Assess, fix, keep it that way

EdgeReadyEdgeResolveEdgeAssure

For investors

EdgeSignalAll services
How it works Find your path Case studies Security About What we take on Book a 20-minute triage call
Subscription architecture

One Azure subscription holding everything, redesigned into a proper management group hierarchy.

Production, staging, security tooling and shared services all sat inside a handful of overloaded Azure subscriptions. A mistake in one had nowhere else to reach — which was the point, once the subscriptions existed to contain it.

← Some of our past work · anonymised prior delivery, no client named

Stack

Management groupsAzure PolicyMicrosoft Entra IDAzure MonitorTerraform

Rough timeline

PhaseTypical duration
Target subscription design1 week
Subscription vending and guardrails2–3 weeks
Workload migration, phased2–6 weeks
The challenge

Blast radius was the whole estate, by construction.

Nobody had decided to run everything in a handful of subscriptions. It was simply the order things had been built, and nobody had gone back to change it.

One mistake, whole-estate reach

An over-broad role assignment in one workload could reach every other workload sharing the subscription.

Security tooling watched the thing it was part of

Activity logs and Microsoft Defender for Cloud findings lived in the same subscription as the workloads they were meant to catch problems in.

Ownership was a conversation, not a boundary

Shared services, one-off scripts and production workloads sat together with the same broad role assignments.

What we found

Standing admin access everywhere, and a network boundary that did not exist.

None of these were dramatic on their own. Together they meant the subscription boundary reflected history, not risk.

Owner was a standing role, not an activated one

Several engineers held the built-in Owner role at the subscription scope permanently, rather than through time-limited elevation for the moments they actually needed it.

Staging and production shared a virtual network

A staging misconfiguration was one route table away from a production one.

Subscriptions did not match ownership

The subscriptions reflected the order things were built, not who was actually responsible for what ran in them.

What InfraEdge changed

A platform management group, a dedicated logging subscription, and guardrails enforced as policy.

Separating identity, logging and workloads holds regardless of which cloud it is built on.

ChangeWhat it did
Management group hierarchyA root management group with Platform and Landing Zones underneath it, the latter split into Production and Non-production. Every subscription sits under exactly one, so a policy assigned at the management group applies to everything beneath it.
Dedicated logging subscriptionActivity logs and diagnostic settings from every subscription route to a Log Analytics workspace owned by a subscription that runs no workloads of its own, isolated from what it watches.
Connectivity subscriptionShared networking — the hub virtual network, firewall and gateway — moved out of any workload subscription and into its own.
Non-production landing zoneNon-production workloads separated from anything customer-facing, under policy that is looser but still enforced, not absent.
Centralised identity, time-limited elevationMicrosoft Entra ID as the single sign-in, with Privileged Identity Management requiring elevated roles to be activated for a limited window rather than held permanently.
Guardrails as policyAzure Policy assigned at the management group enforces the boundaries — denying deployment outside approved regions, auditing storage accounts left open to the internet — so the boundary holds against a well-intentioned mistake.
Outcome

The subscription boundary now matches where the risk actually sits.

A mistake in a non-production subscription no longer has a path into production, and a compromised workload identity no longer has one into the logging subscription used to investigate it. The cross-subscription role assignments that provided those paths were removed; what remains is enforced by policy at the management group.

Cleaner ownership fell out of the same change: each subscription has a name and an owner, not a role assigned by history. Where the client’s platform function was still one person deep, InfraEdge helped scope the role and vet candidates for the infrastructure hire who now owns the hierarchy day to day.

Book a 20-minute triage call

Twenty minutes, no charge. We work out what would actually help — which is sometimes us and sometimes not. Nothing is priced on the call; if there is work worth doing, a written scope and a price reach you within 24 hours.