Experience

Public sector

An Azure landing zone with guardrails in place before the first workload arrived

  • Cloud Security
  • Azure
  • Landing Zone
  • Public Sector
  • Career engagement
Ville de Québec

The question was never the first environment

As the city moved workloads into Azure, securing the first environment was never really in doubt — a small number of subscriptions can be configured carefully by hand. The risk sits in the hundredth. Cloud estates grow by subscription, and controls applied manually decay the moment provisioning outpaces the people applying them. The landing zone was approached as the place to decide, once, what every future environment inherits.

Guardrails the platform enforces on its own

Our founder hardened the landing zone so that security posture is a property of the platform rather than a checklist run against each new environment.

A structure that matches how the city governs
Management groups and subscriptions arranged to mirror real lines of responsibility, so that a policy applied at the right level reaches exactly the environments it should.
Azure Policy guardrails as code
Automated enforcement of regional restrictions, permitted SKUs, NIST SP 800-53 compliance and mandatory tagging — defined in source, reviewed like any other change, rather than clicked into a portal once and quietly diverging.
Least-privilege RBAC with PIM and JIT access
An RBAC and Privileged Identity Management strategy built on least privilege, with privileged roles granted Just-In-Time rather than standing permanently against an account.
Hub & Spoke with strict network segmentation
A hub-and-spoke topology in which each workload lands in its own spoke and inter-zone traffic passes through the hub, so segmentation is a property of the architecture rather than a firewall rule added later.
Centralised logging and continuous compliance
Azure Monitor and Log Analytics integrated so security signals land in one place, with posture measured continuously against the CIS Benchmarks, NIST SP 800-53 and PBMM.

New environments start compliant

The practical effect is a change in direction of travel. Previously each new subscription began as an unknown and was brought toward compliance afterwards, if someone remembered. Now it begins inside a structure that already carries the controls, and the work shifts from remediation to exception handling — a far smaller and more tractable job for the team that has to sustain it.

Resilience, and knowing where the risk is

Guardrails stop an estate drifting, but they do not tell you what you are carrying or get you back after a bad day. Two workstreams ran alongside the landing zone to cover both.

A cloud risk register on CAF
A register built on the Cloud Adoption Framework and maintained over the engagement, covering compliance, security, cost, operations, data and AI — so risk is a tracked list with owners rather than institutional memory.
Secure backup and recovery
Azure backup for SQL Server with encryption and long-term retention, and a Storage Account strategy using geo-redundancy and immutability so backups survive the incident that made them necessary.
Patch and vulnerability management
Azure Update Manager deployed for automated OS patching, closing the gap between a vulnerability being published and the estate actually being updated.

Outcome

New subscriptions inherit their security controls automatically

Want this applied to your estate?

Tell us what you are working on. We reply within one business day.