Session
Governance at Scale: Enforcing Network Security Baselines with Azure Policy & Landing Zones
As organisations grow beyond a handful of subscriptions, manually reviewing every deployment for security compliance becomes impossible — and relying on after-the-fact audits means misconfigurations are often live in production before anyone notices. This session makes the case for "guardrails, not gates": governance that's built into the platform itself rather than bolted on afterward.
We'll start with Azure Policy fundamentals — policy definitions, initiatives, and effects (Deny, Audit, DeployIfNotExists, Modify) — and how each effect type is appropriate for different governance scenarios. From there, we move into practical network security baselines: policies that deny public IP creation on VMs, enforce mandatory NSG association on subnets, require specific Azure Firewall routing, and mandate encryption in transit.
The session then zooms out to the Cloud Adoption Framework Landing Zone model, showing how these individual policies are assembled into a coherent governance architecture applied automatically at subscription vending time — so every new subscription inherits the right guardrails from day one, rather than security being retrofitted later. We'll cover management group hierarchy design, policy assignment scope, and handling policy exemptions for legitimate edge cases without undermining the overall baseline.
Santhoshkumar Anandakrishnan
Lead Cloud Architect
Melbourne, Australia
Links
Please note that Sessionize is not responsible for the accuracy or validity of the data provided by speakers. If you suspect this profile to be fake or spam, please let us know.
Jump to top