Our approach to migrating to Microsoft Azure
Cloud Temple, a European sovereign cloud provider (SecNumCloud, HDS and C5 certified), supports its clients in migrating their on-premises or private cloud-hosted infrastructures to Microsoft Azure, whilst maintaining the requirements for sovereignty, security and service continuity specific to a critical environment.
What we are migrating to Azure
| Plot | Description |
|---|---|
| Migrate Windows Servers to Azure | Lift-and-shift of Windows Server servers to Azure virtual machines, using Azure Migrate |
| Migrate Linux servers to Azure | Lift & shift of Linux servers (Debian, Ubuntu, RHEL, etc.) to Azure |
| Migrate SQL to Azure | Migrating SQL Server databases to Azure VMs without changing the engine |
| Refactor SQL on Azure | Migration of SQL Server databases to Azure SQL Managed Instance / Azure SQL Database, including application adaptation |
-
Assess — Audit of the existing infrastructure, deployment of an Azure Migrate appliance directly within the source environment (VMware or physical), technical and financial assessment (target sizing, costs, Azure Hybrid Benefit eligibility).
-
Plan — Design of the target architecture (Azure landing zone, network, security) and definition of the migration strategy best suited to each workload (rehosting or refactoring).
-
Migrate — Carrying out the migration (lift-and-shift via the Azure Migrate appliance, or rebuilding for components requiring modernisation), whilst ensuring service continuity. The VMs resulting from the rehost are then imported into the Terraform code and state (see the IaC section below).
-
Secure — Integration of native Azure security monitoring (Microsoft Defender for Cloud, Azure Sentinel) from the moment the system goes live.
-
Operate — Management of Azure resources via Azure Lighthouse, with a managed service model tailored to the client’s needs (full Cloud Temple, full client, or hybrid collaboration).
-
Decommissioning — Once the switchover has been approved by the client, the decommissioning of the relevant on-premises infrastructure is tracked.
Building the Azure Landing Zone using Infrastructure as Code
In addition to migrating workloads, Cloud Temple builds the target Azure environment entirely using Infrastructure as Code (IaC):
Terraform
The entire landing zone (networks, security, governance, administrative permissions via Azure Lighthouse) is described and versioned in Terraform.
CI/CD pipeline
The deployment and evolution of the infrastructure are automated via a CI/CD pipeline, ensuring traceability, code reviews and reproducible deployments.
Hub-and-spoke architecture
Azure environments are structured according to a hub-and-spoke topology: a hub network that centralises shared services (connectivity, security, monitoring), and spoke networks that are isolated by environment or customer application scope.
CAF Agreements
Resource naming and the tagging scheme comply with the Cloud Adoption Framework conventions (prefixes by resource type, cost, environment and owner tags), ensuring consistent governance across the entire Azure environment.
Integration of migrated VMs into IaC
Virtual machines migrated via the Azure Migrate appliance (deployed directly within the source environment, whether VMware or physical) are, once the switchover is complete, imported into the Terraform code and state. This step ensures that the entire environment — including resources resulting from a rehost — continues to be managed consistently as Infrastructure as Code after migration, rather than as resources created «out-of-band» by the migration tool.
Why choose Azure with Cloud Temple?
- Continuity of IT outsourcing : our customers receive the same level of MCO/MCS support both before and after migrating to Azure.
- Compliance and sovereignty: selection of Azure regions (e.g. Central France) and security controls tailored to the client’s regulatory requirements.
- Proven methodology: the Assess → Plan → Migrate → Secure → Operate → Decommission approach, applied to critical production environments.
- A French consultancy firm — Rehost Windows Servers on Azure (migrating Active Directory domain controllers using Azure Migrate)
- A trade association for the French metalworking industry — Rehost Linux servers on Azure (lift-and-shift migration of 10 Linux/Windows servers via Azure Migrate)