Securing 2M+ accounts & $15B+ in assets, protected & secure·B5 Secure™ — per data-element authorization for .NET platforms

Cloud & Data Platform Architecture

Cloud & Data Platform Architecture

Built for modern Azure. Governed by Fabric.

B5 Secure runs Never Trust on the current Microsoft stack — .NET 10 LTS on Azure Container Apps and AKS, identity in Microsoft Entra ID, keys in a FIPS 140-3 Level 3 Managed HSM. Every verified request and every authorization decision becomes governed evidence in Microsoft Fabric on OneLake.

.NET 10 LTSAzure Container AppsAKSMicrosoft Entra IDFIPS 140-3 L3 Managed HSMMicrosoft Fabric · OneLakeDefender for Cloud · Sentinel
Reference architecture

One request, from the edge to the evidence lake.

A request enters at the Azure edge, descends the five Never Trust layers inside a .NET 10 service, and — whether it is allowed or denied — leaves a signed record in the data platform. The same vault discipline, mapped onto the Microsoft cloud.

EdgeFront Door + WAF
Azure Front DoorApplication Gateway WAFOWASP Top 10 rulesDDoS Protectionhybrid TLS 1.3 (X25519 + ML-KEM)
IdentityMicrosoft Entra ID
managed identitiesworkload identity federationConditional AccessPIMpasswordless service-to-service
Compute.NET 10 on Container Apps / AKS
B1 XSS screeningB2 HMAC authB3 IP firewall + MFAB4 verification + suspensionB5 ADA — data-aware authz
SecretsKey Vault + Managed HSM
FIPS 140-3 Level 3single-tenant HSMcustomer-managed keyskey attestationPrivate Link
StateAzure SQL · Cosmos DB
TDE + customer-managed keysAlways EncryptedPrivate Endpointsrow-level isolation per tenant
EvidenceFabric Real-Time Intelligence → OneLake
EventstreamKQL databaseDelta ParquetData Activator alertsPurview-governed

Every layer fails closed. Every decision — allow or deny — is emitted as a signed event the platform can never lose track of.

On the current release train

No legacy assumptions. Today’s Azure.

B5 Secure targets the platforms Microsoft supports now — so your security framework never becomes the reason you can’t upgrade.

.NET 10 LTS & C# 14

Built and tested on the .NET 10 long-term-support runtime and ASP.NET Core 10 — supported by Microsoft into November 2028. The pipeline rides minimal APIs, EF Core 10 and the new cryptography APIs without shims.

Container Apps & AKS

Ship the protected service as a container to Azure Container Apps for serverless scale, or to AKS for full control. The pipeline runs identically in either; nothing about Never Trust depends on the host.

Microsoft Entra ID

Service-to-service calls authenticate with managed identities and workload identity federation — no secrets in config. Conditional Access and PIM gate the privileged paths that B5’s MFA layer steps up.

Key Vault & Managed HSM

HMAC signing keys and tenant secrets live in Azure Key Vault, or a single-tenant Managed HSM validated to FIPS 140-3 Level 3. Keys never leave the boundary; B5 calls them by reference, with attestation.

Front Door, WAF & Private Link

A global Front Door entry, a WAF tuned to the OWASP Top 10, and Private Link to every backing service keep traffic on Microsoft’s backbone and off the public internet before B1 ever runs.

Landing zones & policy

Deploys cleanly into Cloud Adoption Framework landing zones, with Azure Policy guardrails enforcing the secure defaults B5 assumes — so the platform stays compliant as it grows.

Azure Well-Architected

Security is a pillar, not a patch.

B5 Secure earns its place against all five pillars of the Azure Well-Architected Framework — the secure default is also the operable, performant one.

Pillar 01

Security

Verify explicitly, least privilege, assume breach — built into every request as a fail-closed pipeline rather than a review checklist.

Pillar 02

Reliability

Stateless services scale horizontally; the HSM runs active-active multi-region. A denied request is a normal, logged outcome, never an outage.

Pillar 03

Performance efficiency

Checks are ordered cheapest-first and short-circuit on the first failure, so the common path stays fast on .NET 10’s improved runtime.

Pillar 04

Operational excellence

Every exception to a secure default is an explicit, auditable attribute in source — reviewable in a pull request, enforced by policy.

Pillar 05

Cost optimization

Serverless Container Apps scale to zero; the evidence lake is one Delta Parquet copy in OneLake, not three duplicated stores.

+

Confidential computing

Run the most sensitive workloads on confidential VMs and containers — AMD SEV-SNP, Intel TDX — so data stays protected even in use.

The data platform

Every decision becomes governed evidence.

Never Trust insists on detection through logging. B5 Secure makes that a first-class data product: each authentication, MFA step-up, suspension and ADA permit decision is streamed through Fabric Real-Time Intelligence into a medallion lakehouse on OneLake — one open Delta Parquet copy, every engine reads it.

Microsoft Purview classifies and labels the stream automatically, so PII and financial records carry their sensitivity from ingestion to report. Data Activator turns anomalies — replay attempts, credential abuse, cross-tenant probing — into alerts the moment they appear.

Medallion · OneLake
IngestEventstream
signed B5 audit eventsno-code routing
BronzeRaw evidence
immutable, append-onlyDelta Parquet
SilverConformed
per-tenant, per-actionPurview-labeled
GoldAudit & risk marts
Power BI Direct Lakecompliance reporting
Detect & respond

Watched the way the vault is watched.

B5’s evidence stream feeds Microsoft’s security operations stack, so the framework that denies the request and the platform that hunts the attacker share one source of truth.

Defender for Cloud

Cloud security posture management and workload protection across the whole footprint, scoring the deployment against the controls B5 assumes are in place.

Microsoft Sentinel

The B5 audit lake lands in Sentinel — now in the unified Defender portal — where analytics rules and Security Copilot turn raw decisions into correlated incidents and hunts.

Supply-chain integrity

Dependencies pinned and hashed, an SBOM on every build, artifacts signed, GitHub Advanced Security in the pipeline — Never Trust extends to what you ship, not just what you run.

Mapped to Zero Trust. Never Trust is Microsoft’s Zero Trust model written for the people who own the endpoint — the same three principles (verify explicitly, least privilege, assume breach) across the identity, endpoint, app, data, infrastructure and network pillars.

Run Never Trust on the cloud you already use.

B5 Secure drops into your Azure landing zone, signs with your FIPS 140-3 keys, and turns every decision into governed Fabric evidence.

Scroll to Top