
Building an Azure Foundation with the Cloud Adoption Framework · by Tony Rough
Make the landing zone decisions that last, then build them as code.
Due on Amazon in December 2026, in Kindle and paperback editions.
This independent guide follows Microsoft's Cloud Adoption Framework through every design area of an Azure landing zone, explains what each decision commits you to, and then builds the result as code. It is written for engineers and architects who already know the individual Azure services and now have to design, build or run an estate of many subscriptions.
Azure changes quickly. This edition reflects Microsoft's documentation as of October 2026, including the move from application to workload landing zones, the Azure Verified Modules-based accelerator and the trimmed Cloud Adoption Framework scenarios.
Written by Tony Rough, a cloud architect with more than twenty years in IT infrastructure who designs Azure landing zones and holds the Azure Solutions Architect Expert, Azure Administrator and Azure Security Engineer certifications.
Part of the Ultra Transcenders series from Distilled Press: Beyond the Exam. An independent publication, not affiliated with, sponsored by or endorsed by Microsoft Corporation.
Start with the exam books this one builds on:
Know which role, setting or tool does the job, and why.
Free with Kindle Unlimited
Choose the right design, and explain why.
Free with Kindle Unlimited
Plus an appendix glossary of 300+ terms, each linked to Microsoft Learn, with the same terms explained free online for print readers.



Some sections of the book, free to read online:
The four environment and four compliance design areas of the Cloud Adoption Framework, what each one decides, and which team usually owns it.
What a first platform landing zone needs on day one, what can safely wait, and how to grow it without redesigning later.
The intermediate root, Platform, Landing zones, Sandboxes and Decommissioned groups: what each is for and why the hierarchy stays shallow.
What each Azure Firewall tier adds, where Basic stops being enough, and how to choose for a hub that many workloads share.
The factors that decide between a customer-managed hub and Azure Virtual WAN, and the constraints that can make the choice for you.
How central private DNS zones and DeployIfNotExists policy register private endpoint records automatically, and the permissions it needs.
When to use Audit, Deny, DeployIfNotExists, Modify and DenyAction in a landing zone, and what each commits you to.
How the two infrastructure-as-code options compare for deploying and running an Azure landing zone, and what decides the choice.