The beautiful tip of the iceberg
Most of what we build you'll never see. This is the part you can.
An independent Azure infrastructure assessment reviews how your workloads are hosted, secured, monitored and paid for. It is structured around Microsoft's Azure Well-Architected Framework and grounded in our own experience of building and running .NET applications on Azure.
Synthetic example. Your audit is scoped to your question.
An Azure infrastructure assessment examines the subscriptions, resources and configuration behind an application to establish whether they meet the business's needs for reliability, security, cost, operational maturity and performance. It is carried out with read-only access and produces prioritised, evidence-based recommendations.
It is part of Assemblysoft's software audit and technical due diligence practice and can run on its own or as part of a comprehensive audit.
Spend has crept up and nobody is sure which resources are needed, oversized or forgotten.
A supplier built the infrastructure in their own way, possibly in their own tenant, and you need to understand it.
Customers, insurers or auditors are asking about identity, network exposure, backups and logging.
More customers, more data or a new market, and you need confidence the platform will scale.
Redundancy, backup and restore, availability targets, single points of failure and recovery documentation.
Identity and RBAC, network exposure, Key Vault and secrets, Defender for Cloud posture, logging and diagnostic settings.
Idle and oversized resources, service tiers, reservations and savings plans, storage lifecycle and architecture-driven cost.
Infrastructure as Code, deployment pipelines, environment parity, tagging, governance and change control.
Scaling configuration, database and cache sizing, hot paths and known performance constraints.
Which tenant and subscriptions hold the workload, who holds owner rights, and what a supplier change would involve.
Scope, access and timescales are agreed before work begins. Anything that could affect a live environment is agreed separately and controlled.
We agree the subscriptions in scope and request Reader and Cost Management Reader roles, nothing more.
Resource inventory, Azure Advisor and Defender for Cloud signals, cost analysis and configuration review against the five pillars.
Short sessions with whoever runs the platform, to understand intent before judging configuration.
Findings by pillar with severity, savings opportunities with their trade-offs, and a prioritised roadmap.
See how findings are presented in our anonymised sample report.
| Area | Supporting authority | How it shapes the audit |
|---|---|---|
| Cloud reliability, security, cost and operational maturity | Azure Well-Architected FrameworkMicrosoft | Structures Azure workload assessment around its five pillars: reliability, security, cost optimisation, operational excellence and performance efficiency. |
| Secure development practices and software acquisition | Secure Software Development Framework (SSDF), NIST SP 800-218US National Institute of Standards and Technology | Gives a vendor-neutral vocabulary for judging whether software was produced with secure development practices, and explicitly supports using those practices when acquiring software. |
These references support the audit methodology and its boundaries. They describe what a properly scoped audit can assess; they are not a claim that any particular client's systems have already been verified, and alignment with a framework is not a certification.
An audit means trusting an outside team with source code, infrastructure and sometimes personal data. Here is how access and evidence are controlled. Certification describes how we run our own business; it does not, on its own, guarantee the security of a client's application.
We sign your NDA or provide ours before receiving anything confidential, including the identity of an acquisition target.
Due-diligence questionsRepository and cloud access at the least privilege needed, time-limited and revoked at the end. Anything that could affect a live system is agreed separately.
Information securityWorking copies are held only as long as the engagement needs, production data is avoided wherever possible, and evidence is returned or deleted on completion.
Data residencyAssemblysoft holds Cyber Essentials Plus, independently audited. Our policies, insurance and certificates are published in the Trust Centre.
Visit the Trust CentreWhere personal data is in scope, a UK GDPR Article 28 Data Processing Agreement applies. Reports are confidential to you and shared only with the people you name, such as your advisors or board.
Reader and Cost Management Reader roles on the subscriptions in scope are normally enough. We do not need Contributor or Owner rights, and we make no changes during the assessment.
Azure Advisor is a useful input and we use it. It cannot know your business context: which workloads are critical, what recovery times you need, or which costs are deliberate. The assessment combines Advisor, Defender for Cloud and cost data with engineering judgement about the application itself.
No. We identify opportunities and estimate their likely effect, alongside any reliability, performance or security trade-off. Actual savings depend on usage patterns, contractual arrangements and the changes you choose to implement.
Our specialism is Microsoft Azure. Where an application runs on-premise or on Windows Server hosting, the legacy software modernisation review covers the hosting platform and the options for moving it.
Yes, as a separately scoped engagement, or through managed application support. The report is equally usable by your own team or another provider.
One evidence-based method, applied to the decision in front of you. Each specialist assessment can run on its own or as part of a comprehensive audit.
Reliability, security, cost and operational maturity of Azure workloads, aligned to the Well-Architected Framework.
Tell us which subscriptions and workloads matter most and what is prompting the review. We will scope the assessment and confirm what reader access is needed.
Discuss Your Requirements All Software Audit ServicesCyber Essentials Plus certified · NDA as standard · UK-based team · Microsoft Partner · No obligation to appoint us for remediation