Layer3 Logo

Microsoft Azure

Azure with clear ownership

Designed, migrated, managed and secured by a New Zealand team.

Most Azure tenants were not designed, they accumulated. We build the structure that should have been there first, move what belongs there, and then run it - with the bill, the access and the security posture all owned by someone.

Microsoft partner

Accredited, and licensing Azure directly

One invoice

Azure billed by Layer3, or manage your own

New Zealand

Engineers here, not a follow-the-sun queue

ISO/IEC 27001:2022

Certified operations

01

The case for change

Most organisations don't have an Azure problem. They have an ownership problem.

The platform works. What is missing is the structure, the cost discipline and the security posture that were supposed to arrive with it - and the person whose job it is to hold all three.

Cost

Unowned cloud spend

It goes up every quarter and no single person can say why. There are no budgets, no reservations, and resources still running that were spun up for a project that finished two years ago.

Structure

Deployed, then left

Subscriptions created ad hoc, flat networks, no policy, and permissions granted once and never reviewed. Nothing is wrong until the first thing goes wrong, and then everything is.

Security

Controls bought, not turned on

The licences include capability that was never configured. Defender sits at a low secure score, conditional access has gaps, and nobody is watching the sign-in logs.

What we do

Four things, in the order they usually happen.

You can start at any of them. Most organisations come to us at the third and we work backwards.

01

Design and landing zones

The structure underneath everything else: subscriptions, networks, policy and access, decided on purpose rather than accumulated.

02

Migration

Moving what belongs in Azure out of your server room, another provider, or our own private cloud.

03

Managed operations

Running it: patching, monitoring, backup, capacity, and a bill that somebody is accountable for.

04

Security

Microsoft controls configured to the agreed baseline, with Layer3 monitoring where your plan includes it.

Design and landing zones

Get the structure right and everything after it is cheaper.

A landing zone is the part nobody sees and everybody pays for the absence of. It is the difference between an Azure tenant you can hand to an auditor and one you have to apologise for.

Hub and spoke

Shared services in the hub, workloads in their own spokes, traffic between them controlled rather than assumed. We have written publicly about how we lay this out.

Subscriptions and resource groups

A structure that maps to how your organisation actually works, so cost, access and blast radius all line up with something real.

Network segmentation

Address planning that leaves room to grow, and separation that means a compromise in one workload is not a compromise in all of them.

Azure Policy

Guardrails that stop the drift rather than reporting on it afterwards - permitted regions, required tags, blocked resource types.

Role-based access

Who can do what, scoped to the smallest thing that works, reviewed on a cadence instead of granted once and forgotten.

Migration

In waves, with a way back.

Out of your server room, off another provider, or out of our own private cloud when that is where the workload has outgrown. We will say so when it is.

01

Assess

What you run, what depends on what, and what is honestly worth moving. Some of it will not be.

02

Plan waves

Grouped so each wave stands alone. Nothing moves that has a dependency still sitting on the other side.

03

Pilot

The smallest wave that proves the pattern, run end to end, including the rollback.

04

Migrate

Wave by wave, in windows you choose, with the source environment intact until each wave is signed off.

05

Decommission

Turning the old thing off, deliberately and on a date, because a migration that leaves both running has not finished.

Managed operations

Somebody's job, on a cadence.

Azure does not run itself, and the parts it does automate still need somebody deciding what good looks like.

Keep it current

Patching and lifecycle

Operating systems patched on a schedule, images kept current, and end-of-support dates tracked before they become an incident.

Know it is working

Monitoring and backup

Alerting that reaches a human, backup configured against a retention policy you have actually agreed, and restores tested rather than assumed.

Keep it right-sized

Capacity and review

Performance and growth reviewed on a cadence, so the environment matches the organisation rather than the one that signed up two years ago.

Cost control

The invoice is a design decision.

Azure spend is rarely a pricing problem. It is a governance problem that shows up as a number, and it responds to the same five things every time.

01

Budgets and alerts

A figure per subscription and an alert before it is passed, so cost is a conversation in the month rather than a surprise after it.

02

Reservations

Anything running all year should not be paid for by the hour. Reserved instances and savings plans, sized against real usage.

03

Rightsizing

Machines specified for a launch that never scaled, brought back to what they actually use.

04

Orphaned resources

Unattached disks, idle gateways, public IPs pointing at nothing. Every tenant has them and nobody has looked.

05

Tagging and showback

Spend attributed to the team or project that caused it, which is the only mechanism that reliably changes behaviour.

We have written about controlling Azure spend before, and the advice has not changed much.

Security

Microsoft's controls, configured. Ours, watching.

Azure includes substantial security capability, but configuration and monitoring are separate responsibilities. From the Protect plan upward, Layer3 adds 24/7 security monitoring and analyst response across the managed environment under agreed containment and escalation rules.

Configured as standard

Defender

Defender for Cloud enabled and tuned, with the secure score treated as a target rather than a dashboard.

Identity

Entra ID Protection, conditional access, and privileged access reviewed rather than permanent.

Policy

Azure Policy enforcing the guardrails set in the landing zone, so drift is prevented and not just reported.

Logging

Diagnostic and sign-in logs collected and retained, so an investigation has something to work with.

