Blogs

6 minutes

Streamlining Azure governance with Azure resource management

Effective management of Microsoft Azure resources is essential for maintaining control over your cloud environment, ensuring robust security and compliance, as well as optimizing costs. Ergo, an Azure Expert MSP, and its Microsoft licensing consultancy subsidiary Micromail work closely with customers to advise them on best way how to organise their cloud resources and optimise cloud investments.

In this blog post, we will explore the basics of Azure cloud resource organisation and best practices we recommend organisations to follow.

Getting started with resource organisation

Resource organisation is one of the design areas of Azure Landing Zones. This aspect is vital for organizations aiming for scalable cloud adoption. A streamlined management group and subscription design, aligned with best practices, can significantly influence adoption, improve cloud governance and operational efficiency.

There are 4 levels of Azure resource management, as shown below:

What are Azure Management groups

On the top of the hierarchy, there are Management Groups. As organizations expand their use of Azure, controlling multiple subscriptions becomes increasingly complex. Management groups provide a structured way to organize and govern subscriptions, ensuring efficient and effective management. All subscriptions within a management group automatically inherit the conditions applied to the management group.

To get started with Azure management groups, we recommend the following:

• Separation Considerations: Evaluate the need for separate functions based on business, operational, regulatory, data residency, security and compliance, or sovereignty requirements. For instance, while the best practise is to utilise the standard Azure landing zone management group structure for multiregional deployments, if your organisation has specific location-based compliance requirements, consider creating a management group structure based on those locations.

Leverage management groups to consolidate policy and initiative assignments using Azure Policy.

Enhance authorization controls for management group by enabling Azure role-based access control (RBAC) to override default settings. If you’d like to learn more about protecting your cloud resources, please read our blog about Microsoft Defender for Cloud.

What are Azure Subscriptions

Subscriptions are a unit of management, billing, and scale within Microsoft Azure. They provide control over resource usage reporting and payments. Each subscription can have unique billing arrangements, allowing for differentiation by office, department, or project. Similarly to management groups, they play a critical role when you design for large-scale Azure adoption.

From our experience, sometimes there is a confusion between Azure Subscription and other units of resource organisation. Let’s explore the most common ones:

• What is the difference between Azure subscription and an account?
Azure subscriptions group resources and assign an owner responsible for billing and permissions management. An Azure account represents the billing relationships.

• What is the difference between Azure subscription and a tenant?
An Azure Tenant is an exclusive instance of Azure Active Directory that corresponds to an organization’s Azure subscription. When an organization subscribes to Azure, Microsoft creates a new Azure Tenant specifically for that organization. This Tenant is connected to the subscription and governs all the resources and services used within Azure.

• What is the difference between Azure Subscription and Resource Groups?
Resource Groups are the next level of resource organisation under Azure subscription. They serve as a container for deploying and managing Azure resources, such as applications or databases. The resource group can include all the resources for the solution, or only those resources that you want to manage together.

Key considerations for planning and creating Azure subscriptions:

Organisation and Cloud Governance Recommendations

Inform Subscription Owners of their roles and responsibilities:

Conduct quarterly or yearly access reviews using Microsoft Entra Privileged Identity Management.

Subscription owners should take ownership of budget spending and resource management.

Ensure policy compliance and address any issues promptly.

New Subscription Requirements: Follow these principles when identifying the need for new subscriptions:

• Scale Limits: For high-volume workloads, it’s recommended to use separate subscriptions to avoid hitting platform limits.

• Management Boundary: For management purposes, it’s recommended separating development, test and production environments.

• Policy Boundary: Subscriptions serve as boundaries for Azure Policy assignments, ensuring compliance for secure workloads without additional overhead.

• Network Topology: Consider which workloads need to communicate with each other when deciding on new subscriptions.

• Group Subscriptions: Organise subscriptions under management groups aligned with your management structure and policy requirements. Ensure subscriptions with similar policies and Azure role assignments are grouped together.

• Use Flexible Grouping Criteria: Use flexible criteria to group subscriptions, allowing for adjustments as your organisation’s structure and workload composition change. Avoid an one-size-fits-all approach, as different business units may have varying needs.

