Azure landing zone for Nonprofits overview

Azure landing zone for Nonprofits helps nonprofit organizations set up a secure Azure foundation for cloud workloads. It provides an Azure-native baseline for management, identity and access, governance, security, monitoring, cost controls, and networking.

It's tailored for nonprofits that need a practical, cost-conscious starting point with fewer enterprise-scale decisions than a general-purpose Azure landing zone implementation.

Use the landing zone when your organization wants a consistent starting point for Azure operations without designing every platform control from the beginning. The baseline can support current workloads and future workloads, including AI-enabled workloads, by giving teams a governed Azure environment to build on.

Azure landing zone for Nonprofits is designed for organizations that need practical deployment choices. You can start with a single-subscription foundation deployment, or use the expanded platform when your organization is ready for dedicated management and connectivity subscriptions.

For an architecture view of the deployment profiles, resource topology, and networking model, see Azure landing zone for Nonprofits architecture.

What the landing zone provides

The deployment creates and configures platform resources and controls that are commonly needed before workload teams start using Azure.

Area What the landing zone helps configure
Governance Azure Policy assignments, required platform tags, and baseline controls for the selected deployment path.
Management and monitoring A Log Analytics workspace, activity log diagnostics, service health and planned maintenance alert routing, and follow-up actions for alert-response readiness.
Security A shared platform Key Vault protected by Azure RBAC, logging, and a deny-by-default network firewall, optional private endpoint access for Key Vault, and optional Microsoft Defender for Cloud coverage for Key Vault and storage when recurring charges are approved.
Cost management Optional monthly budget notifications for the foundation subscription or expanded platform management subscription.
Identity and access Optional Microsoft Entra group-based access assignments for organization platform administrators and partner operators. Access can also be completed after deployment before handover.
Networking Optional simple foundation networking with an application-subnet network security group (NSG), or a dedicated expanded platform hub network with optional private Key Vault connectivity and optional reserved gateway subnet.

The landing zone doesn't deploy application workloads. It prepares the platform baseline that your organization or implementation partner can use before deploying workloads into Azure.

By default, the Key Vault public endpoint remains enabled, but the firewall denies public IP and virtual-network data-plane traffic and doesn't allow a trusted-service bypass. The deployment defines the IP and virtual-network allowlists as empty. Use the private endpoint option when administrators or workloads need durable Key Vault data-plane connectivity.

Choose a deployment path

Azure landing zone for Nonprofits offers two primary deployment paths.

Path Use when Scope
Foundation You need a compact Azure baseline in one existing subscription, with simple operations and minimal upfront decisions. One existing subscription. Foundation doesn't create or modify a management-group hierarchy. You can optionally include simple networking.
Expanded platform You need stronger separation of duties, a dedicated hub network, and a platform model that can grow as you add subscriptions or workloads. Existing management and connectivity subscriptions. Governance is applied to the selected platform subscriptions and can also be assigned to an existing Platform management group when provided.

Choose foundation when your organization is starting with Azure, evaluating a controlled platform baseline, or operating a smaller environment where one subscription is enough. Choose expanded platform when your organization has approved platform subscriptions, needs dedicated shared connectivity, and is ready to operate additional platform responsibilities.

Deployment options

Use one of the following deployment options.

Option Use when Go to
Azure portal deployment You want the recommended deployment experience for most users. The portal flow guides you through the supported foundation or expanded platform inputs and shows what was deployed, skipped, or still needs follow-up. Deploy and configure Azure landing zone for Nonprofits
Azure CLI deployment You're an experienced Azure operator, automation owner, or delivery partner preparing repeatable deployment commands or parameter files. Deploy Azure landing zone for Nonprofits with the Azure CLI

The Azure CLI option doesn't reduce the operator's responsibility to review prerequisites, permissions, costs, and deployment results.

Readiness after deployment

A successful deployment doesn't always mean the environment is ready for handover. You can defer some items, such as customer-owned platform administrator access, partner operator access, budget creation, or alert-response readiness.

After deployment, review the follow-up actions and complete the handover tasks before relying on the environment for steady-state operations.