Azure Cloud Infrastructure
A landing zone as code you own: management groups, hub-spoke networking, identity with PIM, and a policy baseline that keeps production changes in the pipeline. Built in 4-8 weeks, documented to survive us leaving.
Azure CAF + CIS Azure Foundations
Terraform-first (Bicep supported)
Entra ID + PIM + managed identities
4-8 weeks for starter LZ
These are design rules of the delivery kit shown below, enforced by policy and CI, and the runbooks exist on disk before the first client call.
Azure estates rarely fail loudly. They accrue.
One subscription, everything inside it
The estate grew organically: production next to sandbox, IAM granted by hand, nobody sure what breaks if a resource group goes. A landing zone gives every workload a subscription with an owner, a network segment and a policy scope.
The audit asked who approved this change
DORA, NIS2 and ISO 27001 all want change control with evidence. When changes are portal clicks, the honest answer is a shrug. In the pipeline model, every production change is a reviewed pull request with the plan attached, and the auditor reads the log.
A bill nobody can explain
Costs without owner tags make every invoice an archaeology project. The baseline enforces cost-attribution dimensions by policy, so the monthly number splits by team on its own, and anomalies get a name attached the same day.
Azure by portal clicks
Hand-built infrastructure lives in one engineer's head and drifts every week. Everything here is Terraform in your repository: reviewable, repeatable, and still standing after that engineer changes jobs. Including us.
The pipeline is the change control.
Three views of the operating model: one change travelling from pull request through the policy gate to production, the monthly drift-and-cost review that keeps the estate honest, and the delivery kit folder by folder, Terraform included.
Four foundations, all in your tenant and your repo.
A landing zone, deployed and documented
Management groups, subscriptions, hub-spoke networking, identity. Typically 3-7 management groups and 5-15 subscriptions, sized to your estate at discovery, with an ADR for every decision that would be expensive to reverse.
Terraform in your org, with CI/CD
The module library lands in your GitHub organisation, state in your storage account, plan-and-apply workflows included. Contribution guide written so your team extends it without calling us.
Identity with no standing privilege
Entra ID foundation with PIM for every privileged role, break-glass accounts with a tested procedure, and pipelines authenticating through workload identity federation instead of secrets.
A policy baseline that produces evidence
CIS Azure Foundations mapped to Azure Policy initiatives, tagging and region rules with deny effects, Defender for Cloud reporting into a compliance matrix your auditor can actually use.
In scope
- Azure CAF landing zone (management groups + subscriptions)
- Hub-spoke or vWAN networking foundation
- IaC baseline (Terraform / Bicep) with shared module library
- Entra ID + PIM identity foundation
- Azure Policy + tagging + CIS baseline
- Runbook library for top 10 platform tasks
Deliberately out of scope
- Application migration to Azure (separate per-workload scope)
- On-prem AD modernization (case-by-case)
- Custom ISV deployment automation (separate scope)
- Cost optimization beyond landing-zone baseline (see FinOps & Cost Management)
Licences that can sit under Azure Cloud Infrastructure.
ITSailor sells Microsoft and selected marketplace licences through Pax8 at vendor list price. Our margin is the Pax8 wholesale discount; service work is quoted or packaged separately.
Microsoft
Microsoft Entra ID P2
€10.44 / user / month
Monthly commit
Microsoft
Microsoft Azure Plan
Usage-based, quoted
Pay-as-you-go consumption
Pay-as-you-go Azure consumption billed at Microsoft list price through Pax8 CSP, on one invoice. Scoped, governed and cost-reported alongside your landing zone; transferable to an Enterprise Agreement or direct billing via the Exit Kit.
Nord Security
NordLayer Business VPN (ZTNA)
Usage-based, quoted
Monthly commit
Usage-billed on Pax8 (no fixed rate card via API - the /pricing endpoint 404s). Per-user network-access platform: apps plus browser extension, ZTNA/SASE, central gateway and logs. Business-correct alternative to consumer VPNs (Surfshark/NordVPN). Sold quoted/usage-based.
