Azure B2C and Security

Shim Kwan 281 Reputation points
2022-05-20T01:59:39.043+00:00

Hi,

Microsoft has a lot of amazing products and services in their Security Portfolio - just look at the Cyber Security Reference Architecture: https://learn.microsoft.com/en-us/security/cybersecurity-reference-architecture/mcra

With the right license, an Azure Tenant can make use of most, if not all, of these Security technologies.

But what about a B2C Tenant, that, based on our understanding is a 'light weight' version of a proper Azure Tenant?

How does one improve the Security Posture of a B2C tenant?
Could we deploy and run any of the Threat Protection products/services across it? (e.g. Defender for Cloud Apps, Defender for Cloud, Defender for Identity, etc etc).
Could we deploy any of the MS Purview Suite in a B2C tenant?
What about DDOS Protection and Identity Protection and Azure Firewall and this and that....the list goes on...
Could we connect MS Sentinel to a B2C tenant and get some SIEM/SOAR stuff going?

Basically, we'd like to know which of the many MS Security Products/Service could we run on our B2C Tenant to improve its Security Posture?

Thank you,
SK

Microsoft Defender for Cloud
Microsoft Defender for Cloud
An Azure service that provides threat protection for workloads running in Azure, on-premises, and in other clouds. Previously known as Azure Security Center and Azure Defender.
1,191 questions
Microsoft Configuration Manager
Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
974 questions
Microsoft Entra External ID
Microsoft Entra External ID
A modern identity solution for securing access to customer, citizen and partner-facing apps and services. It is the converged platform of Azure AD External Identities B2B and B2C. Replaces Azure Active Directory External Identities.
2,633 questions
Microsoft Entra ID
Microsoft Entra ID
A Microsoft Entra identity service that provides identity management and access control capabilities. Replaces Azure Active Directory.
19,432 questions
0 comments No comments
{count} votes

1 answer

Sort by: Most helpful
  1. 2022-05-31T18:08:33.593+00:00

    Hello @Shim Kwan , Azure AD B2C is a Customer Identity Management System optimized to store millions of user accounts and handle billions of authentication requests per day. Thanks to being built on the same technology that powers Azure AD it shares common security features such as Identity Protection and Conditional Access, MFA, the Zero Trust Security Model, and more.

    Please take a look to the following and subsequent security guidelines for more information for How to Improve the Security of a B2C tenant:

    Currently, Microsoft Defender for Cloud and MS Purview Suite are not available for Azure AD B2C..

    Let us know if this answer was helpful to you or if you need additional assistance. If it was helpful, please remember to accept it so that others in the community with similar questions can more easily find a solution.

    0 comments No comments