12 | Zero-trust solution baseline

Global Security & Governance:两条入口、三层工作负载、一套控制面

Web / mobile API 经 Front Door 与 WAF;设备消息直接进入 IoT Hub / DPS。身份、密钥、防护、观测和数据生命周期通过虚线控制面覆盖应用、设备、AI 与数据层。
CHANNELS & DEVICESAPPLICATION & DEVICE SERVICES区域化工作负载AI & DATA最小权限 + 生命周期TRUST OUTCOMESWeb / mobile APIdevice messagingConsumer web / mobilecustomer identity · TLSglobal API entrySwitchBot device fleetdevice certificate · trusted updatelocal-first / event-level uploadFront Door + WAFWeb / API onlyTLS · WAF · regional routingRegional APIsmanaged identityprivate endpoints where neededIoT Hub / DPSdevice identity · messagingallocation · twin · commandsDevice operationsupdate · monitorfleet risk signalsAI servicesmodel / prompt / tool traceevaluation + safetyData servicesclassification · retentionregion · encryptionPrivate accessnetwork boundariesservice allowlistsOptional confidentialspecific sensitive workloadsSKU / region / perf reviewCross-cutting security control planeEntra ID · Key Vault · Defender for Cloud / IoT · Azure Monitor · policy-as-code · audit / deletion workflowsGlobal service trustconsistent identityregional controlsConsumer privacylocal-first · minimal datatransparent lifecycleEnterprise readinessaudit evidencesecurity review inputs数据 / 事件 / API 流控制 / 策略 / 治理SwitchBot / edgeMicrosoft Azure业务结果
边界:Front Door 仅保护 Web / API;设备消息不经过 Front Door。Defender for IoT 仅面向适配的 B2B / OT / Enterprise IoT 网络。
Business outcome用一致安全基线支持全球扩展、企业采购审查与消费者信任。
Azure roleFront Door / WAF、Entra、Key Vault、Defender for Cloud、Monitor 与数据策略形成控制面;机密计算仅按需评估。