Aaron

Aaron

[LZ 7.1] Standing Up the Policy Guardrails

A builder installing a row of small gates on a track and setting each lever, with one gate propped open as a deliberate exception.

Tags and locations assigned in audit, scanned, then promoted to deny; tag inheritance via Modify with remediation; the gateway subnet exempted; the crown jewels protected from deletion; and a test that a non-compliant resource is blocked and a compliant one accepted.

[LZ 7] Where the Tree Starts Saying No

A person at a desk beside a small gated checkpoint where an inspector waves compliant items through and holds others back, with a lever set between watch and enforce.

The management-group tree has organized, scoped, and inherited, but it has not yet refused anything. Policy is the enforcement layer: audit before deny, mandatory tags and inheritance, exemptions as designed carve-outs, and the tree finally saying no.

[LZ 6.1] Standing Up Posture and the Central Record

A builder wiring many cables from an array of instruments into a single central box, plumbing a system so that everything reports to one place.

The central Log Analytics workspace, Defender for Cloud with the plan you chose, diagnostic settings pushed across the tree by policy, the identity signals routed in, the alerts that matter, and a test that proves a resource logs land in the record. The reproducible build for posture and central logging.

[LZ 6] The Estate You Can See

An operator at a control desk watching a wall of gauges while small records flow inward to a single open ledger, suggesting security posture and a central log.

Two questions the foundation still has to answer: is the estate configured well right now, and what happened when something went wrong. Posture with Defender for Cloud and a single central Log Analytics workspace, stood up as platform services so the estate can see itself and keep the record.

[LZ 5.1] Standing Up Identity and Access

A builder at a workbench mounting keys and locks onto a pegboard and wiring them to a tiered structure, suggesting the deliberate construction of a controlled access system.

Two hardened break-glass accounts, the groups that carry every Azure role, RBAC placed on the management-group tree, Privileged Identity Management if you licensed it, and an end-to-end test that proves inheritance. The reproducible build for identity and access on the foundation.

[LZ 4.2] Wiring Name Resolution End to End

Editorial illustration of a person tracing one clear path through a switchboard of routes, teal and slate tones

The build sheet for name resolution: the DNS private resolver and its inbound endpoint, the private DNS zones, the on-premises conditional forwarders, the catch-all remediation discovery flagged, and a private endpoint proven to resolve privately from both the spoke and on-premises.