So You’ve Deployed Azure Platform Landing Zones — What Comes Next?
Deploying Azure Platform Landing Zones (APLZ) is a major milestone. It gives you a secure, scalable, enterpriseready foundation aligned to the Cloud Adoption Framework (CAF). But here’s the truth many organisations learn the hard way: the real work starts after the platform is deployed.
A Platform Landing Zone isn’t a “set and forget” artefact, well nor is any landing zone in that fact. It’s a living platform that needs governance, maintenance, iteration, and continuous alignment with your organisation’s security, compliance, and operational standards.
If you’ve just deployed APLZ — or you’re about to — here’s what you should be doing next.
1. Keep Your Platform Landing Zone Code Up to Date
Azure evolves constantly. New services, new policies, new security baselines, new platform features — and the APLZ codebase evolves with it.
Why this matters
- Outdated modules = outdated security posture
- New ALZ releases often include critical fixes
- Azure Policy definitions change frequently
- Bicep/Terraform modules get new capabilities
What to do
- Track the APLZ GitHub repo and release notes
- Implement a versioning strategy for your platform code
- Use branching and PR workflows to safely test updates
- Regularly run drift detection against your platform subscriptions
- Automate validation using GitHub Actions or Azure DevOps pipelines
Keeping your platform code current is one of the most important longterm responsibilities of a cloud platform team.
2. Customise Azure Policies to Match Your Organisation’s Security Standards
The default APLZ policy set is a strong baseline — but it’s still a baseline. Every organisation has its own security, compliance, and operational requirements.
Common customisation areas
- Naming conventions
- Tagging standards
- Allowed SKUs and regions
- Backup and retention policies
- Encryption and key management
- Network security rules
- Identity and access controls
How to approach policy customisation
- Start with the CAF policy library
- Map policies to your internal IT and security standards
- Build a custom policy initiative layered on top of APLZ
- Use policy exemptions sparingly and with governance
- Continuously audit compliance using Azure Policy insights
This is where your platform becomes your platform — not just Microsoft’s reference architecture.
3. Build Application Landing Zones – Landing zone for applications
Once the platform is ready, the next step is enabling application teams to onboard safely and consistently.
What an Application Landing Zone (ALZ) should include
- Subscription creation workflow
- RBAC model for app teams
- Network integration (VNet, Private Endpoints, routing)
- Logging and monitoring defaults
- Security baselines
- Backup and DR configuration
- Cost management setup
- Blueprint for IaC deployment
Key principles
- Selfservice where possible
- Guardrails, not gates
- Automation over documentation
- Consistency over creativity
Your platform should make it easy for teams to do the right thing — and hard to do the wrong thing.
4. Manage the APLZ Core Pillars: Identity, Management, Connectivity, Security
This is where longterm platform operations live. APLZ is built on four major pillars, and each requires ongoing ownership.
Identity: Keep Access Secure and Predictable
Identity is the backbone of the platform.
Key responsibilities
- Maintain a clean RBAC model
- Enforce least privilege
- Manage Privileged Identity Management (PIM)
- Review access regularly
- Integrate with Entra ID Conditional Access
- Secure service principals and managed identities
Identity drift is one of the biggest risks in longrunning cloud environments — stay on top of it.
Management: Monitoring, Logging, and Operational Insights
A platform without observability is a platform you can’t trust.
Core components
- Azure Monitor
- Log Analytics workspaces
- Application Insights
- Alerts and action groups
- Automation accounts / Functions for remediation
- Cost monitoring and budgets
Best practices
- Standardise logging across all Landing Zones
- Use DCRbased monitoring (the new standard)
- Implement platformlevel dashboards
- Automate alert tuning to reduce noise
Your platform should tell you when something is wrong — before your users do.
Connectivity: Firewalls, Routing, WAF, and Front Door
Networking is one of the most complex parts of APLZ, and it requires continuous care.
Key areas to manage
- Azure Firewall policies
- Route Server and UDR governance
- Private Link and Private DNS zones
- Hub-and-spoke or Virtual WAN evolution
- Web Application Firewall (WAF) rules
- Azure Front Door for global applications
- Network segmentation and Zero Trust patterns
Ongoing tasks
- Review firewall rule growth
- Validate routing paths
- Monitor Private Endpoint sprawl
- Keep DNS clean and structured
Connectivity is never “done” — it evolves with every new application.
Security: Logging, Auditing, Defender, and Sentinel
Security is not a feature — it’s a continuous process.
Platform security responsibilities
- Enable Microsoft Defender for Cloud
- Configure regulatory compliance standards
- Integrate logs into Sentinel
- Build detection rules and analytics
- Automate incident response where possible
- Review audit logs regularly
- Maintain secure baselines for VMs, AKS, PaaS services
Sentinel considerations
- Create a central SOC workspace
- Build custom analytics for your environment
- Integrate identity, network, and platform logs
- Use automation rules to reduce manual triage
A secure Landing Zone is one that is monitored, audited, and continuously improved.
5. Establish a Platform Operating Model
A Landing Zone without an operating model is just a collection of resources.
Your operating model should define
- Who owns what (RACI)
- How changes are made (change control)
- How subscriptions are created
- How incidents are handled
- How security exceptions are approved
- How platform updates are tested and deployed
- How application teams onboard
This is where the platform becomes a product — not a project.
6. Engage with the Business and Application Teams
The platform only succeeds if the business uses it effectively.
What this looks like
- Regular platform roadmap updates
- Office hours for engineering teams
- Clear documentation and onboarding guides
- A backlog of platform features
- Feedback loops with application owners
A great platform team behaves like an internal SaaS provider.
Final Thoughts
Deploying Azure Platform Landing Zones is a huge achievement — but it’s only the beginning. The real value comes from how you operate, evolve, and govern the platform over time.
A mature ALZ is one that:
- Stays up to date
- Aligns with internal security standards
- Enables application teams
- Maintains strong identity, management, connectivity, and security foundations
- Operates like a product with a roadmap and clear ownership
