Azure services used
This page lists every Azure service and every tool the Azure edition uses, with a link to the explainer for each. Each explainer says what the service does in general and then exactly how BuiltForProd uses it: which subscription runs it, which unit or module creates it, and what it is connected to.
The Used in column names the product whose repositories create or configure the service. "All four products" means the Azure Enterprise Baseline and the Azure Web App, Data and ETL, and Secrets Blueprints. Services that are switched off by default, such as Microsoft Sentinel, Azure DDoS Protection, the VPN Gateway and the IPAM pools of Azure Virtual Network Manager, are listed because the code for them ships and one setting turns them on.
How the areas fit together
Identity comes first because every other service is reached through a role assignment. The network carries the workloads, the governance services constrain and watch everything, and the delivery tooling is the only path by which any of it changes. The architecture overview shows the pieces in context, and the Azure product page says what each Azure product delivers.
Tenant, subscriptions and identity
Who and what can act in each subscription, and how credentials are issued.
| Service | What the page covers | Used in |
|---|---|---|
| Management groups | How the Azure Enterprise Baseline builds one management-group tree, mg-acme with core and plat beneath it, and assigns every guardrail policy at its root. | Azure Enterprise Baseline |
| Subscriptions | How the Azure Enterprise Baseline creates or adopts 14 single-purpose subscriptions and gives each one the same subscription baseline. | Azure Enterprise Baseline, all three blueprints |
| Resource groups and locks | Why every Azure unit owns its own resource group, how the groups are named, and which resource groups and resources carry a CanNotDelete lock. | All four products |
| Microsoft Entra ID | How the Azure Enterprise Baseline uses Microsoft Entra ID: 14 groups for people, sign-in and audit logs exported, and Entra tokens instead of keys for data. | Azure Enterprise Baseline, all three blueprints |
| Azure role-based access control | How the Azure Enterprise Baseline maps its Entra groups to Azure RBAC roles per management group and subscription, narrowing access toward production. | All four products |
| Privileged Identity Management | How the Azure Enterprise Baseline can make Owner and Security Admin eligible rather than standing, with time-boxed activation, and what the switch requires. | Azure Enterprise Baseline |
| Conditional Access | The Conditional Access policies the Azure Enterprise Baseline defines, why they start in report-only mode, and who they exclude. | Azure Enterprise Baseline |
| Managed identities | Where the Azure platform uses user-assigned managed identities and federated credentials, so no workload or pipeline holds a secret. | All four products |
| GitHub OIDC | How GitHub Actions workflows sign in to Azure with federated identity credentials on one managed identity per repository, with no client secret. | All four products |
Governance, security and keys
The preventive, detective and protective controls, and the vaults and keys that hold secrets.
| Service | What the page covers | Used in |
|---|---|---|
| Azure Policy | The guardrail, region, audit-protection, tag and compliance initiatives the Azure Enterprise Baseline assigns at mg-acme, and their effects. | Azure Enterprise Baseline |
| Microsoft Defender for Cloud | Which Defender for Cloud plans the Azure Enterprise Baseline turns on in every subscription, what each costs, and where alerts and findings go. | Azure Enterprise Baseline |
| Microsoft Sentinel | How the Azure Enterprise Baseline can onboard Microsoft Sentinel to its security workspace with one switch, what that workspace already holds, and the cost. | Azure Enterprise Baseline |
| Key Vault | Every Key Vault the Azure platform creates, from the per-stage contract vault to the SOPS keys, and the controls applied to all of them. | All four products |
| SOPS | How the Azure Secrets Blueprint keeps application secrets encrypted in Git with SOPS and per-stage Key Vault keys, then syncs them to the application vaults. | Secrets Blueprint, Azure Enterprise Baseline |
| Azure DDoS Protection | What Azure DDoS Network Protection adds over the default protection, the switch that turns it on, and the virtual networks it covers. | Azure Enterprise Baseline |
| Azure Web Application Firewall | How the WAF rule template the Azure Enterprise Baseline publishes becomes the Front Door WAF policy of each web application stage. | Azure Enterprise Baseline, Web App Blueprint |
Networking and DNS
The hub and spokes, the egress path, private connectivity and name resolution.
