DRAFT: Azure Subscription Standard

Purpose

This standard defines the requirements for Azure subscription design, governance, ownership, operational management, and lifecycle management within University-managed Azure environments.

The standard establishes Azure subscriptions as the primary boundary for workload isolation, administrative separation, billing accountability, and operational management. Governance requirements applicable to subscriptions are defined through the Management Group Governance Model and related governance standards.

Scope

This standard applies to:

  • Production subscriptions
  • Non-production subscriptions
  • HIPAA subscriptions
  • Shared services subscriptions
  • Platform subscriptions
  • Application subscriptions
  • Data platform subscriptions
  • Enterprise-managed Azure environments

This standard does not apply to Azure subscriptions managed outside approved University governance processes.

Requirements

1. Subscription Boundary

Azure subscriptions shall serve as the primary workload isolation, administrative, operational, and accountability boundary for workloads hosted within University-managed Azure environments.

2. Approved Management Group Placement

All subscriptions must be assigned to approved Azure Management Group structures.

Subscriptions must inherit governance controls, policy assignments, monitoring requirements, and security guardrails through approved Management Group hierarchies whenever practical.

3. Workload Isolation

Workloads requiring unique governance, operational ownership, regulatory requirements, or administrative separation should be deployed into dedicated subscriptions.

Regulated workloads must be deployed into approved regulated subscriptions.

4. Ownership Assignment

Every subscription must have documented ownership.

Ownership shall include:

  • Business owner
  • Technical owner
  • Support organization
  • Cost accountability owner

Subscription ownership information must remain current throughout the subscription lifecycle.

5. Identity Integration

Subscriptions must use approved enterprise identity services and approved access management processes.

Administrative access must be governed through approved identity and privileged access controls.

6. Monitoring Enrollment

Subscriptions must participate in approved enterprise monitoring and logging services.

Monitoring configurations must provide operational visibility, auditability, and support for incident investigation activities.

7. Network Integration

Subscriptions must implement approved networking patterns and enterprise connectivity requirements.

Network configurations must support workload isolation, approved connectivity paths, and security monitoring requirements.

8. Shared Service Consumption

Subscriptions may consume approved enterprise shared services when those services have been approved through architecture standards and governance processes.

Shared services must comply with workload-specific regulatory and security requirements.

9. Automation

Subscriptions should be provisioned and configured through approved platform automation whenever practical.

Automation should support:

  • Subscription deployment
  • Management Group assignment
  • Governance configuration
  • Identity integration
  • Monitoring integration
  • Network onboarding

10. Lifecycle Management

Subscriptions must be managed through approved lifecycle processes.

Lifecycle activities include:

  • Provisioning
  • Modification
  • Operational management
  • Decommissioning

Subscriptions that are no longer required must be retired through approved governance processes.

11. Architecture Review

Subscription designs that deviate from approved governance structures or architecture patterns require architecture review and approval before implementation.

12. Exceptions

Exceptions to this standard require documented approval through the approved architecture exception process.