Two zones or three? A design framework for zone-resilient Azure workloads

By Dustin Ward

Takeaway: Zone resiliency isn’t a single number you apply to a whole workload. The useful question isn’t “how many zones?” but “how many zones does each component need to survive the loss of one?” Decide zone patterns component by component, use service-managed zone redundancy wherever it fits, and reserve three-zone designs for the components that…

Introducing Azure Multicloud Interconnect for AWS

By Dustin Ward

As organizations accelerate AI adoption and modernize their digital estates, applications, data, and infrastructure increasingly span multiple cloud environments. Customers are choosing the best platform for each workload, leveraging unique capabilities across providers to drive innovation, resilience, and business agility. Yet while multicloud strategies have become commonplace, networking between cloud environments remains complex. Establishing private…

The patch window is collapsing: Why security needs a new control plane

By Dustin Ward

For decades, cybersecurity defenders have relied on a relatively straightforward model: a vulnerability is disclosed, security teams assess exposure, test available fixes, deploy patches into production, and ultimately close the risk before attackers can exploit it at scale.  That model increasingly reflects a world that no longer exists. Today’s enterprises operate thousands of interconnected workloads…

Powering multi-cluster workloads with seamless cross‑cluster networking for Azure Kubernetes Fleet Manager

By Dustin Ward

In this article The challenge of multi-cluster networking Our vision: Multi-cluster management with seamless networking Strategic resilience with cross-cluster networking Getting started with cross-cluster networking Documentation and resources As organizations modernize their application portfolios, we are witnessing a fundamental shift in how cloud-native infrastructure is architected. No longer is the question “How do we scale…

Azure IaaS: Defense in depth built on secure-by-design principles

By Dustin Ward

In this article Defense in depth as a system Secure by design: Engineering security into the platform Hardware and host-level trust Virtual machine-layer trust Secure by default: Protection enabled without friction Secure defaults across networking Encryption and data protection by default Compute protection defaults Secure in operation: Continuous protection at runtime Monitoring, detection, and signal…