Skip to main content Explore View all products (200+) Microsoft Foundry Azure Copilot GitHub Copilot Azure Kubernetes Service (AKS) Azure Cosmos DB Azure Database for PostgreSQL Azure Arc Microsoft Fabric Linux virtual machines in Azure Foundry Models Foundry Agent Service Foundry IQ Foundry Tools Foundry Control Plane Observability in Foundry Control Plane Azure OpenAI in Foundry Models Azure Speech in Foundry Tools Azure Machine Learning View all databases Azure Cosmos DB Azure DocumentDB Azure SQL Azure Database for PostgreSQL Azure Managed Redis Microsoft Fabric Azure Databricks Linux virtual machines in Azure Windows Server on Azure Azure Functions Azure Virtual Machine Scale Sets Azure API Management Azure Container Apps Azure Kubernetes Service (AKS) Azure Kubernetes Fleet Manager Azure Container Registry Azure Red Hat OpenShift Azure Container Instances Azure Container Storage Azure Arc Azure Local Microsoft Defender for Cloud Azure Monitor Microsoft Sentinel Azure Migrate View all solutions (40+) Cloud solutions for small and medium businesses Cloud migration and modernization center Data analytics for AI Azure Databases AI apps and agents Microsoft Marketplace Microsoft Sovereign Cloud AI apps and agents Responsible AI with Azure AI Infrastructure Data analytics for AI Machine learning operations (MLOps) Low-code application development on Azure Integration Services Serverless computing DevOps Migration and modernization center .NET apps migration Databases on Azure Linux on Azure Oracle on Azure SAP on the Microsoft Cloud Adaptive cloud High-performance computing (HPC) Infrastructure as a service (IaaS) Resiliency Azure Essentials Frontier Accelerate for Azure FinOps on Azure Microsoft Marketplace Azure pricing overview Create an Azure account Free Azure services Flexible purchase options Pricing calculator FinOps on Azure Maximize ROI from AI Azure savings plans Azure reservations Azure Hybrid Benefit Virtual Machines Azure SQL Microsoft Foundry Microsoft Fabric Azure Kubernetes Service (AKS) Microsoft Defender for Cloud View more Software Development Companies Microsoft Marketplace Find a partner Resources for Azure partners Get started with Azure Customer stories Analyst reports, white papers, and e-books Videos Learn more about cloud computing Documentation Explore Azure portal Developer resources Quickstart templates Resources for startups Developer community Students Azure for partners Blog Events and Webinars Learn Support Contact Sales Get started with Azure Sign in

When a physical security operator begins a shift supporting Microsoft’s global datacenter operations, they depend on a collection of applications and systems that help monitor access activity, review video feeds, investigate alerts, and coordinate physical security operations across a complex global environment. Those tools must be available, responsive, and reliable from the moment a shift begins.

As Azure datacenters expanded to support growing demand for cloud and AI services, maintaining that experience became increasingly important. Critical security systems were distributed across hundreds of locations worldwide, while the infrastructure supporting them spanned both on-premises and cloud environments. The challenge wasn’t responding to a specific incident or operational failure but ensuring that as Azure’s physical footprint continued to grow, the systems supporting those operations remained secure, manageable, observable, and consistent at a global scale.

Meeting that goal required more than simply keeping systems online. The team needed a way to manage infrastructure across hybrid environments, standardize operations, automate routine tasks, improve visibility into system health, and provide operators with consistent application experiences regardless of location. By combining Azure Arc, Azure Virtual Desktop, Azure Monitor, and other Azure management services, Microsoft built a more unified operational foundation designed to support the evolving needs of its global physical security environment.

Building a unified management layer across hybrid infrastructure

As Azure datacenters expanded, so did the infrastructure supporting their physical security operations. Critical systems were deployed close to the environments they served and operated within highly segmented networks designed to prioritize resiliency, security, compliance, and local autonomy. That architecture solved one challenge but created another.

The physical security organization was responsible for deploying and managing thousands of servers distributed across Microsoft’s global datacenter footprint in alignment with established protocols. While each deployment met baseline operational requirements, rapid growth and increasing scale made it increasingly difficult to guarantee consistency.

The team needed a way to bring these distributed systems under a common management framework without changing where the workloads ran or weakening the security boundaries that protected them.

Why Azure Arc

The objective wasn’t to move these workloads into Azure. Many of the systems supporting physical security operations needed to remain close to the environments they served and continue functioning independently when required by local operational or resiliency needs. Instead, the team was looking for a way to extend the operational benefits of Azure to on-premises infrastructure.

