Azure AI Landing Zone Framework
Enterprise framework for declarative provisioning of AI infrastructure on Azure – from Microsoft Foundry to AI Search to private networks.
About the Project
The AI market is evolving rapidly – and many companies face a dilemma: Fear of missing out (FOMO) leads to tactical "pop-up" projects without unified strategy. The result is fragmentation and technical debt. Additionally, there is the future-proofing risk: Will today's chosen technology still be relevant tomorrow? And many organizations lack the maturity for structured deployment, governance and enterprise scaling.
The Solution
The Azure AI Landing Zone Framework addresses these challenges with a battle-tested approach: a proven architecture that emerged from real enterprise implementations. The framework is based on four pillars:
Infrastructure Provisioning: Infrastructure is defined via simple YAML files – not through manual Terraform code. A hierarchical override system enables project defaults with environment-specific adjustments.
Azure-Native Development: Access to a documented code library with templates for Azure Functions, Logic Apps and AI agents – based on a proven development path.
Unified Foundation CLI: A powerful CLI that encapsulates the complexity of environment management – a central control point for the entire AI lifecycle.
Standard AI Connectors: Pre-built, production-ready connectors for SharePoint, Outlook and other M365 services – no need to reinvent the wheel.
Resource Groups
The framework provisions up to eight functional resource groups: Terraform State, AI Workloads (Microsoft Foundry), Connectors (Function Apps, Logic Apps), Data Storage (Cosmos DB, AI Search, SQL, Redis), Networking (VNets, Private Endpoints, DNS), Pipelines (Data Factory), Workflows (Durable Functions) and Shared Services (Key Vault, Monitoring, Container Registry).
AI Agent Deployment
A central element is AI agent deployment: Prompt Agents for Microsoft Foundry are defined declaratively in YAML – including model, instructions, tools and RAG connections. A single CLI command syncs this definition with Azure. Workflow Agents enable multi-step orchestrations.
Connector System
The connector system provides reusable tools for agents: SharePoint document search, Outlook email integration, Confluence wiki access and any custom connectors via OpenAPI or MCP server. These are automatically registered as Foundry Connections and can be referenced in agent definitions.
Enterprise Networking
For enterprise requirements, the framework supports fully private networks: Hub-spoke architectures, VPN gateway integration, Private Endpoints for all data services and Private DNS Zones. Managed Identities and Key Vault ensure secret-less deployments.
Unified CLI
The CLI provides a unified entry point for all operations: Infrastructure deployment, workflow management, connector development, AI agent synchronization, search index management, database management via alembic and application deployment. New customer projects are scaffolded via Copier template and can pull updates from the core repo.
Highlights
- Declarative YAML configuration for 50+ Azure resource types
- Unified CLI for infrastructure, agents, connectors and search indexes
- AI agent management: Prompt Agents and Workflow Agents with tool integration
- Enterprise networking: Hub-Spoke, VPN, Private Endpoints, Private DNS Zones
Challenges
Abstracting Terraform complexity to user-friendly YAML configurations. Hierarchical merge system for environment-specific overrides. Private networking with correct DNS resolution across all services.
Results
Framework in production use with enterprise customers. Reduction of setup time for AI projects from weeks to hours. 85%+ test coverage. Enables non-Terraform experts to provision complex Azure AI landscapes.
Interested?
Are you interested in a similar project or want to learn more? Get in touch – we look forward to hearing from you!
Get in touch