Enterprise Capstone: Design a Regulated Azure Landing Zone and AI Workload
This capstone designs a regulated enterprise platform and onboards Northstar as a private AI workload. The deliverable is an evidence-backed architecture, code plan, threat model, policy set, operations model, cost forecast, and tested proof of concept. Do not deploy enterprise-wide controls into a live tenant without the required authority and change process.
Method note: The capstone is an architecture and approval exercise spanning many services, not an interchangeable Portal-versus-code procedure. Use the implementation alternatives in the governance, private networking, recovery, and AI service chapters to build the authorized proof of concept.
Scenario
A global organization requires:
- Production and non-production subscriptions.
- Primary and recovery Azure regions with stated residency.
- ExpressRoute primary and VPN backup.
- No public access to storage, databases, search, model endpoints, or management APIs beyond approved edge services.
- Entra identity, PIM, workload federation/managed identity, and central emergency access.
- Central Defender/Sentinel and controlled logs.
- Governed RAG with synthetic regulated-document patterns.
- RTO 4 hours and RPO 30 minutes for the critical journey.
- Per-workload budgets and chargeback.
What architecture must you produce?
- Management-group/subscription hierarchy.
- Identity/admin/support access model.
- Hub-spoke or Virtual WAN route and DNS diagrams.
- Ingress/egress, Firewall, WAF, DDoS, and private endpoint design.
- Management/monitoring/Sentinel/Defender data flows.
- Workload compute, storage, database, AI Search, Foundry, and Key Vault.
- Backup, region recovery, traffic, and data consistency design.
- CI/CD/GitOps and artifact flow.
- Data classification, lineage, retention, deletion, and AI evaluation.
- Cost allocation and capacity/quota model.
What policy initiative should you design?
At minimum, audit or enforce by scoped rollout:
- Allowed regions and approved resource types/SKUs.
- Required workload/owner/data-classification tags.
- Public network access disabled for protected PaaS.
- Secure transfer/TLS baseline.
- Managed identity and approved authentication.
- Diagnostic settings to central destinations.
- Defender plans and vulnerability controls.
- Encryption/key requirements for the regulated class.
- Backup protection and private DNS patterns.
Include exemption owner, justification, compensating control, and expiry.
How do you prove the platform boundaries?
Run tests in a canary subscription:
- Workload deployer cannot change management-group policy or hub firewall.
- Platform network operator cannot read application data.
- Security responder can investigate without permanent workload Owner.
- App identity can reach only approved search/storage/vault/model endpoints.
- Unapproved public endpoint creation is denied.
- Hybrid DNS resolves private names; internet clients do not.
- Central logs detect a denied policy change and unusual secret access.
How do you prove recovery?
Deploy the secondary region baseline and reserve/confirm capacity for critical services. Execute a controlled failover exercise:
- Declare simulated regional loss.
- Validate replicated/restored authoritative data.
- Deploy/scale secondary compute and regional AI dependencies.
- Verify identities, DNS, certificates, private routes, and quotas.
- Switch synthetic traffic.
- Run the critical user journey and access-leak tests.
- Measure RTO/RPO.
- Reconcile and fail back.
If Microsoft Foundry model availability differs by region, use an already evaluated fallback and record the quality difference.
What evidence goes to the approval board?
- Architecture decision records and diagrams.
- Threat model/privacy/data-impact assessment.
- IaC plans and policy compliance report.
- RBAC/PIM and emergency-access test.
- Penetration/red-team and AI evaluation summaries.
- Load/capacity/quota and regional failover results.
- Backup restore result.
- Monitoring/incident runbooks and alert tests.
- Cost forecast, unit economics, and commitments plan.
- Residual risk register with owners/expiry.
Scoring rubric
- 20% identity/security/data protection.
- 20% network/DNS/hybrid correctness.
- 15% AI governance and evaluation.
- 15% reliability/recovery evidence.
- 10% policy/landing-zone repeatability.
- 10% operations/observability/incident response.
- 10% cost and organizational operating model.
The capstone passes only if critical access-leak, public-exposure, restore, or regional-capacity risks are resolved or explicitly block launch.