Skip to main content

Azure services used

This page lists every Azure service and every tool the Azure edition uses, with a link to the explainer for each. Each explainer says what the service does in general and then exactly how BuiltForProd uses it: which subscription runs it, which unit or module creates it, and what it is connected to.

The Used in column names the product whose repositories create or configure the service. "All four products" means the Azure Enterprise Baseline and the Azure Web App, Data and ETL, and Secrets Blueprints. Services that are switched off by default, such as Microsoft Sentinel, Azure DDoS Protection, the VPN Gateway and the IPAM pools of Azure Virtual Network Manager, are listed because the code for them ships and one setting turns them on.

How the areas fit together​

Identity comes first because every other service is reached through a role assignment. The network carries the workloads, the governance services constrain and watch everything, and the delivery tooling is the only path by which any of it changes. The architecture overview shows the pieces in context, and the Azure product page says what each Azure product delivers.

Tenant, subscriptions and identity​

Who and what can act in each subscription, and how credentials are issued.

ServiceWhat the page coversUsed in
Management groupsHow the Azure Enterprise Baseline builds one management-group tree, mg-acme with core and plat beneath it, and assigns every guardrail policy at its root.Azure Enterprise Baseline
SubscriptionsHow the Azure Enterprise Baseline creates or adopts 14 single-purpose subscriptions and gives each one the same subscription baseline.Azure Enterprise Baseline, all three blueprints
Resource groups and locksWhy every Azure unit owns its own resource group, how the groups are named, and which resource groups and resources carry a CanNotDelete lock.All four products
Microsoft Entra IDHow the Azure Enterprise Baseline uses Microsoft Entra ID: 14 groups for people, sign-in and audit logs exported, and Entra tokens instead of keys for data.Azure Enterprise Baseline, all three blueprints
Azure role-based access controlHow the Azure Enterprise Baseline maps its Entra groups to Azure RBAC roles per management group and subscription, narrowing access toward production.All four products
Privileged Identity ManagementHow the Azure Enterprise Baseline can make Owner and Security Admin eligible rather than standing, with time-boxed activation, and what the switch requires.Azure Enterprise Baseline
Conditional AccessThe Conditional Access policies the Azure Enterprise Baseline defines, why they start in report-only mode, and who they exclude.Azure Enterprise Baseline
Managed identitiesWhere the Azure platform uses user-assigned managed identities and federated credentials, so no workload or pipeline holds a secret.All four products
GitHub OIDCHow GitHub Actions workflows sign in to Azure with federated identity credentials on one managed identity per repository, with no client secret.All four products

Governance, security and keys​

The preventive, detective and protective controls, and the vaults and keys that hold secrets.

ServiceWhat the page coversUsed in
Azure PolicyThe guardrail, region, audit-protection, tag and compliance initiatives the Azure Enterprise Baseline assigns at mg-acme, and their effects.Azure Enterprise Baseline
Microsoft Defender for CloudWhich Defender for Cloud plans the Azure Enterprise Baseline turns on in every subscription, what each costs, and where alerts and findings go.Azure Enterprise Baseline
Microsoft SentinelHow the Azure Enterprise Baseline can onboard Microsoft Sentinel to its security workspace with one switch, what that workspace already holds, and the cost.Azure Enterprise Baseline
Key VaultEvery Key Vault the Azure platform creates, from the per-stage contract vault to the SOPS keys, and the controls applied to all of them.All four products
SOPSHow the Azure Secrets Blueprint keeps application secrets encrypted in Git with SOPS and per-stage Key Vault keys, then syncs them to the application vaults.Secrets Blueprint, Azure Enterprise Baseline
Azure DDoS ProtectionWhat Azure DDoS Network Protection adds over the default protection, the switch that turns it on, and the virtual networks it covers.Azure Enterprise Baseline
Azure Web Application FirewallHow the WAF rule template the Azure Enterprise Baseline publishes becomes the Front Door WAF policy of each web application stage.Azure Enterprise Baseline, Web App Blueprint

Networking and DNS​

The hub and spokes, the egress path, private connectivity and name resolution.

