Articles

An operator at a control desk watching a wall of gauges while small records flow inward to a single open ledger, suggesting security posture and a central log.

[LZ 6] The Estate You Can See

Two questions the foundation still has to answer: is the estate configured well right now, and what happened when something went wrong. Posture with Defender for Cloud and a single central Log Analytics workspace, stood up as platform services so the estate can see itself and keep the record.

A builder at a workbench mounting keys and locks onto a pegboard and wiring them to a tiered structure, suggesting the deliberate construction of a controlled access system.

[LZ 5.1] Standing Up Identity and Access

Two hardened break-glass accounts, the groups that carry every Azure role, RBAC placed on the management-group tree, Privileged Identity Management if you licensed it, and an end-to-end test that proves inheritance. The reproducible build for identity and access on the foundation.

Editorial illustration of a person tracing one clear path through a switchboard of routes, teal and slate tones

[LZ 4.2] Wiring Name Resolution End to End

The build sheet for name resolution: the DNS private resolver and its inbound endpoint, the private DNS zones, the on-premises conditional forwarders, the catch-all remediation discovery flagged, and a private endpoint proven to resolve privately from both the spoke and on-premises.

Editorial illustration of a person arranging a structural framework of a building before the walls go up, teal and slate tones

[LZ 3] The Governance Backbone

The management group hierarchy, the subscriptions inside it, and the naming and tagging decisions that are nearly free on day one and painful to change later. Deploy the whole shape at once, and keep management groups for inheritance, never for workloads.