Secure Azure networking baseline: a practical foundation for landing zones
A runbook-style secure networking baseline for Azure: hub/spoke vs vWAN, DNS ownership, private endpoints, egress control, and inbound protection. Built to scale.
Focus area
Azure changed. Here’s what to do about it.
Connectivity change notes and the Azure updates worth acting on.
What changed in Azure networking, who it actually affects, and the steps to prepare — written up the same way as the baselines.
Basic SKU public IPs have retired. Azure VPN Gateway offers portal-based migration to Standard Public IP on active-active gateways — who’s affected, and the runbook to get off Basic safely.
Jump into the guided path, or browse everything if you’re after something specific.
Hop between landing zones, identity, networking, and more.
Search
Type an Azure service, control, or tag. Results refresh after every deploy.
Examples: landing zone policy, workload identity, vpn gateway