<?xml version="1.0" encoding="utf-8" standalone="yes"?><urlset xmlns="http://www.sitemaps.org/schemas/sitemap/0.9" xmlns:image="http://www.google.com/schemas/sitemap-image/1.1"><url><loc>https://larryjameshenry.com/posts/azure-landing-zone-guide/</loc><lastmod>2026-04-02T00:00:00+00:00</lastmod><image:image><image:loc>https://larryjameshenry.com/images/featured.jpg</image:loc><image:title>Enterprise Azure Landing Zone: The Complete Guide</image:title><image:caption>Build a production-grade Azure Landing Zone from scratch. Covers all 8 CAF design areas with Terraform and Bicep AVM code examples.</image:caption></image:image><image:image><image:loc>https://larryjameshenry.com/posts/azure-landing-zone-guide/images/featured.jpg</image:loc><image:title>images/featured.jpg</image:title></image:image></url><url><loc>https://larryjameshenry.com/posts/azure-management-group-design/</loc><lastmod>2026-04-03T00:00:00+00:00</lastmod><image:image><image:loc>https://larryjameshenry.com/images/featured.jpg</image:loc><image:title>Design Your Azure Management Group and Subscription Hierarchy</image:title><image:caption>Design and deploy a production Azure management group hierarchy with Terraform and Bicep AVM. Covers CAF topology, subscription strategy, and naming.</image:caption></image:image><image:image><image:loc>https://larryjameshenry.com/posts/azure-management-group-design/images/featured.jpg</image:loc><image:title>images/featured.jpg</image:title></image:image></url><url><loc>https://larryjameshenry.com/posts/azure-hub-spoke-networking/</loc><lastmod>2026-04-06T00:00:00+00:00</lastmod><image:image><image:loc>https://larryjameshenry.com/images/featured.jpg</image:loc><image:title>Azure Landing Zone Hub-and-Spoke: Firewall, Bastion, DNS</image:title><image:caption>Build a production hub-and-spoke network for Azure landing zones. Covers Azure Firewall, Bastion, Private DNS Zones, and VNet peering with Terraform and Bicep.</image:caption></image:image><image:image><image:loc>https://larryjameshenry.com/posts/azure-hub-spoke-networking/images/featured.jpg</image:loc><image:title>images/featured.jpg</image:title></image:image></url><url><loc>https://larryjameshenry.com/posts/azure-identity-access-architecture/</loc><lastmod>2026-04-07T00:00:00+00:00</lastmod><image:image><image:loc>https://larryjameshenry.com/images/featured.jpg</image:loc><image:title>Azure Landing Zone Identity: Entra ID, RBAC, and PIM</image:title><image:caption>Design the identity layer of an Azure landing zone. Covers Entra ID vs Azure RBAC, MG-scoped role assignments, PIM, and OIDC for pipelines.</image:caption></image:image><image:image><image:loc>https://larryjameshenry.com/posts/azure-identity-access-architecture/images/featured.jpg</image:loc><image:title>images/featured.jpg</image:title></image:image></url><url><loc>https://larryjameshenry.com/posts/azure-policy-governance-scale/</loc><lastmod>2026-04-08T00:00:00+00:00</lastmod><image:image><image:loc>https://larryjameshenry.com/images/featured.jpg</image:loc><image:title>Azure Policy as Code: Governance with Terraform and Bicep</image:title><image:caption>Deploy Azure Policy definitions and assignments as code using Terraform and Bicep. Covers compliance benchmarks, DINE effects, and exemptions.</image:caption></image:image><image:image><image:loc>https://larryjameshenry.com/posts/azure-policy-governance-scale/images/featured.jpg</image:loc><image:title>images/featured.jpg</image:title></image:image></url><url><loc>https://larryjameshenry.com/posts/azure-subscription-vending-automation/</loc><lastmod>2026-04-09T00:00:00+00:00</lastmod><image:image><image:loc>https://larryjameshenry.com/images/featured.jpg</image:loc><image:title>Azure Subscription Vending: Automated Workload Onboarding</image:title><image:caption>Automate Azure subscription provisioning with a PR-based vending workflow. Deploy spoke networking, RBAC, and monitoring baselines using Terraform and Bicep.</image:caption></image:image><image:image><image:loc>https://larryjameshenry.com/posts/azure-subscription-vending-automation/images/featured.jpg</image:loc><image:title>images/featured.jpg</image:title></image:image></url><url><loc>https://larryjameshenry.com/posts/azure-monitor-centralized-logging/</loc><lastmod>2026-04-10T00:00:00+00:00</lastmod><image:image><image:loc>https://larryjameshenry.com/images/featured.jpg</image:loc><image:title>Azure Centralized Monitoring: Log Analytics and Workbooks</image:title><image:caption>Design a centralized logging architecture for your Azure Landing Zone using Log Analytics, automated Diagnostic Settings via Policy, and Monitor Workbooks.