Azure Landing Zones

Organization and governance design considerations

An Azure subscription serves as a boundary for Azure policy assignments

Deployment settings

OptionChoiceDescription
Azure cloud environmentAzure cloud
Directorygrinntec
RegionWest Europe

Azure core setup

OptionChoiceDescription
Resource prefix (Root ID)grinntec
Platform subscription optionsdedicated
Customer Usage Selection OptionsEnabled

Platform management, security, and governance

OptionChoiceDescription
Deploy Log Analytics workspace and enable monitoring for your platform and resourcesyes
Log Analytics Data Retention (days)30
Management subscriptiongrinntec-management
Agent HealthyesHelps you understand which monitoring agents are unresponsive and submitting operational data
Change TrackingnoTracks changes in virtual machines
Update ManagementnoManage operating system updates for your Windows and Linux virtual machines
VM InsightsnoMonitors the performance and health of your virtual machines and virtual machine scale sets
Service MapnoAutomatically discovers application components on Windows and Linux systems and maps the communication between services
SQL AssessmentnoAssess the risk and health of your server environments
SQL VulnerabilitynoProvides visibility into your security state
SQL Advanced Threat ProtectionnoDetects anomalous activities indicating unusual and potentially harmful attempts to access or exploit databases.
Microsoft Defender for CloudnoCloud Security Posture Management (CSPM) and Cloud Workload Protection Platform (CWPP)
Microsoft SentinelnoCloud-native solution that provides SIEM and SOAR

Network topology and connectivity

OptionChoiceDescription
Networking topologyHub and spoke with Azure Firewall
Connectivity subscriptiongrinntec-connectivity
Address space10.100.0.0/16
RegionWest Europe
DDoS Network Protection
Private DNS Zones for Azure PaaS Services
VPN Gateway
ExpressRoute Gateway
Azure Firewall

Identity

OptionChoiceDescription

References

Azure Agent Health solution

Change tracking and inventory overview

Update Management overview

Overview of VM Insights

Service Map solution

SQL Assessment

SQL Vulnerability assessment

SQL Advanced Threat Protection

Microsoft Defender for Cloud

Azure Sentinel

Last modified July 21, 2024: update (e2ae86c)