Azure

A landing zone before a lift and shift

Most Azure estates we inherit were built one resource group at a time: flat networks, subscriptions named after whoever created them, and a bill nobody can attribute. We start with the boring layer that makes everything after it cheap to change.


Foundation first, workloads second

Identity, subscription topology, naming, tagging, policy and network hub come first — usually inside the first fortnight. Once that exists, moving a workload is a small, reversible piece of work instead of a negotiation.

Everything is delivered as Bicep or Terraform you keep, in a repository you own, documented in language your next engineer can read without ringing us.

Entra IDBicep & TerraformAzure PolicyVirtual WANAzure Backup & ASRAzure Migrate

Migration waves

What moves, when, and what it costs

WaveScopeTypical duration
FoundationTenant, identity, subscriptions, policy, hub network2 weeks
File & printFile servers to SharePoint or Azure Files, print to Universal Print2–3 weeks
ServersAzure Migrate assessment, rehost, right‑size, decommission on‑premises3–6 weeks
DataSQL to Managed Instance or Azure SQL, backup and retention set3–5 weeks
OptimiseReservations, savings plans, Hybrid Benefit, monthly cost reviewOngoing

Durations are indicative for a 10–100 seat estate. Each wave is quoted and approved on its own, so you can stop after any one of them.