Azure Security Services & SOC 2 Readiness for a Growing SaaS Platform

About The Client
The client is a fast-developing SaaS provider whose production environment runs on Microsoft Azure. As the business expanded, it required enhanced security measures, better operational visibility, and a more systematic compliance mechanism. They reached out to Bloom Consulting Services to implement Azure security services to securely strengthen their cloud environment in preparation for a SOC 2 examination while not impacting operations.
Project Objective
The motive of this engagement was to improve the client’s Azure security posture and build the processes and documentation needed to prepare for SOC 2 readiness. The main objectives were:
- Enhancing security in the expanding Azure environment.
- Strengthening identity, privileged access, and least privileged controls.
- Creating centralized security surveillance and threat visibility.
- Validating high-availability controls, backup, recovery, encryption, and patching.
- Establishing Business Continuity and Disaster Recovery critical processes.
- Development of detailed audit evidence to conform to SOC 2 Trust Service.
Project Details
Bloom delivered end-to-end Azure security services around security assessment, identity governance, monitoring, infrastructure protection, backup validation, disaster recovery, and compliance preparation.
The engagement began with an Azure security audit to evaluate the current environment, determine security gaps, and prioritize remediation. With Azure security consulting, Bloom worked side-by-side with the client’s infrastructure team to enhance controls, document processes, and validate security controls across production workloads.
Important Steps
- Conducted an Azure security audit, including infrastructure, identity, network, data protection, monitoring, and operational controls.
- Using Microsoft Entra ID and Azure RBAC, we optimized RBAC, privileged access, MFA, and least-privilege policies.
- Centralized monitoring with Microsoft Sentinel, Azure Monitor, and Log Analytics.
- Implemented Azure Firewall, Network Security Groups, and Azure Policy to enhance network security.
- Validated backup and restore, encryption, patch management, and high availability settings.
- Developed Business Continuity and Disaster Recovery strategy including RTO/RPO objectives, recovery runbooks and testing.
- Created technical documentation and audit evidence to support the external SOC 2 assessment.
Technology Highlights
- Microsoft Azure
- Microsoft Sentinel
- Azure Monitor & Log Analytics
- Microsoft Entra ID (Azure AD)
- Azure RBAC & Azure Policy
- Azure Firewall & Network Security Groups
- Azure Backup & Azure Key Vault
- Azure PostgreSQL
- Azure Update Manager
- KQL
Engagement Model
In the engagement, Bloom collaborated with the client’s infrastructure and security teams to deliver Azure security consulting customized to a fast-growing SaaS environment. The engagement consisted of security assessment, control implementation, monitoring, recovery validation, and compliance documentation while assuring availability of production workloads.
Applying this structured approach, Bloom identified security vulnerabilities, increased operational controls, and assisted the client in creating processes and documentation to support continuous SOC 2 preparedness for compliance.
Business Value Delivered by Bloom
- Enhanced cloud governance and security measures throughout the Azure environment.
- Provided sustained controls and enhanced awareness of security incidents.
- Reduced operational risk through proven backup, recovery, and high-availability solutions.
- Documented Business Continuity and Disaster Recovery procedures for critical services.
- Better audit preparedness with well-organized documentation and SOC 2 evidence.
- Assisted the client with the external SOC 2 assessment process.
Results and Measurable Outcomes
The engagement enabled the client to have a more secure, robust, and audit-ready Azure environment. Integrating Azure cloud security services with the governance and compliance processes, Bloom assisted in developing security practices that went beyond the initial assessment.
The client was in a better position to get enhanced resilience in its operations, better visibility of threats, and a structured basis for how to sustain SOC 2 readiness as its SaaS platform continues to expand. The engagement highlighted how targeted Azure security services assist SaaS organizations in increasing security without compromising business continuity.




