Virtual data center: offloading your own data center to Azure virtual machines

For:
CIOs, CTOs, heads of infrastructure and IT managers deciding whether to expand their data center
Reading time:
6 min
Episode:
17 min

This episode is in Polish. Full Polish version with transcript

After you click, the video loads from YouTube (Google). Google may store data on your device and process it in the USA as well. More (PDF, in Polish) · Watch on YouTube

In brief

When your on-premises data center runs short of resources and the cost of expanding it is uncertain, you can offload it by moving some of your virtual machines to Azure. A virtual data center is a standardized, shared space in Azure where machines are built from templates that meet the same requirements as your data center. Development and test environments are probably a big win: when they shut down automatically outside working hours, you pay for their compute only while they run.

Key takeaways

  • A virtual data center treats Azure as a place for virtual machines (IaaS), not for PaaS or SaaS.
  • You split systems by business risk: less critical ones go to Azure, and critical ones stay in the on-premises data center.
  • Machines that run around the clock can use a savings plan or a reservation, depending on your needs. Windows Server and SQL Server licenses with active Software Assurance can, depending on their type, be used in the cloud through Azure Hybrid Benefit.
  • Decide how to respond to oversized machines: an alert to the owner, who downsizes them, or a more aggressive option in which the platform resizes them automatically or after prior notice.
  • You move existing machines with Azure Migrate, which requires downtime, or restore them from backup in Azure, if your tool supports this and you have a license for it.
  • The first step is a set of workshops: requirements, the network concept, and a check of whether the company already has Azure.

What a virtual data center is

The speakers point out that quotes for expanding an on-premises data center stay valid only briefly, and that prices have risen sharply in some places. Timing can be a problem too: whether an expansion can be done this year depends on the size of the order.

A virtual data center is a standardized landing zone in Azure where virtual machines are created automatically on shared subscriptions. The machines share subscription resources in one place instead of being scattered, which is meant to lower costs. The team gets simple guidelines on how to add another machine or move one from the on-premises data center, so it does not choose a service and a resource group for each machine.

The platform mirrors the requirements you apply on premises, including those from your security policies. It has several layers:

  • a set of subscriptions in the form of a landing zone,
  • a network that matches your on-premises segmentation, that is, the split into VLANs and zones,
  • governance: security policies, tags, budgets and alerts,
  • infrastructure as code (scripts or Terraform, depending on preference) and machine templates that install the same agents as on premises, e.g. for scanning, DLP or monitoring,
  • identity: the access model,
  • backup: native Azure Backup, Veeam (Protopia’s preference) or another vendor’s tool you already use, if it supports Azure.

The platform can also connect to a ticketing system. Teams then order machines themselves through forms (self-service).

Diagram: less critical and nonproduction machines move from the on-premises data center to a virtual data center in Azure. The virtual data center is a landing zone with shared subscriptions and five layers: a network that matches the on-premises segmentation into VLANs and zones, governance with policies, tags, budgets and alerts, infrastructure as code with machine templates, identity with the access model, and backup. Optionally, machines are ordered through forms in a ticketing system.
Diagram: virtual data center architecture.

Which systems to move to the cloud

You move less critical systems to the virtual data center: applications of lower business importance, back-office applications and nonproduction environments, meaning development and test. In this scenario the cloud is an extra source of compute that frees up resources in the on-premises data center.

The selection criterion is business risk. Łukasz Kałużny: “We don’t migrate everything, only what may be getting in our way, or what could free up local resources safely for the business, without much risk.” (translated)

How to match a pricing mechanism to a machine

You pay for the disk separately, even when the machine is off. The amounts in this section cover compute and do not include the disk.

Mechanisms that lower the cost of virtual machines in Azure
Mechanism For which machines Savings or effect
Automatic shutdown outside working hours (the machine runs, e.g. 8 a.m.–6 p.m.) Nonproduction: development, test 71% off the list price
Savings plan or reservation Noncritical, running 24 hours a day 45–61%, depending on the configuration
Azure Hybrid Benefit Windows Server and SQL Server with an active Software Assurance agreement A license bought for the on-premises environment can be used in the cloud, to an extent that depends on its type

A machine that is on only during working hours runs about 210 hours a month instead of an average of 730. Łukasz Kałużny: “We have a very mistaken belief that it has to run 24 hours a day.” (translated)

An example from the price list: compute for a popular machine with an Intel or AMD processor costs about 160–170 USD a month. With automatic shutdown, its cost drops to 46–51 USD.

