Azure Mini Landing Zone - AI Hub and Spoke

azure · architecture diagram.

About This Architecture

Azure mini landing zone implementing hub-and-spoke network topology with centralized security, identity, and logging across nine spoke subscriptions. Hub subscription routes all traffic through FortiGate VM and Azure Firewall with WAF, while management, identity, security, and logging spokes provide platform services. Compute, containerized, and database spokes isolate workloads by deployment model—IaaS, PaaS, AKS, Container Apps, and managed databases—enabling governance, cost allocation, and blast radius containment. This architecture demonstrates Azure landing zone best practices for multi-subscription enterprises requiring centralized network control, compliance monitoring via Sentinel and Log Analytics, and secure hybrid connectivity through VPN Gateway and ExpressRoute. Fork this diagram to customize subscription naming, IP ranges, or add additional spoke tiers for your organization's scale and compliance requirements.

People also ask

How do I design an Azure landing zone with hub-and-spoke topology across multiple subscriptions?

This diagram shows a complete Azure mini landing zone with a central hub subscription routing traffic through FortiGate and Azure Firewall, connected to nine spoke subscriptions organized by function: management, identity, security, logging, compute IaaS, compute PaaS, containerized workloads, non-containerized apps, and databases. Each spoke isolates workloads by deployment model while inheriting

Azure Mini Landing Zone - AI Hub and Spoke

Azureadvancedlanding-zonehub-and-spokemulti-subscriptionnetwork-architectureenterprise-security
Domain: Cloud AzureAudience: Azure solutions architects designing enterprise landing zones with hub-and-spoke topology
0 views0 favoritesPublic

Created by

March 25, 2026

Updated

March 25, 2026 at 1:10 PM

Type

architecture

Need a custom architecture diagram?

Describe your architecture in plain English and get a production-ready Draw.io diagram in seconds. Works for AWS, Azure, GCP, Kubernetes, and more.

Generate with AI