What's new in the Microsoft Cloud Adoption Framework for Azure

We build the Microsoft Cloud Adoption Framework collaboratively with our customers, partners, and internal Microsoft Teams. We release new and updated content for the framework as it becomes available. These new releases pose an opportunity for you to test, validate, and refine the Cloud Adoption Framework guidance along with us.

Partner with us in our ongoing effort to develop the Cloud Adoption Framework.

November 2024

New articles

  • Monitor a cloud environment: This month, we retired outdated content on cloud monitoring and introduced a new overview that provides comprehensive guidance in a simplified format. Explore the importance of monitoring, the key components of a monitoring strategy, and the tools and services you can use to monitor your cloud environment effectively.
  • Well-architected considerations for AI workloads on Azure infrastructure (IaaS): Explore the importance of well-architected AI solutions and how to apply the Azure Well-Architected Framework to your AI workloads. Find guidance on reliability, security, cost optimization, operational excellence, and performance efficiency.

Secure methodology refresh

This month, we made significant updates to the Secure methodology. The Secure methodology provides guidance on how to secure your cloud environment and protect your data. The methodology includes the following articles:

  • Secure overview: Learn about the Secure methodology and how to apply it to secure your cloud environment. Explore the key components of the Secure methodology, including security principles, security controls, and security best practices.
  • Security teams, roles, and functions: Learn about the key security teams, roles, and functions that are essential for securing your cloud environment.
  • Integrate security into your cloud adoption strategy: Explore key considerations for integrating security into your cloud adoption strategy.
  • Plan for a secure cloud adoption: Learn about the key considerations for planning a secure cloud adoption and the tools and services you can use to plan for a secure cloud adoption.
  • Prepare your secure cloud estate: Find guidance on the key considerations for preparing your secure cloud estate and the tools and services you can use to prepare your cloud estate securely.
  • Perform your cloud adoption securely: Explore the importance of security in cloud adoption and the key considerations for securely adopting cloud services.
  • Securely govern your cloud estate: Find guidance on the key considerations for securely governing your cloud estate and the tools and services you can use to securely govern your cloud environment.
  • Manage your cloud estate with enhanced security: Explore the importance of managing your cloud estate with enhanced security and the key considerations for managing your cloud estate securely.

SAP and Power Platform

We introduced new articles that provide guidance on integrating SAP and Power Platform. Learn how to extend an SAP landing zone to support Power Platform, understand the architecture workflow, and explore the fundamentals of SAP and Power Platform integration.