ServiceWhat the page coversUsed in
Virtual NetworkThe hub, spoke and runner virtual networks of the Azure Enterprise Baseline, their purpose-named subnets, security groups and where each range comes from.Azure Enterprise Baseline, Web App Blueprint, Data and ETL Blueprint
Virtual network peeringHow every spoke and the runner network peer with the hub, written from the spoke side into both subscriptions, and how the VPN gateway changes the peering.Azure Enterprise Baseline
Route tablesThe user-defined routes that send spoke traffic to the hub firewall, the Front Door return route, and how the routes change in the spoke NAT egress mode.Azure Enterprise Baseline
Azure FirewallHow Azure Firewall in the hub is the single egress and transit point, the policy rule collections that isolate prod from nonprod, and what each SKU costs.Azure Enterprise Baseline
NAT GatewayHow the spoke NAT egress mode gives each spoke its own NAT gateway in place of the hub firewall, which subnets use it, and why the mode is chosen once.Azure Enterprise Baseline, Web App Blueprint, Data and ETL Blueprint
Azure Virtual Network ManagerHow one address plan file feeds every Azure virtual network its ranges, and the Virtual Network Manager IPAM pools the Baseline can mirror it into.Azure Enterprise Baseline
Private LinkWhere the Azure platform puts private endpoints, which services they reach, and how the Web App Blueprint exposes its ingress through a Private Link Service.All four products
Azure Private DNSThe internal zone and the ten Private Link zones the Azure Enterprise Baseline hosts centrally, how every virtual network links to them, and who writes records.Azure Enterprise Baseline, Web App Blueprint
DNS Private ResolverHow the DNS Private Resolver in the hub answers VPN clients and the firewall DNS proxy at one fixed address, and forwards chosen domains to other resolvers.Azure Enterprise Baseline
Azure DNSThe public zones the Azure Enterprise Baseline hosts, which of them are DNSSEC-signed, and how the Web App Blueprint writes its validation and host records.Azure Enterprise Baseline, Web App Blueprint
VPN GatewayHow the optional point-to-site VPN gateway lets engineers reach private endpoints with their Entra identity, and what each group can reach through it.Azure Enterprise Baseline
Network WatcherHow Network Watcher records VNet flow logs for every Azure virtual network into the immutable audit storage, and the Traffic Analytics switch.Azure Enterprise Baseline

Edge​

Where public traffic enters the web application.

ServiceWhat the page coversUsed in
Azure Front DoorHow the Web App Blueprint puts one Front Door profile in front of each stage: the SPA and API endpoints, origins, certificates and the WAF.Web App Blueprint

Audit, logging and monitoring​

Where every control-plane event, log line, metric and alert ends up.

ServiceWhat the page coversUsed in
Azure MonitorHow the Azure platform exports activity and resource logs with diagnostic settings, and routes activity-log, query and metric alerts to one action group.Azure Enterprise Baseline, Web App Blueprint
Log AnalyticsThe audit, security and per-stage application workspaces of the Azure platform, their retention, the KQL alerts and who can query them.Azure Enterprise Baseline, Web App Blueprint, Data and ETL Blueprint
Application InsightsHow the Web App Blueprint creates workspace-based Application Insights per stage, publishes its connection string and runs the optional availability test.Web App Blueprint

Storage​

The storage accounts and the data lake.

ServiceWhat the page coversUsed in
Azure StorageEvery storage account the Azure platform creates, what each holds, and the controls on all of them: Entra-only access, TLS, redundancy and protection.All four products
Azure Data Lake StorageHow the Data and ETL Blueprint keeps each stage lake in one ADLS Gen2 account with raw, processed, curated and managed zones, private and Entra-only.Data and ETL Blueprint, Azure Enterprise Baseline

Compute, containers and data​

What runs the workloads and holds their data.

