How to Classify and Monitor Customer Data Stores Across Clouds
Retrospective: this article looks back at events from February 2020, written in 2026 with the benefit of hindsight.
You can't protect customer data you can't find. Here is a practical approach to classifying and monitoring customer data stores across Azure, AWS and Microsoft 365.
Step 1: Define what counts as customer data
Agree on categories with legal and privacy teams: contact details, identifiers, payment data, health data, account credentials, behavioral data. Map each to a sensitivity level.
Step 2: Discover data stores
- AWS: Amazon Macie automated sensitive data discovery for S3; inventory RDS, DynamoDB and other databases with tags.
- Azure: Microsoft Purview Data Map can scan Azure storage, SQL and other sources; Defender for Cloud's sensitive data discovery (Defender CSPM) highlights sensitive resources in attack paths.
- Microsoft 365: Purview sensitive information types and Content explorer.
Step 3: Tag and assign ownership
Apply consistent tags to cloud resources holding customer data: data-classification, data-owner, retention. Enforce tagging with Azure Policy and AWS tag policies.
Step 4: Apply controls by classification
For resources tagged as holding customer data:
- Private network access only.
- Encryption with managed keys.
- Access restricted to named roles.
- Diagnostic and access logging enabled.
- Backup and retention rules.
Step 5: Monitor
- Defender for Storage, Defender for SQL and GuardDuty S3 Protection for anomalous access.
- Alerts on new resources containing sensitive data without required tags.
Step 6: Minimize
Review retention annually. Delete or anonymize data you no longer need.
Verify
Every resource holding customer data has an owner, a classification and the required controls — measured as a percentage in a monthly report.
- MGM Resorts Guest Data Leak (Feb 2020): 10 Million Records From a Cloud Server Incident Teardowns
- Detecting Cloud Server Data Exposure: Sentinel and GuardDuty Detections Detection & Response
- CIO Brief: Customer Data Leaks and Reputational Damage CIO Briefings