You probably wouldn't furnish a house you're building with a state-of-the-art entertainment system without first installing doors and an alarm system. Similarly, it isn't advisable to put valuable applications and data used to run your business in the cloud without ensuring the proper foundational security and governance controls are in place.

Many organizations struggle with how they want their cloud home to look, often so anxious to move that proper planning is ignored. Whether adopting PaaS, IaaS, or SaaS, properly planned governance and security foundations are key to ensuring a protected and controlled environment.

Cloud home

Cloud home

Critical design areas

The foundational decisions that are hardest to change later: identity, network topology, management group hierarchy, and policy.

Key components

The building blocks every landing zone needs: management groups, identity, networking, policy, and a consistent naming/tagging strategy.

Cloud Adoption Framework (CAF)

Microsoft's Cloud Adoption Framework provides prescriptive guidance and reference architectures for exactly this kind of foundational planning.

Landing zone

A landing zone is the environment where you deploy and operate your applications — subscriptions, networking, identity, policy, and management tooling designed to scale as you onboard more teams.

Management groups

Management groups let you organize subscriptions hierarchically and apply policy and RBAC at scale, above the subscription level.

Policies

Automation

RBAC

Naming convention

Tagging

Network

Virtual machines

Extra tools