ServiceWhat the page coversUsed in
Azure Container RegistryHow one Azure Container Registry holds every image of the Azure platform with locked tags, Entra-only access, Defender scanning and an untagged-image purge.Azure Enterprise Baseline, Web App Blueprint, Data and ETL Blueprint
Azure Container AppsHow the Azure platform runs event-driven Container Apps jobs: ephemeral GitHub runners inside the landing zone and the ETL trigger that starts Databricks runs.Azure Enterprise Baseline, Data and ETL Blueprint
Azure Kubernetes ServiceHow the Web App Blueprint runs one private AKS cluster per stage: control plane, system pool, network data plane, identities, access and upgrades.Web App Blueprint
Node Auto ProvisioningHow Node Auto Provisioning adds AKS nodes for the application pods, which VM families it may choose, and the vCPU ceiling that bounds the bill.Web App Blueprint
Application routingHow the AKS application routing add-on runs the managed NGINX ingress controllers of the Web App Blueprint and writes its internal DNS records.Web App Blueprint
KubernetesWhat runs inside the Web App Blueprint AKS cluster and how the application pods are hardened, scaled and isolated.Web App Blueprint
HelmWhat Helm is, how the Azure Web App Blueprint chart is structured, and which cluster add-ons are installed as Helm releases.Web App Blueprint
ArgoCDHow ArgoCD in each AKS cluster syncs the Web App Blueprint chart from the GitOps repository, automatically in dev and staging and by hand in prod.Web App Blueprint
cert-managerHow cert-manager issues the origin certificates Front Door validates and the internal-CA certificates of the Azure Web App Blueprint.Web App Blueprint
External Secrets OperatorHow the External Secrets Operator turns application Key Vault secrets into Kubernetes Secrets for the Azure Web App Blueprint.Web App Blueprint, Secrets Blueprint
DockerHow the Azure blueprint images are built, hardened in the Dockerfile, scanned and pushed once to Azure Container Registry.Web App Blueprint, Data and ETL Blueprint
Azure Cosmos DB for MongoDB vCoreHow the Web App Blueprint runs its MongoDB database on Cosmos DB for MongoDB vCore, privately and with Microsoft Entra authentication only.Web App Blueprint
Azure Managed RedisHow the Web App Blueprint runs Azure Managed Redis with TLS, Entra authentication and access keys disabled, sized per stage.Web App Blueprint
Azure Event GridHow Event Grid turns a file landing in the raw zone of the Azure data lake into a queue message the ETL trigger consumes.Data and ETL Blueprint
Azure DatabricksHow the Data and ETL Blueprint runs one VNet-injected Azure Databricks workspace per stage and the job that transforms each landed file.Data and ETL Blueprint, Azure Enterprise Baseline
Unity CatalogHow Unity Catalog governs the Azure data lake: the regional metastore root in the Baseline, and per stage a credential, external locations, catalog and grants.Data and ETL Blueprint, Azure Enterprise Baseline

Delivery and tooling​

The only path by which any of the above changes.

ServiceWhat the page coversUsed in
OpenTofuWhat OpenTofu is, which version the Azure repositories pin, and which providers they use, from azurerm and azuread to databricks.Azure Enterprise Baseline, Web App Blueprint, Data and ETL Blueprint
TerragruntWhat Terragrunt adds on top of OpenTofu and how the Stacks layout of units, templates and stage files works in the Azure repositories.Azure Enterprise Baseline, Web App Blueprint, Data and ETL Blueprint
GitHub ActionsHow every Azure repository plans, applies, builds, scans and promotes through GitHub Actions, on GitHub-hosted runners or the Container Apps runners.All four products
Checkov, Trivy and tflintWhich static scanners run on the Azure infrastructure code and images, where they run, and how findings are suppressed with a reason.Azure Enterprise Baseline, Web App Blueprint, Data and ETL Blueprint
pre-commitWhich pre-commit hooks run in each Azure repository, from formatters and scanners to the guard scripts that keep the layout and address plan consistent.All four products
InfracostHow the Azure Enterprise Baseline plan workflow prices a change with Infracost and posts one cost comment when the optional API key is set.Azure Enterprise Baseline

Terms used on these pages​

The glossary defines the Azure terms these explainers use, from management group and contract vault to Workload ID. The AWS services used page is the same index for the AWS edition.