<?xml version="1.0" encoding="utf-8" standalone="yes"?><urlset xmlns="http://www.sitemaps.org/schemas/sitemap/0.9" xmlns:image="http://www.google.com/schemas/sitemap-image/1.1"><url><loc>https://larryjameshenry.com/posts/azure-landing-zone-guide/</loc><lastmod>2026-04-07T00:00:00+00:00</lastmod><image:image><image:loc>https://larryjameshenry.com/images/featured.webp</image:loc><image:title>Azure Platform Engineering: The Complete Guide to Building an Enterprise Landing Zone</image:title><image:caption>Build a production-grade Azure Landing Zone from scratch. Covers all 8 CAF design areas, Terraform AVM, Bicep Deployment Stacks, and secret-less CI/CD.</image:caption></image:image><image:image><image:loc>https://larryjameshenry.com/posts/azure-landing-zone-guide/images/featured.jpg</image:loc><image:title>images/featured.jpg</image:title></image:image><image:image><image:loc>https://larryjameshenry.com/posts/azure-landing-zone-guide/images/featured.webp</image:loc><image:title>images/featured.webp</image:title></image:image></url><url><loc>https://larryjameshenry.com/posts/azure-management-group-design/</loc><lastmod>2026-04-07T00:00:00+00:00</lastmod><image:image><image:loc>https://larryjameshenry.com/images/featured.webp</image:loc><image:title>Design Your Azure Management Group and Subscription Hierarchy</image:title><image:caption>Design and deploy a production Azure management group hierarchy with Terraform and Bicep AVM. Covers intermediate groups, platform vs workload separation, and subscription placement.</image:caption></image:image><image:image><image:loc>https://larryjameshenry.com/posts/azure-management-group-design/images/featured.jpg</image:loc><image:title>images/featured.jpg</image:title></image:image><image:image><image:loc>https://larryjameshenry.com/posts/azure-management-group-design/images/featured.webp</image:loc><image:title>images/featured.webp</image:title></image:image></url><url><loc>https://larryjameshenry.com/posts/azure-hub-spoke-networking/</loc><lastmod>2026-04-07T00:00:00+00:00</lastmod><image:image><image:loc>https://larryjameshenry.com/images/featured.webp</image:loc><image:title>Hub-and-Spoke Networking for Azure Landing Zones: Azure Firewall, Bastion, and Private DNS</image:title><image:caption>Build a production hub-and-spoke network for Azure landing zones. Covers Azure Firewall Premium, Bastion scaling, DNS Private Resolver, and VNet peering with gateway transit.</image:caption></image:image><image:image><image:loc>https://larryjameshenry.com/posts/azure-hub-spoke-networking/images/featured.jpg</image:loc><image:title>images/featured.jpg</image:title></image:image><image:image><image:loc>https://larryjameshenry.com/posts/azure-hub-spoke-networking/images/featured.webp</image:loc><image:title>images/featured.webp</image:title></image:image></url><url><loc>https://larryjameshenry.com/posts/azure-identity-architecture/</loc><lastmod>2026-04-07T00:00:00+00:00</lastmod><image:image><image:loc>https://larryjameshenry.com/images/featured.webp</image:loc><image:title>Identity and Access Architecture for Azure Landing Zones: Entra ID, RBAC, and PIM</image:title><image:caption>Design the identity layer of an Azure landing zone. Covers Entra ID vs Azure RBAC, Privileged Identity Management (PIM), and secret-less OIDC authentication for GitHub Actions.</image:caption></image:image><image:image><image:loc>https://larryjameshenry.com/posts/azure-identity-architecture/images/featured.jpg</image:loc><image:title>images/featured.jpg</image:title></image:image><image:image><image:loc>https://larryjameshenry.com/posts/azure-identity-architecture/images/featured.webp</image:loc><image:title>images/featured.webp</image:title></image:image></url><url><loc>https://larryjameshenry.com/posts/azure-policy-governance/</loc><lastmod>2026-04-08T00:00:00+00:00</lastmod><image:image><image:loc>https://larryjameshenry.com/images/featured.webp</image:loc><image:title>Governance at Scale: Writing and Deploying Azure Policies with Terraform and Bicep</image:title><image:caption>Write and deploy Azure Policy definitions, initiatives, and assignments as code. Learn to use the Deny and DeployIfNotExists effects to maintain a secure landing zone foundation.