# 7 decisions that make an Azure landing zone enterprise-ready

DevFeed: [7 decisions that make an Azure landing zone enterprise-ready](<https://devfeed.tech/articles/7-decisions-that-make-an-azure-landing-zone-enterprise-ready-57855.md>)

Original publisher: [Read original article](<https://www.infoworld.com/article/4224426/7-decisions-that-make-an-azure-landing-zone-enterprise-ready.html>)

Author: Sachin Suryawanshi

Published: 2026-09-22T09:00:00Z

Content type: article

Language: en

Sources: [InfoWorld](<https://devfeed.tech/sources/infoworld.md>)

Topics: [Azure](<https://devfeed.tech/topics/azure.md>), [cloud-infrastructure](<https://devfeed.tech/topics/cloud-infrastructure.md>), [Cloud](<https://devfeed.tech/topics/cloud.md>), [Security](<https://devfeed.tech/topics/security.md>), [Network](<https://devfeed.tech/topics/network.md>), [Monitoring](<https://devfeed.tech/topics/monitoring.md>), [observability](<https://devfeed.tech/topics/observability.md>), [Deployment](<https://devfeed.tech/topics/deployment.md>), [CI/CD](<https://devfeed.tech/topics/cicd.md>), [Security Information and Event Management (SIEM)](<https://devfeed.tech/topics/siem-security.md>), [GitHub](<https://devfeed.tech/topics/github.md>)

Tags: [architecture](<https://devfeed.tech/tags/architecture.md>), [azure](<https://devfeed.tech/tags/azure.md>), [ci-cd](<https://devfeed.tech/tags/ci-cd.md>), [cloud](<https://devfeed.tech/tags/cloud.md>), [cloud-computing](<https://devfeed.tech/tags/cloud-computing.md>), [cloud-computing-cloud-security-enterprise-architecture-iaas-microsoft-azure-security](<https://devfeed.tech/tags/cloud-computing-cloud-security-enterprise-architecture-iaas-microsoft-azure-security.md>), [cloud-security](<https://devfeed.tech/tags/cloud-security.md>), [configuration](<https://devfeed.tech/tags/configuration.md>), [contributor](<https://devfeed.tech/tags/contributor.md>), [deployment](<https://devfeed.tech/tags/deployment.md>), [engineering](<https://devfeed.tech/tags/engineering.md>), [enterprise](<https://devfeed.tech/tags/enterprise.md>), [enterprise-architecture](<https://devfeed.tech/tags/enterprise-architecture.md>), [firewalls](<https://devfeed.tech/tags/firewalls.md>), [github](<https://devfeed.tech/tags/github.md>), [iaas](<https://devfeed.tech/tags/iaas.md>), [microsoft-azure](<https://devfeed.tech/tags/microsoft-azure.md>), [monitoring](<https://devfeed.tech/tags/monitoring.md>), [network](<https://devfeed.tech/tags/network.md>), [observability](<https://devfeed.tech/tags/observability.md>), [security](<https://devfeed.tech/tags/security.md>), [security-operations](<https://devfeed.tech/tags/security-operations.md>)

## AI overview

An engineering practitioner explains seven decisions for making an Azure landing zone enterprise-ready. The article treats the landing zone as an operating model covering governance, security, networking, observability, deployment workflows, and application-team autonomy.

## Source excerpt

As a designer of enterprise-scale Azure landing zones, I've found that drawing a landing zone is fairly easy. However, building one that engineering teams can use effectively is far more challenging. When I started designing an enterprise Azure landing zone, the building blocks were familiar: management groups, subscriptions, virtual networks, policies, firewalls, monitoring and CI/CD. The difficult part was determining how they would interact without producing a platform that appeared secure on paper yet proved difficult to maintain. Microsoft's Cloud Adoption Framework provided an excellent starting point. However, a reference architecture can only go so far. Real-world environments have security standards, compliance requirements, deployment pipelines and application teams that need enough autonomy to build software without working around governance. My design incorporated two Azure regions in an active-active configuration. Production traffic was routed across both regions via Azure Front Door, with health probes used to identify unhealthy origins and remove them from rotation when necessary. I selected Azure Virtual WAN over a traditional hub-and-spoke network, integrated Palo Alto Networks Cloud NGFW into the networking design, used Datadog for observability and used a dedicated cloud SIEM for security operations. Lastly, I integrated GitHub larger runners with Azure VNets so deployment workflows could access private resources without exposing them publicly. The choices I made were not simply about enabling Azure services. They were about where control should reside, where teams require flexibility and how to make the secure option the easiest option. 1. Consider your landing zone as an operating model, not simply a network I wanted to prevent the landing-zone project from becoming solely a networking exercise. While networking is essential, a landing zone should also address other questions. Who can create resources? Where should workloads reside? How do poli