# Elliott Leighton-Woodruff | L-W Tech > Enterprise Architect, specializing in Azure, Infrastructure as Code and AI services. Elliott Leighton-Woodruff writes from consulting work on Azure, infrastructure as code, platform engineering, and cloud cost. Quote the linked article, not this index. ## Posts - [Enterprise Live Migrations Just Killed Your Best Excuse to Stay on Azure Repos](https://blog.l-w.tech/blog/2026-09-09-Enterprise-Live-Migrations-Just-Killed-Your-Best-Excuse-to-Stay-on-Azure-Repos): Enterprise Live Migrations hit public preview on 31 August. Cutover is typically under 30 minutes, but only if you're on GitHub Enterprise Cloud with data residency. Here's what moves, what doesn't, and the CLI for the first repo. - [AzureRM 5.2 Is Another Sign That Platform Engineering Has Won](https://blog.l-w.tech/blog/2026-08-21-AzureRM-5-2-Platform-Engineering-Has-Won): AzureRM 5.2 is not the story. Managed identities, Terraform and Managed DevOps Pools are. Here's how Azure platform teams are moving from Infrastructure as Code to Platform as Code. - [Actually validating deployments with TF's new AzureRM 5.0](https://blog.l-w.tech/blog/2026-07-30-TF-Preflight-Validation-in-AzureRM-5): AzureRM provider 5.0 adds opt-in preflight validation that calls Azure during plan. It's useful, but it's not magic. Here's where it helps, where it skips resources, and what will bite during the upgrade. - [The Front Door Terraform Quirk That's Really Just Classic Telling You to Migrate](https://blog.l-w.tech/blog/2026-07-23-Terraform-Front-Door-Phantom-Diffs): Your Front Door Terraform plan isn't broken, it's Classic showing its age. Here's why the drift happens, and why the real fix isn't a workaround. - [GitHub Copilot Billing Just Changed. Don't Get Bitten.](https://blog.l-w.tech/blog/2026-06-10-GitHub-Copilot-Billing-Just-Changed-Dont-Get-Bitten): GitHub Copilot moved to usage-based billing on 1 June 2026. For individuals it is mostly a measurement change. For enterprise IT, it is a FinOps problem you need to start solving now. - [Your AI Agents Are in Production. Who's Governing Them?](https://blog.l-w.tech/blog/2026-05-27-AI-Foundry-Agent-Governance-GitOps): A two-repo pattern for managing AI Foundry agents, system prompts, guardrails and APIM policies as code. Approval gates, full audit trail, no portal clicking. - [I'm Still a Terraform Fan. But Bicep's New Snapshot Feature Made Me Look Twice](https://blog.l-w.tech/blog/2026-03-31-Bicep-Snapshot-GA-Terraform-Plan): Bicep v0.41.2 makes Snapshot generally available and gives Azure-only teams an offline, reviewable way to preview change impact without Azure What-If noise. - [Azure Blueprints are dead! Welcome to Deployment Stacks](https://blog.l-w.tech/blog/2026-03-18-AZ-Deployment-Stacks-Landing-Zone-Governance): Azure Deployment Stacks bring predictable lifecycle control to landing zone governance and give IaC teams a practical path away from Azure Blueprints. - [Azure Policy as Code: Getting started with IaC and CI/CD](https://blog.l-w.tech/blog/2026-03-11-azure-policy-as-code-getting-started-iac-cicd): Get started with Azure Policy managed through IaC and deliver governance that scales with your infrastructure. - [IaC and GitHub Copilot on Rails](https://blog.l-w.tech/blog/2026-02-18-AI-Agents-Guardrails-Azure-IaC): How GitHub Copilot agents are reshaping infrastructure delivery—and why guardrails are the difference between automation and chaos. - [Making Tenant Configuration Part of Your IaC Story with UTCM](https://blog.l-w.tech/blog/2026-02-10-Making-Tenant-Configuration-Part-Of-IaC-Story-UTCM): The new Unified Tenant Configuration Management (UTCM) APIs in Microsoft Graph finally give us a native way to treat tenant configuration as code, with snapshots, baselines and drift detection baked in. - [Azure Default Outbound Access Retirement — What's Actually Going On and