Skip to main content
Microsoft Solutions Partner — Azure Migrate + Modernization · 11,000+ engagements

Azure Migrate + Modernization Enterprise Guide (2026)

Discovery, assessment, server + database + app migration, AKS readiness, SAP on Azure, and mainframe modernization — delivered through the EPC Group Cloud Migration Accelerator by a Microsoft Solutions Partner founded in 1997.

What is Azure Migrate and how do enterprises use it? Azure Migrate is the unified first-party Microsoft hub for discovering, assessing, and migrating workloads into Azure. It covers VMware, Hyper-V, physical servers, AWS EC2, and Google Compute Engine sources; SQL Server, PostgreSQL, MySQL, Oracle, and MongoDB databases through Database Migration Service; ASP.NET and Java web tiers through App Service Migration Assistant and App Containerization for AKS; and the VMware estate through Azure VMware Solution readiness scoring. EPC Group ships Azure Migrate through a five-phase Cloud Migration Accelerator — Assess, Foundation, Migrate, Govern, Modernize — priced fixed-fee between $300K and $2M depending on workload count, multi-region scope, regulatory complexity, and SAP or mainframe inclusion.

Azure Migrate is the first-party Microsoft hub for inventorying, assessing, and migrating on-premises and cross-cloud workloads into Azure. Six components: Discovery & Assessment, Server Migration, Database Migration Service, App Service Migration Assistant, App Containerization for AKS, and Azure VMware Solution readiness. Six enterprise patterns from datacenter exit lift-and-shift through SAP on Azure and mainframe modernization. EPC Group Cloud Migration Accelerator: fixed-fee, five phases, senior-architect-led, scoped after discovery.

Key Facts

  • Azure Migrate Discovery & Assessment inventories VMware, Hyper-V, physical, SQL Server, web apps, and file shares — free to use
  • Server Migration replicates from VMware (agentless via vCenter), Hyper-V, physical, AWS EC2, and Google Compute Engine into Azure IaaS
  • Database Migration Service handles SQL Server, PostgreSQL, MySQL, Oracle, and MongoDB online and offline migrations
  • App Service Migration Assistant scans IIS web tiers — 30-60% of legacy ASP.NET workloads land directly on App Service with no code changes
  • App Containerization tool generates Dockerfiles, ACR images, and AKS Helm charts for ASP.NET and Java web workloads
  • Azure VMware Solution readiness lens identifies workloads where AVS lift-and-shift outperforms native rebuild on the calendar
  • SAP on Azure supports S/4HANA, ECC, BW, RISE on Azure, and HANA Large Instances up to 24 TB single-node
  • Mainframe modernization via Astadia, TmaxSoft, Asysco, Micro Focus, and the Microsoft Azure Mainframe Migration program
  • EPC Group five-phase Cloud Migration Accelerator: fixed-fee $300K to $2M, 14 to 36 weeks of activation, senior-architect-led
  • Microsoft Solutions Partner founded in 1997, 70+ Fortune 500 clients, 216+ M&A tenant consolidations

Azure Migrate — six components that cover the entire migration surface

Azure Migrate is no longer a single tool — it is the unified hub for six purpose-built migration capabilities. Discovery and Assessment inventories the estate. Server Migration moves the VM tier. Database Migration Service moves the data tier. App Service Migration Assistant moves the web tier. App Containerization lands the containerizable workloads on AKS. The AVS-readiness lens routes the VMware-anchored workloads through Azure VMware Solution when lift-and-shift outperforms rebuild.

Azure Migrate: Discovery & Assessment

Azure Migrate Discovery and Assessment is the unified hub inside the Azure portal that inventories on-premises VMware, Hyper-V, physical servers, SQL Server instances, web apps, and unstructured file shares — then maps each workload to a costed Azure destination. Discovery captures CPU, memory, storage, IOPS, network throughput, dependencies, and runtime metadata; assessment translates that into Azure VM SKU, Azure SQL target, AKS readiness, App Service compatibility, and right-sized Reserved Instance commitment shape with five-year TCO.

  • Lightweight Azure Migrate appliance — collects performance and dependency data from VMware vCenter, Hyper-V SCVMM, or physical Windows + Linux
  • Agentless dependency analysis via vCenter API; agent-based dependency analysis for Hyper-V and physical workloads using the Dependency Agent and Log Analytics workspace
  • SQL Server assessment — Managed Instance vs Database vs SQL VM target sizing with feature-parity scoring and remediation guidance
  • Web app assessment — App Service compatibility scoring with code-pattern, runtime, and configuration checks
  • AKS readiness scoring — containerizable web tier identification with App Containerization tooling integration
  • Five-year TCO modeling — Reserved Instance shape, Azure Hybrid Benefit, dev/test pricing, and consumption tail

Note: The Discovery & Assessment hub is free to use — customers pay only for the destination Azure consumption after cutover. EPC Group typically anchors a fixed-fee assessment around 3 to 6 weeks of Azure Migrate output.