</image:caption></image:image><image:image><image:loc>https://larryjameshenry.com/posts/azure-monitor-centralized-logging/images/featured.jpg</image:loc><image:title>images/featured.jpg</image:title></image:image></url><url><loc>https://larryjameshenry.com/posts/landing-zone-cicd-pipeline/</loc><lastmod>2026-04-13T15:00:00+00:00</lastmod><image:image><image:loc>https://larryjameshenry.com/images/featured.jpg</image:loc><image:title>CI/CD for Azure Landing Zones: GitHub Actions &amp; AVM</image:title><image:caption>Build a production-grade CI/CD pipeline for your Azure Landing Zone. Automate AVM module deployment using GitHub Actions with Terraform plans and Bicep previews.</image:caption></image:image><image:image><image:loc>https://larryjameshenry.com/posts/landing-zone-cicd-pipeline/images/featured.jpg</image:loc><image:title>images/featured.jpg</image:title></image:image></url><url><loc>https://larryjameshenry.com/posts/landing-zone-cost-governance/</loc><lastmod>2026-04-14T15:00:00+00:00</lastmod><image:image><image:loc>https://larryjameshenry.com/images/featured.jpg</image:loc><image:title>Azure Cost Governance: Tagging, Budgets, and FinOps</image:title><image:caption>Master Azure cost governance by automating tagging enforcement, budget alerts, and anomaly detection. Build a FinOps-ready landing zone using Terraform and Bicep.</image:caption></image:image><image:image><image:loc>https://larryjameshenry.com/posts/landing-zone-cost-governance/images/featured.jpg</image:loc><image:title>images/featured.jpg</image:title></image:image></url><url><loc>https://larryjameshenry.com/posts/landing-zone-day-2-ops/</loc><lastmod>2026-04-15T15:00:00+00:00</lastmod><image:image><image:loc>https://larryjameshenry.com/images/featured.jpg</image:loc><image:title>Azure Landing Zone Day-2 Ops: Maintenance and Evolution</image:title><image:caption>Operate and evolve your Azure Landing Zone. Covers automated drift remediation, RBAC reviews, and migrating to Azure Verified Modules (AVM).</image:caption></image:image><image:image><image:loc>https://larryjameshenry.com/posts/landing-zone-day-2-ops/images/featured.jpg</image:loc><image:title>images/featured.jpg</image:title></image:image></url><url><loc>https://larryjameshenry.com/tags/avm-migration/</loc><lastmod>2026-04-15T15:00:00+00:00</lastmod></url><url><loc>https://larryjameshenry.com/categories/azure/</loc><lastmod>2026-04-15T15:00:00+00:00</lastmod></url><url><loc>https://larryjameshenry.com/tags/azure-landing-zone/</loc><lastmod>2026-04-15T15:00:00+00:00</lastmod></url><url><loc>https://larryjameshenry.com/series/azure-platform-engineering-build-an-enterprise-landing-zone-from-scratch/</loc><lastmod>2026-04-15T15:00:00+00:00</lastmod></url><url><loc>https://larryjameshenry.com/categories/</loc><lastmod>2026-04-15T15:00:00+00:00</lastmod></url><url><loc>https://larryjameshenry.com/tags/day-2-operations/</loc><lastmod>2026-04-15T15:00:00+00:00</lastmod></url><url><loc>https://larryjameshenry.com/categories/devops/</loc><lastmod>2026-04-15T15:00:00+00:00</lastmod></url><url><loc>https://larryjameshenry.com/tags/drift-detection/</loc><lastmod>2026-04-15T15:00:00+00:00</lastmod></url><url><loc>https://larryjameshenry.com/</loc><lastmod>2026-04-15T15:00:00+00:00</lastmod></url><url><loc>https://larryjameshenry.com/tags/policy-remediation/</loc><lastmod>2026-04-15T15:00:00+00:00</lastmod></url><url><loc>https://larryjameshenry.com/posts/</loc><lastmod>2026-04-15T15:00:00+00:00</lastmod></url><url><loc>https://larryjameshenry.com/tags/rbac-review/</loc><lastmod>2026-04-15T15:00:00+00:00</lastmod></url><url><loc>https://larryjameshenry.com/series/</loc><lastmod>2026-04-15T15:00:00+00:00</lastmod></url><url><loc>https://larryjameshenry.com/tags/</loc><lastmod>2026-04-15T15:00:00+00:00</lastmod></url><url><loc>https://larryjameshenry.com/tags/azure-budgets/</loc><lastmod>2026-04-14T15:00:00+00:00</lastmod></url><url><loc>https://larryjameshenry.com/tags/azure-cost-management/</loc><lastmod>2026-04-14T15:00:00+00:00</lastmod></url><url><loc>https://larryjameshenry.com/tags/azure-tagging-policy/</loc><lastmod>2026-04-14T15:00:00+00