How You Fix It](https://blog.l-w.tech/blog/2026-02-02-Azure-Default-Outbound-Access-Retirement): Azure is retiring default outbound access on 31 March 2026 — here's what that means, who it affects, and how to fix it properly with NAT Gateway using Bicep and Terraform. - [Securing AI Foundry with Azure API Management Gateway](https://blog.l-w.tech/blog/2026-01-21-APIM-AI-Foundry-Terraform): Azure API Management fronting AI Foundry secures model endpoints and throttles internal usage via Terraform policies, delivering zero-trust governance for AI workloads in regulated environments. - [Build Production Agents in Minutes with AI Toolkit for VS Code](https://blog.l-w.tech/blog/2026-01-15-AI-Agents-In-mins): How Microsoft's AI Toolkit extension turns VS Code into a complete environment for building enterprise AI agents with Azure Foundry v2, GitHub Copilot Skills, and proper evaluation tools. - [You Probably Don't Need Azure Front Door at All](https://blog.l-w.tech/blog/2026-01-07-You-Dont-Need-Front-Door): Application Gateway with WAF plus Traffic Manager delivers 95% of Front Door's value with simpler operations, better VNet integration, and lower costs for most enterprise workloads. - [Terraforming Azure AI: Deploy Cognitive Projects and GPT Models](https://blog.l-w.tech/blog/2025-12-16-Terraforming-Azure-AI): AzureRM 4.55.0 brings first-class Terraform support for Azure AI projects and model deployments—finally manage GPT models as code alongside your infrastructure. - [Network-as-Code at Enterprise Scale: Virtual Network Manager](https://blog.l-w.tech/blog/2025-11-26-Network-as-Code-Virtual-Network-Manager): Stop managing VNets with portal clicks and manual peering. Azure Virtual Network Manager and Virtual WAN bring code-driven network topology that actually scales. - [Terraform Managed Disk Expansion Without Downtime in Azure](https://blog.l-w.tech/blog/2025-11-19-Terraform-Managed-Disk-Expansion): AzureRM Provider v4.53.0 brings live disk expansion for Ultra Disks and Premium SSD v2—grow storage capacity without shutting down VMs. - [Planned Failover for Azure Storage: Cloud DR on Your Terms](https://blog.l-w.tech/blog/2025-11-13-Azure-Storage-Planned-Failover): Azure Storage's Planned Failover transforms disaster recovery from reactive hoping to proactive testing and validation of your DR strategy. - [Deploying Managed DevOps Pools with Terraform](https://blog.l-w.tech/blog/2025-10-29-Managed-DevOps-Pools-Terraform): Build scalable, secure Azure DevOps agent pools with Microsoft-managed infrastructure using Terraform and Azure Verified Modules. - [Terraform Actions: Post Deployment Control for Azure](https://blog.l-w.tech/blog/2025-10-15-Terraform-Actions-Azure): Terraform 1.14 introduces Actions a native way to handle post-deployment operations like VM power control without resorting to provisioners or workarounds. - [Podcast | Platform Engineering: Why 'A Platform' Beats 'More Servers'](https://blog.l-w.tech/blog/2025-10-06-Platform-Engineering-Azure-Landing-Zones): Discussing Azure landing zones, FinOps, PaaS-first strategies, and AI agents with Alec on Engineer In The Loop. - [Resilience by Design: Multi-Region Infrastructure as Code That Actually Delivers](https://blog.l-w.tech/blog/2025-09-17-Multi-Region-Resilience-IaC): The Azure East US 2 outage proved that single-region deployments are gambling. Build multi-region resilience into your IaC from day one, not as an afterthought. - [Bake Governance into Code Before Azure Retires Default Outbound Access](https://blog.l-w.tech/blog/2025-09-12-Azure-NAT-Gateway-Governance): Azure's default outbound internet access retires in March 2026. Build proper network governance with NAT Gateways and Azure Policy before you're forced to scramble. - [Instantly Bringing Azure Resources Into Terraform: From ClickOps to IaC in Seconds!](https://blog.l-w.tech/blog/2025-09-05-Azure-Resources-Terraform-Export): Transform