| Service model | Managed infrastructure with an agreed responsibility matrix around the selected workload.[1] | Azure Virtual Machines are IaaS. Microsoft's shared-responsibility guidance says the customer manages VMs, operating systems, applications and IaaS network controls; Microsoft manages the physical platform.[3] |
| Provisioning | Engineer-led discovery and design establish dependencies, residency, access, backup and operational ownership before migration or production handover.[1] | VMs can be provisioned in seconds through the Azure portal, APIs and automation, with customers choosing image, size, disks, Virtual Network and other services.[7] |
| Management responsibility | DC Core can manage infrastructure operation, hardening, monitoring, network controls and patching inside scope; the customer normally retains application, users and data.[1] | For Azure IaaS, the customer retains operating-system, application, identity, configuration, data and network-control responsibilities. Azure provides management and governance tools, but those still require configuration and ownership.[3] |
| Networking architecture | DC Core can connect workloads through private addressing, secured ingress and outbound customer-side agents using a tenant-aware relay architecture.[2] | Azure Virtual Network provides private networking for Azure resources and supports traffic filtering, routing, private service access, VPN and ExpressRoute connectivity. Buyers select and configure the controls required by their architecture.[9] |
| Private admin access | Customer-side agents normally establish outbound connections, reducing the need to publish inbound VM management ports.[2] | Azure Bastion provides RDP/SSH to target VMs over their private IP addresses, so those VMs do not need public IPs. Bastion Premium also supports a private-only Bastion deployment.[4] |
| Backups and DR | Encrypted backup and recovery controls are included where agreed. Frequency, retention and recovery targets are stated for the selected workload.[1] | Azure Backup supports scheduled VM protection, Recovery Services vaults and full-VM or file restoration. Buyers should confirm the applied policy, protected resources, retention, vault redundancy and restore-validation ownership.[5] |
| Location and scale | The standard design keeps managed production tenancy data in London and DR capacity in France unless another arrangement is agreed.[1] | Azure operates multiple geographies, each containing one or more regions and associated data-residency and compliance characteristics. The customer selects the region, availability design and service combination that meets its requirements.[10] |
| Support | Support applies to the contracted managed boundary and can include operational action inside that boundary. | Billing and subscription-management support is available to all Azure customers; technical support requires a support plan. Microsoft lists Developer, Standard, ProDirect and enterprise routes for different workload needs.[6] |
| Pricing model | A scoped quote combining infrastructure with agreed management, monitoring, backup and support responsibilities. | Usage-based component pricing across VM compute, managed disks, networking, backup and other services, with savings plans, reservations, Hybrid Benefit and Spot options where applicable.[7][8] |
| Best suited for | Organisations that want a UK-led operator to take defined responsibility for a bounded business workload. | Teams already invested in Microsoft technologies or needing the breadth, geographic reach and automation of the Azure platform. |