FREE NOTES · AZURE LANDING ZONES

Bicep or Terraform for an Azure landing zone platform

How the two infrastructure-as-code options compare for deploying and running an Azure landing zone, and what decides the choice.

From Azure Landing Zones (Ultra Transcenders: Beyond the Exam) by Tony Rough (coming December 2026)

Both languages are fully supported for the platform landing zone, so the choice rests on how each behaves over years of updates, not on whether it can deploy the first release.

Aspect Bicep Terraform
State None; relies on Azure deployments and incremental mode State file mapping code to real resources; must be stored remotely, backed up and secured
Targets Azure only Azure, other clouds, on-premises and other APIs through providers
Preview what-if, run by Resource Manager terraform plan, computed by the client from state and code
Processing Service side, with preflight validation including Azure Policy Client side; a policy denial surfaces when the resource is deployed
Removing resources Complete mode at some scopes, or deployment stacks Tracked in state; the lifecycle meta-argument controls handling, and destroy removes everything a configuration manages
Out-of-band changes Don’t block deployment; reconcile them in code to avoid overwriting Import into state and update the code; Learn advises minimising them
New Azure features Immediate support AzureRM provider for a tailored experience, AzAPI for immediate support
Authentication One token for the deployment; Resource Manager checks permissions Per provider credentials; several can be used in one configuration
Platform landing zone AVM-based accelerator and modules AVM-based accelerator and modules

Learn’s comparison concludes that multicloud or hybrid automation favours Terraform, and that if your environment involves frequent out-of-band changes Bicep is more forgiving. Team skills and your existing pipelines usually decide the rest.

Terraform state is part of the platform

Terraform state is stored in plain text and can contain secrets, so Learn treats it as sensitive. Keep it remotely in an Azure Storage blob container, never locally or in the repository: local state doesn’t work for teams and is easily deleted. Blob storage locks state automatically during writes, preventing corruption from concurrent runs, and encrypts it at rest. Learn’s sample uses an access key, but its own key points tell you to evaluate the backend’s authentication options for production and to restrict network access with a storage firewall, service endpoint or private endpoint. For stateful resources it suggests prevent_destroy in a lifecycle block and a careful review of every plan for unexpected replacements. The accelerator’s bootstrap, described later, creates the state storage and grants the pipeline identities access to it, which settles most of these decisions for you.

Bicep and deployment stacks

A deployment stack manages a set of resources as one unit. When a resource is removed from the template, the stack detaches it by default, or deletes it if actionOnUnmanage is set to delete; deny settings can also block changes to managed resources outside the stack. Stacks can be created at resource group, subscription or management group scope. The AVM-based Bicep accelerator uses management group deployment stacks with DeleteAll, so policy assignments removed from a new ALZ library version are cleaned up on the next deployment. Its documentation says its CI pipelines preview changes with standard deployments because stacks didn’t support what-if when the pipelines were built, and those previews may not show deletions exactly. Learn now documents what-if for deployment stacks, which reports resources that will be deleted or detached, so check whether your pipeline version has moved to it.

Common pitfall: Keeping Terraform state on a laptop or committing it to the repository - Learn warns that state is plain text, can include secrets and is easily lost when local; use a locked, encrypted Azure Storage backend with restricted network access and identity-based access for the pipeline.

Common pitfall: Assuming an incremental Bicep deployment removes what you deleted from the template - incremental deployments leave removed resources in place; use deployment stacks (or Complete mode where supported) and check the stack’s actionOnUnmanage setting, because the default only detaches.

Get the whole book

This note is one section of Azure Landing Zones: Building an Azure Foundation with the Cloud Adoption Framework, an independent guide in the Ultra Transcenders Beyond the Exam series, with comparison tables, diagrams, the common pitfalls and tested companion code, plus a glossary linked to Microsoft Learn.

Amazon.co.ukKindle: coming soonPaperback: coming soon
Amazon.comKindle: coming soonPaperback: coming soon

Due on Amazon in December 2026, in Kindle and paperback editions.

About the book · Azure Landing Zones terms in the glossary · All free notes from Azure Landing Zones

More free notes from Azure Landing Zones