- Do we need a landing zone, or just a subscription?
- If one team is running one workload and nothing has to be governed across subscriptions, a subscription and good habits will hold for a while. A landing zone earns its cost when a second team arrives, when policy has to be provable rather than promised, or when somebody has to answer for what is deployed where. The honest test is whether anyone could currently tell you what exists across the tenant.
- Should we use Microsoft's accelerator or build our own?
- Start from the accelerator. It deploys the recommended patterns as infrastructure as code, and the parts of it you disagree with are visible and changeable. A custom build is justified when a real constraint makes the accelerator wrong - a regulated network boundary, an existing tenant that cannot be reorganised - and not because it feels more tailored.
- We already have Azure. Is it too late?
- No, and this is the usual starting point. An existing estate is retrofitted rather than replaced: the hierarchy is designed around what is already deployed, policy is introduced in audit mode before it enforces anything, and subscriptions move in a planned order. It is slower than starting clean and entirely normal.
- Is there something we can look at first?
- Yes. DBHQ publishes a working application landing zone as an open reference build - golden-path Terraform on Microsoft's own Azure AI Landing Zone Verified Module, for a private-networked workload, with the expensive resources off by default. It is there to be read and judged before anyone is engaged.
- What access do you need?
- For an assessment, read-only across the tenant is enough - the management group hierarchy, subscriptions, policy assignments and network topology. Anything that changes the estate is agreed separately and in writing.
- What does it cost?
- A fixed fee for an agreed scope, quoted after a short call. Where the estate is undocumented enough that the scope cannot be bounded honestly, the investigation is quoted on its own first rather than hidden inside a build price.
An independent view of Microsoft's Azure landing zone guidance. DBHQ is not affiliated with, endorsed by, or certified by Microsoft. Microsoft's architecture, terminology and accelerators change - check the current Cloud Adoption Framework documentation before committing to a design.