Blog

Deploying Azure Virtual Desktop End-to-End in a Landing Zone
- Jonathan Aerts
- Azure Virtual Desktop
- 01 Jul, 2026
TL;DR. This is the deployment walkthrough for a fully private, Entra-only Azure Virtual Desktop environment inside a regulated Azure Landing Zone. Pooled Windows 11 multi-session on a **cust
read more
When terraform plan says 'no changes' and the feature is broken anyway
- Jonathan Aerts
- Landing Zone
- 25 Jun, 2026
Everything was green. Workspace deployed, host pool up, users assigned, RBAC clean. Then a user opens Windows App and hits: "No devices or apps found." The feed never loads. Nothing in the Azure
read more
Azure Virtual Desktop: from POC to prod, the hardening checklist
- Jonathan Aerts
- Azure Virtual Desktop
- 22 Jun, 2026
TL;DR. A fully private AVD POC that works is not a prod. Between the two: harden the FSLogix storage (NTFS ACLs, backup), automate secret rotation, wire up observability (AVD Insights + dedicate
read more
Azure Virtual Desktop in a regulated Landing Zone: the traps no doc tells you about
- Jonathan Aerts
- Azure Virtual Desktop
- 20 Jun, 2026
TL;DR. Deploying Azure Virtual Desktop fully private in a Landing Zone (Private Endpoints everywhere, Palo Alto NVA for egress, centralised DNS) works very well — once you know about a dozen
read more
The AVM ALZ accelerator is solid. Here's what we add on top (and what we'd do differently)
- Jonathan Aerts
- Landing Zone
- 15 May, 2026
TL;DR. The official Azure/avm-ptn-alz/azurerm module covers the essentials of an Azure Landing Zone correctly. Three things aren't in the box and cost us time: explicit pinning of the alz/`a
read more
Building 60+ Terraform Modules for an Azure Landing Zone
- Jonathan Aerts
- Landing Zone
- 15 Apr, 2026
Why Build From Scratch? When I started building the Azure Landing Zone for a regulated European telecom operator, the obvious question was: _why not just use the Azure Verified Modules (AVM) direc
read moreTags
- Argocd
- Gitops
- Azure devops
- Workload identity
- Aks
- Entra id
- Oidc
- Kubernetes
- Security
- Bootstrap
- Self management
- Azure
- Avd
- Azure virtual desktop
- Terraform
- Terragrunt
- Fslogix
- Observability
- Finops
- Conditional access
- Private endpoint
- Landing zone
- Autoscale
- Alz
- Avm
- Infrastructure as code
- Cloud architecture
- Palo alto
- Iac
- Adr
- Multi tenancy
- Appproject
- Rbac
- Platform engineering
- Nva
- Ilb
- Governance
- State management
- Azure policy
- Azapi
- Subnet
- Nsg
- Modules
- Ci cd
- Renovate
- Testing
- Patterns