Our great sponsors
-
ALZ-Bicep
This repository contains the Azure Landing Zones (ALZ) Bicep modules that help deliver and deploy the Azure Landing Zone conceptual architecture in a modular approach. https://aka.ms/alz/docs
-
WorkOS
The modern identity platform for B2B SaaS. The APIs are flexible and easy-to-use, supporting authentication, user identity, and complex enterprise features like SSO and SCIM provisioning.
1) Personally I would deploy the CAF blueprints (through the portal, or even better through CI/CD, I'm personally a fan of the Bicep templates. Then depending on what's already in the cloud (number wise, can you take a weekend of being offline while you fix it etc), you can opt to move the VMs out of the existing subscription/vnet, or recreate connectivity in a separate hub network. Ideally the AD VMs are moved to the identity subscription as well, so that's a 3rd sub.