1. Home
  2. Services
  3. Software Audits
  4. Azure Infrastructure & Cloud
Azure Infrastructure & Cloud Assessment

Is your Azure estate reliable, secure and worth what it costs?

An independent Azure infrastructure assessment reviews how your workloads are hosted, secured, monitored and paid for. It is structured around Microsoft's Azure Well-Architected Framework and grounded in our own experience of building and running .NET applications on Azure.

Microsoft Partner Five Well-Architected pillars Reader access only Cost findings with trade-offs

What is an Azure Infrastructure and Cloud Assessment?

An Azure infrastructure assessment examines the subscriptions, resources and configuration behind an application to establish whether they meet the business's needs for reliability, security, cost, operational maturity and performance. It is carried out with read-only access and produces prioritised, evidence-based recommendations.

It is part of Assemblysoft's software audit and technical due diligence practice and can run on its own or as part of a comprehensive audit.

When to commission one

Situations where this review pays for itself

The bill keeps growing

Spend has crept up and nobody is sure which resources are needed, oversized or forgotten.

Inheriting an estate

A supplier built the infrastructure in their own way, possibly in their own tenant, and you need to understand it.

Security or insurer questions

Customers, insurers or auditors are asking about identity, network exposure, backups and logging.

Preparing for growth

More customers, more data or a new market, and you need confidence the platform will scale.

What we assess

Six areas, each rated for impact and urgency

Reliability

Redundancy, backup and restore, availability targets, single points of failure and recovery documentation.

Security

Identity and RBAC, network exposure, Key Vault and secrets, Defender for Cloud posture, logging and diagnostic settings.

Cost optimisation

Idle and oversized resources, service tiers, reservations and savings plans, storage lifecycle and architecture-driven cost.

Operational excellence

Infrastructure as Code, deployment pipelines, environment parity, tagging, governance and change control.

Performance efficiency

Scaling configuration, database and cache sizing, hot paths and known performance constraints.

Ownership & control

Which tenant and subscriptions hold the workload, who holds owner rights, and what a supplier change would involve.

How it works

From scoping to a prioritised plan

Scope, access and timescales are agreed before work begins. Anything that could affect a live environment is agreed separately and controlled.

1
Day 1

Scope & reader access

We agree the subscriptions in scope and request Reader and Cost Management Reader roles, nothing more.

Output: Scope note and access checklist
2
Days 2+

Configuration & cost review

Resource inventory, Azure Advisor and Defender for Cloud signals, cost analysis and configuration review against the five pillars.

Output: Resource inventory, evidence log
3
Where useful

Interviews

Short sessions with whoever runs the platform, to understand intent before judging configuration.

Output: Context notes
4
Final week

Report & walkthrough

Findings by pillar with severity, savings opportunities with their trade-offs, and a prioritised roadmap.

Output: Report, risk register, roadmap
What you receive

Clear findings, honest boundaries

  Deliverables

  • Executive summary by Well-Architected pillar
  • Resource and ownership inventory
  • Security and identity findings with evidence
  • Cost findings with indicative savings and trade-offs
  • Reliability and recovery gaps
  • Prioritised roadmap: quick wins, planned changes, further investigation

See how findings are presented in our anonymised sample report.

What this review does not do

  • Actual savings depend on usage, contracts and the changes ultimately made.
  • It is not a penetration test or a formal compliance certification.
  • We make no changes to your environment during the assessment.
Methodology

Aligned with recognised guidance

Recognised technical and regulatory guidance the audit methodology is aligned with
AreaSupporting authorityHow it shapes the audit
Cloud reliability, security, cost and operational maturity Azure Well-Architected FrameworkMicrosoft Structures Azure workload assessment around its five pillars: reliability, security, cost optimisation, operational excellence and performance efficiency.
Secure development practices and software acquisition Secure Software Development Framework (SSDF), NIST SP 800-218US National Institute of Standards and Technology Gives a vendor-neutral vocabulary for judging whether software was produced with secure development practices, and explicitly supports using those practices when acquiring software.

These references support the audit methodology and its boundaries. They describe what a properly scoped audit can assess; they are not a claim that any particular client's systems have already been verified, and alignment with a framework is not a certification.

Confidentiality & evidence handling

Your code, credentials and data, handled with care

An audit means trusting an outside team with source code, infrastructure and sometimes personal data. Here is how access and evidence are controlled. Certification describes how we run our own business; it does not, on its own, guarantee the security of a client's application.

NDA before detail

We sign your NDA or provide ours before receiving anything confidential, including the identity of an acquisition target.

Due-diligence questions

Read-only by default

Repository and cloud access at the least privilege needed, time-limited and revoked at the end. Anything that could affect a live system is agreed separately.

Information security

Evidence handled deliberately

Working copies are held only as long as the engagement needs, production data is avoided wherever possible, and evidence is returned or deleted on completion.

Data residency

Cyber Essentials Plus

Assemblysoft holds Cyber Essentials Plus, independently audited. Our policies, insurance and certificates are published in the Trust Centre.

Visit the Trust Centre

Where personal data is in scope, a UK GDPR Article 28 Data Processing Agreement applies. Reports are confidential to you and shared only with the people you name, such as your advisors or board.

Frequently asked questions

Azure Infrastructure & Cloud, answered

What Azure access do you need?

Reader and Cost Management Reader roles on the subscriptions in scope are normally enough. We do not need Contributor or Owner rights, and we make no changes during the assessment.

Isn't Azure Advisor enough?

Azure Advisor is a useful input and we use it. It cannot know your business context: which workloads are critical, what recovery times you need, or which costs are deliberate. The assessment combines Advisor, Defender for Cloud and cost data with engineering judgement about the application itself.

Can you guarantee cost savings?

No. We identify opportunities and estimate their likely effect, alongside any reliability, performance or security trade-off. Actual savings depend on usage patterns, contractual arrangements and the changes you choose to implement.

Do you assess AWS or on-premise hosting?

Our specialism is Microsoft Azure. Where an application runs on-premise or on Windows Server hosting, the legacy software modernisation review covers the hosting platform and the options for moving it.

Can you implement the recommendations?

Yes, as a separately scoped engagement, or through managed application support. The report is equally usable by your own team or another provider.

Get an independent view of your Azure estate

Tell us which subscriptions and workloads matter most and what is prompting the review. We will scope the assessment and confirm what reader access is needed.

Discuss Your Requirements All Software Audit Services

Cyber Essentials Plus certified  ·  NDA as standard  ·  UK-based team  ·  Microsoft Partner  ·  No obligation to appoint us for remediation

Start a meaningful conversation with us today.

FAQs

Assemblysoft are Your Safe Pair of Hands

Microsoft Azure

Azure

Azure DevOps

Azure DevOps

Blazor

Blazor