Quota and Capacity Recommendations

• Scale Out Resources: Expand resources and subscriptions as needed to avoid hitting Azure platform limits.

• Capacity Reservations: Use capacity reservations to ensure availability for high-demand resources in specific regions.

• Monitoring Dashboard: Set up a custom dashboard to monitor capacity levels and configure alerts for critical thresholds, such as 90% CPU usage.

• Quota Limits: Ensure quota limits are set before workloads exceed default limits.

Tenant Transfer Restriction Recommendations

Prevent Subscription Transfers: Configure settings to prevent users from transferring Azure subscriptions to or from your Microsoft Entra tenant:

  • Set “Subscription leaving Microsoft Entra directory” to “Permit no one.”
  • Set “Subscription entering Microsoft Entra directory” to “Permit no one.”

Exempted Users: Configure a limited list of exempted users, including:

  • Members of the Azure platform operations team.
  • Accounts to be used in case of emergency.

Cost Management and optimisation

Optimising and controlling cost in Azure is vital to ensure best value for money and avoid overspend. Fortunately, Microsoft offers the tools to manage and govern Azure costs using the Cost Management blade in Azure Portal.

Collaboration with an experienced Azure specialist like Ergo and Micromail can ensure that the correct Cost Management settings are implemented for your organisation, and you are getting the best value out of the toolset. Some important areas where a partner delivered Cost Management solution can help:

  • Setting cost alerts will flag sudden changes or budget thresholds. This can avoid unexpected bills and highlight potentials mistakes in Azure implementation
  • If internal cross billing of Azure services is needed then this can only be effectively managed utilising Cost Management resources
  • Internal reporting on growing Azure spend can easily be delivered via Cost Management solutions.

Talk to us about your requirements

If you’d like to learn more about how Micromail can help you with optimising Azure resource management, please fill in the form below.

Related Blogs

                            Array
(
    [ID] => 82145
    [id] => 82145
    [title] => Web Banner (2)
    [filename] => Web-Banner-2.png
    [filesize] => 1172033
    [url] => https://ergotechnologygroup.com/wp-content/uploads/2024/08/Web-Banner-2.png
    [link] => https://ergotechnologygroup.com/events/microsoft-fabric-webinar/attachment/web-banner-2-2/
    [alt] => 
    [author] => 18
    [description] => 
    [caption] => 
    [name] => web-banner-2-2
    [status] => inherit
    [uploaded_to] => 81337
    [date] => 2024-08-29 14:44:08
    [modified] => 2024-08-29 14:44:08
    [menu_order] => 0
    [mime_type] => image/png
    [type] => image
    [subtype] => png
    [icon] => https://ergotechnologygroup.com/wp-includes/images/media/default.png
    [width] => 1500
    [height] => 867
    [sizes] => Array
        (
            [thumbnail] => https://ergotechnologygroup.com/wp-content/uploads/2024/08/Web-Banner-2-150x150.png
            [thumbnail-width] => 150
            [thumbnail-height] => 150
            [medium] => https://ergotechnologygroup.com/wp-content/uploads/2024/08/Web-Banner-2-300x173.png
            [medium-width] => 300
            [medium-height] => 173
            [medium_large] => https://ergotechnologygroup.com/wp-content/uploads/2024/08/Web-Banner-2-768x444.png
            [medium_large-width] => 768
            [medium_large-height] => 444
            [large] => https://ergotechnologygroup.com/wp-content/uploads/2024/08/Web-Banner-2-1024x592.png
            [large-width] => 1024
            [large-height] => 592
            [1536x1536] => https://ergotechnologygroup.com/wp-content/uploads/2024/08/Web-Banner-2.png
            [1536x1536-width] => 1500
            [1536x1536-height] => 867
            [2048x2048] => https://ergotechnologygroup.com/wp-content/uploads/2024/08/Web-Banner-2.png
            [2048x2048-width] => 1500
            [2048x2048-height] => 867
        )

