Body
Purpose
This standard defines the requirements for Azure subscription design, governance, ownership, operational management, and lifecycle management within University-managed Azure environments.
The standard establishes Azure subscriptions as the primary boundary for workload isolation, administrative separation, billing accountability, and operational management.
Governance requirements applicable to subscriptions are defined through the Management Group Governance Model and related governance standards.
Scope
This standard applies to:
- Production subscriptions
- Non-production subscriptions
- HIPAA subscriptions
- Shared services subscriptions
- Platform subscriptions
- Application subscriptions
- Data platform subscriptions
- Enterprise-managed Azure environments
This standard does not apply to Azure subscriptions managed outside approved University governance processes.
Requirements
1. Subscription Boundary
Azure subscriptions shall serve as the primary workload isolation, administrative, operational, and accountability boundary for workloads hosted within University-managed Azure environments.
2. Approved Management Group Placement
All subscriptions must be assigned to approved Azure Management Group structures.
Subscriptions must inherit governance controls, policy assignments, monitoring requirements, and security guardrails through approved Management Group hierarchies whenever practical.
3. Workload Isolation
Workloads requiring unique governance, operational ownership, regulatory requirements, or administrative separation should be deployed into dedicated subscriptions.
Regulated workloads must be deployed into approved regulated subscriptions.
4. Ownership Assignment
Every subscription must have documented ownership.
Ownership shall include:
- Business owner
- Technical owner
- Support organization
- Cost accountability owner
Subscription ownership information must remain current throughout the subscription lifecycle.
5. Identity Integration
Subscriptions must use approved enterprise identity services and approved access management processes.
Administrative access must be governed through approved identity and privileged access controls.
6. Monitoring Enrollment
Subscriptions must participate in approved enterprise monitoring and logging services.
Monitoring configurations must provide operational visibility, auditability, and support for incident investigation activities.
7. Network Integration
Subscriptions must implement approved networking patterns and enterprise connectivity requirements.
Network configurations must support workload isolation, approved connectivity paths, and security monitoring requirements.
8. Shared Service Consumption
Subscriptions may consume approved enterprise shared services when those services have been approved through architecture standards and governance processes.
Shared services must comply with workload-specific regulatory and security requirements.
9. Automation
Subscriptions should be provisioned and configured through approved platform automation whenever practical.
Automation should support:
- Subscription deployment
- Management Group assignment
- Governance configuration
- Identity integration
- Monitoring integration
- Network onboarding
10. Lifecycle Management
Subscriptions must be managed through approved lifecycle processes.
Lifecycle activities include:
- Provisioning
- Modification
- Operational management
- Decommissioning
Subscriptions that are no longer required must be retired through approved governance processes.
11. Architecture Review
Subscription designs that deviate from approved governance structures or architecture patterns require architecture review and approval before implementation.
12. Exceptions
Exceptions to this standard require documented approval through the approved architecture exception process.