Cloud Adoption Framework architecture: strategy, planning, migration, modernization, governance, management, and security
Back to the AZ-305 path
AZ-305Chapter 5

Microsoft AZ-305 Certification Study

Cloud Adoption Framework architecture: strategy, planning, migration, modernization, governance, management, and security

Turn cloud ambition into an operating architecture by connecting measurable business outcomes, people and skills, landing zones, workload adoption, governance, observability, resilience, and Zero Trust security.

Suggested study time: 95 minutes • Intermediate • Complete original rewrite updated to the current nine-methodology Cloud Adoption Framework, with a concise summary for every topic

Neon AZ-305 cloud adoption architecture connecting strategy, landing zones, workload adoption, governance, management, and security

1. Cloud adoption as an architecture discipline

The Microsoft Cloud Adoption Framework for Azure combines documentation, technical guidance, tools, and field-tested practices so business intent, organizational readiness, platform design, workload delivery, governance, operations, and security move together. Cloud flexibility increases design choice; the framework turns that freedom into an actionable, repeatable journey.

  • Assess the current adoption position and its roadblocks.
  • Translate motivations into measurable outcomes and an adoption plan.
  • Prepare people, processes, landing zones, workloads, operations, governance, and security.
  • Use the guidance iteratively as the estate and business goals evolve.
Cloud Adoption Framework journey from strategy and planning through workload adoption and continuous operating standards.
The current framework presents nine connected methodologies. The supplied assessment still uses the older umbrella term Innovate; current guidance expresses that work through Modernize and Cloud-native.

Topic summary

Cloud adoption succeeds when business outcomes, organizational change, platform architecture, workload delivery, and continuous controls are treated as one system.

2. Assess the strategy before accelerating

Start by measuring the maturity of the existing cloud strategy rather than assuming the plan is complete. The Cloud Adoption Strategy Evaluator exposes gaps, provides a baseline, and helps communicate the current posture. Findings become improvement actions for technology, skills, operating model, organization, or partner support.

Topic summary

A strategy assessment creates the evidence-based baseline from which priorities and corrective actions can be chosen.

3. Turn motivations into mission, objectives, and KPIs

Common motivations include cost efficiency, agility, scale, innovation, and response to a critical business event. A mission statement connects those motivations to the organizational mission. Actionable objectives then define the work, while key results and KPIs show whether it succeeded. Assign an owner to every key result and review it regularly; an unmeasured aspiration is not an operating strategy.

Topic summary

Motivation explains why, the mission establishes direction, objectives define action, and accountable KPIs prove progress.

4. Build the strategy team and align the organization

Use a small core team spanning IT, finance, security, architecture, and compliance, then involve human resources, marketing, business units, and partners as the scope grows. The team translates business outcomes into architecture and continuously seeks cross-functional input. Executive sponsorship and alignment among business, digital, IT, and adoption strategies prevent cloud work from becoming an isolated technology program.

Assess readiness across people, process, technology, and partners. Gaps might require new roles, training, external expertise, or a shift from time-bounded project delivery to persistent product teams that own development, operations, security, and governance end to end.

Five iterative strategy steps: assess, define motivation and outcomes, form the team, prepare the organization, and inform the strategy.
Strategy is iterative: new evidence, risks, and business goals feed the next assessment.

Topic summary

A representative, sponsored team and a product-oriented operating model connect cloud decisions to the whole organization.

5. Inform strategy with five cross-cutting lenses

Strategic lenses that should shape adoption decisions.
LensArchitecture question
Financial efficiencyHow will the organization maximize value and remove avoidable expense?
AIWhere can analytics, machine learning, and automation improve outcomes or operations?
ResiliencyHow will the platform and workloads continue through disruption?
SecurityHow will Zero Trust and early security engagement modernize protection?
SustainabilityHow will cloud choices reduce emissions and support environmental commitments?