</image:caption></image:image><image:image><image:loc>https://larryjameshenry.com/posts/azure-policy-governance/images/featured.jpg</image:loc><image:title>images/featured.jpg</image:title></image:image><image:image><image:loc>https://larryjameshenry.com/posts/azure-policy-governance/images/featured.webp</image:loc><image:title>images/featured.webp</image:title></image:image></url><url><loc>https://larryjameshenry.com/posts/azure-subscription-vending/</loc><lastmod>2026-04-08T00:00:00+00:00</lastmod><image:image><image:loc>https://larryjameshenry.com/images/featured.webp</image:loc><image:title>Subscription Vending: Automating New Workload Onboarding with IaC</image:title><image:caption>Automate Azure subscription provisioning with a PR-based vending workflow. Learn to deploy spoke networking, RBAC, and budgets using Terraform and Bicep patterns.</image:caption></image:image><image:image><image:loc>https://larryjameshenry.com/posts/azure-subscription-vending/images/featured.jpg</image:loc><image:title>images/featured.jpg</image:title></image:image><image:image><image:loc>https://larryjameshenry.com/posts/azure-subscription-vending/images/featured.webp</image:loc><image:title>images/featured.webp</image:title></image:image></url><url><loc>https://larryjameshenry.com/posts/azure-monitor-logging/</loc><lastmod>2026-04-08T00:00:00+00:00</lastmod><image:image><image:loc>https://larryjameshenry.com/images/featured.webp</image:loc><image:title>Centralized Monitoring: Log Analytics, Diagnostic Settings, and Azure Monitor Workbooks</image:title><image:caption>Design a centralized logging architecture for your Azure Landing Zone using Log Analytics and Data Collection Rules. Learn to automate diagnostic settings at scale.</image:caption></image:image><image:image><image:loc>https://larryjameshenry.com/posts/azure-monitor-logging/images/featured.jpg</image:loc><image:title>images/featured.jpg</image:title></image:image><image:image><image:loc>https://larryjameshenry.com/posts/azure-monitor-logging/images/featured.webp</image:loc><image:title>images/featured.webp</image:title></image:image></url><url><loc>https://larryjameshenry.com/posts/azure-security-baseline/</loc><lastmod>2026-04-08T15:00:00+00:00</lastmod><image:image><image:loc>https://larryjameshenry.com/images/featured.webp</image:loc><image:title>Security Baseline: Defender for Cloud and Microsoft Sentinel in a Landing Zone</image:title><image:caption>Establish a robust security baseline by deploying Microsoft Defender for Cloud and Microsoft Sentinel. Learn to automate threat detection and posture management at scale.</image:caption></image:image><image:image><image:loc>https://larryjameshenry.com/posts/azure-security-baseline/images/featured.jpg</image:loc><image:title>images/featured.jpg</image:title></image:image><image:image><image:loc>https://larryjameshenry.com/posts/azure-security-baseline/images/featured.webp</image:loc><image:title>images/featured.webp</image:title></image:image></url><url><loc>https://larryjameshenry.com/posts/azure-landing-zone-cicd/</loc><lastmod>2026-04-08T15:00:00+00:00</lastmod><image:image><image:loc>https://larryjameshenry.com/images/featured.webp</image:loc><image:title>CI/CD Pipeline for Your Landing Zone: Deploying Azure Verified Modules with GitHub Actions</image:title><image:caption>Build a production-grade CI/CD pipeline for your Azure Landing Zone. Learn to implement OIDC authentication, automated testing with PSRule, and PR-driven workflows.