Microsoft Azure
Designed, migrated, managed and secured by a New Zealand team.
Most Azure tenants were not designed, they accumulated. We build the structure that should have been there first, move what belongs there, and then run it - with the bill, the access and the security posture all owned by someone.
Microsoft partner
Accredited, and licensing Azure directly
One invoice
Azure billed by Layer3, or manage your own
New Zealand
Engineers here, not a follow-the-sun queue
ISO/IEC 27001:2022
Certified operations
01
The case for change
The platform works. What is missing is the structure, the cost discipline and the security posture that were supposed to arrive with it - and the person whose job it is to hold all three.
Cost
It goes up every quarter and no single person can say why. There are no budgets, no reservations, and resources still running that were spun up for a project that finished two years ago.
Structure
Subscriptions created ad hoc, flat networks, no policy, and permissions granted once and never reviewed. Nothing is wrong until the first thing goes wrong, and then everything is.
Security
The licences include capability that was never configured. Defender sits at a low secure score, conditional access has gaps, and nobody is watching the sign-in logs.
What we do
You can start at any of them. Most organisations come to us at the third and we work backwards.
01
The structure underneath everything else: subscriptions, networks, policy and access, decided on purpose rather than accumulated.
02
Moving what belongs in Azure out of your server room, another provider, or our own private cloud.
03
Running it: patching, monitoring, backup, capacity, and a bill that somebody is accountable for.
04
Microsoft controls configured to the agreed baseline, with Layer3 monitoring where your plan includes it.
Design and landing zones
A landing zone is the part nobody sees and everybody pays for the absence of. It is the difference between an Azure tenant you can hand to an auditor and one you have to apologise for.
Hub and spoke
Shared services in the hub, workloads in their own spokes, traffic between them controlled rather than assumed. We have written publicly about how we lay this out.
Subscriptions and resource groups
A structure that maps to how your organisation actually works, so cost, access and blast radius all line up with something real.
Network segmentation
Address planning that leaves room to grow, and separation that means a compromise in one workload is not a compromise in all of them.
Azure Policy
Guardrails that stop the drift rather than reporting on it afterwards - permitted regions, required tags, blocked resource types.
Role-based access
Who can do what, scoped to the smallest thing that works, reviewed on a cadence instead of granted once and forgotten.
Migration
Out of your server room, off another provider, or out of our own private cloud when that is where the workload has outgrown. We will say so when it is.
01
What you run, what depends on what, and what is honestly worth moving. Some of it will not be.
02
Grouped so each wave stands alone. Nothing moves that has a dependency still sitting on the other side.
03
The smallest wave that proves the pattern, run end to end, including the rollback.
04
Wave by wave, in windows you choose, with the source environment intact until each wave is signed off.
05
Turning the old thing off, deliberately and on a date, because a migration that leaves both running has not finished.
Managed operations
Azure does not run itself, and the parts it does automate still need somebody deciding what good looks like.
Keep it current
Operating systems patched on a schedule, images kept current, and end-of-support dates tracked before they become an incident.
Know it is working
Alerting that reaches a human, backup configured against a retention policy you have actually agreed, and restores tested rather than assumed.
Keep it right-sized
Performance and growth reviewed on a cadence, so the environment matches the organisation rather than the one that signed up two years ago.
Cost control
Azure spend is rarely a pricing problem. It is a governance problem that shows up as a number, and it responds to the same five things every time.
01
A figure per subscription and an alert before it is passed, so cost is a conversation in the month rather than a surprise after it.
02
Anything running all year should not be paid for by the hour. Reserved instances and savings plans, sized against real usage.
03
Machines specified for a launch that never scaled, brought back to what they actually use.
04
Unattached disks, idle gateways, public IPs pointing at nothing. Every tenant has them and nobody has looked.
05
Spend attributed to the team or project that caused it, which is the only mechanism that reliably changes behaviour.
We have written about controlling Azure spend before, and the advice has not changed much.
Security
Azure includes substantial security capability, but configuration and monitoring are separate responsibilities. From the Protect plan upward, Layer3 adds 24/7 security monitoring and analyst response across the managed environment under agreed containment and escalation rules.
Defender
Defender for Cloud enabled and tuned, with the secure score treated as a target rather than a dashboard.
Identity
Entra ID Protection, conditional access, and privileged access reviewed rather than permanent.
Policy
Azure Policy enforcing the guardrails set in the landing zone, so drift is prevented and not just reported.
Logging
Diagnostic and sign-in logs collected and retained, so an investigation has something to work with.
From
The Protect plan upward. Below that, the controls above are configured but nobody is monitoring them for you.
Coverage
From the Protect plan upward, Azure is included in the same 24/7 security monitoring and response coverage as the rest of your managed estate.
Response
Analysts investigate and contain, rather than forwarding you an alert to triage yourself.