:00</lastmod></url><url><loc>https://larryjameshenry.com/tags/finops/</loc><lastmod>2026-04-14T15:00:00+00:00</lastmod></url><url><loc>https://larryjameshenry.com/categories/finops/</loc><lastmod>2026-04-14T15:00:00+00:00</lastmod></url><url><loc>https://larryjameshenry.com/tags/focus/</loc><lastmod>2026-04-14T15:00:00+00:00</lastmod></url><url><loc>https://larryjameshenry.com/tags/iac/</loc><lastmod>2026-04-14T15:00:00+00:00</lastmod></url><url><loc>https://larryjameshenry.com/tags/avm/</loc><lastmod>2026-04-13T15:00:00+00:00</lastmod></url><url><loc>https://larryjameshenry.com/tags/bicep/</loc><lastmod>2026-04-13T15:00:00+00:00</lastmod></url><url><loc>https://larryjameshenry.com/tags/github-actions/</loc><lastmod>2026-04-13T15:00:00+00:00</lastmod></url><url><loc>https://larryjameshenry.com/tags/iac-pipeline/</loc><lastmod>2026-04-13T15:00:00+00:00</lastmod></url><url><loc>https://larryjameshenry.com/tags/oidc/</loc><lastmod>2026-04-13T15:00:00+00:00</lastmod></url><url><loc>https://larryjameshenry.com/tags/terraform/</loc><lastmod>2026-04-13T15:00:00+00:00</lastmod></url><url><loc>https://larryjameshenry.com/tags/azure-diagnostic-settings/</loc><lastmod>2026-04-10T00:00:00+00:00</lastmod></url><url><loc>https://larryjameshenry.com/tags/azure-landing-zone-monitoring/</loc><lastmod>2026-04-10T00:00:00+00:00</lastmod></url><url><loc>https://larryjameshenry.com/tags/azure-log-analytics/</loc><lastmod>2026-04-10T00:00:00+00:00</lastmod></url><url><loc>https://larryjameshenry.com/tags/azure-monitor-workbooks/</loc><lastmod>2026-04-10T00:00:00+00:00</lastmod></url><url><loc>https://larryjameshenry.com/tags/azure-subscription-vending/</loc><lastmod>2026-04-09T00:00:00+00:00</lastmod></url><url><loc>https://larryjameshenry.com/tags/platform-engineering/</loc><lastmod>2026-04-09T00:00:00+00:00</lastmod></url><url><loc>https://larryjameshenry.com/tags/subscription-automation/</loc><lastmod>2026-04-09T00:00:00+00:00</lastmod></url><url><loc>https://larryjameshenry.com/tags/azure-governance/</loc><lastmod>2026-04-08T00:00:00+00:00</lastmod></url><url><loc>https://larryjameshenry.com/tags/azure-policy/</loc><lastmod>2026-04-08T00:00:00+00:00</lastmod></url><url><loc>https://larryjameshenry.com/tags/azure-policy-as-code/</loc><lastmod>2026-04-08T00:00:00+00:00</lastmod></url><url><loc>https://larryjameshenry.com/tags/compliance/</loc><lastmod>2026-04-08T00:00:00+00:00</lastmod></url><url><loc>https://larryjameshenry.com/tags/azure-pim/</loc><lastmod>2026-04-07T00:00:00+00:00</lastmod></url><url><loc>https://larryjameshenry.com/tags/azure-rbac/</loc><lastmod>2026-04-07T00:00:00+00:00</lastmod></url><url><loc>https://larryjameshenry.com/tags/entra-id/</loc><lastmod>2026-04-07T00:00:00+00:00</lastmod></url><url><loc>https://larryjameshenry.com/tags/managed-identity/</loc><lastmod>2026-04-07T00:00:00+00:00</lastmod></url><url><loc>https://larryjameshenry.com/tags/workload-identity/</loc><lastmod>2026-04-07T00:00:00+00:00</lastmod></url><url><loc>https://larryjameshenry.com/tags/azure-bastion/</loc><lastmod>2026-04-06T00:00:00+00:00</lastmod></url><url><loc>https://larryjameshenry.com/tags/azure-firewall/</loc><lastmod>2026-04-06T00:00:00+00:00</lastmod></url><url><loc>https://larryjameshenry.com/tags/azure-hub-spoke-networking/</loc><lastmod>2026-04-06T00:00:00+00:00</lastmod></url><url><loc>https://larryjameshenry.com/tags/private-dns-zones/</loc><lastmod>2026-04-06T00:00:00+00:00</lastmod></url><url><loc>https://larryjameshenry.com/tags/azure-caf/</loc><lastmod>2026-04-03T00:00:00+00:00</lastmod></url><url><loc>https://larryjameshenry.com/tags/azure-management-groups/</loc><lastmod>2026-04-03T00:00:00+00:00</lastmod></url><url><loc>https://larryjameshenry.com/tags/azure-subscription-hierarchy/</loc><lastmod>2026-04-03T00:00:00+00:00</lastmod></url><url><loc>https://larryjameshenry.com/tags/enterprise-azure/</loc><lastmod>2026-04-02T00:00:00+00:00</lastmod></url><url><loc>https://larryjameshenry.com/gallery/</loc><lastmod>2022-06-25T18:35:46+05:30</lastmod></url><url><loc>https://larryjameshenry.com/about/</loc><image:image><image:loc>https://larryjameshenry.com/images/larryjameshenry.png</image:loc><image:title>About Larry James Henry</image:title><image:caption>Senior DevOps Engineer and Azure Solutions Architect specializing in Platform Engineering and PowerShell automation.</image:caption></image:image></url></urlset>