
By Nathan Heptinstall, Head of Cloud Delivery at ANS
Moving workloads to Azure is often presented as modernisation, but it is only the beginning.
Rehosting an application on an Azure virtual machine can remove an ageing data centre and improve access to capacity. But if the application and operating procedures remain unchanged, we have moved infrastructure without changing business capability.
A cloud programme should help the organisation release value faster, withstand disruption and use its people and investment better.
Why Azure cloud modernisation matters.
Technology complexity has a direct commercial cost.
A release that takes weeks to organise delays customer value. A maintenance window interrupts sales or service. An application that slows under pressure damages confidence. A failure in an internal system prevents people from working.
The cost is also strategic.
When engineers spend time patching servers, maintaining bespoke integrations or recovering from predictable failures, the organisation loses capacity to improve its products and respond to opportunity.
Cloud modernisation is therefore an operating-model decision, not a technology upgrade for its own sake.
Every workload creates responsibilities for infrastructure, security, deployment, resilience, data protection, monitoring and cost.
Some differentiate the business. Many do not. The strategic question is whether the organisation should continue to own those responsibilities when a reliable managed service can do more of the work.
The goal is not to rewrite everything or adopt the newest platform. It is to move responsibility deliberately, where doing so improves performance, reduces risk or accelerates change, while retaining ownership of the capabilities that genuinely differentiate the business.
That platform should also make the next stage of change easier.
A well-modernised cloud estate gives the organisation a foundation for better data, more automation and practical AI, without treating any of them as separate technology programmes.
Modernisation is a choice, not a sequence.
Modernisation is not a fixed sequence in which every workload should end up on containers. It is a set of choices.
The right option depends on the risk and complexity of change, the benefit available and the capabilities the organisation wants to retain. One application may need a lower change move to a managed service; another may justify redesigning how it runs and scales.
Improve Azure resilience without redesign.
For applications that still need virtual machines, Azure Virtual Machine Scale Sets run workloads across consistent machines, distribute traffic and add capacity as demand changes, with instances spread across availability zones for resilience.
But VM Scale Sets are not a managed application platform.
The organisation still owns patching, image management, application updates, security, monitoring and recovery. They improve consistency and availability without removing operational responsibility.
Move to a managed application platform.
For suitable web applications and APIs, Azure App Service can take over much of the hosting responsibility. The team remains accountable for the application, data and security, while Azure manages more of the platform. This could be a straightforward move to a Windows or Linux plan, or a larger change to how the application is deployed and scaled.
Deployment slots, scaling and deployment integration can reduce the lead time and risk of change.
Managed Instance on App Service is one lower-change route for legacy Windows applications that need compatibility with COM components, registry settings, MSI installers or specialised IIS configuration.
It reduces virtual-machine administration without an immediate rewrite.
Choose the right data platform.
For suitable SQL Server workloads, Azure SQL Managed Instance provides a lower-change path to a managed database service, with Azure handling patching, backups and built-in high availability.
Other workloads may suit Azure SQL Database, Cosmos DB, HorizonDB or another fit-for-purpose data service, particularly where the application can use cloud-native scale, availability or data models.
This can improve resilience and reduce administration without forcing an immediate redesign. Assess compatibility, performance, security, licensing and recovery.
Managed doesn’t mean responsibility-free.
Modernise applications with containers.
For many organisations, containers are an attractive next step because they package an application and its dependencies into a consistent, replaceable unit. They can improve software delivery, portability, and recovery without requiring every application to be rewritten.
They will not suit every workload, but Azure makes the move easier than it has ever been.
Azure Container Apps can reduce the operational burden of running containerised workloads, while AKS provides greater control where Kubernetes is required. Health checks, scaling, traffic management and automated replacement help teams manage day-two operations, while retaining a path to deeper control where the workload needs it.
That consistency supports self-healing, faster recovery and less disruption.
Containers can also improve resource efficiency. Image provenance, vulnerabilities, secrets and network access will still require governance.
Smaller services can be released, scaled and recovered independently. The objective is software that is consistent, quickly recoverable, efficient, secure and faster to change.
Cloud modernisation beyond the application.
Moving an application to a managed platform is only part of modernisation. The surrounding capabilities determine whether it is secure, supportable and able to evolve.
Start with identity, security and visibility. Establish access to the application, data and operational controls, remove unnecessary credentials and make health, performance and customer impact visible.
Services such as Microsoft Entra ID, Key Vault, Defender for Cloud and Azure Monitor provide the foundation, but do not replace decisions about risk, ownership and accountability.
Consider how the application communicates with the organisation.
Event Hubs supports high-volume event streaming, while Service Bus supports reliable business messaging. These patterns can let teams change one service without putting the whole customer journey at risk.
Automate the response where patterns are understood. Deployment pipelines, policy enforcement, alert routing, remediation and routine data movement should be repeatable and auditable.
Cost needs the same discipline.
Budgets, tagging, ownership and FinOps make consumption visible, helping organisations assess total cost, resilience, licensing and capacity.
Finally, assess where to consume rather than build. SaaS products such as Microsoft 365 and Dynamics 365, Azure platform services and governed AI capabilities can provide value without creating another platform to own. Ask whether the capability differentiates the business or should be consumed.
Turn cloud migration into lasting business value.
Cloud modernisation in Azure is a leadership decision about focus.
Virtual machines may be the correct starting point, but they should prompt a further question: what work is the technology team doing that Azure can reliably take on?
The answer will differ by workload.
Some applications will remain on VMs, others will move to managed platforms or containers. Supporting capabilities in security, messaging, observability, cost management and AI may be just as important as the application move itself.
Cloud is most valuable when it becomes the enterprise platform that enables the organisation’s AI, data and application strategy.
Modernisation is how that platform earns its place: by reducing avoidable operational effort, making trusted data more usable and creating the conditions for automation and AI to deliver measurable value.
The outcome we should pursue is an organisation that can adapt faster, recover more confidently and invest more of its engineering capacity in customer and business value.
That is the point at which cloud investment becomes competitive advantage.

