FORMAL TECHNICAL PROPOSAL
FOR INFRASTRUCTURE OVERHAUL
Secure hybrid-cloud engineering design and execution plan
Prepared for
NorthStar Services, Inc. Executive Leadership [Replace with official scenario company]
Prepared by
[Your Name] | External IT/Cloud Consultant
Course
Hybrid Cloud Infrastructure and Orchestration - E028
Date
August 6, 2026
This proposal continues the Task 1 planning assumptions. Replace bracketed fields and
SUBMISSION
all assumed company, workload, network, compliance, budget, and schedule details
NOTE
with the official scenario and rubric before submission.
,WGU E028 | Formal Technical Proposal
Proposal Basis and Engineering Decisions
Relationship to Task 1. Task 1 selected Nutanix Cloud Clusters (NC2) on Microsoft Azure as the hybrid
infrastructure tier, Azure Arc for unified representation and governance of eligible non-Azure servers, and a
staged migration strategy. Task 2 converts that strategy into an implementable technical design.
Authority boundary. CIDR blocks, ports, role assignments, recovery targets, retention periods, and
implementation dates below are proposed design values. Architecture, security, privacy/legal, application,
database, network, finance, and change authorities must approve them after discovery.
Key engineering decisions
Decision Selected design Reason and validation gate
Hybrid platform NC2 on Azure with Nutanix Prism; Azure Consistent infrastructure for compatible VMs plus Azure governance.
Arc for eligible on-premises servers Validate workload, version, instance, support, and license
compatibility.
Identity AD DS synchronized to Microsoft Entra Reduces authentication dependency while preserving a common
ID; password hash sync plus seamless identity. Validate tenant, forests, UPNs, source of authority, and
SSO unless policy requires federation compliance.
Connectivity Dual-path Azure ExpressRoute primary; Private predictable transport plus separately tested contingency.
route-based IPsec VPN backup Validate provider diversity, BGP, throughput, encryption
requirements, and SLA.
Network Hub-and-spoke Azure VNets with Azure Central inspection and tier isolation. Validate application flows before
Firewall, NSGs, private endpoints, and deny enforcement.
NC2-connected workload segments
Automation Azure Bicep modules in a protected CI/CD Azure-native declarative deployment, reviewable changes, and drift
pipeline; manual production GUI creation reduction.
prohibited
Governance Management groups, Policy initiatives, Preventive controls and traceable evidence at scale.
Defender for Cloud, tags, budgets, locks,
and exception workflow
Acceptance principle
No production workload is moved because the platform exists. Each wave must prove identity, connectivity,
security, performance, observability, backup/restore, cost, owner acceptance, and rollback readiness.
NorthStar Services, Inc. | Proposed values require validation against the official scenario Page 2
, WGU E028 | Formal Technical Proposal
1. Executive Summary and Scope Alignment
Purpose. NorthStar requires an infrastructure overhaul because aging on-premises capacity, slow hardware
procurement, geographically concentrated recovery, and fragmented administration constrain growth and
increase operational risk. This proposal implements the Task 1 hybrid strategy by extending the Nutanix
operating model into Microsoft Azure through NC2, onboarding eligible local servers to Azure Arc, and
enforcing a common control structure through Microsoft Entra ID, Azure Policy, Azure Monitor, and
infrastructure as code.
The design intentionally remains hybrid. Regulated, locality-sensitive, unsupported, or ultra-low-latency
workloads remain on the private Nutanix environment until placement approval. Development/test, elastic
web and application tiers, analytics, recovery copies, and approved production workloads move to NC2 on
Azure or selected Azure services. ExpressRoute supplies primary private connectivity; an IPsec VPN is tested
as backup. Hub-and-spoke segmentation and private service access limit exposure.
Engineering objectives
• Establish one governed identity plane while preserving AD DS services required by legacy applications.
• Eliminate routine standing privilege through dedicated administrator identities, PIM activation, MFA,
conditional access, and quarterly reviews.
• Implement deterministic hybrid routing, DNS, segmentation, inspection, logging, and failover with
documented permitted flows.
• Provision the landing zone, controls, and workload patterns from peer-reviewed Bicep modules; detect and
remediate drift.
• Migrate stateful and stateless services in small dependency-aware waves with measurable validation and a
timed rollback path.
• Retire legacy systems only after stabilization, recovery validation, retention approval, secure erasure, and
asset disposition evidence.
Scope boundaries
In scope Out of scope / later design
Azure landing zone; NC2 connectivity and governance; identity Application source-code refactoring; final provider contract;
synchronization; privileged access; hub/spoke network; DNS; final bill of materials; exact regulatory legal opinion; production
firewall/NSGs; Bicep pipeline; tagging and Policy; monitoring; credentials; detailed database-engine commands; physical
migration/rollback; decommissioning. cabling; user endpoint replacement.
Deliverable outcome A technically controlled implementation plan and acceptance
model, not authorization to execute production changes.
Proposed success thresholds
Control objective Threshold before production authorization
Inventory and ownership 100% of in-scope resources have owner, environment, cost center, data classification, criticality,
and lifecycle state.
Identity 100% privileged actions use dedicated admin identity, MFA, and PIM/JIT; zero standard email
accounts hold privileged production roles.
Network All required flows tested; unauthorized east-west and internet paths denied; ExpressRoute/VPN
failover demonstrated.
Security No unresolved critical vulnerability or policy denial; >=95% evaluated policy compliance with
approved exceptions only.
Operations 100% required logs/metrics and alerts received; backup restore and runbook exercises pass.
Performance Application-specific latency, error, throughput, RTO, and RPO thresholds met during stabilization.