Updated articles

October 2024

New articles

Azure VMware Solution and Global Reach

New CAF Scenario: AI Adoption on Azure

  • Establish an AI Center of Excellence: Learn how to create and manage an AI Center of Excellence (AI CoE) to drive AI adoption within an organization. Find guidance on the importance of an AI CoE, defining its functions, building a cross-functional team, structuring operations, and ensuring ongoing monitoring and evolution of AI initiatives.
  • Recommendations for organizations governing AI workloads in Azure: Learn best practices and recommendations for integrating AI risk management into broader risk management strategies, assessing organizational AI risks, documenting and enforcing AI governance policies, and monitoring AI risks.
  • Recommendations for managing AI: Learn best practices for managing AI workloads in Azure, including AI operations, deployment, endpoint sharing, model management, cost management, data management, and business continuity. Explore the need for structured practices, continuous monitoring, and adherence to governance standards to ensure effective and reliable AI system management.
  • Recommendations for organizations planning AI adoption: See guidance on integrating AI into an organization, including assessing and acquiring AI skills, accessing AI resources, prioritizing AI use cases, creating AI proofs of concept, implementing responsible AI practices, and estimating delivery timelines.
  • Recommendations for organizations building AI workloads in Azure: Explore guidance on establishing reliability, governance, networking, and foundational infrastructure for AI workloads in Azure. Learn best practices for ensuring availability, managing costs, securing networks, and creating scalable environments.
  • Recommendations for organizations securing AI workloads in Azure: Review guidelines on assessing AI security risks, implementing security controls for AI resources and data, and maintaining these controls through continuous monitoring and updates. Learn about the importance of protecting the confidentiality, integrity, and availability of AI models and data to prevent breaches and ensure compliance.
  • Recommendations for organizations developing an AI adoption strategy: Learn the latest guidance on identifying AI use cases, defining technology and data strategies, and ensuring responsible AI practices to effectively adopt AI within an organization.
AI workloads on Azure infrastructure (IaaS)
  • Compute recommendations: Learn how to select virtual machines, images, and orchestration solutions to optimize AI workloads on Azure. See recommendations for training and inferencing AI models, managing costs, and using containers for scalable AI solutions.
  • Implementation options: See recommendations for deploying AI workloads using Azure CycleCloud and Slurm. This article covers cluster creation, dynamic management, and infrastructure control, offering guidelines and architecture for efficient AI operations on Azure IaaS.
  • Governance recommendations: Explore guidelines for managing resources, controlling costs, ensuring security, and maintaining operational consistency for AI workloads on Azure.
  • Management recommendations: Learn strategies for effectively managing AI workloads on Azure by emphasizing continuous monitoring, optimizing practices, and establishing robust backup and disaster recovery plans.
  • Networking recommendations: Learn about how to network to optimize bandwidth, minimize latency, and implement high-performance networking for AI workloads on Azure. Explore strategies for resource placement, using proximity placement groups, and utilizing GPU-optimized VMs and InfiniBand for efficient data processing.
  • Security recommendations: Find guidance on securing Azure services, networks, data, access, and operating systems for AI workloads. Learn how to prioritize encryption, network security, access control, and incident response preparation.
  • Storage recommendations: Learn how to use different storage options like Azure Managed Lustre, Azure NetApp Files, and local NVMe/SSD-based storage for active data, transferring inactive data to Azure Blob Storage, implementing checkpointing for model training, automating data migration to lower-cost storage tiers, ensuring data consistency, and enabling data versioning for reproducibility.
AI workloads and Azure AI platform services (PaaS)
  • AI architecture guidance to build AI workloads on Azure: This set of articles provides architecture guidance for building AI workloads on Azure using platform-as-a-service (PaaS) solutions, including references and guides for both generative and nongenerative AI architectures, as well as recommendations for AI resource selection, networking, governance, management, and security.
  • Governance recommendations: Find recommendations and best practices for managing, including AI model governance, cost control, platform policies, security measures, operational management, regulatory compliance, and data governance.
  • Management recommendations: Learn best practices for deployment, model monitoring, operations, data management, and business continuity to ensure effective and secure AI operations.
  • Networking recommendations: Explore networking recommendations, including how to configure and secure virtual networks, manage connectivity, and implement strategies to protect sensitive AI resources and ensure data integrity and privacy.
  • Resource selection recommendations: Find guidance on choosing the right Azure AI platform, compute resources, data sources, and processing tools for both generative and nongenerative AI applications.
  • Security recommendations: Learn security recommendations covering topics such as securing AI resources, models, access, and execution to protect against potential threats and maintain data integrity and compliance.

Updated articles

September 2024

Updated articles

We reviewed and made updates to the following articles to reflect the latest product naming and guidance:

We made updates to the following articles for clarity and accessibility:

August 2024

Updated articles

We made updates to the following articles for clarity:

July 2024

New articles

This month, we introduced new articles that have guidance for Red Hat Enterprise Linux (RHEL) on Azure. We also added new articles and made major updates to existing articles for Oracle on Azure IaaS and Oracle Database@Azure. Take a look at the new and updated content to see how you can apply these recommendations in your organization.

