Cloud services

Azure and AWS design, migration and review for Canadian organizations: landing zones, identity, networking, backup and cost visibility.

Isometric illustration of an on-premises server rack linked to two cloud platforms, with a structured landing zone, a cost gauge and a backup vault.

What we review

  • Landing zones: Subscription or account structure, naming, tagging and guardrails set up before workloads arrive.
  • Identity and access: Entra ID or AWS IAM roles, privileged access, service identities and how permissions are granted.
  • Networking: Virtual networks, segmentation, private connectivity, VPN or dedicated links, DNS and internet exposure.
  • Hybrid integration: How on-premises systems, identity and networks connect to cloud resources.
  • Migration planning: Which workloads move, in what order, by what method, and what stays on-premises.
  • Backup and recovery: What is protected, where copies are kept, and whether restores have been tested.
  • Cost visibility: Where spend goes, what is idle or oversized, and budgets and alerts to keep it visible.
  • Security posture: Logging, exposed services, key and secret handling, and native security recommendations.

Deliverables

  • Cloud architecture design: Structure, networking and identity model, with the reasoning for each choice.
  • Landing zone build or review: Guardrails, policies and baseline configuration, documented.
  • Migration plan: Workload inventory, sequencing, method, cutover windows and rollback for each wave.
  • Cost report: Current spend by service and owner, with specific reduction opportunities.
  • Backup and recovery record: What is covered, retention, and results of restore tests.
  • Security posture findings: Gaps in priority order, with the change needed to close each.

Engagement boundaries

  • Work is carried out during Canadian business hours. There is no round-the-clock monitoring, on-call rota or staffed operations centre. Migration cutovers are scheduled for agreed windows.
  • Cloud provider availability, pricing and service changes are outside our control.
  • Cost estimates are based on stated assumptions; actual bills depend on usage and provider pricing.
  • Changes are made with your approval and through your change process, not unilaterally.
  • Application code changes needed to run in the cloud are not included unless scoped in writing.
  • Backup design is only proven by a restore test; untested backups are reported as unverified.
  • A sound security posture reduces risk. It does not prevent every misconfiguration or compromise.
  • Where your contractual and regulatory obligations affect where data may be stored, you confirm those requirements; this is not legal advice.
  • This work does not certify compliance with any framework or standard.

Questions before the work starts

Should we be in Azure or AWS?

Often the answer follows from what you already use. Organizations heavily invested in Microsoft 365 and Entra ID frequently find Azure simpler to govern, but that is not universal. The recommendation is made against your workloads, skills and contracts, with the trade-offs written down.

Will moving to the cloud save us money?

Not automatically. Some workloads cost less in the cloud and some cost more, especially if they are moved as-is and left running. The migration plan includes a cost view per workload so the decision is made with realistic numbers.

How much disruption does a migration cause?

Most of the work happens in the background. Staff are affected at cutover, which is scheduled in agreed windows and tested beforehand, with a rollback step for each wave.

We already have cloud accounts. Can you review what is there?

Yes. A review of an existing environment is a common starting point, covering structure, access, exposure, backup and cost, and producing a prioritised list of changes.

How is this priced?

By agreed scope, set out in writing before work starts. Design and review work is bounded; migration effort depends on the number and complexity of workloads.

The platforms this work covers

Cloud work covers the providers and the hybrid connections an environment actually depends on.

  • Microsoft Azure
  • Amazon Web Services
  • Microsoft 365 and Entra ID
  • Cloudflare
  • Hybrid and on-premises data centre
  • Site-to-site VPN and private connectivity

Audits available

  • Azure subscription audit: subscription and resource-group boundaries, role assignments, network exposure, key and secret handling, diagnostic logging.
  • AWS account audit: account structure, IAM roles and policies, public exposure, guardrails and CloudTrail coverage.
  • Cloud cost review: spend by service and owner, idle and oversized resources, and budget alerting.

Moving to the cloud, or unsure the cloud you have is set up well?

Start with a free initial consultation. Tell us which provider you use or are considering, roughly what workloads are involved, and what is prompting the question, such as a hardware refresh, a rising bill or a client security request. The reply will suggest a sensible first step.

Contact HAI Consulting