Governance

Design Your Azure Management Group and Subscription Hierarchy

Design Your Azure Management Group and Subscription Hierarchy

Six months after the initial landing zone deployment, a new VP reorganizes the business units. Your management group tree — which you built to mirror the org chart — is now wrong. Every policy assignment, every RBAC scope, every cost report that referenced “BU-Finance” and …

Governance at Scale: Writing and Deploying Azure Policies with Terraform and Bicep

Governance at Scale: Writing and Deploying Azure Policies with Terraform and Bicep

The compliance report arrives on a Friday afternoon. You scan through it and stop on a finding: a Storage Account with public network access enabled, sitting in your production subscription, deployed three weeks ago. Someone bypassed the documented standard, the ARM deployment succeeded, and nobody …