Servers and Cloud

Azure and AWS Setup, Configuration and Migration

We open your Azure or AWS account in your company’s name and under your ownership, put the network, identity, security and cost rules in place from day one, and migrate your servers on a planned schedule.

CybUP TeamLast updated: 6 min read

In short

Azure and AWS setup means opening a company’s cloud subscription or account, building the foundation (landing zone) where network, identity, security and cost rules are defined, and migrating on-premises servers to the cloud. It is for companies that want to use the cloud in a controlled way. CybUp creates and configures resources in the client’s own account; it does not offer hosting of its own.

What does an Azure or AWS setup service cover?

With this service, you own the cloud account. The Azure subscription or AWS account is opened in your company’s name with your company’s billing details; we carry out the configuration with administrator rights and, when the work is done, reduce those rights to whatever level you decide. We do not host on our own servers and we do not resell cloud resources. That means if you ever stop working with us, nothing has to be moved.

A typical scope covers the account and subscription structure, the virtual network and connection to the office, identity and permissions, security rules, cost alerts, server or application migration, backup and monitoring. You can start with a one-off setup and carry on with regular operational support afterwards.

What is an Azure landing zone, and why build it first?

A landing zone is the base cloud environment, prepared before any workloads move, where governance and security rules are set. Microsoft’s definition of an Azure landing zone describes it as an architecture for governing, securing and scaling multiple subscriptions; management groups, central networking, identity and policy assignments are all part of it. On AWS, AWS Control Tower does the same job with a multi-account environment and guardrail controls.

An SME does not need the full enterprise version, but it does need the essentials: production and test resources in separate subscriptions or accounts, a naming and tagging convention, a policy restricting which regions resources can be created in, and admin rights granted to groups rather than individuals. Skip these at the start and, a year later, you have an environment where nobody knows who created what, or why.

“An Azure landing zone is a proven and flexible architecture for governing, securing, and scaling a multi-subscription Azure environment.”

— Microsoft Learn — What is an Azure landing zone?

How do you connect the office to Azure or AWS?

The most common method is a site-to-site IPsec VPN. VPN Gateway on Azure and Site-to-Site VPN on AWS link the firewall in your office to the virtual network in the cloud through an encrypted tunnel. It makes no difference whether the office runs FortiGate, pfSense or MikroTik; we match the IKE and IPsec parameters on both sides. For branch connections, see our VPN server setup page.

Address planning matters here. The IP range of the cloud virtual network must not overlap with the ranges used by your office, your branches or your remote users. Common ranges such as 192.168.1.0/24 are the choices that cause the most trouble later on.

How do you handle identity, security and cost governance in the cloud?

On Azure we grant admin access through Entra ID, with multi-factor authentication and role-based access control (RBAC); on AWS we set up central sign-in with IAM Identity Center. The AWS root account and global administrator accounts are not used for day-to-day work; they get strong passwords and hardware keys and are locked away. If a link to on-premises Active Directory is needed, we plan it alongside our Active Directory and Entra ID work.

To avoid cost surprises, we set budgets and alerts, tag resources and regularly review unused disks, idle IP addresses and oversized VMs. On Azure, Cost Management is the core tool for this. Cloud prices change often, so we do not quote figures on this page; we work out estimated costs with you using the vendor’s current pricing calculator.

  • Subscription/account structure, tagging and region policy
  • MFA and role-based admin access
  • Network security groups, with management ports closed to the internet
  • Budget alerts and a monthly cost review

“Budget alerts notify recipients when cost exceeds a predefined cost or forecast amount.”

— Microsoft Learn — Cost Management

How do you migrate servers and applications to Azure or AWS?

Before any migration we carry out an inventory and dependency analysis. Azure Migrate discovers on-premises VMware, Hyper-V and physical servers, assesses their readiness for Azure, produces sizing recommendations and cost estimates, and then runs the migration. On AWS, AWS Transform MGN continuously replicates source servers at block level and brings them up in AWS with a cutover window of a few minutes.