Topic summary

Cost, AI, resilience, security, and sustainability are decision lenses, not activities postponed until deployment.

6. Convert strategy into an organizational plan

The Plan methodology translates strategy into owned, sequenced work. A startup with no existing estate can emphasize Plan, Ready, and Cloud-native. An enterprise must discover and assess its portfolio, then use Ready, Migrate, and Modernize. Choose centralized operations for consistency in smaller estates, shared management when a platform team owns landing zones and workload teams own applications, or decentralized operations when mature teams can own the full lifecycle.

Map governance, security, management, and AI responsibilities. Name primary and backup owners, define partner boundaries, communicate the model, and revisit it as capabilities and the estate change.

Topic summary

The adoption plan selects the journey and operating model, then makes every governance, security, platform, workload, and partner responsibility explicit.

7. Prepare people and sustain cloud skills

Teams need identity, networking, security, governance, and management foundations. Azure environment managers need Ready, Administer, Monitor, and Protect skills; cloud-native teams add platform engineering, containers, microservices, DevOps, and AI. Close gaps with Microsoft Learn, Microsoft Applied Skills, certifications, specialists, and partners.

  • Use Azure Dev/Test subscriptions as learning sandboxes.
  • Reserve recurring learning time and recognize progress.
  • Participate in Azure community events and curate trusted resources.
  • Treat learning as an operating capability, not a one-time migration task.

Topic summary

Role-based learning, safe practice environments, credentials, and expert support lower delivery risk and keep skills current.

8. Discover and prioritize the workload inventory

Define workload boundaries and discover components with , supplementing automation with manual records where access is limited. Capture ownership, business function, criticality, data sensitivity, compliance, dependencies, constraints, and timelines. Prioritize a backlog by business value, cloud readiness, technical feasibility, and strategic fit.

Topic summary

A migration plan is only credible when it is based on a complete, business-enriched inventory and a dependency-aware priority backlog.

9. Select a strategy for every workload

Cloud disposition choices.
StrategyIntent
RetireRemove redundant or obsolete capability
RehostMove with minimal application change
ReplatformAdopt managed platform services with limited code change
RefactorImprove code structure and cloud fit
RearchitectRedesign around cloud-native patterns
ReplaceAdopt a SaaS alternative
RebuildCreate the capability again
RetainKeep a stable workload where it is

Validate each choice against the business driver, stability, Azure compatibility, skills, timeline, technical debt, architecture, and operational requirements. Decide whether modernization happens during or after migration, document success metrics, and review decisions with stakeholders.

Topic summary

Disposition must follow business urgency and workload evidence rather than a one-size-fits-all preference.

10. Assess architecture, code, data, risk, and total cost

Use and subject-matter experts to validate components and dependencies. Use AppCAT for .NET and Java compatibility, verify frameworks and SDKs, and avoid gratuitous framework changes. Inventory database engines, versions, inbound and outbound dependencies, and whether shared databases should remain shared. Maintain a risk register with impact, mitigation, owner, and deadline.

Design landing-zone and workload architecture from business, technical, region, compliance, and service constraints. Model projected or historic usage with Azure Pricing Calculator, add training and process costs, validate assumptions through test deployments, establish a baseline, and revisit the design when forecasts diverge from budget.

Topic summary

Technical assessment and total-cost modeling turn the portfolio into an evidence-backed architecture, risk register, and financial baseline.

11. Ready: define the cloud operating model

A cloud operating model describes how technology is run: alignment to business strategy, people and team structure, adoption and change processes, operations, governance, compliance, and security. It shifts attention from owning hardware to managing digital assets and workloads, and it selects centralized, shared, or decentralized accountability to keep operations consistent.

Topic summary

The operating model is the agreement that connects business outcomes to day-to-day ownership, controls, and workload operations.

