Not every client group has moved everything into the tenant.
Microsoft 365 administration is one lane, with its own written boundary. Client groups that still run Azure resources, or physical Hyper-V and VMware hosts, need the same treatment applied to a different layer — not a separate, undefined conversation every time it comes up.
What enters the infrastructure lane.
Useful when a client group's footprint is not fully in the cloud, or runs a mix of Azure resources and physical hosts behind it.
Azure resource administration — starting, stopping, or resizing virtual machines against an approved runbook, resource-group and role-assignment hygiene, backup-job monitoring and restore-test coordination, and basic cost or utilization reporting — alongside Hyper-V or VMware host administration: patch-window coordination for hosts and guests, datastore and capacity monitoring, snapshot hygiene, and host-level backup verification.
An approved resource or host change is completed and logged, or returns as an exception naming the capacity, cost, or availability question involved.
A current resource and host inventory, the administrative access method for each platform, an approved runbook per platform, and clear, confirmed ownership of the Azure subscription and the hypervisor license.
Infrastructure decisions escalate faster than user requests.
- Any change with a real cost impactResizing, scaling, or adding resources returns for approval before it is applied — cost is a business decision, not a technical one.
- Anything outside the documented runbookStops before it is applied, the same as any other exception.
- Disaster-recovery failoverIs tested and rehearsed on an agreed schedule, never treated as a first-time routine ticket.
- Hypervisor upgrades and Azure architecture changesAre project work, scoped and estimated separately from the recurring lane.
Who owns what, underneath the tenant.
| Azure subscription and billing relationship | Confirmed at intake — usually the selling practice or the client, never assumed. |
|---|---|
| Hypervisor and virtualization licensing | Confirmed at intake; delivery administers it, it does not hold the license. |
| Approved administrative routines | Delivery executes against the agreed runbook. |
| Capacity, cost, and architecture decisions | Selling practice approves, informed by delivery's reporting. |
Ask these before assuming the infrastructure is covered.
- Does the lane name every subscription, resource group, and host in scope?An undefined "and anything else Azure" clause is not a boundary.
- Who receives the backup-verification and capacity reports, and how often?A report no one reads is not a control.
- Is there a rehearsed disaster-recovery runbook, or only an assumed one?The difference only shows up during an actual failure.
- Who approves a change that would increase the monthly Azure bill?Name the approver before the first resize request, not after the invoice.
See where this connects to the rest of the catalog.
The Microsoft 365 lane covers the tenant; the device-lifecycle lane covers how endpoints and hosts get patched on a rhythm once they are in scope here.