Regroup several landing zones in a Business Zone (Explorer)
Introduction
If you have multiple infrastructure landing zones, you may have encountered some common issues:
- Difficulties to maintain a 360 dashboard to monitor all your landing zones
- Enable to collect infrastructure logs to your dedicate CSOC
- Provide reader or security accesses on multiples landing zones
- Enable to add additional security policies related to your business
What does it change ?
By default, all the infrastructure landing zones are isolated between themselves :
A business group regroups the infrastructure landing zones in a customer management group (providing a transversal visibility to all subscriptions) and centralizes log into a transversal subscription.
How to ask for a business zone ?
Prerequisites:
- have multiple subscriptions associated with a single TDFaccountID
- all subscriptions should be in the same region
Access to postIT, and make a simple request mentioning this documentation. Please provide:
- the TDFaccountID
- the list of subscription to regroup
- the custom permissions you want on the management group
- the identity of the people who need access to the transversal log sink
Impact of business zone:
- all the subscriptions will be switch to "industrialized" service offer
- a new subscription will be created to store all the logs coming from the subscriptions
HOWTO access to my transversal log analytics ?
Let's take an example:
- BZ-SHOWROOM will be the the business room
- BZ-SHOWROOM - Core Services will be the transversal landing zone (added during the creation of the business zone to store all the subscription logs)
On azure portal, search for management group. You should see all the management group you have the permission on. Click on you business zone, like:
Then select your core-service / transversal subscription:
Then select resources, and find the log analytics resource:
This log analytics will store all the logs collected from agent and diagnostic settings enabled on PaaS.
Known limitations
Business zone is only available for landing zone with corporate addon.