12. Implement and continually improve landing zones

Azure landing zones are scalable, modular foundations for identity, connectivity, subscriptions, management groups, governance, security, and resource organization. Select an implementation that fits organizational requirements and deploy through the Azure portal, Bicep, or Terraform. The Azure setup guide helps organize resources, control cost, and secure the platform before workloads arrive.

  • Remove unnecessary spend and improve performance.
  • Find and mitigate vulnerabilities.
  • Scale for new demand.
  • Maintain regulatory compliance.
  • Engineer reliability and resilience.

Topic summary

A landing zone is a product that must evolve as scale, security, compliance, cost, and reliability requirements change.

13. Build readiness skills and avoid antipatterns

Align roles with adoption functions and create or reshape teams where necessary. Three frequent readiness failures are starting without adequate preparation, misunderstanding what cloud services actually provide, and lacking knowledge of provider operations. Architecture reviews, training, and small validated deployments expose these risks before production scale amplifies them.

Topic summary

Readiness depends on capable teams and tested assumptions; weak preparation and false service expectations become expensive production failures.

14. Plan migration sequence, transport, downtime, and rollback

Assess skills across infrastructure, security, and applications and engage Microsoft partners or Azure solution architects where needed. Choose for private high-bandwidth transfer, VPN gateways for encrypted connectivity, for offline bulk movement, or the public internet for suitable nonsensitive data. Map dependencies with , sequence by criticality, avoid business peaks, and select near-zero or planned downtime per workload.

Define tested backup and recovery scripts, rollback deadlines, and nonproduction exercises. Obtain stakeholder agreement on justification, responsibilities, schedule, fallback, and measurable success criteria.

Topic summary

A sound migration plan coordinates skills, data movement, dependency order, downtime, rollback, stakeholders, and explicit acceptance criteria.

15. Prepare workloads and execute a controlled cutover

Resolve compatibility in test subscriptions, replace hard-coded secrets with Azure , and remove local dependencies through Azure-native services. Validate connectivity, authentication, function, and performance with Azure Load Testing against the source baseline. Create reusable or Bicep, automation, version control, runbooks, deployment records, and troubleshooting guidance.

  • Publish the schedule, support model, and readiness review.
  • Freeze source changes and monitor for unauthorized updates.
  • Deploy tested production infrastructure and security policy.
  • For near-zero downtime, replicate data, move static files, briefly pause writes, synchronize, and redirect traffic; for planned downtime, stop, migrate, validate, test, and redirect.
  • Retain the source and connectivity as fallback until formal validation.
  • Verify performance, functionality, and data integrity; obtain owner acceptance and provide enhanced stabilization support.

Topic summary

Migration execution is a reversible, automated, observable change with validated data, function, performance, and stakeholder acceptance.

16. Optimize the migrated workload and retire the source safely

Apply and service guidance, verify telemetry, cost allocation, backup, and security, then capture user feedback with assigned remediation. Review workloads quarterly with the Azure Well-Architected Framework. Monitor hybrid and multicloud dependencies through , secure cross-environment communication, identify PaaS replacements, and report savings with Microsoft Cost Management.

Decommission only with written business approval and an audit trail. Reclaim or reassign licenses, including Azure Hybrid Benefit eligibility; preserve regulated data in with retrieval and lifecycle procedures; and update architecture, operations, monitoring, inventory, and archived documentation.

Topic summary

Optimization proves the migration outcome; controlled decommissioning removes cost without sacrificing rollback, compliance, licensing, or institutional knowledge.

17. Define and prioritize cloud modernization

Modernization improves an existing cloud workload without adding net-new features or performing a complete rewrite. It uses replatforming, refactoring, or rearchitecting. Establish shared ownership across development, operations, security, and architecture; assess cloud, DevOps/CI/CD, patterns, monitoring, and automation skills; and close gaps through learning, hiring, or expert support.

Prioritize with a matrix that combines revenue, customer experience, compliance, and dependency value with technical debt, obsolete technology, maintenance effort, performance, and scalability risk. Use the five Azure Well-Architected Framework pillars to create the roadmap and give workload teams bounded decision authority.

