Identify layer - Physical host/storage network, cloud deployment connectivity, SDN fabric, tenant/workload networking, or VM/AKS workload networking.
Load current docs - Use docs-map for physical network requirements, network reference patterns, SDN overview, private endpoints, and firewall/proxy guidance.
Collect topology - Node count, storage switchless/switched design, converged/non-converged adapters, VLANs, IP ranges, DNS, gateways, proxy, and firewall requirements.
Validate support - Confirm the selected topology is supported for portal or ARM deployment.
Plan changes - For SDN/NSG/load balancer/gateway changes, map dependent workloads and rollback requirements before making changes.
Apply with confirmation - Network changes can interrupt management or workloads. Ask before applying changes.
Start from secure defaults - Azure Local is secure by default with a baseline of security settings. Do not disable baseline controls without an explicit reason.
Map governance - Confirm Azure Policy, Defender for Cloud, Azure Monitor, RBAC, identity, and compliance requirements.
Check secrets and certificates - For private endpoints, SDN, and local identity scenarios, verify certificate and Key Vault requirements from docs.
Apply least privilege - Use Azure RBAC and Azure Local-specific roles for VM/workload administration.
Document exceptions - Any security exception must include reason, scope, owner, and validation plan.