Built for modern Azure. Governed by Fabric.
B5 Secure runs Never Trust on the current Microsoft stack — .NET 10 LTS on Azure Container Apps and AKS, identity in Microsoft Entra ID, keys in a FIPS 140-3 Level 3 Managed HSM. Every verified request and every authorization decision becomes governed evidence in Microsoft Fabric on OneLake.
One request, from the edge to the evidence lake.
A request enters at the Azure edge, descends the five Never Trust layers inside a .NET 10 service, and — whether it is allowed or denied — leaves a signed record in the data platform. The same vault discipline, mapped onto the Microsoft cloud.
Every layer fails closed. Every decision — allow or deny — is emitted as a signed event the platform can never lose track of.
No legacy assumptions. Today’s Azure.
B5 Secure targets the platforms Microsoft supports now — so your security framework never becomes the reason you can’t upgrade.
.NET 10 LTS & C# 14
Built and tested on the .NET 10 long-term-support runtime and ASP.NET Core 10 — supported by Microsoft into November 2028. The pipeline rides minimal APIs, EF Core 10 and the new cryptography APIs without shims.
Container Apps & AKS
Ship the protected service as a container to Azure Container Apps for serverless scale, or to AKS for full control. The pipeline runs identically in either; nothing about Never Trust depends on the host.
Microsoft Entra ID
Service-to-service calls authenticate with managed identities and workload identity federation — no secrets in config. Conditional Access and PIM gate the privileged paths that B5’s MFA layer steps up.
Key Vault & Managed HSM
HMAC signing keys and tenant secrets live in Azure Key Vault, or a single-tenant Managed HSM validated to FIPS 140-3 Level 3. Keys never leave the boundary; B5 calls them by reference, with attestation.
Front Door, WAF & Private Link
A global Front Door entry, a WAF tuned to the OWASP Top 10, and Private Link to every backing service keep traffic on Microsoft’s backbone and off the public internet before B1 ever runs.
Landing zones & policy
Deploys cleanly into Cloud Adoption Framework landing zones, with Azure Policy guardrails enforcing the secure defaults B5 assumes — so the platform stays compliant as it grows.
Security is a pillar, not a patch.
B5 Secure earns its place against all five pillars of the Azure Well-Architected Framework — the secure default is also the operable, performant one.
Security
Verify explicitly, least privilege, assume breach — built into every request as a fail-closed pipeline rather than a review checklist.
Reliability
Stateless services scale horizontally; the HSM runs active-active multi-region. A denied request is a normal, logged outcome, never an outage.
Performance efficiency
Checks are ordered cheapest-first and short-circuit on the first failure, so the common path stays fast on .NET 10’s improved runtime.
Operational excellence
Every exception to a secure default is an explicit, auditable attribute in source — reviewable in a pull request, enforced by policy.
Cost optimization
Serverless Container Apps scale to zero; the evidence lake is one Delta Parquet copy in OneLake, not three duplicated stores.
Confidential computing
Run the most sensitive workloads on confidential VMs and containers — AMD SEV-SNP, Intel TDX — so data stays protected even in use.
Every decision becomes governed evidence.
Never Trust insists on detection through logging. B5 Secure makes that a first-class data product: each authentication, MFA step-up, suspension and ADA permit decision is streamed through Fabric Real-Time Intelligence into a medallion lakehouse on OneLake — one open Delta Parquet copy, every engine reads it.
Microsoft Purview classifies and labels the stream automatically, so PII and financial records carry their sensitivity from ingestion to report. Data Activator turns anomalies — replay attempts, credential abuse, cross-tenant probing — into alerts the moment they appear.
Watched the way the vault is watched.
B5’s evidence stream feeds Microsoft’s security operations stack, so the framework that denies the request and the platform that hunts the attacker share one source of truth.
Defender for Cloud
Cloud security posture management and workload protection across the whole footprint, scoring the deployment against the controls B5 assumes are in place.
Microsoft Sentinel
The B5 audit lake lands in Sentinel — now in the unified Defender portal — where analytics rules and Security Copilot turn raw decisions into correlated incidents and hunts.
Supply-chain integrity
Dependencies pinned and hashed, an SBOM on every build, artifacts signed, GitHub Advanced Security in the pipeline — Never Trust extends to what you ship, not just what you run.
Mapped to Zero Trust. Never Trust is Microsoft’s Zero Trust model written for the people who own the endpoint — the same three principles (verify explicitly, least privilege, assume breach) across the identity, endpoint, app, data, infrastructure and network pillars.
Run Never Trust on the cloud you already use.
B5 Secure drops into your Azure landing zone, signs with your FIPS 140-3 keys, and turns every decision into governed Fabric evidence.