Turn Cloud Adoption Framework and Well-Architected guidance into a landing-zone design with clear identity, policy, networking, logging, and workload ownership boundaries.
Separate platform and workload responsibilities
Azure landing zones provide a scalable operating model for subscriptions, management groups, identity, connectivity, governance, and operations. Platform teams own shared foundations. Workload teams inherit guardrails and own controls inside their application boundary.
Design the hierarchy before the policies
Management groups should reflect policy and operating boundaries, not the organizational chart. Apply common controls high in the hierarchy and exceptions only where a documented requirement exists. Use subscriptions as isolation, billing, and quota boundaries where appropriate.
Combine CAF and Well-Architected guidance
The Cloud Adoption Framework helps organize cloud strategy, governance, and operations. The Well-Architected Framework helps evaluate workload design across pillars, including security. Use both: landing-zone controls establish the platform baseline, while workload reviews verify that each application uses it safely.
Build measurable guardrails
Guardrails should define an expected state and produce evidence. Examples include allowed regions, diagnostic settings, private access requirements, encryption, Defender plans, approved images, and required tags. Prefer policy-driven prevention or remediation for repeatable controls, with a reviewed exception process for legitimate deviations. Architecture decision: Centralize capabilities that benefit from consistency, such as identity, policy definitions, and security monitoring. Delegate workload decisions that require application context, while retaining evidence and escalation paths.