)
1
                            

Blogs

The Evolution of Microsoft Fabric

                            Array
(
    [ID] => 98211
    [id] => 98211
    [title] => SON5860-001 1-min
    [filename] => SON5860-001-1-min-scaled.jpg
    [filesize] => 583117
    [url] => https://ergotechnologygroup.com/wp-content/uploads/2025/01/SON5860-001-1-min-scaled.jpg
    [link] => https://ergotechnologygroup.com/insights/blogs/dell-apex-cloud-platform-for-microsoft-azure-certified-partner/attachment/son5860-001-1-min/
    [alt] => Dell APEX Cloud Platform for Azure certified partner in Ireland
    [author] => 18
    [description] => 
    [caption] => 
    [name] => son5860-001-1-min
    [status] => inherit
    [uploaded_to] => 98210
    [date] => 2025-01-31 09:54:34
    [modified] => 2025-01-31 09:55:35
    [menu_order] => 0
    [mime_type] => image/jpeg
    [type] => image
    [subtype] => jpeg
    [icon] => https://ergotechnologygroup.com/wp-includes/images/media/default.png
    [width] => 2560
    [height] => 1754
    [sizes] => Array
        (
            [thumbnail] => https://ergotechnologygroup.com/wp-content/uploads/2025/01/SON5860-001-1-min-150x150.jpg
            [thumbnail-width] => 150
            [thumbnail-height] => 150
            [medium] => https://ergotechnologygroup.com/wp-content/uploads/2025/01/SON5860-001-1-min-300x206.jpg
            [medium-width] => 300
            [medium-height] => 206
            [medium_large] => https://ergotechnologygroup.com/wp-content/uploads/2025/01/SON5860-001-1-min-768x526.jpg
            [medium_large-width] => 768
            [medium_large-height] => 526
            [large] => https://ergotechnologygroup.com/wp-content/uploads/2025/01/SON5860-001-1-min-1024x702.jpg
            [large-width] => 1024
            [large-height] => 702
            [1536x1536] => https://ergotechnologygroup.com/wp-content/uploads/2025/01/SON5860-001-1-min-1536x1053.jpg
            [1536x1536-width] => 1536
            [1536x1536-height] => 1053
            [2048x2048] => https://ergotechnologygroup.com/wp-content/uploads/2025/01/SON5860-001-1-min-2048x1403.jpg
            [2048x2048-width] => 2048
            [2048x2048-height] => 1403
        )

)
1
                            
Dell APEX Cloud Platform for Azure certified partner in Ireland

Blogs

Ergo becomes first Dell APEX Cloud Platform for Microsoft Azure certified partner in Ireland

                            Array
(
    [ID] => 96577
    [id] => 96577
    [title] => iStock-1331397297-min
    [filename] => iStock-1331397297-min.jpg
    [filesize] => 277161
    [url] => https://ergotechnologygroup.com/wp-content/uploads/2025/01/iStock-1331397297-min.jpg
    [link] => https://ergotechnologygroup.com/insights/blogs/tech-trends-for-2025/attachment/istock-1331397297-min/
    [alt] => tech trends for 2025 blog
    [author] => 18
    [description] => 
    [caption] => 
    [name] => istock-1331397297-min
    [status] => inherit
    [uploaded_to] => 96496
    [date] => 2025-01-14 09:47:11
    [modified] => 2025-01-14 09:47:44
    [menu_order] => 0
    [mime_type] => image/jpeg
    [type] => image
    [subtype] => jpeg
    [icon] => https://ergotechnologygroup.com/wp-includes/images/media/default.png
    [width] => 1254
    [height] => 836
    [sizes] => Array
        (
            [thumbnail] => https://ergotechnologygroup.com/wp-content/uploads/2025/01/iStock-1331397297-min-150x150.jpg
            [thumbnail-width] => 150
            [thumbnail-height] => 150
            [medium] => https://ergotechnologygroup.com/wp-content/uploads/2025/01/iStock-1331397297-min-300x200.jpg
            [medium-width] => 300
            [medium-height] => 200
            [medium_large] => https://ergotechnologygroup.com/wp-content/uploads/2025/01/iStock-1331397297-min-768x512.jpg
            [medium_large-width] => 768
            [medium_large-height] => 512
            [large] => https://ergotechnologygroup.com/wp-content/uploads/2025/01/iStock-1331397297-min-1024x683.jpg
            [large-width] => 1024
            [large-height] => 683
            [1536x1536] => https://ergotechnologygroup.com/wp-content/uploads/2025/01/iStock-1331397297-min.jpg
            [1536x1536-width] => 1254
            [1536x1536-height] => 836
            [2048x2048] => https://ergotechnologygroup.com/wp-content/uploads/2025/01/iStock-1331397297-min.jpg
            [2048x2048-width] => 1254
            [2048x2048-height] => 836
        )