</image:caption></image:image><image:image><image:loc>https://larryjameshenry.com/posts/azure-landing-zone-cicd/images/featured.jpg</image:loc><image:title>images/featured.jpg</image:title></image:image><image:image><image:loc>https://larryjameshenry.com/posts/azure-landing-zone-cicd/images/featured.webp</image:loc><image:title>images/featured.webp</image:title></image:image></url><url><loc>https://larryjameshenry.com/posts/azure-landing-zone-costs/</loc><lastmod>2026-04-08T15:00:00+00:00</lastmod><image:image><image:loc>https://larryjameshenry.com/images/featured.webp</image:loc><image:title>Cost Governance in the Landing Zone: Tagging Enforcement, Budgets, and FinOps Automation</image:title><image:caption>Master Azure cost governance by automating tagging enforcement, budget alerts, and anomaly detection. Build a FinOps-ready landing zone using Terraform and Bicep.</image:caption></image:image><image:image><image:loc>https://larryjameshenry.com/posts/azure-landing-zone-costs/images/featured.jpg</image:loc><image:title>images/featured.jpg</image:title></image:image><image:image><image:loc>https://larryjameshenry.com/posts/azure-landing-zone-costs/images/featured.webp</image:loc><image:title>images/featured.webp</image:title></image:image></url><url><loc>https://larryjameshenry.com/posts/azure-landing-zone-ops/</loc><lastmod>2026-04-08T15:00:00+00:00</lastmod><image:image><image:loc>https://larryjameshenry.com/images/featured.webp</image:loc><image:title>Day-2 Operations: Maintaining and Evolving Your Azure Landing Zone</image:title><image:caption>Learn how to operate, maintain, and upgrade your Azure Landing Zone. Covers policy drift remediation, RBAC reviews, and migrating to Azure Verified Modules (AVM).</image:caption></image:image><image:image><image:loc>https://larryjameshenry.com/posts/azure-landing-zone-ops/images/featured.jpg</image:loc><image:title>images/featured.jpg</image:title></image:image><image:image><image:loc>https://larryjameshenry.com/posts/azure-landing-zone-ops/images/featured.webp</image:loc><image:title>images/featured.webp</image:title></image:image></url><url><loc>https://larryjameshenry.com/categories/azure/</loc><lastmod>2026-04-08T15:00:00+00:00</lastmod></url><url><loc>https://larryjameshenry.com/tags/azure-avm-migration/</loc><lastmod>2026-04-08T15:00:00+00:00</lastmod></url><url><loc>https://larryjameshenry.com/tags/azure-budget-alert-automation/</loc><lastmod>2026-04-08T15:00:00+00:00</lastmod></url><url><loc>https://larryjameshenry.com/tags/azure-cost-management-landing-zone/</loc><lastmod>2026-04-08T15:00:00+00:00</lastmod></url><url><loc>https://larryjameshenry.com/tags/azure-finops-platform-engineering/</loc><lastmod>2026-04-08T15:00:00+00:00</lastmod></url><url><loc>https://larryjameshenry.com/tags/azure-landing-zone-cicd/</loc><lastmod>2026-04-08T15:00:00+00:00</lastmod></url><url><loc>https://larryjameshenry.com/tags/azure-landing-zone-day-2-operations/</loc><lastmod>2026-04-08T15:00:00+00:00</lastmod></url><url><loc>https://larryjameshenry.com/tags/azure-landing-zone-maintenance-bicep-terraform/</loc><lastmod>2026-04-08T15:00:00+00:00</lastmod></url><url><loc>https://larryjameshenry.com/series/azure-platform-engineering-build-an-enterprise-landing-zone-from-scratch/</loc><lastmod>2026-04-08T15:00:00+00:00</lastmod></url><url><loc>https://larryjameshenry.com/tags/azure-policy-drift-remediation/</loc><lastmod>2026-04-08T15:00:00+00:00</lastmod></url><url><loc>https://larryjameshenry.com/tags/azure-security-baseline-tutorial/</loc><lastmod>2026-04-08T15:00:00+00:00</lastmod></url><url><loc>https://larryjameshenry.com/tags/azure-tagging-policy-terraform-bicep/</loc><lastmod>2026-04-08T15:00:00+00:00</lastmod></url><url><loc>https://larryjameshenry.com/tags/bicep-deployment-stacks-guide/</loc><lastmod>2026-04-08T15:00:00+00:00</lastmod></url><url><loc>https://larryjameshenry.com/categories/</loc><lastmod>2026-04-08T15:00:00+00:00</lastmod></url><url><loc>https://larryjameshenry.com/tags/cloud-security-posture-management-asb/</loc><lastmod>2026-04-08T15:00:00+00:00</lastmod></url><url><loc>https://larryjameshenry.com/categories/devops/</loc><lastmod>2026-04-08T15:00:00+00:00</lastmod></url><url><loc>https://larryjameshenry.com/categories/finops/</loc><lastmod>2026-04-08T15:00:00+00:00</lastmod></url><url><loc>https://larryjameshenry.com/tags/github-actions-azure-oidc/</loc><lastmod>2026-04-08T15:00:00+00:00</lastmod></url><url><loc>https://larryjameshenry.com/tags/gitops-for-azure-landing-zone/</loc><lastmod>2026-04-08T15:00:00+00:00</lastmod></url><url><loc>https://larryjameshenry.com/</loc><lastmod>2026-04-08T15:00:00+00:00</lastmod></url><url><loc>https://larryjameshenry.com/tags/microsoft-defender-for-cloud-guide/</loc><lastmod>2026-04-08T15:00:00+00:00</lastmod></url><url><loc>https://larryjameshenry.com/tags/microsoft-sentinel-landing-zone/</loc><lastmod>2026-04-08T15:00:00+00:00</lastmod></url><url><loc>https://larryjameshenry.com/categories/operations/</loc><lastmod>2026-04-08T15:00:00+00:00</lastmod></url><url><loc>https://larryjameshenry.com/posts/</loc><lastmod>2026-04-08T15:00:00+00:00</lastmod></url><url><loc>https://larryjameshenry.com/categories/security/</loc><lastmod>2026-04-08T15:00:00+00:00</lastmod></url><url><loc>https://larryjameshenry.com/tags/sentinel-data-connectors-bicep/</loc><lastmod>2026-04-08T15:00:00+00:00</lastmod></url><url><loc>https://larryjameshenry.com/series/</loc><lastmod>2026-04-08T15:00:00+00:00</lastmod></url><url><loc>https://larryjameshenry.com/tags/</loc><lastmod>2026-04-08T15:00:00+00:00</lastmod></url><url><loc>https://larryjameshenry.com/tags/terraform-github-actions-tutorial/</loc><lastmod>2026-04-08T15:00:00+00:00</lastmod></url><url><loc>https://larryjameshenry.com/tags/automated-subscription-provisioning/</loc><lastmod>2026-04-08T00:00:00+00:00</lastmod></url><url><loc>https://larryjameshenry.com/tags/azure-diagnostic-settings-policy/</loc><lastmod>2026-04-08T00:00:00+00:00</lastmod></url><url><loc>https://larryjameshenry.com/tags/azure-governance-best-practices/</loc><lastmod>2026-04-08T00:00:00+00:00</lastmod></url><url><loc>https://larryjameshenry.com/tags/azure-monitor-logging-tutorial/</loc><lastmod>2026-04-08T00:00:00+00:00</lastmod></url><url><loc>https://larryjameshenry.com/tags/azure-monitor-workbooks-guide/</loc><lastmod>2026-04-08T00:00:00+00:00</lastmod></url><url><loc>https://larryjameshenry.com/tags/azure-policy-as-code/</loc><lastmod>2026-04-08T00:00:00+00:00</lastmod></url><url><loc>https://larryjameshenry.com/tags/azure-subscription-vending/</loc><lastmod>2026-04-08T00:00:00+00:00</lastmod></url><url><loc>https://larryjameshenry.com/tags/bicep-lz-vending/</loc><lastmod>2026-04-08T00:00:00+00:00</lastmod></url><url><loc>https://larryjameshenry.com/tags/bicep-policy-assignment/</loc><lastmod>2026-04-08T00:00:00+00:00</lastmod></url><url><loc>https://larryjameshenry.com/tags/data-collection-rules-kql/</loc><lastmod>2026-04-08T00:00:00+00:00</lastmod></url><url><loc>https://larryjameshenry.com/tags/dine-policy-remediation/</loc><lastmod>2026-04-08T00:00:00+00:00</lastmod></url><url><loc>https://larryjameshenry.com/categories/governance/</loc><lastmod>2026-04-08T00:00:00+00:00</lastmod></url><url><loc>https://larryjameshenry.com/tags/landing-zone-automation/</loc><lastmod>2026-04-08T00:00:00+00:00</lastmod></url><url><loc>https://larryjameshenry.com/tags/log-analytics-workspace-v2/</loc><lastmod>2026-04-08T00:00:00+00:00</lastmod></url><url><loc>https://larryjameshenry.com/tags/terraform-azure-policy-tutorial/</loc><lastmod>2026-04