How does shared responsibility shift between IaaS and SaaS?

Tests your understanding of security ownership across cloud stacks. Strong answer: in IaaS you own OS, apps, and network controls; in SaaS you only own data, identities, endpoints, and accounts while the provider manages the rest.
What's really being asked
This question tests whether you understand the division of security and management responsibilities between a cloud provider and the customer across different service models. Interviewers want to see that you know which stack layers shift to the provider as you move from IaaS to SaaS, and which responsibilities you always retain regardless of deployment type.
The full answer
First, define the shared responsibility model as a framework that allocates security and management duties based on the service model. Second, explain that in IaaS the customer manages everything above the physical host including the operating system, applications, network controls, and configurations, while the provider secures the physical datacenter, network, and hosts. Third, explain that in SaaS the provider manages the entire stack including applications, network controls, operating system, and infrastructure, while the customer retains responsibility for data classification and protection, identity and access management, endpoint security, and account governance. Fourth, note that some areas like applications and network controls can be shared in PaaS and SaaS, meaning the provider manages the platform but the customer still configures application-level security and access controls.
The mistakes people make
A major red flag is claiming that using cloud services means the provider secures your data or endpoints. Another is saying that SaaS requires no security effort from the customer, which ignores the fact that data, identities, accounts, and endpoints remain customer responsibilities. Confusing who owns the operating system layer is also common, specifically forgetting that IaaS leaves the OS with the customer.
What usually comes next
Interviewers may ask how this model applies to a hybrid or multi-cloud environment, or how responsibilities change with PaaS offerings like Azure App Service or Azure SQL Database. They might also probe how you enforce your retained responsibilities in practice, such as through encryption, RBAC, MFA, conditional access policies, or data loss prevention.
A concrete example
If you deploy a web application on Azure Virtual Machines under IaaS, you are responsible for patching the guest OS, configuring the firewall and virtual network, securing the application code, and managing data encryption. If you switch to a SaaS product like Microsoft 365 for the same workload, Microsoft patches the OS, manages the network, and runs the application, but you still must classify sensitive data, enforce MFA on user accounts, manage access policies, and ensure employee laptops are compliant and secure.
Interview question
When moving from IaaS to SaaS, which responsibility shifts to the cloud provider?
- a.Classifying and protecting sensitive data
- b.Securing employee endpoints and devices
- c.Patching the guest operating systemCorrect
- d.Enforcing multi-factor authentication on user accounts
Why? this is the answer
In IaaS the customer manages the guest OS, but in SaaS the provider assumes that duty. Many beginners incorrectly think the provider also secures their data in SaaS, yet data classification and protection always remain the customer's responsibility.
Just read this? Test yourself on what you have been reading.
Read the original → learn.microsoft.com
You just looked this up. Could you explain it out loud?
That is the part interviews actually test. Tezvyn takes questions like this one and gives you what the interviewer is really checking, the answer that lands, and the mistake that ends the conversation, in the four minutes before your next meeting.
The iPhone app is on the way
We are building it. Until it lands, nothing here is held back from you: every interview card, your saved cards, streaks and the job board all work in Safari, plus hundreds of free practice quizzes of thirty questions each. Sign in and it all carries over to the app the day it arrives.
Want it as an icon? Tap Share at the bottom of Safari, then Add to Home Screen. It opens full screen and the cards you have read stay available offline.
We are hiring for this. Open roles that interview on cloud — each one lists the topics its interview covers.
See open roles