Topic summary

Modernization is business-driven improvement of existing workloads, prioritized by value and technical risk and governed by the five architecture pillars.

18. Plan modernization in phases with governed deployment

Choose replatform for quick PaaS gains, refactor for code improvement without functional change, or rearchitect for microservices, serverless, and other cloud-native patterns. Avoid over-modernization. Slice work by component, complexity, or business function; begin with low-risk, high-value work and define technical goals and quality gates per phase.

Use formal change approval, planned freezes, a controlled backlog, and protection against scope creep. Choose in-place deployment for low-risk reversible changes or parallel environments for complex changes. Prefer progressive exposure such as canary or blue-green patterns, automate rollback, staff hypercare, quantify value for each audience, disclose risk, and secure stakeholder approval.

Topic summary

Phased, governed modernization balances value, complexity, deployment risk, rollback, and stakeholder confidence.

19. Develop, validate, and deploy modernization

Announce dates, freezes, user actions, support, escalation, workarounds, and fallback. Develop incrementally in production-like nonproduction environments with Git, CI/CD, and infrastructure as code. Run unit, integration, regression, end-to-end, user acceptance, vulnerability, compliance, and load tests - including the supplied 150% expected-load target - and resolve critical findings before release.

For in-place release, use deployment slots or traffic splitting. For parallel release, create infrastructure from tested templates, replicate databases and files, synchronize without data loss, start weighted traffic at a small percentage, then cut over through DNS or load balancing. Keep the former estate as a hot standby for the agreed period, validate owners and metrics, provide shorter support SLAs, update runbooks and inventory, and train operations.

Topic summary

A modernization release uses production-like testing, reusable automation, progressive traffic, explicit fallback, operational handoff, and measured validation.

20. Make modernization continuous

Review recommendations and Well-Architected service guides, resolve high-severity findings quickly, and ensure captures logs, metrics, and traces. Test alerts through failure experiments, update dashboards, monitor budgets and anomalies with Microsoft Cost Management, rightsize weekly, and validate or point-in-time restores against documented RTO and RPO.

Collect surveys, support tickets, and retrospectives; track work in or GitHub Issues with severity, value, owner, and deadline; compare actual ROI to targets. Schedule recurring reviews and automate policy, autoscale, and cost controls while publishing reusable playbooks and lessons.

Topic summary

Modernization becomes durable when telemetry, recovery, cost, security, feedback, and recurring architecture reviews drive the next improvement.

21. Plan a cloud-native solution around business outcomes

Cloud-native work creates new value or features through cloud scale, resilience, and agility. Define measurable objectives, constraints, success criteria, functional scope, reliability targets, and security baselines. Explore Azure Architecture Center references, select an architecture style and patterns, apply the five Well-Architected pillars, map integrations, select services and tiers, choose regions from reliability targets, and record diagrams and decisions.

Plan DevOps automation, operational readiness, incident response, development standards, pilot exposure, in-place versus blue-green change, ownership, support, and a complete rollback procedure before implementation.

Topic summary

Cloud-native architecture begins with measurable value and nonfunctional requirements, then selects patterns, services, regions, delivery, operations, and rollback.

22. Build and deploy cloud-native solutions

Develop in a production-like nonproduction environment with source control and CI/CD. Embed and Application Insights from the beginning and run functional, performance, security, and user acceptance tests. Package reusable infrastructure and deployment, configuration, and operating documentation.

Before production, align stakeholders, support teams, access, roles, and expected impact. Deploy the same artifacts and IaC tested in staging, perform smoke tests, expose a small pilot, expand only when telemetry and feedback are healthy, validate journeys, integrations, jobs, dashboards, and alerts, then operate an enhanced one- to two-week stabilization period with explicit exit criteria.

Topic summary

Repeatable infrastructure, observable code, comprehensive testing, progressive exposure, and a defined stabilization exit turn a build into an operable product.