Decision tree. If a machine does not have to run around the clock, it shuts down outside working hours and runs, e.g. 8 a.m.–6 p.m.: it runs about 210 hours instead of 730, and the cost of its compute is 71% lower than the list price. If it has to run around the clock, a savings plan or a reservation saves 45–61%. Machines with Windows Server or SQL Server covered by Software Assurance can also use their own license through Azure Hybrid Benefit, to an extent that depends on the license type. The disk is billed separately.
Diagram: which pricing mechanism for which machine.

How to keep costs in check after launch

Two layers keep costs in check, and both are built into the platform from day one. The first is the standard FinOps tooling in Azure: budgets and Azure Advisor. The second is a set of alerts and scripts that Protopia adds to the platform. The scripts regularly look for unused and oversized resources.

The speakers often come across machines sized for headroom, with unused CPU. In the milder response, an alert goes to the machine’s owner, who downsizes it. In the more aggressive one, if the organization agrees to it, the platform regularly checks usage metrics, e.g. every week. It then resizes machines automatically or after prior notice, according to the agreed policy.

An example policy: a machine gets 2 cores instead of 4, and the RAM stays the same. For one machine that runs around the clock, the cost drops from 177 to 117 USD.

How to move existing machines

You deploy new systems with scripts and templates as soon as the platform is built. Existing machines move in one of two ways:

  • Azure Migrate assesses machines from VMware, Hyper-V and other platforms, then converts and moves them. The migration requires downtime because the machine has to be transferred.
  • A backup tool that integrates with Azure, e.g. Veeam, restores the machine from an existing backup directly in the virtual data center. The tool must support this scenario, and you must have a license for it. This kind of migration is faster or, depending on the approach, runs without downtime.
Diagram of migration to a virtual data center. Machines from VMware, Hyper-V and other platforms reach Azure through Azure Migrate, which assesses, converts and moves them, and this requires downtime. The second path restores the machine from an existing backup, e.g. in Veeam, faster or with no downtime, if the tool supports it and you have a license. New systems are built right away from scripts and templates.
Diagram: two paths for migrating existing machines.

How the rollout works and how long it takes

Protopia estimates 4–8 weeks to build a working platform.

The platform build has three stages:

  1. Discovery in workshops: whether the company already has Azure, what the network concept looks like, what the requirements are and which approach to choose.
  2. Design: adapting Protopia’s standardized infrastructure as code to the company’s needs.
  3. Setup and configuration, the main phase: the subscription, the network, tests of the scripts and machine templates, and the rollout of the governance, identity and backup layers described above.

After these stages, you deploy new virtual machines on the platform. Migrations are a separate stage.

  1. Pilot migrations of the first machines.
  2. After successful pilots, migration of less critical systems at a larger scale.

Speakers

  • Łukasz Kałużny

    Łukasz Kałużny

    Founder, Managing Partner, Technology Advisor.

    Łukasz Kałużny co-founded Protopia and is a Microsoft MVP in the Microsoft Foundry category. He has co-hosted Patoarchitekci since 2019, talking about IT architecture, GenAI and AI agents without the marketing spin.

    All posts by this author
  • Mikołaj Szczerbicki

    Mikołaj Szczerbicki

    Head of Sales & Business Development.

    Mikołaj Szczerbicki is Head of Sales & Business Development at Protopia and co-hosts the Powered by Protopia podcast. He scopes and prices projects, so he asks about the cost, risk and timeline of AI, Azure and Kubernetes work.

    All posts by this author

FAQ

Do the same security rules apply in Azure as in our data center?

Network segmentation is the same, and the agents required on the machines, e.g. for scanning or DLP, are built into the template, so every new machine has them from the start.

Do we have to change our backup tool?

No, if your current tool supports Azure. If it can also restore machines in Azure and your license allows it, you can use it to migrate: you restore a machine from backup in the cloud faster than through Azure Migrate, and, depending on the approach, even without downtime.

Can the platform resize our machine without our consent?

Only if you accept an automatic resizing policy beforehand. Otherwise, the owner of an oversized machine gets an alert and downsizes it.