Azure Infrastructure Architect
Platform Engineer

Building the cloud,
the right way.

Platform engineer specialising in Azure infrastructure automation, identity & access management, and multi-tenant cloud governance at enterprise scale.

Current role
Platform Engineer
Olympus · Digital Unit · Platform Engineering
Certifications
AZ-900 AZ-104
Core stack
Azure Terraform PowerShell Azure DevOps Entra ID
CL
Colin Landers
Azure Infrastructure Architect · Platform Engineer · DevOps Architect · Security Architect
Cloud infrastructure,
done deliberately.

I'm a platform engineer on a Digital Unit team, where I design and build the Azure infrastructure foundations that product teams build on top of. That means Landing Zone patterns, hub-spoke networking, multi-tenant Entra ID governance, and everything in between.

My philosophy is simple: automate everything that can be automated, keep security posture tight with least-privilege by default, and treat infrastructure as code — always. I live in Azure, Terraform, PowerShell, and Azure DevOps pipelines day to day.

Outside of infrastructure, I'm expanding my roots in infrastructure and related services while keeping a close eye on how AI tooling is reshaping the cloud engineering workflow.

23+
Years in Technology
8+
Years in Azure
2
Azure certifications
What I bring to the table

From infrastructure design to security architecture and DevOps automation — here's what I do best.

Azure Infrastructure
Hub-spoke networking, Landing Zone architecture, private endpoints, Azure Monitor, Defender for Cloud, and multi-subscription governance.
AZ-104Hub-SpokeAPIMFront Door
Identity & Access (UIAM)
Entra ID governance, External ID/CIAM platform, Entra B2B, custom RBAC roles, ABAC conditions, app registrations, and least-privilege IAM patterns.
Entra IDExternal IDAZ-900SAML/OIDC
Infrastructure as Code
Terraform Cloud (azurerm, azuread, azapi, tfe), reusable modules, state management, Terraform Cloud workspace orchestration, and EPAC.
TerraformTerraform CloudazapiScalr
DevOps & Automation
Azure DevOps pipelines, PowerShell 7+ scripting, Graph SDK, REST API automation, and scheduled compliance tooling.
Azure DevOpsPowerShellGraph APIKQL
Microsoft Fabric & Analytics
Fabric capacity provisioning, Log Analytics workspace integration, Power BI Admin API, GraphQL APIs, lakehouses, and KQL query engineering.
Microsoft FabricLog AnalyticsKQLPower BI
Security & Compliance
ISO 27001 controls, Defender for Cloud, Microsoft Purview, Azure Policy, RBAC audit automation, and least-privilege service principal governance.
DefenderPurviewISO 27001Azure Policy
Microsoft Certified: Azure Fundamentals
AZ-900 · Microsoft
Microsoft Certified: Azure Administrator Associate
AZ-104 · Microsoft
Selected projects

A cross-section of platform engineering work spanning infrastructure automation, identity, and observability.

Identity
UIAM Platform — Entra External ID

End-to-end External ID / CIAM platform build for a multi-tenant organisation. Terraform-managed app registrations, custom RBAC roles, Log Analytics bootstrapping, and cross-tenant user sync automation via Azure DevOps pipelines.

Infrastructure
Enterprise Production Landing Zone

Multi-subscription hub-spoke network deployment for enterprise production workloads. Private endpoints, Defender for Cloud integration, DNS hierarchy management, and Terraform Cloud workspace orchestration across environments.

Security
Azure RBAC Audit Automation

Scheduled weekly RBAC audit pipeline covering service principal security, managed identity permissions, and cross-subscription role assignments. PowerShell + Azure DevOps with CSV audit trail output and anomaly flagging.

DevOps
Microsoft Fabric Monitoring Pipeline

Bulk Log Analytics workspace integration across 24+ Microsoft Fabric workspaces via Power BI Admin API. Terraform-managed Fabric capacity, lakehouses, and GraphQL API health index with KQL-based monitoring dashboards.

Infrastructure
Azure APIM + Fabric GraphQL

APIM integration layer over Microsoft Fabric GraphQL APIs using User-Assigned Managed Identity. Policy XML templating, UAMI attachment via azapi_update_resource, and production 500 error incident resolution.

Security
Cross-Tenant User Sync

Automated cross-tenant Entra ID user synchronisation comparing ~1,000 workforce tenant users against ~200 non-prod users using UPN prefix matching, with ADO pipeline YAML orchestration and Terraform Cloud variable sourcing.

Thoughts on the cloud

Practical write-ups on Azure architecture, identity patterns, and platform engineering from the trenches.

☁️
Mar 20258 min read
Least-privilege Entra ID app secret rotation with custom RBAC roles
Why App Owner is too broad and how to scope secret management to exactly the permissions needed — with Terraform examples.
Read article →
🔧
Jan 202512 min read
Terraform state drift in Azure custom RBAC roles: a production post-mortem
How a 409 conflict from a renamed custom role turned into a lesson on Terraform import strategies and lifecycle ignore rules.
Read article →
📊
Nov 202410 min read
Bulk Log Analytics integration across Microsoft Fabric workspaces
A deep dive into the Power BI Admin API, the resourceId BadRequest gotcha, and how to audit LAW config across 24+ workspaces at once.
Read article →
Let's work together

Whether you need an Azure architect for a greenfield platform build, fractional consulting on identity and governance, or someone to review your IaC foundations — I'm open to conversations.