IBM's Azure Foundry Enterprise Kit

Zero Trust Compliance Model

Complete inventory of 86 security controls across 9 domains. Shows what the Composer automates and what requires manual action to achieve full Zero Trust posture.

48Automated by Composer
56%
10Conditional (Permissions)
12%
14Documentation / Config
16%
14Manual Steps Required
16%
How to read this page: Controls marked Automated by Composer are deployed automatically when you run the Bicep deployment. Conditional controls are coded in the templates but require elevated Azure permissions (Owner/User Access Administrator). Documentation/Configitems need agent manifest configuration or process documentation. Manual items require external actions (Entra admin, PTU purchase, red-teaming).
Showing 86 of 86 controls

Understanding Automation Levels

Automated by Composer

Deployed automatically when you run the Bicep deployment (az deployment sub create). No manual action needed. Clients get this security posture out of the box.

Conditional (Elevated Permissions)

Code exists in the Bicep templates but requires elevated Azure RBAC roles (Owner, User Access Administrator, Resource Policy Contributor). Enable by setting the corresponding parameter to true once permissions are granted.

Documentation / Configuration

Requires authoring agent manifests, evaluation configs, or process documentation. The kit provides schemas, templates, and tooling — but content must be customized per deployment.

Manual Steps Required

Actions that cannot be automated via IaC: tenant-level configurations, license purchases (PTU, Entra P2), third-party processes (red teaming), or organizational decisions.