Watched by our SOC

From

The Protect plan upward. Below that, the controls above are configured but nobody is monitoring them for you.

Coverage

From the Protect plan upward, Azure is included in the same 24/7 security monitoring and response coverage as the rest of your managed estate.

Response

Analysts investigate and contain, rather than forwarding you an alert to triage yourself.

Detection and response is a service in its own right. How our managed SOC works

Desktops and identity

Where your people sign in.

Identity is the perimeter now, and for a lot of organisations the desktop has moved with it.

Azure Virtual Desktop

Session hosts sized and scheduled against real usage, with the applications and profiles that make it feel like a desktop rather than a compromise.

Windows 365

A fixed per-user Cloud PC where predictability matters more than density. We will tell you which of the two your usage pattern actually suits.

Entra ID

The identity plane underneath all of it - conditional access, multi-factor, privileged access management, and hybrid join where domain controllers are still in the picture.

How you buy it

Your subscription or ours. Both work.

Some organisations want one invoice and one number to call. Others have an agreement with Microsoft already, or a policy that says the subscription stays in their name. Neither changes what we do on top of it.

Billed by Layer3

Invoice

Azure consumption on the same invoice as everything else Layer3 provides.

Support

Your first call is to a New Zealand engineer who can already see the tenant.

Cost work

Reservations and savings plans purchased and managed on your behalf.

Billed to you

Invoice

Your existing agreement with Microsoft is untouched. Layer3 charges for the management, not the consumption.

Access

Delegated administration into your tenant, scoped and reviewable, revocable by you.

Cost work

The same analysis and the same recommendations. You place the purchases.

Azure or private cloud

Azure is not always the answer, and we will say so.

Layer3 also operates private-cloud infrastructure in Auckland. For steady, predictable virtual-machine workloads, it can offer a simpler operating and cost model than Azure; for other workloads, Azure's platform services and scale may be a better fit. These eleven questions help identify which model fits.

Question

Points to

Layer3 private cloud

Points to

Azure

Is this a set of virtual machines you already run, or something you would rebuild?

Servers as they are, Windows and Linux

We want to re-platform onto managed services

Do those machines carry Microsoft server licensing - Windows Server, SQL Server?

Yes, and the licensing cost matters

Little or no Microsoft server licensing

Is the load steady, or does it spike?

Steady - it runs much the same all year

Spiky, seasonal, or growing in bursts

Would an agreed monthly service charge be easier to govern than consumption billing?

Yes - finance wants one number

We can manage a variable bill

Do these systems talk constantly to people or equipment on your own sites?

Yes - file, SQL, virtual desktops, plant systems

Mostly reached over the internet

Is New Zealand data residency a hard requirement you have to evidence?

Yes, and we get asked to prove it

Preferred, not mandatory

Do you want platform services rather than servers - managed databases, app hosting, functions?

Servers are what we run

Yes, that is the direction

Are you already building on Entra ID, Intune and the wider Microsoft cloud?

Some of it

Yes, it is where we are heading

Do you need capacity or disaster recovery outside New Zealand?

No

Yes

Is this development and test that gets created and destroyed?

No, it is production

Yes, frequently

Do you need to scale to nothing outside business hours?

No

Yes

Most organisations land split, and that is a real answer rather than a fudge - the steady core in Auckland, elastic and platform workloads in Azure. We run both, so the recommendation is not decided by what we happen to sell. How our private cloud works

Questions

Questions about Azure

If yours is not here, ask us directly — you will get an engineer, not a form response.

Book a discovery call

Either. We can bill your Azure consumption on the same invoice as everything else, or manage a subscription that stays in your own name under your existing Microsoft agreement. What we do on top is the same in both cases.

Yes, and that is how most engagements start. We assess what is there, document it, fix the structural problems that can be fixed in place, and give you a plan for the ones that need rebuilding.

It is the structure underneath your workloads — subscriptions, networks, policy and access — designed on purpose. You need one if you plan to keep growing in Azure. Retrofitting it later is possible but it is always more expensive than doing it first.

Usually, and the levers are consistent: budgets, reservations, rightsizing, removing orphaned resources, and attributing spend to whoever caused it. The last one changes behaviour more than the other four combined.

Microsoft's own controls are configured as standard on every environment we manage. Monitoring — a security operations centre watching what those controls report, around the clock — comes with the Protect plan and above, and it covers Azure as part of your whole estate rather than as a separate service.

It depends on the workload, and there is a question-by-question comparison on this page. Broadly: steady virtual machines carrying Microsoft licensing and talking to your own sites usually belong in our Auckland private cloud. Elastic demand, platform services and anything you want to re-platform usually belong in Azure. Plenty of organisations end up with both.

Migration runs in waves, each one piloted first and each one with a rollback. Most waves cut over in a window you choose rather than requiring an outage, and the source environment stays intact until the wave is signed off.

Yes, along with Windows 365. They suit different usage patterns and different budgets, and part of the work is telling you which one your organisation actually needs.

Next step

Tell us what you are trying to do in Azure.

Including when the honest answer is that it belongs somewhere else.

Layer3

Book a discovery call - 30 minutes, no obligation