23. Optimize and evolve cloud-native products

Review and Well-Architected guidance, remediate Defender for Cloud findings, test alerts, and document monitoring coverage. Set budgets and cost alerts, apply cost optimization across governance, rates, usage, components, and monitoring, remove idle resources, and schedule nonproduction shutdowns. Test restores and disaster recovery drills against recovery objectives.

Collect and prioritize user feedback in or GitHub Issues. Reassess the architecture periodically, automate , autoscale, and anomaly controls, and share patterns so product learning raises the organization’s cloud maturity.

Topic summary

Cloud-native products require continuous cost, reliability, security, recovery, feedback, and architecture optimization after launch.

24. Govern: form the team and assess cloud risk

A small, diverse governance team needs defined scope, authority, functions, and executive support. Inventory assets and risks with Azure tools, give risks qualitative or quantitative severity, determine business impact such as downtime or cost, document owners and stakeholders, and reassess both periodically and after material events.

Continuous governance cycle from team formation and risk assessment through policy, enforcement, monitoring, and improvement.
Governance repeats because the estate, threats, regulations, and business priorities keep changing.

Topic summary

Governance begins with an empowered team and a living, prioritized risk portfolio tied to business impact.

25. Document, enforce, monitor, and improve governance policy

Translate risks into centralized, maintained policy statements that define requirements, standards, and goals for people and automation. Delegate responsibility, use hierarchical inheritance, apply naming and tagging, and begin with monitor-first controls before gradually automating more enforcement through tools such as .

Monitor compliance, alert the appropriate owner at clear thresholds, prioritize high-risk violations, execute remediation, and update both policy and enforcement to prevent recurrence.

Topic summary

Healthy governance connects documented risk controls to inherited enforcement, measurable compliance, rapid remediation, and feedback into the next policy version.

26. Manage: ready and administer cloud operations

Separate estate-wide from workload responsibilities across compliance, security, resources, deployment, development, monitoring, cost, reliability, and performance. Select centralized or shared teams, document changes, releases, disaster recovery, daily tasks, and incident runbooks, provide global or on-call coverage, automate repetition, and review metrics, incidents, changes, risk, sprawl, debt, and skills every week.

  • Define the customer responsibility for IaaS, PaaS, SaaS, and on-premises models.
  • Control change with tickets, approval, Change Analysis, , and Bicep deployment stacks.
  • Use , least-privilege RBAC, MFA, Conditional Access, and secure IaC.
  • Map ISO 27001 or NIST SP 800-53 controls through .
  • Classify and govern data with , regional placement, management groups, access control, and deletion protection.
  • Control cost with Microsoft Cost Management and team-level visibility.
  • Use Well-Architected operational excellence, Bicep or Terraform, CI/CD, drift control, and limited portal deployment.
  • Assess relocations by compliance, proximity, downtime, risk, and cost.
  • Automate VM maintenance and updates; use Change Tracking and Machine Configuration.

Topic summary

Cloud management converts the operating model into controlled administration across identity, change, compliance, data, cost, code, resources, relocation, and operating systems.

27. Design monitoring for the whole cloud estate

Define monitoring ownership for service health, security, compliance, cost, data, and workload performance. Inventory with Azure Resource Graph, select centralized or shared operations, define required telemetry and alert classes, and test the design continuously. Use as the hub and for hybrid or multicloud collection; automate configuration through and control ingestion cost.

Combine Microsoft Entra and Defender signals, compliance, Cost Management, and Application Insights. Use dynamic alert thresholds and severities, route through action groups to email, SMS, or ITSM, and provide detailed workbooks plus concise portal dashboards for different audiences.

Topic summary

Estate monitoring centralizes inventory, telemetry, alerts, security, compliance, cost, and application performance while presenting role-appropriate views.

