Virtual data center: offloading your own data center to Azure virtual machines
- For:
- CIOs, CTOs, heads of infrastructure and IT managers deciding whether to expand their data center
- Reading time:
- 6 min
- Episode:
- 17 min
This episode is in Polish. Full Polish version with transcript
After you click, the video loads from YouTube (Google). Google may store data on your device and process it in the USA as well. More (PDF, in Polish) · Watch on YouTube
In brief
When your on-premises data center runs short of resources and the cost of expanding it is uncertain, you can offload it by moving some of your virtual machines to Azure. A virtual data center is a standardized, shared space in Azure where machines are built from templates that meet the same requirements as your data center. Development and test environments are probably a big win: when they shut down automatically outside working hours, you pay for their compute only while they run.
Key takeaways
- A virtual data center treats Azure as a place for virtual machines (IaaS), not for PaaS or SaaS.
- You split systems by business risk: less critical ones go to Azure, and critical ones stay in the on-premises data center.
- Machines that run around the clock can use a savings plan or a reservation, depending on your needs. Windows Server and SQL Server licenses with active Software Assurance can, depending on their type, be used in the cloud through Azure Hybrid Benefit.
- Decide how to respond to oversized machines: an alert to the owner, who downsizes them, or a more aggressive option in which the platform resizes them automatically or after prior notice.
- You move existing machines with Azure Migrate, which requires downtime, or restore them from backup in Azure, if your tool supports this and you have a license for it.
- The first step is a set of workshops: requirements, the network concept, and a check of whether the company already has Azure.
What a virtual data center is
The speakers point out that quotes for expanding an on-premises data center stay valid only briefly, and that prices have risen sharply in some places. Timing can be a problem too: whether an expansion can be done this year depends on the size of the order.
A virtual data center is a standardized landing zone in Azure where virtual machines are created automatically on shared subscriptions. The machines share subscription resources in one place instead of being scattered, which is meant to lower costs. The team gets simple guidelines on how to add another machine or move one from the on-premises data center, so it does not choose a service and a resource group for each machine.
The platform mirrors the requirements you apply on premises, including those from your security policies. It has several layers:
- a set of subscriptions in the form of a landing zone,
- a network that matches your on-premises segmentation, that is, the split into VLANs and zones,
- governance: security policies, tags, budgets and alerts,
- infrastructure as code (scripts or Terraform, depending on preference) and machine templates that install the same agents as on premises, e.g. for scanning, DLP or monitoring,
- identity: the access model,
- backup: native Azure Backup, Veeam (Protopia’s preference) or another vendor’s tool you already use, if it supports Azure.
The platform can also connect to a ticketing system. Teams then order machines themselves through forms (self-service).

Which systems to move to the cloud
You move less critical systems to the virtual data center: applications of lower business importance, back-office applications and nonproduction environments, meaning development and test. In this scenario the cloud is an extra source of compute that frees up resources in the on-premises data center.
The selection criterion is business risk. Łukasz Kałużny: “We don’t migrate everything, only what may be getting in our way, or what could free up local resources safely for the business, without much risk.” (translated)
How to match a pricing mechanism to a machine
You pay for the disk separately, even when the machine is off. The amounts in this section cover compute and do not include the disk.
| Mechanism | For which machines | Savings or effect |
|---|---|---|
| Automatic shutdown outside working hours (the machine runs, e.g. 8 a.m.–6 p.m.) | Nonproduction: development, test | 71% off the list price |
| Savings plan or reservation | Noncritical, running 24 hours a day | 45–61%, depending on the configuration |
| Azure Hybrid Benefit | Windows Server and SQL Server with an active Software Assurance agreement | A license bought for the on-premises environment can be used in the cloud, to an extent that depends on its type |
A machine that is on only during working hours runs about 210 hours a month instead of an average of 730. Łukasz Kałużny: “We have a very mistaken belief that it has to run 24 hours a day.” (translated)
An example from the price list: compute for a popular machine with an Intel or AMD processor costs about 160–170 USD a month. With automatic shutdown, its cost drops to 46–51 USD.

How to keep costs in check after launch
Two layers keep costs in check, and both are built into the platform from day one. The first is the standard FinOps tooling in Azure: budgets and Azure Advisor. The second is a set of alerts and scripts that Protopia adds to the platform. The scripts regularly look for unused and oversized resources.
The speakers often come across machines sized for headroom, with unused CPU. In the milder response, an alert goes to the machine’s owner, who downsizes it. In the more aggressive one, if the organization agrees to it, the platform regularly checks usage metrics, e.g. every week. It then resizes machines automatically or after prior notice, according to the agreed policy.
An example policy: a machine gets 2 cores instead of 4, and the RAM stays the same. For one machine that runs around the clock, the cost drops from 177 to 117 USD.
How to move existing machines
You deploy new systems with scripts and templates as soon as the platform is built. Existing machines move in one of two ways:
- Azure Migrate assesses machines from VMware, Hyper-V and other platforms, then converts and moves them. The migration requires downtime because the machine has to be transferred.
- A backup tool that integrates with Azure, e.g. Veeam, restores the machine from an existing backup directly in the virtual data center. The tool must support this scenario, and you must have a license for it. This kind of migration is faster or, depending on the approach, runs without downtime.

How the rollout works and how long it takes
Protopia estimates 4–8 weeks to build a working platform.
The platform build has three stages:
- Discovery in workshops: whether the company already has Azure, what the network concept looks like, what the requirements are and which approach to choose.
- Design: adapting Protopia’s standardized infrastructure as code to the company’s needs.
- Setup and configuration, the main phase: the subscription, the network, tests of the scripts and machine templates, and the rollout of the governance, identity and backup layers described above.
After these stages, you deploy new virtual machines on the platform. Migrations are a separate stage.
- Pilot migrations of the first machines.
- After successful pilots, migration of less critical systems at a larger scale.
Speakers

Łukasz Kałużny
Founder, Managing Partner, Technology Advisor.
Łukasz Kałużny co-founded Protopia and is a Microsoft MVP in the Microsoft Foundry category. He has co-hosted Patoarchitekci since 2019, talking about IT architecture, GenAI and AI agents without the marketing spin.
All posts by this author
Mikołaj Szczerbicki
Head of Sales & Business Development.
Mikołaj Szczerbicki is Head of Sales & Business Development at Protopia and co-hosts the Powered by Protopia podcast. He scopes and prices projects, so he asks about the cost, risk and timeline of AI, Azure and Kubernetes work.
All posts by this author
FAQ
Do the same security rules apply in Azure as in our data center?
Network segmentation is the same, and the agents required on the machines, e.g. for scanning or DLP, are built into the template, so every new machine has them from the start.
Do we have to change our backup tool?
No, if your current tool supports Azure. If it can also restore machines in Azure and your license allows it, you can use it to migrate: you restore a machine from backup in the cloud faster than through Azure Migrate, and, depending on the approach, even without downtime.
Can the platform resize our machine without our consent?
Only if you accept an automatic resizing policy beforehand. Otherwise, the owner of an oversized machine gets an alert and downsizes it.