Lifting and shifting every server as it is is not always right. Take an e-commerce company with 50 users: the web application and database might move to the cloud while the accounting software and file server stay in the office. Moving the database to a managed service (Azure SQL or Amazon RDS) reduces the patching burden, but licensing and compatibility need checking separately. We make that call server by server, with the application owner.

Migrated workloads also need backup and monitoring. Backups can be taken with Azure Backup on Azure, and with AWS Backup or Veeam on AWS; we handle monitoring with the cloud’s own tools or by connecting it to your on-premises monitoring system.

Which country is cloud data stored in, and what does KVKK require?

The region you choose when creating resources on Azure or AWS determines which country’s data centre physically holds the data. Storing personal data in a region outside Türkiye may count as a transfer abroad under Article 9 of KVKK, Türkiye’s Personal Data Protection Law (Law No. 6698). According to KVKK’s page on transfers abroad, an amendment in force since 1 June 2024 introduced a tiered regime of adequacy decisions, appropriate safeguards such as standard contracts and binding corporate rules, and limited exceptions; standard contracts must be notified to the Authority within five business days of signing.

Which legal basis to rely on is a decision for your legal adviser. Our contribution is on the technical side: documenting which region the data is in, blocking resource creation outside that region by policy, and configuring encryption and access logging. For the other technical measures, see our KVKK technical measures page.

What you receive

  • Azure subscription or AWS account opened in your company’s name, with delegated access
  • Landing zone: account/subscription structure, policies and tagging rules
  • Site-to-site VPN to the office and branches
  • MFA, role-based access and budget alerts
  • Server and application migration with post-migration checks
  • Backup, monitoring and an operations document

How we work

  1. 1

    Free review

    Together we assess the workloads to move, their dependencies, data location requirements and the target cloud.

  2. 2

    Design

    You receive the account structure, network address plan, identity model, cost rules and migration waves in writing.

  3. 3

    Foundation build

    The account is opened and the landing zone, VPN, identity and security rules are put into service.

  4. 4

    Migration

    After a test migration, servers move in planned windows and are signed off by the application owner.

  5. 5

    Operations

    Backup and monitoring are set up; monthly cost and security reviews can continue if you want them.

Frequently asked questions

Whose name is the cloud account opened in?

Always yours, with your billing details. You own the account; we are granted access to configure it and, at the end of the work, reduce that access to the level you decide.

Should we choose Azure or AWS?

For companies using Microsoft 365 and Active Directory, Azure is often the more natural extension. If your existing application was built for AWS, or your team already knows AWS, AWS can make more sense. We make the choice with you based on the workload and the licences you already hold.

Do you host on your own servers?

No. We create and configure resources in your own Azure or AWS account. We do not offer hosting or server rental.

How much will our cloud bill be?

That depends on the region, resource sizes and how long resources run, and vendor prices change often. After the review we produce an estimate with the vendor’s current calculator, and during setup we configure budget alerts.

Will there be downtime during the migration?

With methods that use continuous replication, downtime is limited to the final sync and the time it takes the machine to start in the cloud. We schedule critical servers for out-of-hours windows and keep a rollback step ready.

Can we move data to the cloud under KVKK?

Yes, but if the region holding the data is outside Türkiye, the rules on transfers abroad must be assessed. The legal assessment is for your legal adviser; we apply technical measures such as region restrictions, encryption and access logging.

Do you provide support after setup?

Yes. We offer regular support for monthly cost reviews, security settings checks, backup tests and creating new resources in line with the landing zone rules.

How much does an Azure or AWS setup cost?

We give you a written quote once we have reviewed the scope, and the review is free. The quote depends on the number of servers to migrate, network connectivity needs and whether you want ongoing support.

Sources and official documentation

CybUP Team

Written and reviewed by the CybUP technical team in Istanbul. Last updated: 10 October 2026.

Request a free review for this service

Fill in the form and we will get back to you as soon as possible. For urgent matters, WhatsApp or phone is faster.

Message on WhatsApp

Cookie preferences

Strictly necessary

Required for the core functions of the site and to remember your choices. Cannot be turned off.

Analytics

Lets us measure which pages are visited, anonymously (Google Analytics via Google Tag Manager).

Marketing

Used for advertising measurement and personalisation.