Red Hat Enterprise Linux on Azure

  • Azure RHEL landing zone accelerator: Learn how to use the RHEL landing zone accelerator to create a consistent, repeatable, and secure environment deployment. Use the architectural guidance and reference implementation recommendations to accelerate the migration and deployment of RHEL-based workloads to Microsoft Azure.
  • Identity and access management (IAM) for RHEL: Discover IAM considerations for your RHEL landing zone accelerator deployment. Learn how to carefully design your hybrid cloud IAM implementation to ensure smooth integration and management of your instance landscape in the Azure cloud.
  • Business continuity and disaster recovery for RHEL: Learn how to improve business continuity and disaster recovery for your RHEL on Azure environment. Explore recommendations that you can use to support RHEL workloads and to deploy RHEL platform-management components.
  • Network topology and connectivity for RHEL: Learn how to implement design considerations and recommendations for network topology and connectivity in RHEL on Azure infrastructure. See how you can deploy various RHEL platform components and roles on virtual machines (VMs) with specific sizing and redundancy as needed.
  • Resource organization for RHEL: Learn key tactics for how to choose management groups and subscriptions that will help to ensure that you effectively govern and manage resources for your RHEL deployment.
  • Security for RHEL: See how you can design your security to target multiple areas to protect your RHEL systems. Learn how to create a secure and resilient cloud environment by implementing a strategic approach that applies both Azure and Red Hat security mechanisms.
  • Management and monitoring for RHEL: Learn about best practices for effective management and monitoring in your RHEL on Azure infrastructure.
  • Governance and compliance for RHEL: Learn about design considerations and recommendations for governance and compliance in an RHEL on Azure infrastructure. Discover key tactics for establishing efficient and effective governance and compliance in a cloud environment.
  • Platform automation for RHEL: Learn about the tools, features, and services you can use to automate various tasks and manage the RHEL lifecycle within your Azure environment. Discover how to implement automation to improve the efficiency and reliability of your RHEL on Azure infrastructure.

Oracle

  • Oracle on Azure IaaS landing zone accelerator: Learn how you can use the Oracle on Azure IaaS landing zone accelerator to automate the deployment of an environment capable of hosting Oracle on Azure IaaS Virtual Machines. See how the landing zone accelerator can be adapted to produce an architecture that fits your scenario and puts your organization on a path to sustainable scale.
  • Manage and monitor Oracle Database@Azure: Explore best practices for management and monitoring Oracle Exadata Database Service on a Dedicated Infrastructure with Oracle Database@Azure. Learn about key design considerations for health and metrics monitoring.
  • Business continuity and disaster recovery for Oracle Database@Azure: Learn about business continuity and disaster recovery for Oracle Database@Azure and how to build a resilient architecture for your workload environment. Discover how you can design your architecture to meet the recovery time objective (RTO) and recovery point objective (RPO) of your solution.
  • Business continuity and disaster recovery for Oracle on Azure Virtual Machines landing zone accelerator: Find significant updates that reflect new guidance including the deprecation of availability sets and new recommendations for Virtual Machine Scale Sets flexible orchestration.

Updated articles

We made updates to the following articles to provide the latest guidance on networking:

These files were updated to include considerations for Azure Arc-enabled VMware vSphere and Azure Arc-enabled System Center Virtual Machine Manager:

June 2024

New articles

  • Establish common subscription vending product lines: Give application teams the flexibility to deliver their workloads and services effectively by offering different subscription vending product lines. Implement subscription vending in your Azure landing zones to establish consistent scaling, security, and governance of Azure environments.

Updated articles

We updated these articles to provide the latest guidance on Azure carbon optimization:

Hybrid/Azure Arc retirement

We retired several articles in the Hybrid/Azure Arc scenario in the best practices area. The content was outdated and no longer relevant to the Cloud Adoption Framework.

May 2024

New articles

This month, we introduced a new article related to Azure Virtual Network Manager that has recommendations for networking topologies in Azure landing zones. We also added new articles that have guidance on Oracle Database@Azure. Take a look at the new content to see how you can apply these recommendations in your organization.

Azure Virtual Network Manager

  • Azure Virtual Network Manager in Azure landing zones: Use Azure's Virtual Network Manager to implement landing zone design principles for application migrations, modernization, and innovation at scale. Learn more about two recommended networking topologies: Azure Virtual WAN and traditional hub-and-spoke. The Virtual Network Manager allows for the expansion and implementation of networking changes as business requirements evolve. See how these changes can be made without disrupting deployed Azure resources.

Oracle Database@Azure

Explore new articles on Oracle Database@Azure.