| Service | What the page covers | Used in |
|---|---|---|
| Virtual Network | The hub, spoke and runner virtual networks of the Azure Enterprise Baseline, their purpose-named subnets, security groups and where each range comes from. | Azure Enterprise Baseline, Web App Blueprint, Data and ETL Blueprint |
| Virtual network peering | How every spoke and the runner network peer with the hub, written from the spoke side into both subscriptions, and how the VPN gateway changes the peering. | Azure Enterprise Baseline |
| Route tables | The user-defined routes that send spoke traffic to the hub firewall, the Front Door return route, and how the routes change in the spoke NAT egress mode. | Azure Enterprise Baseline |
| Azure Firewall | How Azure Firewall in the hub is the single egress and transit point, the policy rule collections that isolate prod from nonprod, and what each SKU costs. | Azure Enterprise Baseline |
| NAT Gateway | How the spoke NAT egress mode gives each spoke its own NAT gateway in place of the hub firewall, which subnets use it, and why the mode is chosen once. | Azure Enterprise Baseline, Web App Blueprint, Data and ETL Blueprint |
| Azure Virtual Network Manager | How one address plan file feeds every Azure virtual network its ranges, and the Virtual Network Manager IPAM pools the Baseline can mirror it into. | Azure Enterprise Baseline |
| Private Link | Where the Azure platform puts private endpoints, which services they reach, and how the Web App Blueprint exposes its ingress through a Private Link Service. | All four products |
| Azure Private DNS | The internal zone and the ten Private Link zones the Azure Enterprise Baseline hosts centrally, how every virtual network links to them, and who writes records. | Azure Enterprise Baseline, Web App Blueprint |
| DNS Private Resolver | How the DNS Private Resolver in the hub answers VPN clients and the firewall DNS proxy at one fixed address, and forwards chosen domains to other resolvers. | Azure Enterprise Baseline |
| Azure DNS | The public zones the Azure Enterprise Baseline hosts, which of them are DNSSEC-signed, and how the Web App Blueprint writes its validation and host records. | Azure Enterprise Baseline, Web App Blueprint |
| VPN Gateway | How the optional point-to-site VPN gateway lets engineers reach private endpoints with their Entra identity, and what each group can reach through it. | Azure Enterprise Baseline |
| Network Watcher | How Network Watcher records VNet flow logs for every Azure virtual network into the immutable audit storage, and the Traffic Analytics switch. | Azure Enterprise Baseline |
Edge
Where public traffic enters the web application.
| Service | What the page covers | Used in |
|---|---|---|
| Azure Front Door | How the Web App Blueprint puts one Front Door profile in front of each stage: the SPA and API endpoints, origins, certificates and the WAF. | Web App Blueprint |
Audit, logging and monitoring
Where every control-plane event, log line, metric and alert ends up.
| Service | What the page covers | Used in |
|---|---|---|
| Azure Monitor | How the Azure platform exports activity and resource logs with diagnostic settings, and routes activity-log, query and metric alerts to one action group. | Azure Enterprise Baseline, Web App Blueprint |
| Log Analytics | The audit, security and per-stage application workspaces of the Azure platform, their retention, the KQL alerts and who can query them. | Azure Enterprise Baseline, Web App Blueprint, Data and ETL Blueprint |
| Application Insights | How the Web App Blueprint creates workspace-based Application Insights per stage, publishes its connection string and runs the optional availability test. | Web App Blueprint |
Storage
The storage accounts and the data lake.
| Service | What the page covers | Used in |
|---|---|---|
| Azure Storage | Every storage account the Azure platform creates, what each holds, and the controls on all of them: Entra-only access, TLS, redundancy and protection. | All four products |
| Azure Data Lake Storage | How the Data and ETL Blueprint keeps each stage lake in one ADLS Gen2 account with raw, processed, curated and managed zones, private and Entra-only. | Data and ETL Blueprint, Azure Enterprise Baseline |
Compute, containers and data
What runs the workloads and holds their data.
