Cloud Migration & Modernization · Case study

Enterprise ERP Migration
to Microsoft Azure.

Modernizing an on-premises ERP platform through a phased Azure migration.

Executive summary

Context, direction, and delivery.

An organization operating a business-critical ERP platform needed to reduce its dependency on traditional on-premises infrastructure without placing production continuity at unnecessary risk.

The engineering team used a phased migration approach: assess the estate, establish the Azure foundation, rehost suitable Windows workloads, migrate and validate data, prove the application in staging, and then execute a controlled production cutover.

Business challenge

Modernisation without unnecessary disruption.

The existing operating model depended on physical infrastructure, local power and cooling, hardware maintenance, and available on-premises capacity.

The migration needed to preserve the ERP application’s dependencies across Windows Server, IIS, SQL Server, identity, networking, DNS, and storage while supporting remote access and business-continuity requirements.

Production was not moved immediately. The delivery approach was deliberately phased to create evidence and reduce disruption before cutover.

Existing environment

The operating baseline.

  • Windows Server virtual machines
  • IIS-hosted ERP and application workloads
  • Microsoft SQL Server
  • SAN and RAID-based storage
  • Active Directory
  • Firewall and WAN connectivity
  • Separate staging and production environments

Assessment & discovery

Evidence before investment decisions.

  • Application and infrastructure inventory
  • Dependency mapping across virtual machines, SQL, DNS, network, and storage
  • Security, performance-baseline, backup, and continuity requirements
  • Migration sequencing and staging-validation plan

Target Azure architecture

A controlled target state.

The target Azure architecture was designed around security, recoverability, operational visibility, and room for future scale. Optional services were included only where approved for the workload.

  • Azure landing-zone and resource foundation
  • Virtual Network and application segmentation
  • Network security groups and firewall controls where required
  • Azure Virtual Machines with Managed Disks
  • Storage Accounts and approved SQL migration capabilities
  • Azure Key Vault
  • Azure Backup and Recovery Services Vault
  • Azure Monitor and Log Analytics
  • DNS and load balancing where required
  • Azure Site Recovery where approved and implemented
On-premises to Azure migration architecture
On-premises
Users
Firewall / WAN
Windows Server / IIS ERP
SQL Server
SAN / RAID storage
Migration
Assessment
Replication / migration
Staging validation
Production cutover
Azure
Users
Network / security layer
Azure VM / IIS ERP
SQL / data layer
Managed Disks / Storage
Key VaultAzure BackupRecovery Services VaultAzure MonitorLog AnalyticsSite Recovery where applicable

Migration approach

Sequenced for evidence
and control.

  1. 01

    Discovery & assessment

    Inventory the ERP estate and map application, database, network, identity, and storage dependencies.

  2. 02

    Azure foundation

    Prepare resource organization, networking, security, storage, monitoring, and backup foundations.

  3. 03

    VM rehosting

    Replicate or rehost suitable Windows Server workloads while maintaining application dependencies.

  4. 04

    SQL & data migration

    Assess compatibility, verify backups, migrate data, validate integrity, update connections, and validate performance.

  5. 05

    Application & IIS configuration

    Configure IIS, application services, DNS, TLS, dependencies, and network connectivity.

  6. 06

    Staging validation

    Complete application, database, user-acceptance, security, performance, backup, recovery, and applicable DR validation.

  7. 07

    Production cutover

    Complete final synchronization, database cutover, endpoint updates, application and user validation, monitoring, and hypercare.

Security & governance

Control built into the approach.

  • Network and application segmentation
  • Approved firewall and NSG controls
  • Secrets and certificate handling through Key Vault where applicable
  • Backup governance and recovery evidence
  • Centralized monitoring and operational visibility
  • Controlled staging validation before production change

Business continuity & recovery

Recovery remains an operational capability.

Azure Backup and Recovery Services Vault simplified centralized backup management and recovery planning.

Azure Monitor and Log Analytics improved operational visibility across the migrated environment.

Azure Site Recovery was considered where approved and implemented; no unverified recovery-time or recovery-point claims are published.

The target model reduced reliance on individual on-premises hardware, while documented procedures and validation remained essential to dependable recovery.

Outcomes

Qualitative, evidence-based outcomes.

  • Reduced dependency on physical hardware, local power, and cooling infrastructure
  • Improved availability and disaster-recovery readiness
  • Centralized monitoring and simplified backup management
  • Faster infrastructure provisioning and improved scalability
  • Stronger security capabilities and improved support for remote users
  • Reduced operational risk through phased validation and controlled cutover

Technology stack

Platforms and capabilities.

Microsoft AzureWindows ServerIISMicrosoft SQL ServerAzure Virtual MachinesAzure Managed DisksAzure StorageAzure networking and DNSAzure Key VaultAzure BackupRecovery Services VaultAzure MonitorLog AnalyticsLoad balancing where requiredAzure Site Recovery where approved

Lessons learned

What made the work dependable.

  • Dependency discovery is as important as workload inventory for ERP migration.
  • A staging-first approach gives application, database, security, and operational teams evidence before production cutover.
  • Backup configuration is not enough: restoration and recovery expectations must be validated.
  • Cutover planning should integrate data synchronization, DNS, monitoring, user validation, and hypercare as one controlled sequence.

A relevant priority?

Discuss a similar challenge
with Meynkern.