-08T00:00:00+00:00</lastmod></url><url><loc>https://larryjameshenry.com/tags/terraform-subscription-vending/</loc><lastmod>2026-04-08T00:00:00+00:00</lastmod></url><url><loc>https://larryjameshenry.com/tags/azure-bastion-scaling/</loc><lastmod>2026-04-07T00:00:00+00:00</lastmod></url><url><loc>https://larryjameshenry.com/tags/azure-dns-private-resolver/</loc><lastmod>2026-04-07T00:00:00+00:00</lastmod></url><url><loc>https://larryjameshenry.com/tags/azure-firewall-premium-tutorial/</loc><lastmod>2026-04-07T00:00:00+00:00</lastmod></url><url><loc>https://larryjameshenry.com/tags/azure-governance-as-code/</loc><lastmod>2026-04-07T00:00:00+00:00</lastmod></url><url><loc>https://larryjameshenry.com/tags/azure-hub-and-spoke-networking/</loc><lastmod>2026-04-07T00:00:00+00:00</lastmod></url><url><loc>https://larryjameshenry.com/tags/azure-identity-architecture/</loc><lastmod>2026-04-07T00:00:00+00:00</lastmod></url><url><loc>https://larryjameshenry.com/tags/azure-landing-zone-tutorial/</loc><lastmod>2026-04-07T00:00:00+00:00</lastmod></url><url><loc>https://larryjameshenry.com/tags/azure-management-group-design/</loc><lastmod>2026-04-07T00:00:00+00:00</lastmod></url><url><loc>https://larryjameshenry.com/tags/azure-pim-best-practices/</loc><lastmod>2026-04-07T00:00:00+00:00</lastmod></url><url><loc>https://larryjameshenry.com/tags/azure-platform-engineering-guide/</loc><lastmod>2026-04-07T00:00:00+00:00</lastmod></url><url><loc>https://larryjameshenry.com/tags/azure-subscription-hierarchy/</loc><lastmod>2026-04-07T00:00:00+00:00</lastmod></url><url><loc>https://larryjameshenry.com/tags/azure-verified-modules-avm/</loc><lastmod>2026-04-07T00:00:00+00:00</lastmod></url><url><loc>https://larryjameshenry.com/tags/azure-verified-modules-ptn-alz/</loc><lastmod>2026-04-07T00:00:00+00:00</lastmod></url><url><loc>https://larryjameshenry.com/tags/caf-enterprise-scale/</loc><lastmod>2026-04-07T00:00:00+00:00</lastmod></url><url><loc>https://larryjameshenry.com/tags/entra-id-rbac-tutorial/</loc><lastmod>2026-04-07T00:00:00+00:00</lastmod></url><url><loc>https://larryjameshenry.com/tags/landing-zone-architecture/</loc><lastmod>2026-04-07T00:00:00+00:00</lastmod></url><url><loc>https://larryjameshenry.com/tags/landing-zone-as-code/</loc><lastmod>2026-04-07T00:00:00+00:00</lastmod></url><url><loc>https://larryjameshenry.com/categories/networking/</loc><lastmod>2026-04-07T00:00:00+00:00</lastmod></url><url><loc>https://larryjameshenry.com/tags/oidc-github-actions-azure/</loc><lastmod>2026-04-07T00:00:00+00:00</lastmod></url><url><loc>https://larryjameshenry.com/tags/vnet-peering-gateway-transit/</loc><lastmod>2026-04-07T00:00:00+00:00</lastmod></url><url><loc>https://larryjameshenry.com/tags/zero-trust-azure-identity/</loc><lastmod>2026-04-07T00:00:00+00:00</lastmod></url><url><loc>https://larryjameshenry.com/gallery/</loc><lastmod>2022-06-25T18:35:46+05:30</lastmod></url><url><loc>https://larryjameshenry.com/about/</loc><image:image><image:loc>https://larryjameshenry.com/images/larryjameshenry.webp</image:loc><image:title>About Larry James Henry</image:title><image:caption>Senior DevOps Engineer and Azure Solutions Architect specializing in Platform Engineering and PowerShell automation.</image:caption></image:image></url><url><loc>https://larryjameshenry.com/tags/azure-devops/</loc></url><url><loc>https://larryjameshenry.com/series/azure-devops-yaml-expression-masterclass/</loc></url><url><loc>https://larryjameshenry.com/tags/ci/cd/</loc></url><url><loc>https://larryjameshenry.com/tags/compile-time/</loc></url><url><loc>https://larryjameshenry.com/tags/devops/</loc></url><url><loc>https://larryjameshenry.com/tags/pipeline-expressions/</loc></url><url><loc>https://larryjameshenry.com/tags/runtime/</loc></url><url><loc>https://larryjameshenry.com/tags/yaml/</loc></url></urlset>