Summary
In this module, you learned to restrict environment creation and sharing at the tenant level, preventing uncontrolled sprawl and accidental data exposure. You configured environment-level protections including IP firewall, token replay prevention, and audit logging to create defense-in-depth for sensitive environments. And you implemented Entra ID security group governance to control precisely who can access each environment, with automated provisioning and deprovisioning tied to group membership.
Zava's admin team faced unauthorized access from departed contractors, unrestricted sharing that exposed payment data, and session tokens replayed from unauthorized networks. This module equipped you to address those risks with a layered security approach spanning tenant, environment, and identity controls.
These security controls complement your governance foundation (environments and data policies from Path 1) and set the stage for the next layer: configuring the Dataverse security model to control what authorized users can do with data once inside an environment.