← Architect · Practitioner

Knowledge material · ~6 min read

Architect · Practitioner

Landing zones, identity at scale, IR (Incident Response) design, enterprise network.

Overview

Practitioner Architects design the platforms others build on. A good landing zone makes the secure path the easy path. A good IR plan turns chaos into choreography. A good network at scale routes by intent, not by 'we added another VLAN (Virtual Local Area Network).'

Cloud landing zones

  • ▸Hierarchy: management groups → platform subs (identity, mgmt, connectivity) → workload subs.
  • ▸Hub-and-spoke network; shared services in the hub.
  • ▸Policy-as-code baseline before anyone deploys workloads.
  • ▸Logging to a central, immutable account.

Identity at scale

  • ▸SSO (Single Sign-On) + SCIM (System for Cross-domain Identity Management) for every SaaS that supports it.
  • ▸Privileged roles in PIM (Privileged Identity Management) with approval + just-in-time.
  • ▸Separate admin identities from daily-use identities.
  • ▸Continuous access evaluation; revoke fast, not eventually.

Incident response design

  • ▸Prepare → Detect → Contain → Eradicate → Recover → Lessons.
  • ▸Named roles: IC, comms, scribe, technical lead.
  • ▸Severity matrix tied to communication cadence.
  • ▸Tabletop quarterly; full game-day once a year.

Enterprise network architecture

  • ▸SD-WAN (Wide Area Network) replaces site-to-site MPLS (Multiprotocol Label Switching) for most mid-market.
  • ▸Microsegmentation at the workload, not the perimeter.
  • ▸DNS (Domain Name System), NTP (Network Time Protocol), and identity are the three silent dependencies.
  • ▸Design for 'how does this recover' first, 'how fast is it' second.

Glossary

Landing zone
Opinionated cloud baseline ready for workloads.
IC
Incident Commander — single decision-maker during IR.
SD-WAN
Software-defined WAN routing intelligently over multiple links.
CAE
Continuous Access Evaluation — near-real-time token revocation.

Common pitfalls

Practice drills