6.1 A secure foundation6.1.1 Defense in depth6.2 Shared responsibility model6.2.1 On premises6.2.2 IaaS6.2.3 PaaS6.2.4 SaaS6.2.5 Compliance and data classification6.2.6 Using cloud-enabled security6.3 The zero-trust approach and Entra ID6.4 Microsoft Defender for Cloud6.4.1 Security recommendations6.4.2 Secure Score6.4.3 Security alerts6.5 Multifactor authentication6.5.1 Passwordless6.6 Managing users with Entra ID6.6.1 Understanding tenants, subscriptions, users, and more6.6.2 Creating service principals for application access to Azure resources6.6.3 Managed identity6.7 Role-based access control6.7.1 Security principal6.7.2 Role definition6.7.3 Scope6.8 Azure Key Vault6.8.1 Creating a Key Vault6.8.2 Adding and retrieving a secret