Glasscliff

Azure landing zone

Before anything runs in Azure, there's a platform underneath it: where subscriptions sit, what they're allowed to do, where their logs go and what they're allowed to cost. This is a miniature version of that, governing the identity lab next door.

About this landing zone

The hierarchy

Every subscription under Glasscliff inherits the policies below. The identity lab's subscription sits under Landing Zones / Online.

Policies

Mode: Deny: new resources that break a rule are refused.

RuleCompliantNon-compliant
Resources stay in East US 200
Every resource has an owner tag00
Every resource has an environment tag00
No standalone public IP addresses00
Storage accepts only HTTPS and TLS 1.200

Counts come from Azure Policy's latest evaluation of every existing resource.

Try to break the rules

Describe a resource and Azure Policy will say whether it could be deployed here. Nothing is created. Azure checks the proposal against the real policies and answers.

Resource
Region
Tags
Storage settings (storage accounts only)

Tag coverage

Resource groupFully tagged
mtc-resources0 of 3
rg-basic-webapp4 of 6
rg-dns0 of 1
rg-glasscliff-lab8 of 8
rg-glasscliff-platform1 of 1
rg-resume0 of 2
rg-tfstate0 of 2

Fully tagged means both an owner and an environment tag.

Spend

$3.89 spent of a $30.00 monthly budget (13%), forecast $9.72.

Alerts go out at 50% and 80% of actual spend, and at 100% of forecast.

Read live from Azure with a read-only identity. Last read Sat, 10 Oct 2026 15:32:40 GMT.