Azure cloud architecture consulting

Treating Azure like AWS Organizations produces the wrong identity and networking model. Management groups, Azure Policy and Hub-spoke VNets are the primitives this engagement uses.

Who this engagement is for

Teams whose production subscriptions sit under Azure management groups and who need landing-zone, identity or hub-spoke decisions written in Azure terms.

Information required to begin

  • Management group and subscription hierarchy
  • Entra ID tenant and role-assignment model
  • Hub-spoke or Virtual WAN topology
  • Azure Policy assignments that already exist

Engineering process

  1. Consultation scoped to Azure tenants and subscriptions
  2. Review against Microsoft Learn Cloud Adoption Framework and product docs
  3. Written findings using Azure names, not AWS translations

Deliverables

  • Current-state assessment in Azure terms
  • Target architecture and ADRs
  • Risk register

Provider-specific scope

  • Management groups, subscriptions, Azure Policy
  • Microsoft Entra ID, managed identities
  • Virtual Network, Hub-spoke, Virtual WAN, Private Link, Azure Firewall or NAT Gateway as used
  • Azure Cost Management + Billing

Limitations

  • We do not replace Microsoft support.
  • CAF is a framework, not a mandatory product. We say when a CAF pattern does not fit.

What is not included

  • Microsoft 365 tenant administration except where Entra ID is shared

Author

Written by Ankit Mehta. Methods used in this engagement are documented in the related guides below.

Related technical guides

Official sources