Detection and response is a service in its own right. How our managed SOC works
Desktops and identity
Identity is the perimeter now, and for a lot of organisations the desktop has moved with it.
Azure Virtual Desktop
Session hosts sized and scheduled against real usage, with the applications and profiles that make it feel like a desktop rather than a compromise.
Windows 365
A fixed per-user Cloud PC where predictability matters more than density. We will tell you which of the two your usage pattern actually suits.
Entra ID
The identity plane underneath all of it - conditional access, multi-factor, privileged access management, and hybrid join where domain controllers are still in the picture.
How you buy it
Some organisations want one invoice and one number to call. Others have an agreement with Microsoft already, or a policy that says the subscription stays in their name. Neither changes what we do on top of it.
Invoice
Azure consumption on the same invoice as everything else Layer3 provides.
Support
Your first call is to a New Zealand engineer who can already see the tenant.
Cost work
Reservations and savings plans purchased and managed on your behalf.
Invoice
Your existing agreement with Microsoft is untouched. Layer3 charges for the management, not the consumption.
Access
Delegated administration into your tenant, scoped and reviewable, revocable by you.
Cost work
The same analysis and the same recommendations. You place the purchases.
Azure or private cloud
Layer3 also operates private-cloud infrastructure in Auckland. For steady, predictable virtual-machine workloads, it can offer a simpler operating and cost model than Azure; for other workloads, Azure's platform services and scale may be a better fit. These eleven questions help identify which model fits.
Question
Points to
Points to
Is this a set of virtual machines you already run, or something you would rebuild?
Servers as they are, Windows and Linux
We want to re-platform onto managed services
Do those machines carry Microsoft server licensing - Windows Server, SQL Server?
Yes, and the licensing cost matters
Little or no Microsoft server licensing
Is the load steady, or does it spike?
Steady - it runs much the same all year
Spiky, seasonal, or growing in bursts
Would an agreed monthly service charge be easier to govern than consumption billing?
Yes - finance wants one number
We can manage a variable bill
Do these systems talk constantly to people or equipment on your own sites?
Yes - file, SQL, virtual desktops, plant systems
Mostly reached over the internet
Is New Zealand data residency a hard requirement you have to evidence?
Yes, and we get asked to prove it
Preferred, not mandatory
Do you want platform services rather than servers - managed databases, app hosting, functions?
Servers are what we run
Yes, that is the direction
Are you already building on Entra ID, Intune and the wider Microsoft cloud?
Some of it
Yes, it is where we are heading
Do you need capacity or disaster recovery outside New Zealand?
No
Yes
Is this development and test that gets created and destroyed?
No, it is production
Yes, frequently
Do you need to scale to nothing outside business hours?
No
Yes
Most organisations land split, and that is a real answer rather than a fudge - the steady core in Auckland, elastic and platform workloads in Azure. We run both, so the recommendation is not decided by what we happen to sell. How our private cloud works
Questions
If yours is not here, ask us directly — you will get an engineer, not a form response.
Book a discovery callEither. We can bill your Azure consumption on the same invoice as everything else, or manage a subscription that stays in your own name under your existing Microsoft agreement. What we do on top is the same in both cases.
Yes, and that is how most engagements start. We assess what is there, document it, fix the structural problems that can be fixed in place, and give you a plan for the ones that need rebuilding.
It is the structure underneath your workloads — subscriptions, networks, policy and access — designed on purpose. You need one if you plan to keep growing in Azure. Retrofitting it later is possible but it is always more expensive than doing it first.
Usually, and the levers are consistent: budgets, reservations, rightsizing, removing orphaned resources, and attributing spend to whoever caused it. The last one changes behaviour more than the other four combined.
Microsoft's own controls are configured as standard on every environment we manage. Monitoring — a security operations centre watching what those controls report, around the clock — comes with the Protect plan and above, and it covers Azure as part of your whole estate rather than as a separate service.
It depends on the workload, and there is a question-by-question comparison on this page. Broadly: steady virtual machines carrying Microsoft licensing and talking to your own sites usually belong in our Auckland private cloud. Elastic demand, platform services and anything you want to re-platform usually belong in Azure. Plenty of organisations end up with both.
Migration runs in waves, each one piloted first and each one with a rollback. Most waves cut over in a window you choose rather than requiring an outage, and the source environment stays intact until the wave is signed off.
Yes, along with Windows 365. They suit different usage patterns and different budgets, and part of the work is telling you which one your organisation actually needs.
Next step
Including when the honest answer is that it belongs somewhere else.

Layer3 is a managed IT provider operating an ISO/IEC 27001-certified ISMS, with offices across New Zealand.
Contact
0508 LAYER3 Book a discovery call Service status Notices
Level 2, CBD Towers
84-90 Main Street
Upper Hutt, Wellington 5018
Layer3
Book a discovery call - 30 minutes, no obligation