Azure · 10 min read
Seven Azure landing zone decisions to make before migration
The governance, identity, connectivity, and operations choices that are expensive to revisit later.
The executive view
An Azure landing zone is a governed platform for workload delivery, not merely a subscription template. Teams should settle the operating decisions that affect every workload before migration waves make those decisions expensive to reverse.
A practical decision framework
01
Tenant and subscription organization
Define management groups, subscription purposes, ownership boundaries, and the process used to create and retire environments.
02
Identity and privileged access
Separate daily administration from privileged workflows and define emergency access, workload identities, and access reviews.
03
Network topology and name resolution
Choose connectivity patterns, inspection points, private access, DNS ownership, and hybrid routing with application dependencies in view.
04
Policy, operations, and automation
Agree on enforceable guardrails, logging, cost ownership, deployment methods, and exception processes before onboarding workloads.
The best landing zone is one the platform team can operate repeatedly while workload teams can understand and consume safely.
What to do next
- Document the eight Azure landing-zone design areas.
- Assign a decision owner and acceptance evidence to each area.
- Pilot subscription vending and workload onboarding before scaling migration.
Authoritative sources
- What is an Azure landing zone? — Microsoft Learn
- Azure landing zone design principles — Microsoft Learn
Related Retia Global guidance
Retia Global publishes practical guidance across cloud, cybersecurity, networking, resilience, and responsible AI.
This article provides general guidance. Validate recommendations against your workloads, regulatory obligations, vendor documentation, and operating capacity.