Azure Landing Zone: 4-Weeks Design and Implementation

Mismo Systems LLP

We help you design and build a secure, scalable, and compliant Azure foundation with Azure Landing Zone that enables application migration, modernization, and innovation at enterprise-scale in Azure


Azure Landing Zone is the result of a multi-subscription environment focused on Scale, Security, Governance, Networking, and Identity & Access Management. Our Azure Architect will conduct a series of workshop covering different design areas of Cloud Platform. We will assess the existing Azure Landing Zone, identify gaps, and provide recommendations based on the Microsoft Cloud Adoption Framework for Azure enterprise-scale landing zone architecture.

What Mismo Systems offers

Azure Landing Zone - Design (2 weeks)

  • Conduct design workshops to present, discuss and explore initial Azure design proposals. The Design Workshops will align with the following 8 design areas of the Azure Landing Zone:
  • Azure billing and Active Directory tenant
  • Identity and access management
  • Network topology and connectivity
  • Resource organization
  • Security
  • Management
  • Governance
  • Platform automation and DevOps
  • Assist the customer in reaching design decisions for the implementation of the components under each design area, including Management Groups hierarchy, Subscriptions, Naming and Tagging, Identity and Access Management, Network design, Security, Compliance, and Governance, BCDR and Automation.
  • Capture additional design requirements that are iteratively inherited.
  • Finalize the Azure Landing Zone Design

Azure Landing Zone – Implementation (2 weeks)

  • Resource organization
  • Management Group hierarchy and subscription structure
  • Naming and Tagging Standards
  • Resource Groups
  • Network Topology and Connectivity
  • Hub and Spoke network topology implementation
  • Connectivity with on-premises, using Express Route or Site-to-site VPN
  • Connectivity with all spoke’s networks in platform and application landing zones
  • Network Security Groups
  • User Defined Routs
  • Management and Monitoring
  • Azure Monitor -basic implementation
  • Log Analytics workspace
  • Centralized Key Vault for Management
  • Security and Governance
  • Default Security benchmark
  • Cost Management and alerts
  • Network security
  • Microsoft Defender for Cloud


  • Up to 6 design workshops to present, discuss and explore Azure design proposals
  • Azure Landing Zone design documentation
  • Azure Landing Zone implementation as per the finalized design
  • No Resource/Application creation or Migration is included in this project