[LZ 8.1] Standing Up the Operating Loop

Cost views and budgets by tag, the subscription-vending checklist, the add-a-spoke runbook, and the monthly health and drift checks. The operating loop made concrete, and the final build sheet of the series.
Designing, deploying, and operating a right-sized Azure landing zone for small and mid-sized organizations.

Cost views and budgets by tag, the subscription-vending checklist, the add-a-spoke runbook, and the monthly health and drift checks. The operating loop made concrete, and the final build sheet of the series.

The foundation is built; now it is operated and grown. Day-two cost management where the mandatory tags finally pay off, the where-does-new-X-go framework, and the series-closing argument that a real foundation grows by placement, not by rebuild.

Tags and locations assigned in audit, scanned, then promoted to deny; tag inheritance via Modify with remediation; the gateway subnet exempted; the crown jewels protected from deletion; and a test that a non-compliant resource is blocked and a compliant one accepted.

The management-group tree has organized, scoped, and inherited, but it has not yet refused anything. Policy is the enforcement layer: audit before deny, mandatory tags and inheritance, exemptions as designed carve-outs, and the tree finally saying no.

The central Log Analytics workspace, Defender for Cloud with the plan you chose, diagnostic settings pushed across the tree by policy, the identity signals routed in, the alerts that matter, and a test that proves a resource logs land in the record. The reproducible build for posture and central logging.

Two questions the foundation still has to answer: is the estate configured well right now, and what happened when something went wrong. Posture with Defender for Cloud and a single central Log Analytics workspace, stood up as platform services so the estate can see itself and keep the record.

Two hardened break-glass accounts, the groups that carry every Azure role, RBAC placed on the management-group tree, Privileged Identity Management if you licensed it, and an end-to-end test that proves inheritance. The reproducible build for identity and access on the foundation.

The management-group tree, the hub, the name resolution: all of it is inert until an identity has the authority to act on it. In Azure, identity is the control plane, and this is how you arrange it so a small team can operate the foundation safely.