Workload teams should receive environments where networking, identity, security, observability, governance and deployment paths have already been established while maintaining enough flexibility to develop and manage applications.
If each new workload requires the architecture team to rethink networking, negotiate firewall rules again, manually configure monitoring, determine where logs should be directed and devise another deployment strategy, then the landing zone has not become a true platform.
Microsoft’s reference architecture provides a valuable foundation. However, it remains the architect’s responsibility to convert that foundation into something that operates effectively for the organization.
In my case, Azure Front Door, Azure Virtual WAN, Palo Alto Cloud NGFW, governance boundaries, Datadog, a dedicated cloud SIEM, private GitHub runner connectivity and a repeatable active-active regional design collectively formed a single platform.
The real advantage came from enabling these components to work together so that connectivity, security, observability, governance, deployment and resiliency supported one another instead of being solved independently.
That represents, for me, where an Azure landing zone develops beyond a reference diagram.



