practice

Landing Zone

A pre-configured, governed cloud environment — accounts, networking, identity, logging, guardrails — into which workloads can be deployed safely.

governancefoundationcloud

It exists because the alternative is every team building its own foundation slightly differently, which produces an estate that cannot be secured, audited or costed coherently, and which is far more expensive to remediate than to have got right once.

What a landing zone typically fixes centrally: the account or subscription structure (separation by environment and by blast radius), the network topology and non-overlapping address plan, identity federation and role structure, centralised logging and audit into an account nobody can delete from, guardrails as preventive policy rather than as detective alerts, cost allocation tagging enforced at provisioning, and a baseline of encryption and network defaults.

The failure mode is building it as a one-off. A landing zone is a product with versions, an owner and a migration path for existing accounts — otherwise the estate splits into "accounts created before the standard" and "after", and the first group is never brought forward.