NorthStar Services, Inc. | Proposed values require validation against the official scenario Page 3
FOR INFRASTRUCTURE OVERHAUL
Secure hybrid-cloud engineering design and execution plan
Prepared for
NorthStar Services, Inc. Executive Leadership [Replace with official scenario company]
Prepared by
[Your Name] | External IT/Cloud Consultant
Course
Hybrid Cloud Infrastructure and Orchestration - E028
Date
August 6, 2026
This proposal continues the Task 1 planning assumptions. Replace bracketed fields and
SUBMISSION
all assumed company, workload, network, compliance, budget, and schedule details
NOTE
with the official scenario and rubric before submission.
,WGU E028 | Formal Technical Proposal
Proposal Basis and Engineering Decisions
Relationship to Task 1. Task 1 selected Nutanix Cloud Clusters (NC2) on Microsoft Azure as the hybrid
infrastructure tier, Azure Arc for unified representation and governance of eligible non-Azure servers, and a
staged migration strategy. Task 2 converts that strategy into an implementable technical design.
Authority boundary. CIDR blocks, ports, role assignments, recovery targets, retention periods, and
implementation dates below are proposed design values. Architecture, security, privacy/legal, application,
database, network, finance, and change authorities must approve them after discovery.
Key engineering decisions
Decision Selected design Reason and validation gate
Hybrid platform NC2 on Azure with Nutanix Prism; Azure Consistent infrastructure for compatible VMs plus Azure governance.
Arc for eligible on-premises servers Validate workload, version, instance, support, and license
compatibility.
Identity AD DS synchronized to Microsoft Entra Reduces authentication dependency while preserving a common
ID; password hash sync plus seamless identity. Validate tenant, forests, UPNs, source of authority, and
SSO unless policy requires federation compliance.
Connectivity Dual-path Azure ExpressRoute primary; Private predictable transport plus separately tested contingency.
route-based IPsec VPN backup Validate provider diversity, BGP, throughput, encryption
requirements, and SLA.
Network Hub-and-spoke Azure VNets with Azure Central inspection and tier isolation. Validate application flows before
Firewall, NSGs, private endpoints, and deny enforcement.
NC2-connected workload segments
Automation Azure Bicep modules in a protected CI/CD Azure-native declarative deployment, reviewable changes, and drift
pipeline; manual production GUI creation reduction.
prohibited
Governance Management groups, Policy initiatives, Preventive controls and traceable evidence at scale.
Defender for Cloud, tags, budgets, locks,
and exception workflow
Acceptance principle
No production workload is moved because the platform exists. Each wave must prove identity, connectivity,
security, performance, observability, backup/restore, cost, owner acceptance, and rollback readiness.
NorthStar Services, Inc. | Proposed values require validation against the official scenario Page 2
, WGU E028 | Formal Technical Proposal
1. Executive Summary and Scope Alignment
Purpose. NorthStar requires an infrastructure overhaul because aging on-premises capacity, slow hardware
procurement, geographically concentrated recovery, and fragmented administration constrain growth and
increase operational risk. This proposal implements the Task 1 hybrid strategy by extending the Nutanix
operating model into Microsoft Azure through NC2, onboarding eligible local servers to Azure Arc, and
enforcing a common control structure through Microsoft Entra ID, Azure Policy, Azure Monitor, and
infrastructure as code.
The design intentionally remains hybrid. Regulated, locality-sensitive, unsupported, or ultra-low-latency
workloads remain on the private Nutanix environment until placement approval. Development/test, elastic
web and application tiers, analytics, recovery copies, and approved production workloads move to NC2 on
Azure or selected Azure services. ExpressRoute supplies primary private connectivity; an IPsec VPN is tested
as backup. Hub-and-spoke segmentation and private service access limit exposure.
Engineering objectives
• Establish one governed identity plane while preserving AD DS services required by legacy applications.
• Eliminate routine standing privilege through dedicated administrator identities, PIM activation, MFA,
conditional access, and quarterly reviews.
• Implement deterministic hybrid routing, DNS, segmentation, inspection, logging, and failover with
documented permitted flows.
• Provision the landing zone, controls, and workload patterns from peer-reviewed Bicep modules; detect and
remediate drift.
• Migrate stateful and stateless services in small dependency-aware waves with measurable validation and a
timed rollback path.
• Retire legacy systems only after stabilization, recovery validation, retention approval, secure erasure, and
asset disposition evidence.
Scope boundaries
In scope Out of scope / later design
Azure landing zone; NC2 connectivity and governance; identity Application source-code refactoring; final provider contract;
synchronization; privileged access; hub/spoke network; DNS; final bill of materials; exact regulatory legal opinion; production
firewall/NSGs; Bicep pipeline; tagging and Policy; monitoring; credentials; detailed database-engine commands; physical
migration/rollback; decommissioning. cabling; user endpoint replacement.
Deliverable outcome A technically controlled implementation plan and acceptance
model, not authorization to execute production changes.
Proposed success thresholds
Control objective Threshold before production authorization
Inventory and ownership 100% of in-scope resources have owner, environment, cost center, data classification, criticality,
and lifecycle state.
Identity 100% privileged actions use dedicated admin identity, MFA, and PIM/JIT; zero standard email
accounts hold privileged production roles.
Network All required flows tested; unauthorized east-west and internet paths denied; ExpressRoute/VPN
failover demonstrated.
Security No unresolved critical vulnerability or policy denial; >=95% evaluated policy compliance with
approved exceptions only.
Operations 100% required logs/metrics and alerts received; backup restore and runbook exercises pass.
Performance Application-specific latency, error, throughput, RTO, and RPO thresholds met during stabilization.
NorthStar Services, Inc. | Proposed values require validation against the official scenario Page 3