The architecture Microsoft recommends for running a multi-subscription Azure environment that is governed, secure and able to scale. It consists of a single platform landing zone plus workload landing zones operating inside the guardrails it provides.
Also called ALZ.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains Azure landing zone in context, with comparison tables and the common traps.
Terms in this definition
- Azure Machine Learning environment
Versioned asset that pairs a Docker image with a pip or conda specification, so every job or deployment using it gets identical dependencies. You point to it by name plus a version number, or by name with @latest.
- HTTP / HTTPS
The protocols of the web, with HTTPS being HTTP secured by TLS.
- Platform landing zone
Typically one per Microsoft Entra tenant, this is the shared core that everything else rests on. It comprises the management group structure, common services for networking, identity, management and security, and the route by which teams receive their own landing zones.
- Workload
Also called an experience: a Fabric toolset aimed at one job role, e.g. Data Factory, Data Engineering, Data Warehouse, Real-Time Intelligence or Power BI. Each keeps its data in OneLake.
Related terms
- AI landing zone
There is no distinct AI landing zone to build. According to the Azure landing zone FAQ, AI workloads simply go into normal workload landing zones beneath the platform you already have.
- Azure Governance Visualizer
An open-source script that produces a report on a tenant's governance setup, including management groups, policy and RBAC, and highlights Azure landing zone policies that are out of date or obsolete. The Architecture Center offers an accelerator for running it.
- Local management group
Azure Local clusters, and the workloads they run, go in this management group of the Azure landing zone hierarchy, because their policy needs differ from those of the other landing zones.
- Platform automation and DevOps
One of the Azure landing zone design areas. It brings DevOps tools, templates and ways of working into line with how the landing zone evolves, so the platform is built and updated by pipelines running infrastructure as code.
- Policy-driven governance
Compliance enforced through Azure Policy guardrails regardless of which deployment tool is used, a core Azure landing zone principle; it is what makes it safe to give workload teams their own subscriptions.
- Security design area
Of the Azure landing zone design areas, this one deals with the protective controls and processes baked into the platform, drawing on the broader advice in the Cloud Adoption Framework's Secure methodology.
- Sovereign Landing Zone
Builds on the Azure platform landing zone's design principles and library, adding sovereignty measures such as keeping data in a region, customer-managed keys and confidential computing. It is not meant to replace an Azure landing zone already in place.
- Starter module
A choice made while bootstrapping the Azure landing zone IaC accelerator: which template the platform code starts from, for example platform_landing_zone (offered in Bicep and Terraform). You then pick a scenario and set its options.