Mycelium 365 — Managed IT, Microsoft 365 and Azure across Australia, New Zealand and the United States
    Cloud fundamentals

    Shared Responsibility Model

    The shared responsibility model defines the split of security and operational duties between a cloud provider and its customer. The provider secures the underlying platform; the customer remains responsible for their data, identities, access configuration, application settings and device security, with the boundary shifting by service type.

    What Shared Responsibility Model means in practice

    Every cloud provider publishes a version of this model, and every provider is asked about it after an incident. The principle is straightforward: the provider is responsible for the security of the cloud, and the customer is responsible for security in the cloud. The complication is that the boundary moves depending on whether the service is infrastructure, platform or software.

    With infrastructure as a service — Azure virtual machines, for example — the provider handles physical facilities, hardware and the hypervisor, while the customer handles the guest operating system, patching, network configuration, applications, identity and data. With platform services the provider takes on the operating system and runtime, leaving configuration, access and data with the customer. With software as a service such as Microsoft 365, the provider runs almost the whole stack, but identities, access policy, sharing configuration, retention and the data itself remain the customer's responsibility.

    Three things are always the customer's, regardless of service model: the data, the identities and their access rights, and the endpoints used to reach the service. Those three are also where the overwhelming majority of real incidents occur, which is why the model matters practically rather than academically.

    The most expensive misunderstandings we encounter are assuming the provider backs up customer data, assuming default configuration is secure configuration, and assuming that because the provider holds certifications the customer's deployment inherits compliance. Certification of the platform reduces the assessment burden; it does not cover how the customer configured it.

    The useful exercise is to write the split down for each significant service, name the internal or provider owner for each line, and reconcile it against the managed services contract. Gaps show up quickly, and they are almost always in patching, backup, log retention and identity governance.

    How we help with this

    Related terms

    Back to the full glossary

    Ready to simplify and secure your technology?

    Book a free, no-obligation Discovery Call to talk through your Microsoft 365, Azure, security, or support needs — no sales pitch, just a straight conversation.

    We respond to every enquiry within 4 business hours. Monday to Friday, 7am–7pm AEST.