Azure Well-Architected Review

All 59 of Microsoft's Well-Architected checks, scored and evidenced against your Azure estate, then put in fix order. Read-only, independent, and done by the engineer who then builds the fixes.

Every Azure estate drifts

Drift is rarely one bad decision. It is a hundred sensible ones, taken under deadline by people who have since moved on: a database with no zone redundancy, a subscription nobody owns, a secret in a config file, a spend line that quietly doubled. Nothing is urgent, so nothing gets fixed, and the bill for not knowing arrives in one go.

Microsoft's Well-Architected Framework is the standard for judging whether a cloud workload is sound. This review applies it to your estate in full and hands you the fix list in priority order.

Microsoft's framework, in full

Five pillars, 59 checklist recommendations. This review scores every one of them.

  • REReliability10
  • SESecurity12
  • COCost Optimization14
  • OEOperational Excellence11
  • PEPerformance Efficiency12
  • Total59

Reliability

Resilience to malfunction, and recovery to a fully functioning state after failure.

Two sturdy interlocked rings, blue and turquoise, holding firm over the line they bear on

Design principles

  • Design for business requirements
  • Design for resilience
  • Design for recovery
  • Design for operations
  • Keep it simple

Design review checklist · all 10, scored

  • RE:01Focus your workload design on simplicity and efficiency
  • RE:02Identify and rate user and system flows
  • RE:03Use failure mode analysis (FMA) to identify potential failures
  • RE:04Define reliability and recovery targets
  • RE:05Add redundancy at different levels, especially for critical flows
  • RE:06Implement a timely and reliable scaling strategy
  • RE:07Strengthen resiliency with self-preservation and self-healing measures
  • RE:08Test for resiliency and availability using chaos engineering
  • RE:09Implement structured, tested and documented disaster recovery (DR) plans
  • RE:10Continuously measure and track system health

Security

Protecting the confidentiality, integrity and availability of the workload and its data.

A closed chain link forming the shackle of an abstract padlock, sealed shut

Design principles

  • Plan your security readiness
  • Design to protect confidentiality
  • Design to protect integrity
  • Design to protect availability
  • Sustain and evolve your security posture

Design review checklist · all 12, scored

  • SE:01Establish a security baseline aligned to compliance requirements and standards
  • SE:02Align a secure development lifecycle (SDL) throughout the software development lifecycle
  • SE:03Classify and consistently apply sensitivity and information-type labels
  • SE:04Create intentional segmentation and perimeters
  • SE:05Implement strict, conditional and auditable identity and access management (IAM)
  • SE:06Isolate, filter and control network traffic across ingress and egress flows
  • SE:07Encrypt data using modern, industry-standard methods
  • SE:08Harden all workload components
  • SE:09Protect application secrets
  • SE:10Implement a holistic monitoring strategy with modern threat detection
  • SE:11Establish a comprehensive testing regimen
  • SE:12Define and test effective incident response procedures

Cost Optimization

The highest return per unit of spend - cost treated as a first-class design constraint.

A balanced beam with a stack of small blue tokens level against one larger turquoise token

Design principles

  • Develop cost-management discipline
  • Design with a cost-efficiency mindset
  • Design for usage optimization
  • Design for rate optimization
  • Monitor and optimize over time

Design review checklist · all 14, scored

  • CO:01Create a culture of financial responsibility
  • CO:02Create and maintain a cost model
  • CO:03Collect and review cost data
  • CO:04Set spending guardrails
  • CO:05Get the best rates from providers
  • CO:06Align usage to billing increments
  • CO:07Optimize component costs
  • CO:08Optimize environment costs
  • CO:09Optimize flow costs
  • CO:10Optimize data costs
  • CO:11Optimize code costs
  • CO:12Optimize scaling costs
  • CO:13Optimize personnel time
  • CO:14Consolidate resources and responsibility

Operational Excellence

DevOps culture, standardised process, observability, and safe, repeatable deployment.

Three chain links meshed in a row like a well-run production line, checks passing above each

Design principles

  • Embrace DevOps culture
  • Establish development standards
  • Evolve operations with observability
  • Automate for efficiency
  • Adopt safe deployment practices

Design review checklist · all 11, scored

  • OE:01Define standard practices to develop and operate the workload
  • OE:02Use standardization for routine, ad-hoc and emergency operations
  • OE:03Formalize processes across the full software development lifecycle
  • OE:04Enhance software development and quality assurance
  • OE:05Use a standardized infrastructure as code (IaC) approach
  • OE:06Build a workload supply chain with automated pipelines
  • OE:07Design a monitoring stack
  • OE:08Establish a clear, structured incident management process
  • OE:09Enhance the quality of your workload through testing
  • OE:10Design automation to be reliable, secure and maintainable
  • OE:11Clearly define safe deployment practices

Performance Efficiency

Meeting performance targets efficiently as demand and the system evolve.