Start with the landing zone. Keep us only if the reviews earn it.
Each tier carries its delivery arc inside it: discovery and ADRs first, build with a pilot workload next, then operate or a documented hand-off. The scope sheet gets signed during discovery.
Essential
The starter landing zone, built and handed over.
- Weeks 1-2: discovery, regulatory mapping, ADR set signed
- Weeks 3-6: landing zone + Terraform library deployed, pilot workload through it
- CAF starter topology: 2 management groups, 3-5 subscriptions
- Entra ID + PIM foundation, CIS policy + tagging baseline
- 10 platform runbooks + 30-day hand-off support window
Outcome
A governed Azure estate your own team operates, with the design decisions on paper.
Operate
The landing zone plus the platform team that keeps it honest.
- Everything in Essential
- Nightly drift scans; findings arrive as pull requests
- Monthly platform review: drift, policy compliance, cost by owner
- Quarterly Azure Policy + RBAC review with Defender tuning
- Named platform engineer, same-day incident triage
Outcome
The estate stays as designed, and the monthly review proves it with pipeline evidence.
Sovereign
Audit-grade change control for regulated, multi-region estates.
- Everything in Operate
- Multi-region topology (hub-spoke or vWAN)
- Audit-grade change records mapped to DORA / NIS2 / ISO 27001
- Weekly platform review with a dedicated cloud architect
- Exit kit + Terraform state hand-off procedure, rehearsed
Outcome
The platform passes its audit on pipeline logs, and leaving us is a documented procedure.
Honest answers to the questions buyers actually ask.
Do you support Bicep, Pulumi, CDK or Terraform?
+
Terraform is our default for cross-cloud portability. We support Bicep where the team is already invested, CDK or Pulumi where TypeScript / Python is the operational language. We pick what the team will actually maintain in 18 months.
Do we need a full CAF deployment, or can we start smaller?
+
Most clients start with a "Landing Zone Starter" - 2 management groups, 3 subscriptions, core networking + identity - and graduate to full CAF over 6-12 months. We size to your current scale.
Can we keep our existing subscriptions?
+
Yes. Brownfield onboarding is part of every engagement. We document the current state, plan the migration to landing-zone subscriptions, and execute in waves.
Can our team still use the portal?
+
For reading, dashboards and diagnostics: absolutely. Production writes are denied by policy, with a documented break-glass path for real emergencies (RUNBOOK-02). Sandbox subscriptions stay open for experiments, so the guardrails protect production without slowing anyone's learning down.
Who approves changes: you or us?
+
Your people. Reviewers on the repository and PIM approvers are named client roles from day one; we submit pull requests like everyone else. On Operate tiers we also review, but the approval authority never moves to our side.
What does the landing zone itself cost to run?
+
The management plane (management groups, policy, RBAC) costs nothing. Real run-rate comes from the hub: Azure Firewall, logging retention and gateways, and those are sized and priced in the design phase before anything is deployed. If a Firewall SKU is oversized for your estate, the design says so.
We already have resources in Azure. Greenfield only?
+
Brownfield is the normal case. Existing subscriptions are inventoried at discovery, imported into state or migrated in planned waves (RUNBOOK-04), and nothing is moved without its owner knowing the window.
What happens to the Terraform if we part ways?
+
Nothing: it was in your GitHub organisation and your state storage from the first commit. The exit kit adds the state hand-off procedure, access removal on our side, and the honest list of anything unfinished. That is the Sovereign Mastery rule, and it applies to every tier.
The landing zone is the floor. Build on it.
Cloud Infrastructure Modernization
The architecture narrative around this service, with the landing-zone blueprint explorable.
OpenAzure Sentinel
The SIEM that plugs into the Log Analytics foundation this landing zone lays down.
OpenCloud Licensing & Procurement
Azure consumption billed at list through Pax8, with the renewal calendar owned.
OpenWrite the subscription design down before the next resource group appears.
Half a day on the estate you have: subscriptions, identity, network boundary, policy intent and who is allowed to change what.