Azure Migrate: Server Migration

Server Migration is the replication-and-cutover engine for VMware, Hyper-V, physical servers, AWS EC2, and Google Compute Engine VMs into Azure IaaS. Two replication modes — agentless for VMware (using vCenter snapshots) and agent-based for Hyper-V, physical, and cross-cloud — both deliver continuous block-level replication into an Azure replication storage account, then cutover with seconds to minutes of downtime per VM.

  • Agentless replication for VMware vSphere 6.5+ using vCenter and ESXi snapshot mechanics — no software inside the guest
  • Agent-based replication for Hyper-V, physical Windows + Linux, AWS EC2, and Google Compute Engine — the Mobility Service runs in-guest
  • Continuous block-level replication into Azure replication storage with minute-level RPO during the steady-state replication phase
  • Test migration before cutover — full failover into an isolated Azure VNet for validation without affecting the production replication stream
  • Cutover with seconds-to-minutes downtime — final delta sync, source shutdown, target boot, and the workload runs in Azure
  • Replaces the deprecated Azure Site Recovery-based migration flow as of mid-2024 — Server Migration is the current first-party Microsoft path

Note: Azure Migrate Server Migration superseded the Azure Site Recovery migration scenario. New projects should always start in Server Migration, not ASR. ASR remains the BCDR product, not a migration tool.

Azure Migrate: Database Migration (DMS)

Azure Database Migration Service — now exposed through the Azure Migrate hub — orchestrates online and offline migrations of SQL Server, PostgreSQL, MySQL, Oracle, and MongoDB into Azure SQL Database, Azure SQL Managed Instance, Azure Database for PostgreSQL, Azure Database for MySQL, and Azure Cosmos DB. Online migration delivers near-zero-downtime cutover; offline migration accepts a maintenance window in exchange for simpler operational handling.

  • SQL Server → Azure SQL Managed Instance (online) for highest-fidelity SQL feature parity with single-digit-minute cutover
  • SQL Server → Azure SQL Database (online or offline) for modernized PaaS workloads with built-in HA and autoscale
  • SQL Server → SQL Server on Azure VM — lift-and-shift when feature parity or vendor-supported configuration mandates IaaS
  • PostgreSQL on-prem → Azure Database for PostgreSQL Flexible Server with logical decoding for online migration
  • Oracle → Azure SQL Managed Instance through SSMA (SQL Server Migration Assistant) with schema and stored-procedure translation
  • MongoDB → Cosmos DB for MongoDB API with online replication-based cutover

Note: Database modernization is rarely a one-tool exercise. EPC Group typically pairs Azure Migrate DMS with SSMA, Data Migration Assistant (DMA), and per-engine native replication tooling. Skills Assessment + Compatibility Scoring lands in week one of every database engagement.

App Service Migration Assistant

The App Service Migration Assistant is a downloadable Windows tool that scans on-premises IIS web servers and ASP.NET / .NET / Java / PHP applications for App Service compatibility, then migrates compatible workloads to Azure App Service with a single click. The Assistant handles the configuration translation — IIS bindings, application pools, runtime settings, environment variables — and surfaces the gaps for the applications that need code-level remediation before migration.

  • IIS server scanning — discovers every site, app pool, runtime version, binding, and configuration setting
  • Compatibility scoring per application — green for direct migration, yellow for minor remediation, red for significant refactor
  • Direct migration to App Service for compatible apps — automated provisioning, configuration translation, deployment, and DNS cutover scripts
  • Migration to Azure Kubernetes Service for containerizable workloads via the App Containerization tool
  • Migration to Azure SQL Database for the back-end SQL Server data tier paired with the App Service front-end

Note: The Assistant is best used early in the assessment phase to surface the compatibility profile of the web tier across the estate. EPC Group routinely finds 30% to 60% of legacy IIS workloads migrate directly to App Service with no code changes.

App Containerization + AKS Migration

The App Containerization tool — bundled with Azure Migrate — automates the containerization of ASP.NET, ASP.NET Core, and Java web applications running on IIS or Tomcat, then deploys the resulting container images into Azure Kubernetes Service. The tool handles Dockerfile generation, image build, ACR publishing, Helm chart generation, and the AKS deployment manifest so the modernization team gets a working AKS workload without bespoke containerization labor per app.

  • ASP.NET on Windows containers, ASP.NET Core on Linux containers, Java on Tomcat Linux containers
  • Automated Dockerfile generation including dependency capture, configuration externalization, and runtime base-image selection
  • Azure Container Registry publishing with image scanning via Microsoft Defender for Containers
  • AKS deployment manifest generation with Helm charts, ConfigMaps, and Secret handling
  • Azure Arc-enabled Kubernetes for hybrid edge AKS deployments with central governance

Note: App Containerization is the AKS on-ramp for the legacy web tier. The pattern works best for stateless web workloads with externalized state — stateful applications need additional refactor before containerization.

