Skip to main content

Regroup several landing zones in a Business Zone (Explorer)

Introduction

If you have multiple infrastructure landing zones, you may have encountered some common issues:

  • Difficulties to maintain a 360 dashboard to monitor all your landing zones
  • Enable to collect infrastructure logs to your dedicate CSOC
  • Provide reader or security accesses on multiples landing zones
  • Enable to add additional security policies related to your business

What does it change ?

By default, all the infrastructure landing zones are isolated between themselves :

img

A business group regroups the infrastructure landing zones in a customer management group (providing a transversal visibility to all subscriptions) and centralizes log into a transversal subscription.

img

How to ask for a business zone ?

Prerequisites:

  • have multiple subscriptions associated with a single TDFaccountID
  • all subscriptions should be in the same region

Access to postIT, and make a simple request mentioning this documentation. Please provide:

  • the TDFaccountID
  • the list of subscription to regroup
  • the custom permissions you want on the management group
  • the identity of the people who need access to the transversal log sink

Impact of business zone:

  • all the subscriptions will be switch to "industrialized" service offer
  • a new subscription will be created to store all the logs coming from the subscriptions

HOWTO access to my transversal log analytics ?

Let's take an example:

  • BZ-SHOWROOM will be the the business room
  • BZ-SHOWROOM - Core Services will be the transversal landing zone (added during the creation of the business zone to store all the subscription logs)

On azure portal, search for management group. You should see all the management group you have the permission on. Click on you business zone, like: img

Then select your core-service / transversal subscription: img

Then select resources, and find the log analytics resource: img

img

This log analytics will store all the logs collected from agent and diagnostic settings enabled on PaaS.

Known limitations

Business zone is only available for landing zone with corporate addon.

Additional HOWTO