| Method | Best For | Considerations |
|---|---|---|
| Cloud-only | New organizations | No on-premises dependency |
| Password Hash Sync | Hybrid, simplicity | Passwords synced to cloud |
| Pass-through Auth | Hybrid, on-prem validation | Requires agents on-prem |
| Federation (AD FS) | Complex requirements | Higher complexity, full control |
| Scenario | Policy Effect | Example |
|---|---|---|
| Restrict regions | Deny | Only allow East US, West US |
| Enforce tagging | Deny/Modify | Require cost center tag |
| Audit compliance | Audit | Check for encryption |
| Auto-configure | DeployIfNotExists | Enable diagnostics |
Use Azure Landing Zone accelerator for:
• Platform landing zones (shared services)
• Application landing zones (workloads)
• Subscription vending for self-service