Landing zone design
The Azure foundation — Entra ID identity, VNet topology, Azure Firewall or NSGs, naming and tagging policy, RBAC roles, Log Analytics workspace and Defender for Cloud. Built once, properly, so everything that comes after has a stable base. We use Microsoft's small-enterprise reference architecture, scaled to your size.