Microsoft Azure
Management-group hierarchy with policy inherited from the root, a Virtual WAN hub per region, and every PaaS and model endpoint reachable only through Private Link.
Text description of the diagram
Management groups: Tenant Root Group → Platform, Landing Zones, Sandbox.
- Edge: Front Door + WAF — DDoS Network Protection
- Identity: Entra ID — PIM · Conditional Access
- Network: Virtual WAN hub-spoke — Azure Firewall · Private Link
- Workload: App spoke — AKS · App Service; Azure AI Foundry attached via Private Link
- Data: Microsoft Purview — Storage · SQL via private endpoint
Security plane: Defender for Cloud · Sentinel, across every layer. IaC: Bicep + Terraform (Azure Policy as code · subscription vending).