Azure

Enterprise architecture assessment: what it should produce

September 30, 2026

Anyone selling an enterprise architecture assessment should have to answer one question first: why not use the free ones? Microsoft publishes a shelf of assessment tools that cost nothing, take under an hour each, and cover a good deal of what a consultancy charges for. A buyer who has found them and then reads a proposal that pretends they do not exist has learned something useful about the firm that wrote it.

So this article starts there, with what the free tools give you and when they are genuinely enough. Then the harder part: what an enterprise architecture assessment has to add to be worth paying for.

Start with Microsoft’s free assessments

These exist, they are good, and you can run them this week:

The full set sits in Microsoft’s assessments library. If you have one workload, one clear owner, and a team that will act on a list, run the Well-Architected Review and spend the money elsewhere. That is not a reluctant admission. It is the correct answer often enough that it should be said first.

What the free tools actually are

Knowing what they are explains exactly where they stop.

They are questionnaires. Microsoft describes the Well-Architected Review as “a collection of questionnaires tied to the pillar checklists to evaluate your design choices”. Every output is derived from the answers somebody typed. Nothing inspects your subscriptions, reads your configuration or looks at what is running. The score is a reflection of what your team believes about the estate.

That matters for two reasons. The first is obvious: if the answers are wrong, the report is confidently wrong. The second is subtler and more common. The person filling in the questionnaire answers for the estate as designed, not as it drifted, and the gap between those two is usually the whole problem.

There is also a scope limit that is easy to miss. The Well-Architected Framework is scoped to a single workload. Microsoft says so directly, and points anyone assessing a portfolio of workloads through centralised controls at the Cloud Adoption Framework instead. So running the Well-Architected Review against “our Azure estate” is a category error: you either run it once per workload, or you are answering for an average that does not exist.

The frameworks, briefly, because proposals misquote them

Two Microsoft frameworks turn up in every architecture proposal, usually described loosely.

The Cloud Adoption Framework now organises Azure adoption into seven phases: Strategy, Plan, Ready, Adopt, Govern, Secure and Manage. The first four run in sequence; Govern, Secure and Manage run in parallel once you are operating. If a proposal still describes five phases with Secure folded into Govern, it was written against an older version.

The Well-Architected Framework has five pillars: Reliability, Security, Cost Optimization, Operational Excellence and Performance Efficiency. It now also carries a maturity model, five levels per pillar, which is more useful than a single score because it tells you what the next step is rather than only how far away the destination is. The levels run from establishing a foundation, through building workload assets and becoming production-ready, to learning from production and designing for change. Read against a real estate the levels work as a diagnostic rather than a grade, because they identify which pillar is lagging rather than averaging the estate into one number.

And on the question that comes up in every enterprise conversation: Microsoft’s own architect guidance recommends using the Well-Architected Framework together with established frameworks such as TOGAF, not instead of them. Anyone presenting that as a choice is selling a preference.

What a paid assessment has to add

If the free tools are questionnaires scoped to a workload, then a paid enterprise architecture assessment earns its fee in four places, and you should be able to see all four in a proposal.

Verifying the answers against the running estate. Reading the actual subscription layout, policy assignments, network topology and identity model, then comparing that to what the questionnaire said. In our experience this is where the surprises are, and it is the one thing a self-assessment structurally cannot do.

One example, because it is the shape this nearly always takes. A client’s Well-Architected Review answers recorded a defined recovery time objective and a tested failover. That is what the team believed, and it is what they typed. When we looked at the running estate, the failover had last been exercised before two of the current architecture’s components existed. Nobody had lied. The answer was true when someone first wrote it down, and no one had gone back to check whether it still was. The questionnaire captures what a team believes about its estate. The estate captures what is actually there. The gap between the two is usually where the risk is sitting.

Covering the estate, not one workload. Landing zone design areas, subscription boundaries, the governance model and the operating model across everything, which is Cloud Adoption Framework territory rather than Well-Architected territory. We have written separately about how subscription boundaries decide more than people expect, and about which landing zone accelerator path fits.

Replacing default assumptions with your numbers. Any business case built from a tool’s defaults is a template. The Azure Migrate business case is the clearest example, because Microsoft publishes exactly what it assumes when you have told it nothing: storage at $2 per GB per month, a 7% weighted average cost of capital, and $250 per server per year for security management, among others. Every one of those is meant to be replaced. A buyer should ask which assumptions were changed, to what, and on whose authority, and should treat a business case that still carries the defaults as an illustration rather than a case. The value is in substituting your contracted rates, your real cost of capital and your own support costs, and then showing how far the answer moved. How far is that? Far enough to change decisions, in our experience, and not a rounding error. We would rather put it that way than publish a percentage from one engagement dressed up as typical.

Sequencing. A free assessment gives you a prioritised list. It does not tell you what to do in which quarter, what depends on what, or which item is not worth doing at all given your constraints. That judgement is the deliverable.

Our position: buy the assessment for the estate, not the score

In our view an enterprise architecture assessment is worth buying when the question spans workloads, and is usually not worth buying when it does not.

One workload, one team, one owner: run the Well-Architected Review, act on the list, re-run it in six months. We would not charge for that, and we tell clients so. The moment the question involves several workloads, shared platform decisions, an operating model that nobody owns, or a business case that has to survive a finance review, the free tools stop being able to answer it, because they were not built to.

The corollary is worth stating plainly, since it cuts against our own interest. If a proposal for an architecture review reads like the output of a free questionnaire with a logo on it, it probably is one. Ask which parts came from looking at the estate, and ask to see the evidence for one finding. A firm that has actually looked will enjoy the question.

Where to start

Three steps, in order:

  1. Run the free assessments first, this week. They take an afternoon and they will sharpen the brief for anything you buy afterwards.
  2. Write down what they could not answer. Anything spanning two or more workloads, anything about who operates a control, anything where your team disagreed about the answer.
  3. Scope the paid work to that list, not to a framework. A fixed-fee review should name its deliverables against your questions.

Veratas runs a fixed-fee enterprise architecture review, and the first thing it does is check what your estate actually looks like against what the questionnaires said it does. For the platform work that usually follows, our Azure practice picks it up. If you have run the free assessments already and want to know whether anything is left worth paying for, talk to our team, and we will tell you if the answer is no.

Frequently asked questions

Is there a free alternative to a paid architecture review? Yes, several. Microsoft publishes the Azure Well-Architected Review, the Azure Landing Zone Review, the Cloud Adoption Strategy Evaluator and the Cloud Journey Tracker, among others. For a single workload with a clear owner, the Well-Architected Review is often all you need.

What does the Azure Well-Architected Review actually check? It is a questionnaire, not an inspection. Microsoft describes it as questionnaires tied to the pillar checklists, scoring the design choices you report against Reliability, Security, Cost Optimization, Operational Excellence and Performance Efficiency. It does not read your configuration.

Can we assess our whole Azure estate with the Well-Architected Framework? No. Microsoft scopes it to a single workload and directs portfolio-level assessment to the Cloud Adoption Framework. Running it once for a whole estate produces an average that describes nothing.

How many phases does the Cloud Adoption Framework have? Seven for Azure adoption: Strategy, Plan, Ready, Adopt, Govern, Secure and Manage. The first four are sequential and the last three run in parallel during operations.

Does Microsoft’s framework replace TOGAF? No. Microsoft’s own architect guidance recommends using the Well-Architected Framework alongside established frameworks such as TOGAF rather than choosing between them.

When is an enterprise architecture assessment worth paying for? When the question spans workloads, when shared platform or operating-model decisions are involved, or when a business case has to hold up under finance scrutiny with your own numbers rather than default assumptions.