Azure landing zone
Before anything runs in Azure, there's a platform underneath it: where subscriptions sit, what they're allowed to do, where their logs go and what they're allowed to cost. This is a miniature version of that, governing the identity lab next door.
The hierarchy
- Glasscliff
- Decommissioned
- Landing Zones
- Online
- Azure for Students
- Online
- Platform
- Sandbox
Every subscription under Glasscliff inherits the policies below. The identity lab's subscription sits under Landing Zones / Online.
Policies
Mode: Deny: new resources that break a rule are refused.
| Rule | Compliant | Non-compliant |
|---|---|---|
| Resources stay in East US 2 | 0 | 0 |
| Every resource has an owner tag | 0 | 0 |
| Every resource has an environment tag | 0 | 0 |
| No standalone public IP addresses | 0 | 0 |
| Storage accepts only HTTPS and TLS 1.2 | 0 | 0 |
Counts come from Azure Policy's latest evaluation of every existing resource.
Try to break the rules
Describe a resource and Azure Policy will say whether it could be deployed here. Nothing is created. Azure checks the proposal against the real policies and answers.
Tag coverage
| Resource group | Fully tagged |
|---|---|
| mtc-resources | 0 of 3 |
| rg-basic-webapp | 4 of 6 |
| rg-dns | 0 of 1 |
| rg-glasscliff-lab | 8 of 8 |
| rg-glasscliff-platform | 1 of 1 |
| rg-resume | 0 of 2 |
| rg-tfstate | 0 of 2 |
Fully tagged means both an owner and an environment tag.
Spend
$3.89 spent of a $30.00 monthly budget (13%), forecast $9.72.
Alerts go out at 50% and 80% of actual spend, and at 100% of forecast.
Read live from Azure with a read-only identity. Last read Sat, 10 Oct 2026 15:32:40 GMT.