legacy Azure resources into version-controlled Terraform code using Microsoft's new VSCode exporter—no more excuses for unmanaged infrastructure. - [Real-Time DevOps Security: What Continuous Access Evaluation Means for Your Azure Pipelines](https://blog.l-w.tech/blog/2025-08-20-Real-Time-DevOps-Security-CAE): Microsoft's rollout of Continuous Access Evaluation in Azure DevOps transforms authentication from 'set and forget' to real-time security enforcement that actually works. - [Podcast | Demystifying Infrastructure as Code for Microsoft 365 and Azure](https://blog.l-w.tech/blog/2025-08-18-IaC-for-Microsoft-365-Azure): Discussing IaC fundamentals, ARM vs Bicep vs Terraform, and AI-assisted workflows with Zach and Ben on 365 Explained. - [Azure Templates: ARM To Bicep](https://blog.l-w.tech/blog/2025-08-13-Azure-Templates-ARM-To-Bicep): Modernize your Azure infrastructure by migrating legacy ARM JSON templates to cleaner, more maintainable Bicep code. - [IP Allocation Like a Boss: Winning Patterns for Azure Networking in Terraform](https://blog.l-w.tech/blog/2025-07-30-IP-Allocation-Azure-Terraform): Master dynamic IP allocation in Azure with cidrsubnet, cidrsubnets, and cidrhost for scalable, error-free networking. - [Podcast | Azure Migration: Beyond Lift and Shift](https://blog.l-w.tech/blog/2025-07-19-Azure-Migration-Beyond-Lift-and-Shift): Discussing migration strategies, IaC, cost optimization and SaaS vs build decisions on the sql_squared podcast. - [Policy as Code for Azure - Worth your time?](https://blog.l-w.tech/blog/2025-07-15-EPAC-Policy-As-Code): Transform Azure governance from manual portal clicking to version-controlled Policy as Code for consistency and compliance. - [Terraform Azure Verified Modules: What, Why and How to Use Them](https://blog.l-w.tech/blog/2025-07-08-TF-Azure-Verified-Modules): Use Microsoft's Azure Verified Modules for secure, consistent Terraform deployments. - [New Rules for Azure DevOps Access: How to Set Up Conditional Access Properly](https://blog.l-w.tech/blog/2025-07-02-AZ-ADO-Policy): Update Conditional Access policies for Azure DevOps before July 28, 2025 deadline. - [Azure Quota Groups Explained: Less Admin, More Control](https://blog.l-w.tech/blog/2025-06-25-AZ-Quota-Groups): Share Azure quotas across subscriptions with Quota Groups for flexible scaling. - [From Portal to Code: Your First Steps Importing Azure Resources into Terraform](https://blog.l-w.tech/blog/2025-06-11-AZ-IaC-Importing-Resources): Import existing Azure resources into Terraform to eliminate drift and gain consistency. - [When to Click, When to Code: The Azure Admin's Dilemma](https://blog.l-w.tech/blog/2025-06-04-AZ-IaC-When-to-Click): Decide when to use ClickOps versus Infrastructure as Code for Azure deployments. - [Smarter Routing in Azure: Route-Maps for Virtual WAN](https://blog.l-w.tech/blog/2025-05-28-AZ-Virtual-WAN-Route-Maps): Control BGP route advertisements in Azure Virtual WAN with newly available route-maps. - [Modern APIs Need Modern Protection with Azure API Management](https://blog.l-w.tech/blog/2025-05-14-AZ-Modern-APIs-Need-Modern-Protection): Secure modern APIs with Azure API Management for authentication and visibility. - [Private Azure DevOps Agents with Azure DevCenter](https://blog.l-w.tech/blog/2025-05-07-AZ-CICD-With-Azure-DevCenter): Deploy private Azure DevOps agents efficiently using Azure DevCenter for better control. - [Creating Your First Terraform Module for Azure](https://blog.l-w.tech/blog/2025-04-23-TF-Creating-Your-First-Module): Build reusable Terraform modules to maintain consistency and eliminate copy-paste chaos. - [Still Running Terraform Locally? Let's Talk.](https://blog.l-w.tech/blog/2025-04-16-TF-Deploying-Locally-Lets-Talk): Move from local Terraform deployments to CI/CD pipelines for security and