Zero Trust Compliance Model
Complete inventory of 86 security controls across 9 domains. Shows what the Composer automates and what requires manual action to achieve full Zero Trust posture.
Understanding Automation Levels
Deployed automatically when you run the Bicep deployment (az deployment sub create). No manual action needed. Clients get this security posture out of the box.
Code exists in the Bicep templates but requires elevated Azure RBAC roles (Owner, User Access Administrator, Resource Policy Contributor). Enable by setting the corresponding parameter to true once permissions are granted.
Requires authoring agent manifests, evaluation configs, or process documentation. The kit provides schemas, templates, and tooling — but content must be customized per deployment.
Actions that cannot be automated via IaC: tenant-level configurations, license purchases (PTU, Entra P2), third-party processes (red teaming), or organizational decisions.