Architecture
Azure landing zones: the security decisions that are hard to reverse
Subscription topology, management groups and network design get set once and inherited forever. Which choices you can revisit, and which you cannot.
Some of this is genuinely permanent
Most Azure design decisions are reversible with effort. A few are not, or are reversible only at a cost nobody will approve. Knowing which is which at the start is most of the value of a landing zone conversation.
The genuinely painful ones are the tenant the subscriptions live in, the management group hierarchy that policy inherits through, and the address space you chose for your virtual networks.
The four decisions to get right first
Management group hierarchy
Azure Policy and RBAC inherit down this tree. A hierarchy built around the current org chart breaks at the first reorganisation. Build it around workload characteristics and environment instead, because those are stable.
Subscription as the unit of isolation
Subscriptions are the practical blast radius boundary and the billing boundary. Deciding late that production and non-production should have been separate subscriptions means moving resources, and some resources do not move.
IP address space
Overlapping address space with on-premises or with a company you later acquire is the classic unrecoverable mistake. Allocate generously from a plan, not per project on request.
Where policy is enforced
Deny policies at management group level are inherited and consistent. Policies applied per subscription drift immediately and nobody notices which subscription is missing one.
The decisions you can safely defer
Which specific Defender for Cloud plans you enable, your tagging taxonomy, whether you use a hub-and-spoke or Virtual WAN topology, and most naming conventions. All of these can be changed later with ordinary effort.
Deferring these is not laziness. Deciding everything before the first workload lands produces a design based on assumptions rather than usage, and a landing zone nobody follows.
The verdict
Fix hierarchy, subscription strategy, address space and policy scope. Defer the rest
Those four are the expensive-to-reverse decisions. Everything else can be improved once you have real workloads telling you what is needed.
Do not build the full reference architecture before the first workload. A landing zone nobody uses is a diagram, and it will be rebuilt by the first team that finds it inconvenient.
Disclosure. Some links on this site are affiliate links. Scoring weights are published before any programme is joined, and commission is never a ranking input. Full policy, and the method behind this guide.