28. Protect reliability, data, continuity, and incident response

Assign SLOs, RTOs, and RPOs by workload criticality. Use zone-level synchronous replication and cross-region protection where justified, design self-healing applications, deploy redundant zones or regions, calculate composite SLAs, and load balance. Maintain tested continuity procedures, target rapid failure detection, execute the correct recovery response, and learn from every incident.

Standardize security tooling and baselines, access controls, encryption, and ownership. Prepare tested incident roles and procedures, use for monitoring and response, activate containment quickly, and use post-incident analysis to improve defenses.

Topic summary

Protection aligns redundancy, recovery, resilient software, continuity, security operations, and incident learning to business criticality.

29. Secure every adoption methodology

Security is not a final phase. The Secure methodology protects the estate and platform teams; Azure Well-Architected security guides workload owners and DevSecOps; the Microsoft cloud security benchmark supplies service baselines and optimal configurations; and Zero Trust guidance supplies modernization capabilities. Across all phases, assume breach, verify explicitly, grant least privilege, modernize defenses, and prepare detection and response to limit blast radius.

Topic summary

Cloud security is a shared, end-to-end responsibility supported by estate, workload, benchmark, DevSecOps, and Zero Trust guidance.

30. Apply the CIA triad and assign security roles

CIA security objectives.
ObjectiveDesign implication
ConfidentialityEncryption and access controls restrict sensitive data to authorized parties.
IntegrityControls prevent or detect unauthorized modification so information remains accurate and complete.
AvailabilityArchitecture and operations keep authorized access working when it is needed.

The triad supports data protection and compliance, business continuity, and customer trust. Map current security functions, find gaps, decide whether to invest, and document a cross-team shared-responsibility model similar to RACI. Continuous monitoring, retrospectives, and training keep roles and practices aligned to evolving threats.

Topic summary

CIA defines what security must preserve; explicit roles and continuous learning define who maintains it and how teams collaborate.

31. Module assessment with explained answers

Reworded knowledge check.
QuestionBest answerWhy
How should business alignment be maintained?Continuously seek input from other business areas.Cloud adoption is cross-functional and must track changing goals.
How should sustainability enter strategy?Measure current emissions and plan carbon-footprint reduction.Sustainability needs a baseline and measurable action.
What is Ready for?Environment setup, operating model, landing zones, operations, and skills.Ready establishes the Azure foundation before workload scale.
What follows workload migration?Prepare management and perform validated test migrations and checks.Migration is followed by stabilization, validation, and operations - not immediate blind retirement.
What was the source assessment’s Innovate goal?Meet customer needs and expectations.Current guidance expresses innovation through Modernize and Cloud-native value delivery.
What is the first Govern step?Build the cloud governance team.The team needs authority before risk and policy cycles can operate.
What determines management depth?Workload criticality.Business impact drives SLO, protection, monitoring, and recovery rigor.
Why improve security continuously?Threats and techniques evolve.A static posture loses effectiveness over time.

Topic summary

The assessment connects organizational alignment, sustainability, readiness, adoption, governance, criticality-based management, and continuous security.

32. Final architecture checklist and official references

  • Start with business motivations, measurable outcomes, and accountable owners.
  • Plan people, responsibilities, inventory, dispositions, architecture, risk, and total cost.
  • Establish an operating model and a continuously improved landing zone.
  • Migrate reversibly, modernize deliberately, and build cloud-native only for measurable value.
  • Run governance, security, and management continuously across the entire estate.
  • Use feedback, telemetry, cost, incidents, and Well-Architected reviews to drive the next iteration.
  1. Microsoft Cloud Adoption Framework for Azure
  2. Cloud adoption strategy
  3. Plan cloud adoption
  4. Migrate workloads to Azure
  5. Modernize workloads in the cloud
  6. Build cloud-native solutions
  7. Azure Well-Architected Framework
  8. AZ-305 study guide

Topic summary

The framework is iterative: strategy, platform, workloads, governance, security, and operations must keep adapting to evidence and business change.