top of page

AI Landing Zone (AILZ) - Deployment

Sep 1
3 min read

Updated: Sep 2

The AI Landing Zone delivers an enterprise-scale, production-ready reference architecture implemented via Portal, Bicep, and Terraform to deploy secure and resilient AI applications and agent workloads in Azure. It establishes a standardized framework that isolates operational domains while simplifying governance, security, and lifecycle management.

AI Landing Zones (Hub & Spoke Architecture)

The architecture follows a classic hub-and-spoke pattern designed to balance enterprise-wide governance with business-unit agility. As a best practice, organizations deploy one AI Gateway Landing Zone as the hub and multiple AI Foundry Landing Zones as spokes serving distinct business domains such as HR, IT, Sales, and Finance.


  • AI Gateway Landing Zone: Functions as the centralized hub for models. It provides shared governance, security policies, access controls, and model management across both production and non-production environments. It serves as the single foundation for foundation models that can be reused across the enterprise.  

  • AI Foundry Landing Zone: Functions as a dedicated spoke for agents and applications. It gives individual business units the autonomy to build, test, and run AI agents that consume upstream models from the AI Gateway Landing Zone while maintaining strict workload isolation.


AI Gateway Subscription Or Governance HUB Subscription

The AI Gateway Subscription (or Governance Hub) acts as the operational backbone for enterprise AI services.  

  • Platform Purpose: Centralizes model hosting, compliance enforcement, and security controls. This avoids redundant model deployments and fragmented infrastructure across teams.  

  • Core Services: Hosts Azure OpenAI Services, foundation model deployments, and Azure AI Foundry Hub/Project resources. Shared platform controls include Azure API Management (AI Gateway), Azure Key Vault, Azure Storage, Content Safety, Language Service PII processing, Azure Cosmos DB, Managed Redis Semantic Cache, and Azure Monitor/Log Analytics workspaces.  

  • Networking & Protection: Integrated within dedicated subnets using Private Endpoints, Azure Private DNS Resolver, UDRs to hub firewalls, and security layers backed by Microsoft Defender, Microsoft Entra ID, and Microsoft Purview. 

AI Foundry Subscription

The AI Foundry Subscription hosts the application landing zone where business-specific innovation takes place.  

  • Workload Isolation: Provides dedicated environments tailored to individual business units or specific AI use cases.  

  • Application Components: Deploys Azure AI Foundry Projects, AI Agents, Agent Workflows, optional Azure AI Search instances, Application Insights, Key Vaults, and Storage Accounts.  

  • Consumption Model: Rather than deploying their own foundation models, AI Foundry projects establish private, authenticated network connections to the AI Gateway. AI agents dispatch requests through these secure channels, where the AI Gateway applies governance, token tracking, and content safety filters before returning responses. 

AI Gateway Architecture Explorer

Conclusion

The AI Landing Zones architecture establishes an enterprise‑grade operational model where the AI Gateway Landing Zone acts as the centralized hub for hosting, securing, and governing shared AI models, and individual AI Foundry Landing Zone projects operate as dedicated spokes where business units build, test, and run tailored AI agents and applications. Together, they balance enterprise‑wide compliance, cost management, and content safety with domain‑level innovation and agility. The AI Landing Zones comprise an AI Foundry Landing Zone and an AI Gateway Landing Zone, both of which can be deployed together or independently based on the specific needs and maturity of an organization’s use cases.

For architecture implementation details and deployment templates (Portal, Bicep, and Terraform), see the official GitHub repository: https://github.com/Azure/AI-Landing-Zones. This repository is published under the MIT License; if you reproduce substantial portions of the code or documentation, include the original copyright and license notice and a link back to the repository. This reference is provided for informational purposes and does not imply endorsement by Microsoft.


Comments

Rated 0 out of 5 stars.
No ratings yet

Add a rating
bottom of page