Azure landing zones — Microsoft's opinion on getting started
Azure's landing zone framework is the most mature of the three majors. We explain the management group hierarchy, how to use it, and which parts of the official docs to ignore.
- · Management groups, subscriptions, resource groups — Azure's 4-tier hierarchy
- · Azure Policy + Blueprints for guard-rails at scale
- · Cost Management + Budgets — alerts that actually fire
- · Entra ID (formerly AAD): conditional access, MFA, PIM
- · Hub-and-spoke virtual network pattern