Multi-CloudHow-To & HardeningRetrospectives

How to Classify and Monitor Customer Data Stores Across Clouds

By OnCloudSec Research Team · Published Oct 6, 2026 · 1 min read

Retrospective: this article looks back at events from February 2020, written in 2026 with the benefit of hindsight.

You can't protect customer data you can't find. Here is a practical approach to classifying and monitoring customer data stores across Azure, AWS and Microsoft 365.

Step 1: Define what counts as customer data

Agree on categories with legal and privacy teams: contact details, identifiers, payment data, health data, account credentials, behavioral data. Map each to a sensitivity level.

Step 2: Discover data stores

  • AWS: Amazon Macie automated sensitive data discovery for S3; inventory RDS, DynamoDB and other databases with tags.
  • Azure: Microsoft Purview Data Map can scan Azure storage, SQL and other sources; Defender for Cloud's sensitive data discovery (Defender CSPM) highlights sensitive resources in attack paths.
  • Microsoft 365: Purview sensitive information types and Content explorer.

Step 3: Tag and assign ownership

Apply consistent tags to cloud resources holding customer data: data-classification, data-owner, retention. Enforce tagging with Azure Policy and AWS tag policies.

Step 4: Apply controls by classification

For resources tagged as holding customer data:

  • Private network access only.
  • Encryption with managed keys.
  • Access restricted to named roles.
  • Diagnostic and access logging enabled.
  • Backup and retention rules.

Step 5: Monitor

  • Defender for Storage, Defender for SQL and GuardDuty S3 Protection for anomalous access.
  • Alerts on new resources containing sensitive data without required tags.

Step 6: Minimize

Review retention annually. Delete or anonymize data you no longer need.

Verify

Every resource holding customer data has an owner, a classification and the required controls — measured as a percentage in a monthly report.

classify customer data cloudMGM guest data2020

More on this story