Skip to content

Platforms · Microsoft Azure Engineering

Microsoft Azure engineering built for Canadian workloads

We design, migrate and run Azure environments that fit how your organisation already works: Entra ID for sign in, Microsoft 365 alongside it, Canadian regions for data residency, and pipelines that ship changes without drama.

You own the code and IP Weekly demos Reply within one business day

infra · ci/cd

$oldevs deploy --env production

Build passed · 212 tests · 0 warnings

Migrations applied · postgres 16

API v2 healthy · 142ms p95

Rolling out to 3 regions…

API
Postgres
Redis
K8s

Microsoft Azure Engineering, in short

OlDevs is a full-stack technology studio in Vancouver, British Columbia that builds and operates Microsoft Azure environments for corporations, public sector bodies, franchises and startups.We work across App Service, Azure Functions, Azure SQL Database, Azure Database for PostgreSQL, Blob Storage, Azure Front Door, Microsoft Entra ID and Azure DevOps Pipelines. We handle lift and shift migrations, hybrid setups that keep some systems on premises, and greenfield builds deployed to the Canada Central and Canada East regions where data residency matters. One accountable team runs the work, you see a working demo every week, and you own all code, designs, accounts and IP.

Key facts

01Platform
Microsoft Azure, current at the time of writing
02Canadian regions
Canada Central and Canada East for data residency
03Identity
Microsoft Entra ID, single sign on, conditional access
04Delivery
Azure DevOps Pipelines or GitHub Actions, infrastructure as code
05Ownership
You own the subscription, the code, the designs and the IP
06Studio
Vancouver, British Columbia, building since 2014

Platform expertise

What we build and run on Azure

01

App Service and Azure Functions

Web apps, APIs and background jobs on Azure App Service and Azure Functions, with deployment slots for safe releases, autoscale rules tied to real traffic, managed identities instead of stored secrets, and private networking where the security review calls for it.

App Service · Functions · Autoscale

02

Azure SQL, PostgreSQL and Blob Storage

Azure SQL Database, Azure SQL Managed Instance and Azure Database for PostgreSQL flexible server, sized against your query patterns rather than a guess, plus Blob Storage tiers for documents, media and archives with lifecycle rules that keep storage honest.

Azure SQL · PostgreSQL · Blob Storage

03

Front Door, CDN and edge delivery

Azure Front Door and Azure CDN in front of your applications for global routing, TLS termination, caching and web application firewall rules. We tune cache behaviour per route so static assets fly and authenticated pages stay private and correct.

Front Door · CDN · WAF

04

Entra ID and Microsoft 365 integration

Microsoft Entra ID for single sign on, app registrations, role based access and conditional access policies. We connect custom applications to the Microsoft 365 estate you already run, reading and writing SharePoint, Teams and calendar data through Microsoft Graph.

Entra ID · SSO · Microsoft Graph

05

Azure DevOps pipelines and IaC

Build and release pipelines in Azure DevOps or GitHub Actions, with environments, approvals and automated tests. Infrastructure is defined in Bicep or Terraform and reviewed like any other code, so a rebuild is a pipeline run instead of an afternoon of clicking.

Azure DevOps · Bicep · Terraform

06

Monitoring, cost control and recovery

Azure Monitor, Log Analytics and Application Insights wired to alerts people actually act on. Azure Policy and Microsoft Cost Management keep spend and configuration in line, and Azure Backup with tested restore steps covers the day something goes wrong.

Azure Monitor · Cost Management · Azure Backup

Process

The engagement, step by step

  1. Discovery

    We map workloads, data, identity, compliance obligations and the Microsoft 365 estate, then agree what success looks like and what stays out of scope.

  2. Architecture and plan

    You get a written architecture, a region and residency decision, a migration or build sequence, and a risk list with mitigations. Nothing starts until you approve it.

  3. Build in weekly slices

    One accountable team builds in short cycles with a working demo every week, so you see the landing zone, the pipeline and the first workload land in order.

  4. Migrate and cut over

    We rehearse the cutover, run a dry migration, measure the real downtime window, and keep a documented rollback path ready before we move production traffic.

