{
  "id": 11168712,
  "title": "A No-Nonsense Cloud Landing Zone Checklist (Azure, AWS, Google Cloud)",
  "url": "https://urgent.news/2026/10/01/a-no-nonsense-cloud-landing-zone-checklist-azure-aws-google-cloud",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-10-01T10:38:47.000Z",
  "source": {
    "name": "Dev.to",
    "slug": "dev-to",
    "url": "https://dev.to/wiewave/a-no-nonsense-cloud-landing-zone-checklist-azure-aws-google-cloud-1ek4"
  },
  "original_language": "en",
  "account": "The cloud landing zone concept refers to the foundation necessary for securely launching workloads in cloud environments like Azure, AWS, and Google Cloud. This foundational platform, encompassing identity, network, guardrails, and logging, is distinct from the workloads themselves.\n\nKey components of a cloud landing zone include groups for everything, subscriptions or projects for workloads, identity managed by Microsoft Entra ID, AWS IAM Identity Center, or Google Cloud Identity, and policies like Azure Policy, AWS Service Control Policies, or Google Cloud Organization Policies to enforce security rules.\n\nAzure, AWS, and Google Cloud each present their landing zones differently. Azure's management groups, AWS Organizational Units, and Google Cloud folders serve as grouping entities. Subscriptions, AWS accounts, and Google Cloud projects denote workload boundaries. Centralized logging, network hubs, and shared virtual private clouds create a cohesive architecture.\n\nBefore deploying any resources, define the identity provider, enforce multi-factor authentication, and assign roles at the highest applicable scope. Avoid placing workloads within the management account as it bypasses governance controls. Establish non-overlapping IP ranges for each environment before creating the first spoke network.\n\nGuardrails serve as preventative measures against misconfigurations that could result in incidents. Azure Policy, AWS Service Control Policies, and Google Cloud Organization Policies all aim to restrict permissions and enforce security standards. Begin with basic guardrails such as restricting regions, blocking public storage, enforcing encryption, and limiting access to the logging account. Test these rules in a controlled environment before organization-wide deployment.\n\nLogging and cost tagging are equally crucial. Aggregated logs should be centralized for visibility but secured from deletion. A standard tagging scheme must be established upfront to track cost and ownership effectively. Adopting a codified approach for landing zones is integral to their success. Utilize managed identities and service accounts for workload identities, and employ tools like Azure Verified Modules, AWS Account Factory, or Terraform-based blueprints to maintain infrastructure as code.",
  "summary": "If you've ever been handed a brand-new Azure subscription, AWS account or Google Cloud project and told to \"just get something running,\" you already know the real problem isn't the workload. It's everything around it: who's allowed to log in, how the network is wired, what stops someone from spinning up a public storage bucket at 2am, and where the audit logs actually end up. That governed…",
  "key_points": [
    "Cloud landing zone is foundational platform for secure workload launch in Azure, AWS, Google Cloud",
    "Key components include identity management, policies for security enforcement, centralized logging",
    "Define identity provider, enforce MFA, avoid workloads in management account before deployment"
  ],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 1,
    "also_reported_by": []
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}