FREE NOTES · AZURE LANDING ZONES

Azure Firewall Basic, Standard or Premium for a landing zone hub

What each Azure Firewall tier adds, where Basic stops being enough, and how to choose for a hub that many workloads share.

From Azure Landing Zones (Ultra Transcenders: Beyond the Exam) by Tony Rough (coming December 2026)

The firewall is the most expensive and most consequential component in the hub, and the SKU you choose decides which controls you can offer workload teams.

Azure Firewall is a managed, stateful network security service with built-in high availability. In the hub-spoke reference it is the primary egress point from spokes to the internet, can inspect inbound traffic with intrusion detection and prevention rules, and can act as a DNS proxy so that FQDN-based rules work. It comes in three SKUs:

Capability Basic Standard Premium
Throughput (autoscale) Up to 250 Mbps Up to 30 Gbps Up to 100 Gbps
Fat flow support N/A 1 Gbps 10 Gbps
Application FQDN filtering (HTTPS/SQL) Yes Yes Yes
Network-level FQDN filtering, all ports and protocols No Yes Yes
DNS proxy and custom DNS No Yes Yes
Web categories No Yes Yes
Threat intelligence filtering Alert only Yes Yes
Outbound TLS inspection, IDPS, full-path URL filtering No No Yes
Availability zones and Firewall Manager Yes Yes Yes

Learn’s sizing advice is to choose the lowest SKU that meets your security and throughput requirements. Basic suits small or medium environments; Standard adds enterprise features; Premium adds advanced threat protection for sensitive workloads such as payment processing. CAF recommends Premium when you need TLS inspection, IDPS, URL filtering or web categories (web categories are also in Standard).

Several deployment details are easy to miss:

When an NVA is justified

CAF says the landing zone architecture is fully compatible with partner NVAs when an organisation prefers them or when native services don’t meet a requirement. If you go that way, follow the vendor’s guidance to confirm the deployment is supported, highly available and free of conflicting Azure configuration, deploy the NVAs in the central hub (for non-Virtual WAN topologies), and consider Azure Route Server to exchange routes with the NVA over BGP instead of maintaining route tables. The Architecture Center’s case for its own hub includes freedom over NVA sizing and the use of NVAs that Virtual WAN doesn’t support. Learn also notes that a shared Azure Firewall consumed by many workloads can save significant cost compared with other NVAs.

Common pitfall: Starting on Basic and later promising teams FQDN network rules - Basic has no DNS proxy and only application-level FQDN filtering, while FQDN filtering in network rules needs the DNS proxy; decide which controls the platform offers before choosing the SKU.

Get the whole book

This note is one section of Azure Landing Zones: Building an Azure Foundation with the Cloud Adoption Framework, an independent guide in the Ultra Transcenders Beyond the Exam series, with comparison tables, diagrams, the common pitfalls and tested companion code, plus a glossary linked to Microsoft Learn.

Amazon.co.ukKindle: coming soonPaperback: coming soon
Amazon.comKindle: coming soonPaperback: coming soon

Due on Amazon in December 2026, in Kindle and paperback editions.

About the book · Azure Landing Zones terms in the glossary · All free notes from Azure Landing Zones

More free notes from Azure Landing Zones