Azure cloud architecture consulting
Treating Azure like AWS Organizations produces the wrong identity and networking model. Management groups, Azure Policy and Hub-spoke VNets are the primitives this engagement uses.
Who this engagement is for
Teams whose production subscriptions sit under Azure management groups and who need landing-zone, identity or hub-spoke decisions written in Azure terms.
Information required to begin
- Management group and subscription hierarchy
- Entra ID tenant and role-assignment model
- Hub-spoke or Virtual WAN topology
- Azure Policy assignments that already exist
Engineering process
- Consultation scoped to Azure tenants and subscriptions
- Review against Microsoft Learn Cloud Adoption Framework and product docs
- Written findings using Azure names, not AWS translations
Deliverables
- Current-state assessment in Azure terms
- Target architecture and ADRs
- Risk register
Provider-specific scope
- Management groups, subscriptions, Azure Policy
- Microsoft Entra ID, managed identities
- Virtual Network, Hub-spoke, Virtual WAN, Private Link, Azure Firewall or NAT Gateway as used
- Azure Cost Management + Billing
Limitations
- We do not replace Microsoft support.
- CAF is a framework, not a mandatory product. We say when a CAF pattern does not fit.
What is not included
- Microsoft 365 tenant administration except where Entra ID is shared
Author
Written by Ankit Mehta. Methods used in this engagement are documented in the related guides below.