| Service | What the page covers | Used in |
|---|---|---|
| Azure Container Registry | How one Azure Container Registry holds every image of the Azure platform with locked tags, Entra-only access, Defender scanning and an untagged-image purge. | Azure Enterprise Baseline, Web App Blueprint, Data and ETL Blueprint |
| Azure Container Apps | How the Azure platform runs event-driven Container Apps jobs: ephemeral GitHub runners inside the landing zone and the ETL trigger that starts Databricks runs. | Azure Enterprise Baseline, Data and ETL Blueprint |
| Azure Kubernetes Service | How the Web App Blueprint runs one private AKS cluster per stage: control plane, system pool, network data plane, identities, access and upgrades. | Web App Blueprint |
| Node Auto Provisioning | How Node Auto Provisioning adds AKS nodes for the application pods, which VM families it may choose, and the vCPU ceiling that bounds the bill. | Web App Blueprint |
| Application routing | How the AKS application routing add-on runs the managed NGINX ingress controllers of the Web App Blueprint and writes its internal DNS records. | Web App Blueprint |
| Kubernetes | What runs inside the Web App Blueprint AKS cluster and how the application pods are hardened, scaled and isolated. | Web App Blueprint |
| Helm | What Helm is, how the Azure Web App Blueprint chart is structured, and which cluster add-ons are installed as Helm releases. | Web App Blueprint |
| ArgoCD | How ArgoCD in each AKS cluster syncs the Web App Blueprint chart from the GitOps repository, automatically in dev and staging and by hand in prod. | Web App Blueprint |
| cert-manager | How cert-manager issues the origin certificates Front Door validates and the internal-CA certificates of the Azure Web App Blueprint. | Web App Blueprint |
| External Secrets Operator | How the External Secrets Operator turns application Key Vault secrets into Kubernetes Secrets for the Azure Web App Blueprint. | Web App Blueprint, Secrets Blueprint |
| Docker | How the Azure blueprint images are built, hardened in the Dockerfile, scanned and pushed once to Azure Container Registry. | Web App Blueprint, Data and ETL Blueprint |
| Azure Cosmos DB for MongoDB vCore | How the Web App Blueprint runs its MongoDB database on Cosmos DB for MongoDB vCore, privately and with Microsoft Entra authentication only. | Web App Blueprint |
| Azure Managed Redis | How the Web App Blueprint runs Azure Managed Redis with TLS, Entra authentication and access keys disabled, sized per stage. | Web App Blueprint |
| Azure Event Grid | How Event Grid turns a file landing in the raw zone of the Azure data lake into a queue message the ETL trigger consumes. | Data and ETL Blueprint |
| Azure Databricks | How the Data and ETL Blueprint runs one VNet-injected Azure Databricks workspace per stage and the job that transforms each landed file. | Data and ETL Blueprint, Azure Enterprise Baseline |
| Unity Catalog | How Unity Catalog governs the Azure data lake: the regional metastore root in the Baseline, and per stage a credential, external locations, catalog and grants. | Data and ETL Blueprint, Azure Enterprise Baseline |
Delivery and tooling
The only path by which any of the above changes.
| Service | What the page covers | Used in |
|---|---|---|
| OpenTofu | What OpenTofu is, which version the Azure repositories pin, and which providers they use, from azurerm and azuread to databricks. | Azure Enterprise Baseline, Web App Blueprint, Data and ETL Blueprint |
| Terragrunt | What Terragrunt adds on top of OpenTofu and how the Stacks layout of units, templates and stage files works in the Azure repositories. | Azure Enterprise Baseline, Web App Blueprint, Data and ETL Blueprint |
| GitHub Actions | How every Azure repository plans, applies, builds, scans and promotes through GitHub Actions, on GitHub-hosted runners or the Container Apps runners. | All four products |
| Checkov, Trivy and tflint | Which static scanners run on the Azure infrastructure code and images, where they run, and how findings are suppressed with a reason. | Azure Enterprise Baseline, Web App Blueprint, Data and ETL Blueprint |
| pre-commit | Which pre-commit hooks run in each Azure repository, from formatters and scanners to the guard scripts that keep the layout and address plan consistent. | All four products |
| Infracost | How the Azure Enterprise Baseline plan workflow prices a change with Infracost and posts one cost comment when the optional API key is set. | Azure Enterprise Baseline |
Terms used on these pages
The glossary defines the Azure terms these explainers use, from management group and contract vault to Workload ID. The AWS services used page is the same index for the AWS edition.