🎯 Governance

Azure Governance at Scale

Enterprise governance strategies: tags, policies, RBAC, and compliance automation for 31,000+ resources.

Governance is a People Problem (Not a Tech Problem)

The governance trap: Teams implement Azure Policy, tag policies, and RBAC—then wonder why nobody follows them. The technical implementation was easy. Getting people to comply is the hard part.

Managing 31,000+ Azure resources taught me that effective governance requires three layers:

  • Business buy-in — Tags and policies must solve business problems (showback, compliance, automation), not just "governance".
  • Automated enforcement — Make compliance the path of least resistance with deny policies, auto-tagging, and remediation.
  • Continuous measurement — KQL dashboards showing compliance trends, not just snapshots.

This hub contains the governance frameworks, tag strategies, and policy patterns I've used to maintain compliance in enterprise Azure environments—without creating bureaucracy that teams ignore.

1. Tag Strategy Fundamentals

Design tag taxonomies that teams will actually use and finance can trust.

2. Policy, Patching, and Automation

Use Azure Policy, Update Manager, and automation to enforce standards instead of begging for them.

3. Audit, Support, and Process Governance

Close audit gaps, fix ticketing reality, and make process part of governance instead of an afterthought.

4. Hybrid & Azure Arc Governance

Extend Azure governance to VMware and on-prem servers with Azure Arc and a real CMDB strategy.

Azure Arc Ghost Registrations: Detection and Cleanup at Enterprise Scale

Azure Arc Ghost Registrations: Detection and Cleanup at Enterprise Scale

2025-12-06

Azure Arc ghost registrations occur when VMs are deleted from VMware without Arc cleanup. At 64% ghost rate (300 of 467 Arc VMs non-existent), inventory becomes unusable for governance and ESU compliance. Includes RVTools reconciliation method, PowerShell cleanup scripts, and Arc Resource Bridge deployment guide for automatic lifecycle sync with vCenter.

azure azure-arc ghost-registrations
💻

GitHub Resources

Production-ready code and tools

Azure Admin Workstation Setup
Automated configuration for Azure governance and management tooling.
Enhanced Azure Inventory Workbook
Compliance tracking across subscriptions with governance metrics.

Explore Related Topics

💰
FinOps
8 articles
🔍
KQL Mastery
7 articles
📊
Azure Monitoring
5 articles
🎯

Stop Begging for Compliance

Get the Azure Integration Assessment Framework

  • Governance questions that expose institutional knowledge gaps before migration
  • Compliance, licensing, ownership, and dependency assessment in one spreadsheet
  • If you can't answer 50% with high confidence, you're not ready to migrate
📥 Download Governance Assessment (Free)

Excel template • No email required