About This Architecture
Azure Virtual WAN hub-spoke architecture with centralized security and hierarchical management group governance across enterprise subscriptions. Virtual WAN connects a Secure Hub running Azure Firewall, VPN Gateway, and ExpressRoute Gateway, routing traffic through Route Tables and UDRs to landing zones organized by function. Management Group hierarchy spans Tenant Root through Enterprise Framework, Platform, Connectivity, Identity, and Landing Zone tiers, each controlling subscriptions for infrastructure services, legacy systems, and managed workloads. This design enforces least-privilege access, centralized threat protection, and scalable multi-region connectivity while maintaining clear cost allocation and compliance boundaries. Fork and customize this diagram on Diagrams.so to model your own subscription strategy and hub configuration.