)
1
                            
tech trends for 2025 blog

Blogs

Ergo’s Top Tech Trends for 2025

                            Array
(
    [ID] => 96098
    [id] => 96098
    [title] => Building cyber resilience
    [filename] => iStock-161147253-min.jpg
    [filesize] => 524089
    [url] => https://ergotechnologygroup.com/wp-content/uploads/2025/01/iStock-161147253-min.jpg
    [link] => https://ergotechnologygroup.com/insights/blogs/building-cyber-resilience-in-financial-services/attachment/istock-161147253-min/
    [alt] => Building cyber resilience in the financial sector with Ergo
    [author] => 18
    [description] => 
    [caption] => 
    [name] => istock-161147253-min
    [status] => inherit
    [uploaded_to] => 96086
    [date] => 2025-01-08 10:12:22
    [modified] => 2025-01-08 10:13:35
    [menu_order] => 0
    [mime_type] => image/jpeg
    [type] => image
    [subtype] => jpeg
    [icon] => https://ergotechnologygroup.com/wp-includes/images/media/default.png
    [width] => 2121
    [height] => 1414
    [sizes] => Array
        (
            [thumbnail] => https://ergotechnologygroup.com/wp-content/uploads/2025/01/iStock-161147253-min-150x150.jpg
            [thumbnail-width] => 150
            [thumbnail-height] => 150
            [medium] => https://ergotechnologygroup.com/wp-content/uploads/2025/01/iStock-161147253-min-300x200.jpg
            [medium-width] => 300
            [medium-height] => 200
            [medium_large] => https://ergotechnologygroup.com/wp-content/uploads/2025/01/iStock-161147253-min-768x512.jpg
            [medium_large-width] => 768
            [medium_large-height] => 512
            [large] => https://ergotechnologygroup.com/wp-content/uploads/2025/01/iStock-161147253-min-1024x683.jpg
            [large-width] => 1024
            [large-height] => 683
            [1536x1536] => https://ergotechnologygroup.com/wp-content/uploads/2025/01/iStock-161147253-min-1536x1024.jpg
            [1536x1536-width] => 1536
            [1536x1536-height] => 1024
            [2048x2048] => https://ergotechnologygroup.com/wp-content/uploads/2025/01/iStock-161147253-min-2048x1365.jpg
            [2048x2048-width] => 2048
            [2048x2048-height] => 1365
        )