consistency. - [VMware's Latest Licensing Change – An April Surprise, But It's No Joke](https://blog.l-w.tech/blog/2025-04-01-AZ-VMware-Latest-Licensing-Change): Navigate Broadcom's VMware licensing changes with Azure VMware Solution migration strategies. - [The End of AzureAD and MSOnline PowerShell: Time to Move On](https://blog.l-w.tech/blog/2025-03-26-PS-The-End-of-AzureAD-MSOline): Migrate from deprecated AzureAD and MSOnline modules to Microsoft Graph PowerShell now. - [A Smarter Way to Manage Azure Firewall Policy Changes](https://blog.l-w.tech/blog/2025-03-19-AZ-Firewall-Policy-Draft-Deployment): Batch Azure Firewall policy changes using Draft + Deployment for efficient governance. - [Mastering the Basics: Terraform and Infrastructure as Code in Azure](https://blog.l-w.tech/blog/2025-03-18-TF-Mastering-the-basics): Master Terraform fundamentals for scalable, secure Azure infrastructure deployments. - [Terraform State Management in Azure: Don't Let Your Backend Bite You](https://blog.l-w.tech/blog/2025-02-26-TF-Backend-Bite-You): Manage Terraform state securely in Azure Storage with locking and versioning enabled. - [Why Aren't You Tagging Azure Resources?](https://blog.l-w.tech/blog/2025-02-19-AZ-Why-Arent-You-Tagging-Resources): Master Azure resource tagging for cost management, governance, and automation success. - [The Issue with Azure Bastion in Virtual WAN](https://blog.l-w.tech/blog/2025-02-12-AZ-vwan-bastion-issues): Solve Azure Bastion routing issues in Virtual WAN with custom route configurations. - [What's the best IaC tool for Azure?](https://blog.l-w.tech/blog/2025-01-29-Whats-the-best-IaC-tool): Compare PowerShell, ARM, Bicep, and Terraform to choose the right Azure IaC tool. - [Why-aC | Why infrastructure as code?](https://blog.l-w.tech/blog/2025-01-22-TF-Why-aC): Why Infrastructure as Code delivers reliability, speed, and auditing for cloud platforms. - [The Importance of Using Web Application Firewalls in Azure](https://blog.l-w.tech/blog/2023-01-06-WAF-in-Azure): Protect Azure applications from SQL injection and XSS attacks with Web Application Firewalls. - [Azure Sentinel - Log4J](https://blog.l-w.tech/blog/2021-12-15-Azure-Sentinel-log4j): Detect and mitigate Log4Shell (CVE-2021-44228) vulnerabilities using Azure Sentinel. - [Why Terraform?](https://blog.l-w.tech/blog/2021-03-06-Why-Terraform): Discover why Terraform outshines ARM templates for Azure infrastructure deployments. - [Create enterprise applications for external access using Terraform](https://blog.l-w.tech/blog/2021-01-08-Create-Enterprise-Application-For-External-Access): Automate Azure Enterprise Application creation with Terraform for secure third-party access. - [Deploy VM from Azure Marketplace image using Terraform](https://blog.l-w.tech/blog/2021-01-05-deploy-vm-azuremarketplace-terraform): Deploy Azure Marketplace images with Terraform using publisher, offer, SKU, and version IDs. - [Azure to Azure Migration](https://blog.l-w.tech/blog/2021-01-04-Azure-to-Azure-Migration): Migrate Azure resources across tenants using MigAZ for mergers and acquisitions. - [Removing ADE v1.1](https://blog.l-w.tech/blog/2021-01-04-Removing-ADE-v1.1): Remove Azure Disk Encryption v1.1 from VMs for migration and modification scenarios. - [Configuring a Routable Domain](https://blog.l-w.tech/blog/2020-12-17-Configure-Routable-Domain): Configure routable domain suffixes for Azure AD Connect and Office 365 migration success. - [Rename Azure VM with Powershell](https://blog.l-w.tech/blog/2020-12-15-Rename-Azure-VM): Learn how to rename Azure VMs while retaining private IP addresses using PowerShell automation. ## Events - [Talks and community events](https://blog.l-w.tech/events): Upcoming and past sessions. - [Build //localhost Manchester](https://developer.microsoft.com/en-us/reactor/events/27257/): 2026-06-13, ANS Office, Manchester. Build //localhost