The Microsoft Azure Well-Architected Framework structures the assessment of a workload around 5 pillars: reliability, security, cost optimisation, operational excellence and performance efficiency. Yet most organisations run architectures designed during accelerated migrations, where these pillars were never explicitly examined: year after year, Flexera's State of the Cloud surveys put estimated waste at around 30% of cloud spend, a direct symptom of architectures that have never been reviewed.
The gap is widening for two reasons. First, the platform evolves faster than the architectures running on it: service deprecations, new SKUs, new availability guarantees — a single-instance VM stays at 99.9% SLA while a multi-zone deployment reaches 99.99%. Second, the shared responsibility model places most security failures on the customer configuration side, not the provider's: Gartner has long estimated that nearly all cloud security incidents stem from customer errors.
The good news: a Well-Architected Review is tooled and repeatable. Between Microsoft's WAF assessment, Azure Advisor, Defender for Cloud and platform metrics, most findings can be measured without additional instrumentation. This document provides the method to run the review in a few weeks, rate each gap according to its impact and effort, build a remediation plan prioritised in waves, and maintain a register of residual risks accepted at executive level.
Why audit your architecture now
An Azure architecture is not fixed: it drifts, under the effect of fast migrations, platform changes and trade-offs made under pressure. The question is therefore not whether to audit it, but at what point the cost of delay exceeds the cost of the review.
The following sections detail the method: scoping the review, examining the five pillars, rating the findings, building the remediation plan and steering residual risks.
Scoping and collecting evidence
A Well-Architected Review never applies to "all of Azure": it applies to a bounded workload, with its subscriptions, its dependencies and its service commitments.
Set the scope on a named workload, with its owner and its service objectives, and require exportable evidence for every finding: without a dated artefact, a finding is only an opinion.
Assessment tools: what to choose
No single tool covers all five pillars on its own: the structured assessment provides the framework, Azure telemetry provides the evidence, and custom queries fill the remaining gaps.
Mistaking a secure score or an Advisor score for a level of architectural maturity: these scores rate the configuration of existing resources, not design choices. A perfectly configured single-region architecture can display an excellent score while being incapable of meeting its RTO.
Scoring and prioritising risks
An unrated finding is a finding that will never be arbitrated: rating turns a list of gaps into an order of play that can be defended before a steering committee.
Remediation plan and follow-up
The value of a review is measured by the number of findings actually closed six months later, not by the number of pages in the report.
Formalise every untreated risk in a dated, named register with a review date: a risk accepted explicitly is a risk under control, a forgotten risk is an on-call surprise.
Key takeaways
- Does each critical workload have a named owner and service objectives (SLO, RTO, RPO) that are written down and validated by the business?
- Do you have, for every finding from your last review, a dated and exportable artefact (ARM/Bicep export, Advisor screenshot, diagram, policy extract)?
- Can you distinguish, in your reporting, what relates to resource configuration (secure score, Advisor) and what relates to design choices?
- Are your findings scored against an explicit scale combining impact and likelihood, rather than ranked by expert gut feeling?
- Are remediation batches embedded in the product backlog, with an estimated effort and a target sprint, rather than kept in a separate document?
- Are the risks you have decided not to address formally accepted, dated, signed and reviewed at least once a year?
