2025 / Azure / AZ-LZ

Azure Landing Zone Foundation

Azure landing zone, identity, network, security, and operations foundation.

Project profile

  • Engagement: ออกแบบและวางรากฐาน Azure สำหรับองค์กร
  • Focus: Governance, identity, connectivity, security และ operations
  • Output: Architecture records, configuration evidence และ operational notes

Before the first workload

ก่อนนำ workload แรกขึ้น Azure ต้องตอบคำถามพื้นฐานให้ได้ก่อนว่า subscription จะอยู่ตรงไหน ใครมีสิทธิ์ทำอะไร policy ใดจะถูกสืบทอด network จะเชื่อมต่อกันอย่างไร และข้อมูลใดจำเป็นสำหรับงาน operation คำตอบเหล่านี้ถูกนำมาวางเป็น landing zone

งานส่วนนี้เกิดขึ้นก่อนนำ production systems และ business integrations ขึ้นใช้งาน เพื่อไม่ให้แต่ละ workload ต้องตัดสินใจเรื่อง platform ซ้ำ และเพื่อให้เห็น ownership ชัดเจนก่อน environment ขยายตัว

Landing zone คือ baseline ไม่ใช่สิ่งที่ใช้แทน workload architecture, security review หรือการดูแล platform อย่างต่อเนื่อง

What the foundation covers

  • โครงสร้าง management group และ subscription
  • การสืบทอด policy และขอบเขตของ role
  • Shared connectivity และ private service access
  • Logging, monitoring และ operational ownership
  • จุดเริ่มต้นที่ทำซ้ำได้สำหรับ workload subscriptions
ชั้นของรากฐาน Azure Landing Zone แบบ generalized
ภาพที่ 1 — Shared platform controls และ workload landing zones แบบ generalized.

Decisions recorded

Resource organization

Management groups ใช้จัดการการสืบทอด policy และ access โดยรวม environment ที่มี control และ lifecycle ใกล้เคียงกัน โครงสร้างนี้จึงไม่ได้คัดลอก organization chart โดยตรง ส่วน subscription ใช้เป็นขอบเขตของ workload ownership และ operation

Identity and access

การเปลี่ยนแปลง shared platform ถูกแยกออกจากการดูแล workload เพราะเป็นคนละความรับผิดชอบ พร้อมบันทึก role assignments, privileged activities, emergency access และ escalation paths เพื่อให้ทีมที่รับช่วงต่อยังเข้าใจได้ว่าแต่ละสิทธิ์มีไว้เพราะอะไร

Connectivity and operations

Connectivity, routing, DNS และ private access ถูกพิจารณาร่วมกัน เพราะการตัดสินใจแต่ละเรื่องมีผลต่อกัน ส่วน logging และ monitoring อยู่ใน baseline พร้อมแบ่งความรับผิดชอบระหว่าง platform owner กับ workload owner เป้าหมายคือเก็บ signal ที่นำไปใช้ในงาน operation ได้จริง ไม่ใช่เก็บทุกอย่างเพียงเพราะระบบรองรับ

Topology ของ management group และ subscription แบบ generalized
ภาพที่ 2 — ความรับผิดชอบและ lifecycle ใน hierarchy แบบ generalized.

What to be aware of

Landing zone ไม่ใช่ cloud platform ที่เสร็จสมบูรณ์ หลังส่งมอบแล้วยังต้องมีเจ้าของ กระบวนการเปลี่ยนแปลง และการทบทวนอย่างสม่ำเสมอ

  • Policy ต้องมี owner และ exception process ไม่เช่นนั้นจะเปลี่ยนแปลงอย่างปลอดภัยได้ยาก
  • Subscription ที่ผ่าน policy ไม่ได้หมายความว่า workload ภายในปลอดภัยหรือออกแบบดีแล้ว
  • Identity, network และ logging decisions ต้องทบทวนเมื่อองค์กรและ Azure services เปลี่ยน
  • Reference diagram เป็นเพียงจุดเริ่มต้น โครงสร้างจริงต้องตาม responsibility และ constraints

Delivery and handover

งานแบ่งเป็น discovery, design decisions, implementation, validation และ handover โดย architecture notes และ configuration evidence ถูกปรับไปพร้อมกับการส่งมอบ ไม่ได้รอเขียนเมื่อจบโครงการ ส่วนเรื่องที่ยังไม่ตัดสินใจหรือควรปรับปรุงภายหลังถูกบันทึกไว้ใน backlog เพื่อให้ทีมรับช่วงต่อเห็นบริบทเดียวกัน

ลำดับการส่งมอบ Azure Landing Zone
ภาพที่ 3 — ลำดับการส่งมอบตั้งแต่ discovery ถึง handover.

Outcome

โครงการนี้จัดทำ Azure baseline ที่ระบุ ownership, controls, connectivity expectations และ operational responsibilities ไว้ชัดเจน Workload ในอนาคตจึงเริ่มจาก baseline เดียวกันได้ แต่แต่ละ workload ยังต้องออกแบบ architecture และ security ของตัวเอง และ baseline ยังต้องได้รับการทบทวนเมื่อ environment เปลี่ยน

Evidence of delivery

  • Architecture และ topology notes
  • การตัดสินใจเรื่อง management group และ subscription
  • หลักฐาน policy และ role assignments
  • Connectivity และ private-access records
  • บันทึก logging และ operational responsibility
  • Runbooks และ handover backlog