← AZ-305: Azure architecture and production decisions
08 / 8 · 25 MIN

Networking and complete-service migration

Relate protocol, routing, and cutover dependencies.

Concept and mechanism

Network design starts with source, destination, protocol, scope, and required guarantees. Front Door offers global HTTP(S)application capabilities, while Load Balancer handles transport distribution. Traffic Manager makes DNS-based decisions and does not inspect HTTP paths like a proxy. Choosing a private connection also does not demonstrate encryption: ExpressRoute does not encrypt all traffic by default. Define protection scope and applicable mechanisms. Two hub peerings do not automatically create transit between spokes.

Guided application

For migration, combine inventory, dependency observation, and owner validation. One day without traffic does not exclude a monthly batch. Define groups that can be migrated and validated as a service, including files, certificates, identities, and networking. Plan rollback before the window and decommission after acceptance. The PM should track retirement cost, retention, support, and consumer communication alongside new-resource creation.

IN PRACTICE

RUN identifies a monthly file absent from discovery. The plan adds transfer, batch consumption, and validation before legacy retirement.

Common pitfalls

Treating private as encrypted; treating peering as transitive; retiring legacy before validating representative cycles.

Related topics: Identity and access boundaries · Governance, cost, and observation

Take this idea with you

Include business-flow dependencies in the migration plan.

Create account

Reference: Migration dependency analysis · AZ-305 objectives 2026-04-17