Landing zone

The First Apply Is Local (and That's Fine)
- Jonathan Aerts
- Landing Zone
- 14 Aug, 2026
TL;DR. The deployment chain that applies your IaC is itself infrastructure — and something has to create it first. Instead of hand-building the pipeline chain before the code could run, we appli
read more
The Second Landing Zone Is the Real Test of the First
- Jonathan Aerts
- Landing Zone
- 14 Aug, 2026
TL;DR. We stamped out a second application landing zone from the first one. The diff between the two repos is six values: subscription, name acronym, address space, project, service connecti
read more
Deploying Azure Virtual Desktop End-to-End in a Landing Zone
- Jonathan Aerts
- Azure Virtual Desktop
- 01 Jul, 2026
TL;DR. This is the deployment walkthrough for a fully private, Entra-only Azure Virtual Desktop environment inside a regulated Azure Landing Zone. Pooled Windows 11 multi-session on a **cust
read more
When terraform plan says 'no changes' and the feature is broken anyway
- Jonathan Aerts
- Landing Zone
- 25 Jun, 2026
Everything was green. Workspace deployed, host pool up, users assigned, RBAC clean. Then a user opens Windows App and hits: "No devices or apps found." The feed never loads. Nothing in the Azure
read more
Azure Virtual Desktop in a regulated Landing Zone: the traps no doc tells you about
- Jonathan Aerts
- Azure Virtual Desktop
- 20 Jun, 2026
TL;DR. Deploying Azure Virtual Desktop fully private in a Landing Zone (Private Endpoints everywhere, Palo Alto NVA for egress, centralised DNS) works very well — once you know about a dozen
read more
Building 60+ Terraform Modules for an Azure Landing Zone
- Jonathan Aerts
- Landing Zone
- 15 Apr, 2026
Why Build From Scratch? When I started building the Azure Landing Zone for a regulated European telecom operator, the obvious question was: _why not just use the Azure Verified Modules (AVM) direc
read more
Azure Landing Zone with Palo Alto NVA: Lessons Learned
- Jonathan Aerts
- Networking
- 12 Apr, 2026
Deploying Palo Alto VM-Series as a Network Virtual Appliance in an Azure Landing Zone sounds straightforward — until you actually do it. This article covers the hard-won lessons from building the fire
read more
SubnetWithNsg: How Azure Policy Deny Forced Me to Use azapi
- Jonathan Aerts
- Networking
- 05 Apr, 2026
The Problem Every production Azure Landing Zone deploys a Deny policy: "Subnets must have a Network Security Group." It is a security best practice — no subnet should exist without an NSG cont
read more