Azure Arc was designed to address exactly this type of challenge. At its core, Azure Arc extends Azure’s management and governance capabilities to servers and resources running outside Azure. Rather than treating on-premises systems as separate operational islands with their own tools and processes, Azure Arc allows organizations to manage those resources through Azure’s control plane. This makes it possible to apply, at scale, many of the same monitoring, policy, automation, security, and update-management workflows used in Azure to infrastructure running elsewhere.

For Microsoft’s physical security organization, Azure Arc made it possible to manage servers across its global datacenter footprint through a common operational model, regardless of where they were physically located.

More importantly, Azure Arc allowed the team to preserve the resiliency and security characteristics of their existing deployments while gaining centralized visibility, governance, and automation capabilities.

Establishing a consistent operational foundation

Once onboarded to Azure Arc, the team began extending familiar Azure management capabilities to infrastructure running outside Azure. Using Azure Update Manager, patching activities that had historically required significant coordination across distributed environments could be scheduled, tracked, and governed through a centralized framework. According to the team, this automation now saves thousands of hours annually while enabling a relatively small operations team to support a growing infrastructure footprint.

At the same time, Azure Policy, Guest Configuration, Azure Monitor, Azure Monitor Agent, and Log Analytics helped create a common framework for governance, compliance monitoring, and observability. The team could continuously assess critical security configurations, identify drift, monitor system health, and surface operational telemetry through centralized dashboards, alerts, and reporting workflows regardless of where infrastructure was deployed.

Security remained a primary consideration throughout the design. Managed Identities and Azure role-based access control (RBAC) helped reduce reliance on stored credentials while providing more granular control over access to operational resources. Azure Automation further reduced manual effort by standardizing remediation, maintenance, and configuration-management activities through reusable runbooks. Together, these capabilities helped establish a more consistent operating model across the environment while improving visibility, strengthening governance, and reducing the operational overhead associated with managing a globally distributed infrastructure.

Delivering a consistent operator experience with Azure Virtual Desktop

Unified management solved one part of the challenge. The next was ensuring that operators interacting with those systems received the same level of consistency, performance, and visibility.

The team’s objective extended beyond providing remote access. They needed a way to improve application performance, simplify lifecycle management, and gain better insight into the end-user experience. Azure Virtual Desktop provided a flexible platform for delivering applications closer to the infrastructure they depended on, while also enabling centralized image management and integration with Azure monitoring services. This allowed the team to maintain consistent host configurations, simplify updates, and incorporate user-session telemetry into existing operational workflows.

To improve the operator experience, the team relocated the application environment closer to the infrastructure it supported and delivered access through Azure Virtual Desktop sessions. The impact was immediate: application launch times improved by approximately 12x, helping operators access critical tools more quickly and consistently.

The team also adopted a centralized image-management strategy and automated host refresh process. Instead of maintaining individual systems over time, hosts could be rebuilt from approved images and deployed consistently across the environment. This approach accelerated release cycles by ~6x, reduced configuration drift, and allowed updates that once required weeks or months of coordination to be completed in hours.

Equally important was the visibility Azure Virtual Desktop unlocked. By integrating Azure Virtual Desktop with Azure Monitor, Azure Monitor Agent, Log Analytics, and Azure Virtual Desktop Insights, the team gained access to telemetry on session health, round-trip time, bandwidth usage, and client-side application behavior. Engineers could better understand how applications performed from the operator’s perspective, identify trends earlier, and shift from reactive troubleshooting to a more proactive, data-informed approach.

Key lessons for managing hybrid environments at scale

As Azure’s global datacenter footprint continued to grow, Microsoft’s physical security organization needed a management and delivery model that could scale alongside it. By combining Azure Arc and Azure Virtual Desktop, the team established a more consistent approach to managing infrastructure, delivering applications, and monitoring operational health across a complex hybrid environment.

The result wasn’t a single breakthrough technology, but a unified operating model that improved visibility, reduced operational overhead, and helped ensure critical systems remained resilient, manageable, and ready to support future growth.

Learn more

Bring consistency and control to hybrid operations

See how Azure Arc helps organizations extend Azure management and governance capabilities across distributed infrastructure, enabling centralized visibility, automation, compliance, and operational consistency without changing where workloads run.

WE ARE MICROSOFT

Explore Microsoft Foundry

The future of AI starts here. Envision your next great AI app with the latest technologies. Get started with Azure.