A single chain link leaning forward in motion with speed lines trailing it

Design principles

  • Negotiate realistic performance targets
  • Design to meet capacity requirements
  • Achieve and sustain performance
  • Optimize for long-term improvement

Design review checklist · all 12, scored

  • PE:01Define performance targets
  • PE:02Conduct capacity planning
  • PE:03Select the right services
  • PE:04Establish consistent performance measurement
  • PE:05Optimize scaling and partitioning
  • PE:06Optimize performance by testing in a production-like environment
  • PE:07Optimize code and infrastructure
  • PE:08Optimize data usage
  • PE:09Prioritize the performance of critical flows
  • PE:10Optimize operational tasks
  • PE:11Respond to live performance issues
  • PE:12Continuously optimize performance

How the review runs

  1. Scope

    The workload, the subscriptions, the critical flows, and the reliability and performance targets the business needs.

  2. Baseline

    A read-only collection from your estate: resource inventory, Azure Advisor signal and Defender secure score.

  3. Assess

    All 59 checks judged against your estate - met, partial, gap or not applicable - with the evidence for each.

  4. Score

    A maturity score per pillar, weighted by how serious the gaps are. Tradeoffs you made on purpose are recorded as decisions.

  5. Readout

    The findings and the prioritised roadmap, walked through with your team.

Two to three weeks, kickoff to readout · read-only access, nothing changed

What you get

  • A score against all 59 checks, pillar by pillar, with the evidence for each finding
  • Every gap rated for severity and for the effort to fix it
  • Tradeoff notes - where you traded one pillar for another on purpose, recorded and justified
  • A remediation roadmap in priority order, costed and buildable
  • A baseline milestone, so a later review can show whether the score moved

Why a review, not a scan

The framework is public and anyone can read the 59 recommendations. What you pay for is a senior engineer applying them to your estate, then fixing what they find.

Judgement a scan cannot have
at least 40 of the 59
What a scan can read
at most 19 - configuration and telemetry

The reviewer builds

The engineer who finds the gap closes it. You get Terraform and pull requests, not recommendations for someone else to interpret. The roadmap is costed, buildable, and flows into a fixed-price sprint.

All 59 scored, because we built the tooling to

Most reviews sample: the pillars they know best, the subscriptions that matter most, then extrapolate. We look at all of it, because our tooling makes looking cheap. The judging is not automated, and will not be.

Judgement a scan cannot have

About two-thirds of the checklist cannot be read off a machine: whether you have done failure-mode analysis, whether your data is classified, whether your segmentation was deliberate, whether your recovery targets match what the business can carry.

Your tradeoffs recorded as decisions

Microsoft's framework says plainly that tightening one pillar costs another. A scan marks it wrong. We record why you chose it, and whether it still holds.

Evidence, severity and effort on every finding

Each gap is rated for what it costs you against what it costs to fix, so you can sequence the work and hand it to a team.

Independent

No licences to resell, no migration to sell, no partner funding behind the findings. A cloud vendor assesses you free because the assessment serves the sale that follows it.

Twenty-six years building where failure was expensive - defence, banking, insurance, energy, commodities, healthcare and identity.

We build our own tools. Here is one, free

An open tool that scans your Azure estate and scores the five pillars from the platform's own signals. Deterministic, read-only, no sign-up, and nothing leaves your tenant. It runs in about a minute and shows roughly where you stand.

A machine sees configuration and telemetry. The judgement is what the review adds.

Get the free Well-Architected taster →

Questions, answered

What access do you need?
Read-only. The review works from resource inventory, configuration and the platform's own signals - Azure Advisor and Defender. Nothing in your live environment changes.
Isn't the Well-Architected Review free from Microsoft?
Microsoft's assessment is a free questionnaire: you grade your own homework. It is a good tool, and this review uses the same framework. The difference is that a senior engineer does the assessing, evidences every finding against your real resources, and then builds the fixes.
How is this different from a free vendor assessment?
A cloud vendor or reseller funds the assessment because they then sell you the migration, the managed service or the licences. The findings serve that sale. This review has no product behind it and no licences to resell.
What does it cost?
A fixed fee, never open-ended, scoped to the size of your estate and quoted after a short call. Commission the remediation and the fee comes off it.
What if we don't go ahead with the fixes?
The review, the scores and the roadmap are yours, and useful to any engineer. You are not obliged to use us for the remediation.
How long does it take?
Two to three weeks from kickoff to readout, depending on the size of the estate.

An independent review conducted against the Microsoft Azure Well-Architected Framework. DBHQ is not affiliated with, endorsed by, or certified by Microsoft.

Fifteen minutes will tell you if this fits

Bring the problem - the stalled pilot, the systems that do not talk, the manual process eating your team. You will get a straight answer on whether it is sprint-shaped, roughly what it would cost, and when it could be running.

I reply within 24 hours