← cd ~/learn
// learning path · beginner to intermediate
Azure landing zone guardrails
The cheap, high-value controls every Azure estate should have before it grows.
0 of 5 read · about 12 minutes in total
- 01Azure Policy guardrails every subscription should haveA handful of built-in Azure Policy assignments stop the most common mistakes before they happen. Start with these at the management group level.3 min✓ read
- 02Resource locks: a cheap insurance policy against the wrong clickA delete lock takes seconds to add and can save a production outage. Here's how locks work, and the ReadOnly gotchas to avoid.2 min✓ read
- 03Stop surprise Azure bills with budgets and anomaly alertsAzure won't stop you spending, but it will tell you early if you set it up. Two features take five minutes and catch most surprises.3 min✓ read
- 04Turning on Defender CSPM across a landing zoneFoundational CSPM is free and already on. Defender CSPM adds attack paths and agentless scanning. Here's how I'd roll it out across many subscriptions.2 min✓ read
- 05Private endpoints and DNS: why your private endpoint isn't being usedYou created a private endpoint, but traffic still goes to the public IP. It's almost always DNS. How private endpoint name resolution works and how to fix it.2 min✓ read
Progress is saved in this browser only. A post counts as read once you've scrolled most of the way through it.