Skip to main content

Service inventory

The Azure Baseline deploys the services below across its 14 subscriptions. Most are on by default; the ones with a high fixed price or a license prerequisite are built, wired and off, each one switch with its price beside it in the code. The tables below list each service by area, the subscription it runs in and the unit that manages it.

Switches live in three places: environments/core/network/eastus2/network.hcl for the hub network, environments/core/security/security.hcl for the security services, and the unit definition itself for a choice that only one unit reads. Multi-subscription topology shows which units each subscription runs.

Governance​

ServiceSubscriptionUnitDefault
Management groupsacme-core-rootorganizationsOn: mg-acme, mg-acme-core, mg-acme-plat
Subscriptions (created or adopted)acme-core-rootorganizationsOn: the 14 subscriptions, placed under their management groups
Azure Policy guardrails and tag policyacme-core-rootorganizationsOn: four assignments at mg-acme; the tag policy audits until enforce_tag_policy
Azure Policy compliance initiativesacme-core-rootpolicy-complianceOn: Microsoft cloud security benchmark and SOC 2 baseline; nine more off, one switch each
Resource locksEvery subscriptionEach unit's moduleOn: CanNotDelete on the resource groups that hold state, keys, logs and networks
Storage for OpenTofu stateacme-core-rootstate-backendOn

Identity​

ServiceSubscriptionUnitDefault
Entra ID groups and Azure RBAC role assignmentsacme-core-identityentra-rbacOn: group lookups (creation is create_groups), the custom auditor role
Privileged Identity Managementacme-core-identitypimOff: enable_pim in the identity stack file (Entra ID P2, about $9 per user per month)
Conditional Accessacme-core-identityconditional-accessOn, in report-only mode until conditional_access_state is enabled
Managed identities federated to GitHubacme-core-autogithub-oidcOn: one per infrastructure and code repository
Managed identity of the secrets repositoryacme-core-securitysecrets-syncerOn
Entra ID diagnostic settingsacme-core-rootentra-diagnosticsOn: enable_entra_log_export (needs Entra ID P1 or P2)

Network​

ServiceSubscriptionUnitDefault
Virtual networks and network security groupsacme-core-network, acme-core-auto, the four plat subscriptionsvnet-hub, vnet-runner, vnet-spokeOn: the hub, the runner VNet and one spoke per stage
Virtual network peeringacme-core-auto, plat subscriptionsvnet-peeringOn: every spoke to the hub
Route tablesacme-core-auto, plat subscriptionsroutes-spokeOn: default and organization routes to the firewall
Azure Firewall and Firewall Policyacme-core-networkfirewall, firewall-policyOn: Standard, three zones; hub_egress, firewall_sku, firewall_zones
NAT gateway per spokeplat subscriptions, acme-core-autovnet-spoke, vnet-runnerOff: only with hub_egress = "spoke_nat", about $33 per month each
Azure DNS Private Resolveracme-core-networkdns-resolverOn: enable_dns_private_resolver, about $365 per month for both endpoints
Azure Private DNS zones and linksacme-core-network, every VNetprivate-dns, private-dns-linkOn: internal.company.com and ten Private Link zones
Azure DNS public zones with DNSSECacme-core-dnsdns-zonesOn: the apex zone and the stage zones; DNSSEC on the apex, prod and staging zones
VPN Gateway, point-to-siteacme-core-networkclient-vpnOff: enable_client_vpn, about $263 per month plus connection hours
Network Watcher and VNet flow logsEvery subscriptionsubscription-baseline, VNet unitsOn: flow logs to the audit storage
Traffic AnalyticsEvery VNetVNet unitsOff: enable_traffic_analytics (ingestion cost)
Azure Virtual Network Manager IPAM poolsacme-core-networkipamOff: enable_avnm_ipam, about $0.10 per managed subscription-hour

Security​

ServiceSubscriptionUnitDefault
Microsoft Defender for CloudEvery subscriptionsubscription-baselineOn: Containers, Storage, Key Vault, Resource Manager; off: Servers, Cosmos DB, CSPM, API
Defender for Storage malware scanningEvery subscriptionsubscription-baselineOff: defender_storage_malware_scanning, $0.15 per GB scanned
Defender for Cloud continuous exportEvery subscription but acme-core-securityobservability-linkOn: to the security workspace
Microsoft Sentinelacme-core-securityobservability-sinkOff: enable_sentinel, $2.46 per GB analytics tier
Azure DDoS Network Protectionacme-core-securityddos-planOff: enable_ddos_protection, $2,944 per month
Key Vault for the SOPS keysacme-core-securitysops-keysOn: one key per stage
Key Vault for the audit customer-managed keyacme-core-auditaudit-cmkOn
Key Vault for CIacme-core-autoplatform-kvOn
Key Vault for the workload contractplat subscriptionskv-publishOn: one per stage

Logging and alerting​

ServiceSubscriptionUnitDefault
Log Analytics, audit workspaceacme-core-auditaudit-workspaceOn: 365-day retention
Storage, immutable audit archiveacme-core-auditaudit-storageOn: 365-day immutability, customer-managed key
Log Analytics, security workspaceacme-core-securityobservability-sinkOn: 365-day retention
Azure Monitor action groupacme-core-securityobservability-sinkOn: email to the security mailbox
Log Analytics, stage application workspacesplat subscriptionsobservability-linkOn: retention 30 days (sandbox, dev), 90 (staging), 365 (prod)
Azure Monitor activity-log alertsEvery subscriptionactivity-alertsOn: enable_cis_alerts, ten per subscription
Azure Monitor scheduled query alertsacme-core-auditcis-alertsOn: enable_cis_alerts, six KQL alerts

Delivery​

ServiceSubscriptionUnitDefault
Azure Container Registryacme-core-artifactsacrOn: Standard, about $20 per month; Premium is the switch for private endpoints and retention
Storage for shared build inputsacme-core-artifactsshared-storageOn
Storage for the Unity Catalog metastoreacme-core-artifactsuc-metastoreOn, with its Databricks access connector
Azure Container Apps job for GitHub runnersacme-core-autogithub-runnersOn: enable_github_runners, scale to zero, about $0.12 per runner-hour

Prices are list prices in eastus2 as the code comments state them. The tool and provider versions that deploy these services are on the versions page.