Azure foundations

Azure Landing Zone Consulting

Techrupt Digital designs and deploys Azure landing zones aligned to Microsoft's Cloud Adoption Framework. Management groups, policy, identity, networking and logging are delivered as infrastructure as code your team owns and can change safely.

Last updated

Proudly collaborated with

  • Aritzia
  • BC Cancer
  • MEC
  • Meridian University
  • Contracts 365
  • KCU
  • Sunrise
  • Transworld

Why it matters

Every workload inherits the foundation you build first

A landing zone decides where workloads live, who can change them, how they reach each other and what gets logged. Get it right and new projects start in days with security already in place. Get it wrong and every migration drags through the same approval fights. We build new landing zones and fix existing ones, and we're based in Metro Vancouver, working with organizations across Canada and the US.

What we deliver

Covering all eight design areas

Microsoft's Cloud Adoption Framework defines eight design areas for a landing zone. We work through each one with you and record the decisions, so the design outlives the project.

Design guide

Designing an Azure landing zone

The design areas, greenfield versus brownfield, requirements for BC regulated organizations, and keeping the platform maintainable.

The eight design areas

Microsoft's Cloud Adoption Framework breaks a landing zone into eight design areas. Each has decisions that are cheap to make early and expensive to change later:

  • Azure billing and Microsoft Entra tenant
  • Identity and access management
  • Resource organization
  • Network topology and connectivity
  • Security
  • Management
  • Governance
  • Platform automation and DevOps

We work through each area with your team and record the decisions and the reasons behind them, so the design survives staff changes and future audits.

Greenfield or brownfield

A greenfield landing zone starts clean, which makes it the easiest case. Most organizations aren't there. They have subscriptions created project by project, networks that grew organically and permissions nobody wants to touch.

For brownfield environments we don't start over. We deploy the target management group structure and policies alongside what exists, use policy in audit mode to measure the gap, then move subscriptions and fix findings in order of risk, without taking running workloads offline.

Landing zones for BC public sector and regulated organizations

Regulated organizations need the landing zone to prove compliance, not just support it. We restrict resource locations to Canada Central and Canada East with Azure Policy, set log retention to match your records obligations, and use Microsoft Defender for Cloud's regulatory compliance dashboard to track controls against standards such as CIS and NIST.

Azure also includes a built-in policy initiative for the Canadian federal Protected B profile, which many BC and Canadian public sector organizations use as a reference baseline. We document how the landing zone supports your privacy impact assessment under FIPPA, so the design and the paperwork stay in step.

Keeping it maintainable

A landing zone is a product, not a project. We deliver it as infrastructure as code in your repository, using Microsoft's landing zone accelerators and Azure Verified Modules, with pipelines that validate and deploy changes through pull requests.

That lets your team add subscriptions, change policies and adopt Microsoft's updates to the reference architecture safely, long after our engagement ends.

Common landing zone problems we fix

Most of the landing zones we review weren't designed badly. They were never designed at all, and grew one project at a time. The same problems come up again and again:

  • Everything in one or two subscriptions, so costs and access can't be separated
  • Owner or Contributor granted broadly and permanently
  • Azure Policy missing, or left in audit mode indefinitely
  • Flat networks with public IP addresses on workloads that don't need them
  • Logs not centralized, or not retained long enough for an investigation
  • Inconsistent naming and tagging, which makes cost allocation impossible

Each of these has a known fix, and none of them requires starting over. The order matters, though. We fix identity and access first, because it limits the damage anything else can do.

How we work

Let's figure out what you need

Every engagement starts with understanding your business. From there we plan, then deliver with senior Microsoft-certified consultants at every step.

  1. STEP 01

    Consultation

    You're the expert in your business. We learn your goals, constraints and current environment so we can recommend what will actually move the needle.

  2. STEP 02

    Gameplan

    You get a clear plan with scope, timeline and costs, built by senior specialists, so you know exactly what you're getting before work begins.

  3. STEP 03

    Implementation

    Our certified team delivers, documents and hands over, with measurable results and support after go-live.

FAQ

Azure landing zones, answered

What is an Azure landing zone?

An Azure landing zone is the pre-configured foundation of an Azure environment, covering subscriptions, identity, networking, security policy and monitoring, that workloads are deployed into. Microsoft defines it in the Cloud Adoption Framework across eight design areas. A good landing zone lets teams launch new workloads quickly while security and cost controls apply automatically.

Should we use hub-and-spoke or Virtual WAN?

Hub-and-spoke gives you more control and is often cheaper for a single region with a handful of spokes. Virtual WAN suits organizations with many branches, multiple regions or heavy site-to-site connectivity, because Microsoft manages the routing. We compare both for your requirements, and our article on hub-and-spoke versus Virtual WAN covers the trade-offs in detail.

Bicep or Terraform?

Both work well, and Microsoft maintains landing zone accelerators and Azure Verified Modules for each. Choose Bicep if your team is Azure-only and wants Microsoft-native tooling. Choose Terraform if you manage other clouds or services too, or already have Terraform skills. We deliver in whichever your team will maintain.

Can you fix a landing zone we already have?

Yes. Most of our landing zone work is brownfield. We assess what exists against the Cloud Adoption Framework, then fix the highest-risk gaps first, such as missing policy, flat networking or shared admin accounts, without disrupting running workloads.

How do we keep data in Canada?

We assign Azure Policy that only allows resources in Canadian regions, Canada Central and Canada East, at the management group level, so every subscription inherits it. Exceptions for global services are documented for your privacy and compliance review.

How long does a landing zone take?

A greenfield landing zone using Microsoft's accelerators can be designed and deployed relatively quickly. Brownfield work takes longer because existing workloads have to keep running while we fix the foundation underneath them. We commit to a timeline in the proposal once we've seen your environment.

What does a landing zone engagement cost?

Landing zone builds are fixed-price once scoped, so you know the cost before you start. The scope depends on how many subscriptions and networks are involved, your compliance requirements and whether it's greenfield or brownfield.

Do small environments need a landing zone?

Yes, just a smaller one. Even a handful of subscriptions benefits from management groups, baseline policy, central logging and sensible networking. Microsoft's accelerators can be scaled down, and starting with the right structure is far cheaper than retrofitting it once the environment grows.

Will a landing zone slow our developers down?

Done well, it does the opposite. With subscription vending, teams request a new subscription through a pull request or a form and get one that already has networking, policy, access and monitoring in place, instead of waiting on a ticket queue.

Insights

Latest Azure articles

All insights →

Next steps

Build the foundation once, properly

Book a free 30-minute call. We'll talk through your current Azure setup and whether a new landing zone or a targeted fix makes more sense.