Azure

Your Azure foundation, built in 15 to 30 days.

We set up your Azure landing zone with Entra ID sign-in, policy guardrails, central logging, and encryption. We build it from our private template library and hand it over as Terraform. This page is for teams that have already chosen Azure.

Price
From $8,500
Fixed in writing before we start.
Time
15 to 30 days
For the standard foundation, counted from the day we agree the design and get access.

Already decided on Azure? Then start here. We do not spend your first week choosing a cloud. Already running workloads? We fix existing accounts too.

What the price covers

Standard foundation

$8,500, fixed

The subscriptions shown below, in one region, with the full baseline, in 15 to 30 days. This is the scope we can price before we even talk.

Extended foundation

From $12,500

When you need more than the standard scope, we price it after the call. Common reasons are more subscriptions or regions, a VPN or private link to an office, data center, or another cloud, and controls mapped to a framework like SOC 2 or ISO 27001. Each one adds to the scope, so we quote the total and the timeline in writing before any work starts.

Running dozens of subscriptions, several regions, or a complex hybrid network? We scope that as its own project. We build everything in your own Azure environment. Azure bills you directly for usage, including security services like threat detection and logging, and that is separate from our fee.

The structure you get

We set up 4 subscriptions under one Management group hierarchy, and each one has a single job. When you need more, you add them from the same code.

Management group hierarchy

  • Management

    Runs central logging and monitoring.

  • Connectivity

    Holds the hub network that every workload connects through.

  • Production

    Runs your live workloads.

  • Development

    Gives your team a place to build and test.

What gets built

Each part starts in plain words and then lists exactly what we configure. Whoever approves the budget and whoever checks the work can read the same page.

One login for everyone, with MFA

Your team signs in with their Microsoft Entra ID account. When someone leaves, you disable them once and their Azure access goes with it.

  • Clear roles. We map your Entra ID groups to Azure RBAC roles.
  • MFA everywhere. Conditional Access requires MFA for Azure management.
  • Just-in-time admin. Privileged Identity Management grants Owner and Contributor only when needed, if your license includes it.
  • Emergency access. We set up break-glass accounts, exclude them from normal policies, and monitor them.
  • Secretless pipelines. Your pipelines sign in with workload identity federation instead of stored secrets.

Separate subscriptions for separate jobs

We put production, development, and the shared platform in their own subscriptions. A mistake in one stays there.

  • Clear hierarchy. Management groups separate platform, landing zones, and sandbox.
  • Shared services. Management and connectivity get subscriptions of their own.
  • Room to grow. You start with production and development and can add more later.
  • Policies from day one. New subscriptions land under the right policies automatically.

Guardrails nobody can switch off

We assign rules at the management group, so every subscription underneath follows them.

  • Azure Policy. We limit regions, require tags, and block public storage accounts.
  • Logging by default. Diagnostic settings deploy automatically to new resources.
  • Continuous checks. We assign the Microsoft cloud security benchmark.

An audit trail nobody can edit

We send every change and every sign-in to a central workspace that the people making changes do not control.

  • Central workspace. Every subscription sends its activity log to one Log Analytics workspace.
  • Sign-in records. We collect Microsoft Entra sign-in and audit logs alongside.
  • Your retention rules. Archive storage is immutable and keeps logs as long as your audit requires.

Threats and misconfigurations flagged early

Risky settings and suspicious activity reach your team while they are still easy to fix.

  • Posture tracking. Microsoft Defender for Cloud gives you a secure score and recommendations.
  • Workload protection. We turn on Defender plans for the resource types you run, where they are in scope.
  • Alerts that reach people. Findings go to email or Teams.

A network built to your plan

Everything is private by default. Your workloads connect through one hub that you control.

  • Your IP plan. We build hub-and-spoke virtual networks to the ranges you agree.
  • Private access. Network security groups and private endpoints protect platform services.
  • Wider connections. We scope and quote Azure Firewall, VPN, and ExpressRoute separately, as part of an extended foundation.

Data encrypted, with keys you control

We encrypt your stored data and keep secrets and keys in one audited place.

  • Protected vault. Key Vault runs with RBAC, soft delete, and purge protection.
  • Your keys. Storage uses customer-managed keys where your review requires them.
  • Modern encryption. Policy enforces TLS 1.2 as the minimum.

No surprise bills

You see spending by team and environment, and you get a warning before you hit a budget.

  • Budget alerts. Cost Management warns you per subscription.
  • Cost by team. Policy enforces the tags that show who spends what.

What you get

  • Your code. Terraform lives in your repository, and a pipeline runs a plan on every pull request.
  • Your state. Remote state sits encrypted and locked in your own account.
  • A clear README. Your next engineer can pick it up without calling us.
  • An auditor-ready list. One page lists every control we turned on.
  • A walkthrough. We take your team through it on a call.

What you bring

  • Your environments. Tell us which accounts you need.
  • Your network. Share your IP ranges and anything the network has to reach.
  • Your people. Name your identity provider and who gets which access.
  • An administrator. Someone who can grant us access on day one.

We start once these are settled, so your 15 to 30 days go into building.

What we leave out

  • Deploying or changing your application
  • Migrating an existing estate
  • Overnight or on-call support
  • Policies, training, and vendor reviews
  • The audit itself, or a certificate

How it runs

  1. 1

    Free call

    We spend thirty minutes on what you run, what is coming, and what you need.

  2. 2

    Fixed quote

    You get a price and a short agreement in writing before any work starts.

  3. 3

    Design decisions

    We agree the account structure, IP plan, identity provider, and access groups with you. The clock starts here.

  4. 4

    Build and check

    We build from our private library, apply through the pipeline, and check every agreed control.

  5. 5

    Handover

    You get the code, the README, and the control list, and we walk your team through it.

For the standard foundation, we count the 15 to 30 days from the day we agree the accounts, network, and access. For an extended scope, we confirm the timeline with your quote. If you have those ready on day one, expect something closer to 15. If your team is still settling the network or the login, the clock waits until you do.

Security that pays off every day

A secure foundation means fewer ways in, a smaller blast radius when something goes wrong, and problems caught while they are still small. When an auditor or a customer's security team asks, the Azure settings are easy to show. If you need a certificate, your auditor issues it. We do not certify you.

Customer security reviews
SOC 2, ISO 27001
Healthcare
HIPAA
Payments
PCI DSS
Security standards
NIST CSF, CIS Benchmarks

We work with US-based companies. If your company is outside the US, we can still help through an engagement agreement written for you, and we follow the laws and frameworks that apply to you, such as GDPR.

Book a free call

Tell us what you run and what is coming. We reply within one business day to set up a call, then send you a fixed price and a short agreement.

Once the foundation is live, our managed cloud operations can keep running changes as code from $4,500 a month, with your team approving each one.

Other clouds: AWS, Google Cloud.

Request

Cloud foundation