)
1
                            
Building cyber resilience in the financial sector with Ergo

Blogs

Navigating Cyber Resiliency in Financial Services Key Considerations for 2025

                            Array
(
    [ID] => 95960
    [id] => 95960
    [title] => quishing
    [filename] => c793c147-20bd-4ece-bd09-19920cf2853a.jpg
    [filesize] => 424537
    [url] => https://ergotechnologygroup.com/wp-content/uploads/2025/01/c793c147-20bd-4ece-bd09-19920cf2853a.jpg
    [link] => https://ergotechnologygroup.com/insights/blogs/quishing-and-qr-code-attacks/attachment/c793c147-20bd-4ece-bd09-19920cf2853a/
    [alt] => what is quishing
    [author] => 18
    [description] => 
    [caption] => 
    [name] => c793c147-20bd-4ece-bd09-19920cf2853a
    [status] => inherit
    [uploaded_to] => 95959
    [date] => 2025-01-06 14:22:54
    [modified] => 2025-01-06 14:39:21
    [menu_order] => 0
    [mime_type] => image/jpeg
    [type] => image
    [subtype] => jpeg
    [icon] => https://ergotechnologygroup.com/wp-includes/images/media/default.png
    [width] => 1956
    [height] => 1340
    [sizes] => Array
        (
            [thumbnail] => https://ergotechnologygroup.com/wp-content/uploads/2025/01/c793c147-20bd-4ece-bd09-19920cf2853a-150x150.jpg
            [thumbnail-width] => 150
            [thumbnail-height] => 150
            [medium] => https://ergotechnologygroup.com/wp-content/uploads/2025/01/c793c147-20bd-4ece-bd09-19920cf2853a-300x206.jpg
            [medium-width] => 300
            [medium-height] => 206
            [medium_large] => https://ergotechnologygroup.com/wp-content/uploads/2025/01/c793c147-20bd-4ece-bd09-19920cf2853a-768x526.jpg
            [medium_large-width] => 768
            [medium_large-height] => 526
            [large] => https://ergotechnologygroup.com/wp-content/uploads/2025/01/c793c147-20bd-4ece-bd09-19920cf2853a-1024x702.jpg
            [large-width] => 1024
            [large-height] => 702
            [1536x1536] => https://ergotechnologygroup.com/wp-content/uploads/2025/01/c793c147-20bd-4ece-bd09-19920cf2853a-1536x1052.jpg
            [1536x1536-width] => 1536
            [1536x1536-height] => 1052
            [2048x2048] => https://ergotechnologygroup.com/wp-content/uploads/2025/01/c793c147-20bd-4ece-bd09-19920cf2853a.jpg
            [2048x2048-width] => 1956
            [2048x2048-height] => 1340
        )

)
1
                            
what is quishing

Blogs

Quishing and QR code attacks: new threat to your digital security

                            Array
(
    [ID] => 95964
    [id] => 95964
    [title] => Lorne Haeder 1 (1)
    [filename] => Lorne-Haeder-1-1.png
    [filesize] => 167121
    [url] => https://ergotechnologygroup.com/wp-content/uploads/2025/01/Lorne-Haeder-1-1.png
    [link] => https://ergotechnologygroup.com/insights/blogs/a-cios-new-years-resolutions-for-2025/attachment/lorne-haeder-1-1/
    [alt] => 
    [author] => 18
    [description] => 
    [caption] => 
    [name] => lorne-haeder-1-1
    [status] => inherit
    [uploaded_to] => 95946
    [date] => 2025-01-06 14:45:21
    [modified] => 2025-01-06 14:45:21
    [menu_order] => 0
    [mime_type] => image/png
    [type] => image
    [subtype] => png
    [icon] => https://ergotechnologygroup.com/wp-includes/images/media/default.png
    [width] => 748
    [height] => 444
    [sizes] => Array
        (
            [thumbnail] => https://ergotechnologygroup.com/wp-content/uploads/2025/01/Lorne-Haeder-1-1-150x150.png
            [thumbnail-width] => 150
            [thumbnail-height] => 150
            [medium] => https://ergotechnologygroup.com/wp-content/uploads/2025/01/Lorne-Haeder-1-1-300x178.png
            [medium-width] => 300
            [medium-height] => 178
            [medium_large] => https://ergotechnologygroup.com/wp-content/uploads/2025/01/Lorne-Haeder-1-1.png
            [medium_large-width] => 748
            [medium_large-height] => 444
            [large] => https://ergotechnologygroup.com/wp-content/uploads/2025/01/Lorne-Haeder-1-1.png
            [large-width] => 748
            [large-height] => 444
            [1536x1536] => https://ergotechnologygroup.com/wp-content/uploads/2025/01/Lorne-Haeder-1-1.png
            [1536x1536-width] => 748
            [1536x1536-height] => 444
            [2048x2048] => https://ergotechnologygroup.com/wp-content/uploads/2025/01/Lorne-Haeder-1-1.png
            [2048x2048-width] => 748
            [2048x2048-height] => 444
        )

)
1
                            

Blogs

A CIO's New Year's Resolutions for 2025