About This Architecture

Azure Landing Zone following Cloud Adoption Framework (CAF) governance structure with Tenant Root Group, management groups, and policy-driven compliance through Azure Security Benchmark. Traffic flows from users through CDN and WAF to Application Gateway, distributing across VM Scale Sets in multiple availability zones with SQL Database failover, while platform services including API Management, Cosmos DB, and Data Factory operate in isolated subscriptions. Identity management via Entra ID, centralized logging through Log Analytics, and infrastructure automation via Automation Account enforce least-privilege access and operational visibility across all workloads. Fork this diagram to customize management group hierarchies, subscription layouts, or regional deployments for your enterprise governance model.

People also ask

How do I structure Azure subscriptions and management groups following Cloud Adoption Framework best practices?

This diagram shows the complete Azure CAF landing zone hierarchy: Tenant Root Group at the top, with Platform and Landing Zones management groups organizing subscriptions for Identity, Management, Connectivity, and workloads (Corp, Online, Corp2, Data, Sandbox, Decommissioned). Azure Security Benchmark policies enforce compliance across all resources.

Azure Landing Zone - CAF Architecture

AzureadvancedCloud Adoption FrameworkLanding ZonesGovernanceEnterprise ArchitectureManagement Groups
Domain: Cloud AzureAudience: Azure solutions architects implementing Cloud Adoption Framework landing zones
2 views0 favoritesPublic

Created by

July 22, 2026

Updated

August 3, 2026 at 4:39 PM

Type

architecture

Need a custom architecture diagram?

Describe your architecture in plain English and get a production-ready Draw.io diagram in seconds. Works for AWS, Azure, GCP, Kubernetes, and more.

Generate with AI

AI-generated. Verify before production use. Learn more

Report this diagram