Cloud landing zones

Hand over the platform as a service, not a diagram

Workload teams need clear requests, support routes and change expectations. Explain how they use the foundation and who resolves problems at each boundary.

In this article

Publish the supported paths

Describe how a team requests an environment, deploys a workload, obtains necessary access and asks for a policy exception. Link the maintained tools and examples.

Keep the explanation focused on decisions the workload team needs to make. Internal implementation details can live in platform documentation without becoming required knowledge for every application engineer.

Provide one working example that follows the normal process. An example maintained outside the baseline can become misleading as soon as the platform changes.

Assign responsibilities at the boundary

State which team owns identity integration, shared networks and audit infrastructure, and which responsibilities remain with the application team.

Make recovery responsibilities explicit. A platform backup capability does not automatically prove that an application's business workflow can be restored.

Include escalation for issues spanning both teams. A connectivity incident should not circulate indefinitely because each side can show that its own component appears healthy.

Explain changes and exceptions

Publish how baseline updates are announced, tested and applied to existing environments. Workload teams need time and a supported path to resolve incompatible dependencies.

Keep exceptions discoverable with their scope, owner and review condition. Avoid placing sensitive details in a broadly visible catalogue, but ensure authorised operators can understand the effective policy.

Document how a team reports a control that blocks a legitimate use case. Useful feedback should improve the platform rather than encourage unofficial bypasses.

Verify the receiving team's independence

Ask a workload team to provision a test environment, deploy the example, diagnose an intentional denial and find its logs. Observe where undocumented help is required.

Use those gaps to improve the service interface and guidance. The exercise is not a test of whether the team can remember the platform engineer's instructions.

Schedule ownership reviews for shared components and abandoned environments. A cloud foundation remains useful only while its operating responsibilities stay current as teams and workloads change.

Primary sources

Microsoft: Azure landing zones

References checked 11 September 2026.