What each Azure Firewall tier adds, where Basic stops being enough, and how to choose for a hub that many workloads share.
From Azure Landing Zones (Ultra Transcenders: Beyond the Exam) by Tony Rough (coming December 2026)
The firewall is the most expensive and most consequential component in the hub, and the SKU you choose decides which controls you can offer workload teams.
Azure Firewall is a managed, stateful network security service with built-in high availability. In the hub-spoke reference it is the primary egress point from spokes to the internet, can inspect inbound traffic with intrusion detection and prevention rules, and can act as a DNS proxy so that FQDN-based rules work. It comes in three SKUs:
| Capability | Basic | Standard | Premium |
|---|---|---|---|
| Throughput (autoscale) | Up to 250 Mbps | Up to 30 Gbps | Up to 100 Gbps |
| Fat flow support | N/A | 1 Gbps | 10 Gbps |
| Application FQDN filtering (HTTPS/SQL) | Yes | Yes | Yes |
| Network-level FQDN filtering, all ports and protocols | No | Yes | Yes |
| DNS proxy and custom DNS | No | Yes | Yes |
| Web categories | No | Yes | Yes |
| Threat intelligence filtering | Alert only | Yes | Yes |
| Outbound TLS inspection, IDPS, full-path URL filtering | No | No | Yes |
| Availability zones and Firewall Manager | Yes | Yes | Yes |
Learn’s sizing advice is to choose the lowest SKU that meets your security and throughput requirements. Basic suits small or medium environments; Standard adds enterprise features; Premium adds advanced threat protection for sensitive workloads such as payment processing. CAF recommends Premium when you need TLS inspection, IDPS, URL filtering or web categories (web categories are also in Standard).
Several deployment details are easy to miss:
CAF says the landing zone architecture is fully compatible with partner NVAs when an organisation prefers them or when native services don’t meet a requirement. If you go that way, follow the vendor’s guidance to confirm the deployment is supported, highly available and free of conflicting Azure configuration, deploy the NVAs in the central hub (for non-Virtual WAN topologies), and consider Azure Route Server to exchange routes with the NVA over BGP instead of maintaining route tables. The Architecture Center’s case for its own hub includes freedom over NVA sizing and the use of NVAs that Virtual WAN doesn’t support. Learn also notes that a shared Azure Firewall consumed by many workloads can save significant cost compared with other NVAs.
Common pitfall: Starting on Basic and later promising teams FQDN network rules - Basic has no DNS proxy and only application-level FQDN filtering, while FQDN filtering in network rules needs the DNS proxy; decide which controls the platform offers before choosing the SKU.
This note is one section of Azure Landing Zones: Building an Azure Foundation with the Cloud Adoption Framework, an independent guide in the Ultra Transcenders Beyond the Exam series, with comparison tables, diagrams, the common pitfalls and tested companion code, plus a glossary linked to Microsoft Learn.
Due on Amazon in December 2026, in Kindle and paperback editions.
About the book · Azure Landing Zones terms in the glossary · All free notes from Azure Landing Zones
The four environment and four compliance design areas of the Cloud Adoption Framework, what each one decides, and which team usually owns it.
What a first platform landing zone needs on day one, what can safely wait, and how to grow it without redesigning later.
The intermediate root, Platform, Landing zones, Sandboxes and Decommissioned groups: what each is for and why the hierarchy stays shallow.
The factors that decide between a customer-managed hub and Azure Virtual WAN, and the constraints that can make the choice for you.
How central private DNS zones and DeployIfNotExists policy register private endpoint records automatically, and the permissions it needs.
When to use Audit, Deny, DeployIfNotExists, Modify and DenyAction in a landing zone, and what each commits you to.
How the two infrastructure-as-code options compare for deploying and running an Azure landing zone, and what decides the choice.