  • Introduction to the Oracle on Azure adoption scenario: Learn how to set up and manage Oracle workloads within your Azure landing zone. Learn about specific architectural strategies and implementations for Oracle database systems on Azure.
  • Identity and access management for Oracle Database@Azure: Learn key tactics for proper identity and access management for Oracle Database@Azure. Deploy your initial Oracle Database@Azure instance to create specific groups within Microsoft Entra ID and in the corresponding tenant. Learn how to use Microsoft Entra administrator groups and how to establish other groups and roles to enhance the granularity of access permissions.
  • Network topology and connectivity for Oracle on Azure Virtual Machines: Learn about network topology and connectivity considerations for running Oracle on Azure Virtual Machines. Explore the importance of security for Oracle workloads, and receive a high-level network design with various recommendations.
  • Network topology and connectivity for Oracle Database@Azure: Learn how to set up network topologies and connectivity for Oracle Database@Azure. Explore options for physical placement, learn about the use of virtual machine clusters, and learn the importance of private subnets. See how to configure network security groups and why you should use Azure Firewall to protect your Oracle Database@Azure instance.
  • Security guidelines for Oracle Database@Azure: Receive design considerations and recommendations for implementing security measures for Oracle Database@Azure. See the importance of a defense-in-depth strategy, which layers multiple defense mechanisms for comprehensive security. This strategy includes strong authentication and authorization frameworks, network security, and encryption of data.

Updated articles

Azure Blueprint deprecation

We made updates to reflect the deprecation of Azure Blueprint.

Oracle Database@Azure updates

We updated articles to include guidance on Oracle Database@Azure.

Azure landing zone multiregion updates

We updated articles to provide recommendations for multiregion deployments in Azure landing zones.

DevOps updates

  • DevOps considerations: The DevOps technologies list was updated to include bootstrapping and infrastructure as code (IaC) tools.

April 2024

New articles

This month, we completely refreshed articles related to the Migrate and Govern methodologies in the Cloud Adoption Framework. We also added a few articles about Azure landing zones in the Ready methodology. Take a look to make sure you're applying the relevant recommendations.

Migrate methodology refresh

Explore dozens of new and updated articles to guide you through the migration process.

Govern methodology refresh

We overhauled our collection of articles in the Govern methodology, making the concepts easier to consume and understand as you set up cloud governance in your organization.

Ready methodology

Find new articles about Azure landing zones in the Ready methodology.

Updated articles

March 2024

Updated articles

February 2024

New articles

Updated articles

  • Hybrid identity with Active Directory and Microsoft Entra ID in Azure landing zones: We updated this article to include information about how to design and implement Microsoft Entra ID and hybrid identity for Azure landing zones. Microsoft Entra ID is a cloud-based identity and access management service that provides robust capabilities to manage users and groups. You can use it as a standalone identity solution or integrate it with a Microsoft Entra Domain Services infrastructure or an on-premises Active Directory Domain Services (AD DS) infrastructure.
  • Landing zone identity and access management: Find out about considerations and recommendations for implementing identity and access control within Azure application and platform landing zones. This article has extensive new content.
  • Azure identity and access management design area: Learn about the identity and access management design area, which provides best practices to establish the foundation of your public cloud architecture. This article has extensive new content.
  • Cloud adoption journey: Learn about various types of cloud adoption journeys, including when to retire, replace, rearchitect, rebuild, rehost, or replatform your solution.
  • Azure migration tools decision guide: We added information about tools for application migration, modernization, replatforming, and rehosting.
  • Azure workload management and monitoring: Find new guidance about sovereign workloads.

January 2024

New articles

  • Define a sovereignty strategy: Organizations that use cloud services can find guidance for meeting the sovereignty requirements for their countries/regions. We also updated several articles with sovereignty considerations, which you'll find under the "Updated articles" section for this month.

  • Advanced Azure Policy management: Find out how to manage Azure Policy at scale by using the Enterprise Policy as Code (EPAC) open-source project and integrating IaC into your environment.

Updated articles

December 2023

New articles

Find new guidance about Azure landing zones:

Updated articles

In the following articles, find updated guidance about workload discovery processes that help you understand the many dimensions involved in migrating a workload. You can use that information to help you effectively migrate cloud workloads to another region.

In Centralized security operations with external identities for multitenant defense organizations, we updated our guidance for centralized security operations.

In Identity and access management for Azure Virtual Desktop, we added updates for Azure Virtual Desktop design considerations and supported identity scenarios.