brings Microsoft Build to Manchester — a hands-on, community-run afternoon packed with lightning talks on AI agents, new Azure platform capabilities and developer tooling, followed by a guided hands-on workshop lab. - [Drift Happens: Intelligent Ways to Detect and Remediate It](https://www.meetup.com/northern-azure-user-group/events/314437390): 2026-05-19, Manchester, United Kingdom. Northern Azure User Group. Explore intelligent ways to detect configuration drift in Azure, understand its real impact and remediate it safely using GitHub driven Infrastructure as Code workflows. It is a practical session for teams that want stronger governance without slowing delivery. - [AZUGPT: IaC for AI - Secured, Version-Controlled Agent Infrastructure](https://www.meetup.com/azure-user-group-portugal/events/314439222/): 2026-05-14, Online. Azure & AI User Group Portugal. Learn how to treat your agent infrastructure with the same care as your application code using IaC to build secure, auditable and version-controlled AI services. Covering the journey from AI Foundry models through API Management to production-deployed agents. - [Azure Policy as Code: Getting Started with IaC and CI/CD](https://www.azurespringclean.com/): 2026-03-11, Online. Azure Spring Clean 2026. Store policy definitions in Git alongside Terraform or Bicep, deploy via CI/CD pipelines, and eliminate portal drift across every environment. - [Building on SaaS | The Modern Law Firm Utopia](https://sessionize.com/elliott-lw): 2025-09-01, Ware, United Kingdom. Accesspoint Innovators Forum '25. Guided legal IT leaders from legacy infrastructure to a secure, cloud-first, AI-ready platform covering SaaS adoption, Microsoft Entra identity, Azure AI Foundry and IaC delivery. - [365 Explained: Infrastructure as Code (Ep. 005)](https://www.youtube.com/watch?si=_HJRxVRZAW62Zq8w&t=71&v=wfiFHvY6tTo&feature=youtu.be): 2025-08-18, Online. Guest on the 365 Explained podcast. Covered what IaC means in Azure and M365, the differences between Bicep, ARM and Terraform, real-world use cases, and how IaC can standardise tenant setups and improve security. - [sql_squared Podcast: Mastering Azure Migrations & DevOps](https://www.youtube.com/watch?v=d2LijxaYHcU): 2025-07-19, Online. Guest on the sql_squared Podcast. Covered moving beyond lift and shift to true application modernisation, the Five Rs of cloud migration, avoiding cost pitfalls and the build vs. buy dilemma for cloud architecture and DevOps. - [Scaling Securely: How Platform Engineering Supports Developer Velocity](https://www.youtube.com/watch?v=Gci7AVc7pAU): 2025-04-01, Warrington, United Kingdom. Explored how Platform Ops bridges developer autonomy and operational governance, enabling teams to ship faster with built-in security, compliance and cost controls. - [Mastering the Basics: Terraform and IaC in Azure](https://sessionize.com/elliott-lw): 2025-03-01, Manchester, United Kingdom. North Azure User Group. Covered core IaC principles, real-world deployment patterns and best practices for scalable, reliable infrastructure. - [An Introduction to Terraform and Infrastructure as Code in Azure](https://www.azurespringclean.com): 2025-03-01, Online. Azure Spring Clean 2025. An introduction to IaC fundamentals with Terraform on Azure, covering real-world deployment patterns and best practices for scalable, reliable infrastructure. - [Innovation In Azure](https://sessionize.com/elliott-lw): 2025-01-01, London, United Kingdom. SAM Club. Session exploring the latest Azure innovations and how organisations can leverage cloud-native capabilities to drive efficiency and competitive advantage. ## Also - [RSS](https://blog.l-w.tech/rss.xml): Full article text for each post. - [Sitemap](https://blog.l-w.tech/sitemap.xml): Every public page. - [Full text](https://blog.l-w.tech/llms-full.txt): The same posts, in Markdown, in one file.