  5. Operate and improve

    After go live we watch monitoring and cost together, tune scaling and storage tiers, test restores, and plan the next increment against what the data shows.

How we work

How we approach an Azure engagement

01

Start with the estate you have

Before we propose anything we inventory what is running: servers, databases, licences, identity, network paths and the Microsoft 365 tenant. Azure Migrate assessments and a short discovery workshop give us dependencies rather than assumptions.

02

Choose the right landing spot per workload

Some applications belong on App Service, some in containers on Azure Container Apps or Kubernetes Service, some stay on virtual machines for a while. We recommend per workload and say plainly when rehosting first is the sensible move.

03

Design for Canadian data residency

Where residency is a requirement we place data and compute in Canada Central and Canada East, document where every copy lives including backups and logs, and configure private endpoints so traffic stays off the public internet.

04

Make identity the first build

Entra ID groups, app registrations and conditional access come early, not last. Staff sign in with the accounts they already have, permissions map to real roles, and administrative access is scoped and reviewable from day one.

05

Automate the path to production

Every environment is built from code and deployed by pipeline. That makes a staging environment cheap to recreate, rollbacks predictable, and a security patch a change request rather than a scramble across a dozen portals.

06

Hand over so your team can drive

You keep the subscription, the repositories and the pipelines. We write runbooks for the routine tasks, record walkthroughs, and stay available for support or the next phase, with a reply to every enquiry within one business day.

Who it's for

Microsoft Azure Engineering for organisations that have to get it right.

Corporations

Enterprises already standardised on Microsoft 365 and Entra ID that need custom applications, integrations and data platforms built to the same identity, security and change control rules as the rest of the estate.

Associations and government

Public sector bodies, agencies and member associations with procurement processes, accessibility duties and data residency requirements. We build to WCAG 2.2 AA and can deliver in English and French.

Franchises

Multi location brands that need one Azure platform serving head office and every franchisee: shared identity, per location data separation, reporting that rolls up, and rollouts that do not need a technician in each site.

Entrepreneurs and startups

Founders who want an Azure footprint that starts small and grows: serverless and managed services first, costs visible from week one, and an architecture that will not need a rewrite at the first serious traffic.

1 week

Working demo cadence

2

Canadian regions in scope

1 day

Reply to every enquiry

FAQ

Microsoft Azure Engineering — questions we hear first.

Yes. Azure offers the Canada Central and Canada East regions, and we can place compute, databases, storage, backups and log data in them. We document where every copy lives, including replicas and diagnostic data, so your privacy team has a clear answer for an assessment or an audit.

No. Most engagements run as a sequence. We often rehost the workloads with the least coupling first, keep sensitive systems on premises for a period, and connect the two with site to site VPN, ExpressRoute or Azure Arc. You approve each wave before it starts.

We use Microsoft Entra ID, the identity service behind Microsoft 365. Staff sign in with existing work accounts, permissions map to Entra groups, and conditional access policies apply multi factor rules. Custom applications register as Entra apps rather than keeping separate passwords.

That is usually the point. Through Microsoft Graph and the Microsoft 365 connectors we read and write SharePoint documents, Teams messages, calendars and directory data, and we can trigger Power Automate flows. Your custom app becomes part of the estate people already use every day.

We size resources against measured load, prefer consumption and serverless options where the pattern suits, apply lifecycle rules on storage, and tag everything so spend maps to a team or project. Microsoft Cost Management budgets and alerts are set up before go live, not after the first surprise.

We do not claim partner status, certifications or awards on this page. What we offer is a Vancouver studio that has built and run production Azure workloads since 2014, one accountable team on your project, and references we can discuss with you directly when you request a quote.

You own everything from the start: the Azure subscription, the repositories, the pipelines, the infrastructure code, the designs and the IP. Nothing sits in an OlDevs account. Any competent engineering team can read the Bicep or Terraform and take over without a rebuild.

Still have a question? Ask us when you request a quote

Let’s connect

Let’s scope your microsoft azure engineering project.

Tell us what you’re building. We’ll reply within one business day with next steps and a tailored quote — no obligation.

We’ll only use your details to prepare your quote. No lists, no spam.

Call us Request a quote