Cloud / Azure

Azure architecture, identity and cost review.

An Azure tenant where identity grew by exception. We review it and write the fixes down.

Azure services

What we examine on Azure.

Entra ID

Privileged roles, conditional access gaps, legacy authentication and standing global administrators.

Management groups

Subscription placement, inherited assignments and the landing zone that drifted.

Azure Policy

Whether policies audit or actually deny, and what the exemptions quietly allow.

Defender for Cloud

Plan coverage per subscription, secure score signal, and who acts on it.

Cost

Reservations and savings plan coverage, orphaned disks, and non-production running a production SKU.

Failure modes

What we find on Azure estates.

  • Conditional access enforced for staff but bypassed by a service principal.
  • Azure Policy left in audit mode for a year, so nothing was ever blocked.
  • Standing Global Administrator instead of eligible assignment through PIM.
  • Defender plans enabled on one subscription and off on the one holding customer data.
  • A landing zone deployed once, then every new subscription placed outside it.
How to start

Three reviews, one platform.

Questions before you book

Practical answers.

Are you a Microsoft partner?

No. We hold no Microsoft partner competency. Nothing in the review is shaped by a vendor arrangement.

Do you cover Microsoft 365 as well?

Only where it touches the identity boundary under review. A full tenant assessment is a separate scope.

Do you work in Australia East?

Yes. Residency in the Australian regions is part of the review for Australian buyers.

Let’s scope it

Scope a Azure review.

Send the accounts in scope and what prompted the question. We confirm scope and fee before any access.

Request a quote

Last reviewed: