

Microsoft Defender for cloud recommendations and compliance tracking

Is lift-and-shift less secure than modernization?

Lift-and-shift is not automatically insecure, but it can transfer outdated configurations, excessive permissions and vulnerable software into Azure. Modernization creates opportunities to replace those weaknesses with managed services and cloud-native controls.

Approach

Main security consideration

Rehost

Existing vulnerabilities and operating-system responsibilities remain

Replatform

New managed services require updated access and configuration controls

Refactor

DevSecOps, API, container and code-security controls become critical

Retire

Data must be securely retained or deleted

Retain

Hybrid monitoring and policy consistency remain necessary

The best approach is workload-specific. A stable application may be safely rehosted when controls are strengthened first. A fragile or unsupported application may require remediation or modernization before migration. Fortude’s analysis of lift-and-shift Azure migration pitfalls examines the related governance, performance and operational risks.

How should security continue after a cutover?

Cloud migration security continues after go-live because permissions, configurations, resources and threats change continuously. Continuous monitoring through a Security Information and Event Management (SIEM) platform helps organizations maintain visibility across their Azure environment, detect suspicious activity, correlate security events and respond to emerging threats before they escalate.

Post-migration activities should include:

  • Reviewing privileged access and inactive identities
  • Monitoring configuration drift and exposed resources
  • Tracking Microsoft Defender for Cloud recommendations
  • Using Microsoft Sentinel to collect, analyze and correlate security events across cloud and hybrid environments
  • Investigating incidents and hunting for threats using Microsoft Sentinel workbooks, queries and threat intelligence capabilities
  • Testing backup restoration and incident-response procedures
  • Reviewing compliance evidence and policy exceptions
  • Updating workload architecture as risks and business needs change

Defender for cloud can assess posture, prioritize recommendations and track assigned compliance standards. Its risk model considers factors such as exposure, data sensitivity, lateral movement and exploitability. Microsoft Sentinel complements this by providing SIEM and security orchestration capabilities, enabling security teams to monitor, investigate and respond to threats across the Azure environment from a centralized platform. Security findings should still have named owners, remediation deadlines and exception processes.

When is an Azure cloud security partner worth considering?

External support is most valuable when an organization has regulated workloads, a complex hybrid estate, limited Azure expertise or unclear ownership across internal teams.

This is where a capable partner can step in to assess readiness before proposing migration tooling. The engagement should produce an actionable roadmap covering identity, landing-zone design, governance, compliance, workload sequencing and ongoing support.

Fortude supports this through Azure readiness workshops, security posture and compliance assessments, Azure well-architected reviews, Azure Landing Zone reviews, tenant governance and ongoing optimization. Fortude helps enterprises assess their Azure environment, establish practical security controls and create a roadmap for deployment and ongoing optimization. Schedule an Azure CAF Accelerated Review to identify readiness, governance and security gaps before your next migration wave.

FAQ

How should temporary access be managed during an Azure migration?

Temporary access should be time-bound, approved and removed immediately after the migration task is complete. Teams should avoid creating permanent administrator roles for short-term activities such as data transfer, testing or cutover. Privileged Identity Management, access reviews and documented expiry dates can help prevent temporary permissions from becoming long-term risks.

Third-party access, integrations and support processes should be assessed before migration. Organizations need to collaborate with the vendors and confirm what data can be accessed, how they authenticate, whether their permissions follow least privilege and how access will be revoked. Contractual responsibilities, incident notification requirements and data-processing obligations should also be reviewed.

The workload should not move into production until the risk is either remediated or formally accepted by the appropriate business and security owners. Teams may choose to delay the workload, apply compensating controls, redesign part of the architecture or retain it temporarily on-premises. Migration deadlines should not override defined security acceptance criteria.

CONTENTS

Receive the latest
Fortude Newsletter
updates.

Share

Related Blogs