Azure VMware Solution readiness

Azure Migrate Discovery includes an AVS-readiness lens that classifies the on-premises VMware estate against Azure VMware Solution AV36, AV52, and AV64 host SKUs. When the customer portfolio includes hundreds of VMware-anchored workloads with NSX-T security policy, vSAN storage policy, and tight datacenter-exit timelines, AVS lift-and-shift through HCX often outperforms native Azure VM rebuild on schedule, cost, and risk. The AVS lens lands in the same assessment deliverable as the Server Migration scoring.

  • AVS host count modeling against AV36 / AV52 / AV64 capacity with workload SKU-fit scoring
  • HCX wave plan integrated into the assessment — vMotion, Replication Assisted vMotion, Bulk Migration, Cold Migration sequencing
  • ExpressRoute Global Reach network design including the on-prem to AVS private Layer-3 path
  • Reserved Instance commitment shape vs native Azure VM commitment comparison in the same TCO
  • NSX-T policy translation and identity integration into the AVS environment

Note: See the /azure-vmware-solution-migration-enterprise-2026 hub for the dedicated AVS architecture, HCX migration patterns, and Broadcom licensing analysis.

Six enterprise migration + modernization patterns

Every enterprise Azure Migrate engagement composes from one or more of these patterns. EPC Group sequences the rollout against the business priority list — datacenter lease exits, M&A close timelines, SAP renewal pressure, mainframe vendor end-of-life, and regulatory boundary attestation.

Pattern 1 — Datacenter exit lift-and-shift (rehost dominant)

A regulated enterprise with two on-premises datacenters faces a lease expiration in 12 to 18 months and a board mandate to leave the building. Time-to-cloud is the gating constraint, not workload modernization. The Azure Migrate assessment classifies the entire estate against Server Migration and DMS as the rehost path, identifies the 10% to 20% of workloads that are end-of-life or duplicate and can be retired in place, and builds a five-year financial model anchored on 3-year Reserved Instances with Azure Hybrid Benefit applied to the Windows Server and SQL Server estate. The migration program then runs in 8-to-16-week waves through Azure Migrate Server Migration and DMS, with HCX-routed AVS taking the heavy VMware lift where native rebuild does not fit the calendar. The customer exits the datacenter on schedule, the cost model converts from capex to OpEx, and the modernization roadmap to App Service, AKS, and Azure SQL PaaS runs over the following 24 months on cloud time.

Pattern 2 — Lift-and-improve (replatform + repurchase blend)

A Fortune 500 enterprise with a mature modernization appetite combines rehost for the workloads that need to move quickly with replatform for the workloads that gain meaningful operational and cost benefit from minor PaaS shifts. IIS web tiers move into App Service via the Migration Assistant. SQL Server workloads land in Azure SQL Managed Instance for the feature-parity tier and Azure SQL Database for the modern tier. File shares move into Azure Files with AD authentication preserved. Mailboxes finish the move to Exchange Online. Legacy line-of-business applications get repurchased onto Microsoft Dynamics 365 or modern SaaS where the business case justifies the refactor. The Azure Migrate assessment surfaces the rehost-vs-replatform-vs-repurchase decision per workload, and the EPC Group Migration Accelerator phases the rollout against the dependency graph.

Pattern 3 — Lift-and-replace strategic (selective refactor + rearchitect)

A customer with a focused, business-critical workload portfolio elects to rearchitect the strategic applications onto Azure-native PaaS rather than rehost them. The Azure Migrate assessment runs alongside an App Modernization Assessment that scores each strategic workload for App Service, AKS, Azure Functions, Azure SQL Database, Cosmos DB, and Event Grid fit. Containerization runs through App Containerization for the web tier; data-tier modernization runs through DMS into Managed Instance or Database. The legacy estate around the strategic core gets rehosted through Server Migration to clear the datacenter, while the strategic apps land directly on native PaaS in a parallel workstream. The result is a modernized strategic portfolio and a clean, cost-optimized landing zone for the long-tail rehost workloads — both delivered inside the same overall program.

Pattern 4 — SAP on Azure (S/4HANA, ECC, BW, RISE blend)

SAP customers running ECC, S/4HANA, BW, or SAP on HANA pick Azure as the destination of choice for SAP-certified scale — Azure is SAP-certified up to 24 TB single-node HANA on the Azure HANA Large Instances family and 11.4 TB on the M-series VM line. Azure Migrate Discovery captures the SAP landscape, the EPC Group SAP on Azure architect models the right blend of HANA Large Instances vs M-series VMs vs Azure NetApp Files for /hana/data and /hana/log, and the migration pattern picks between the SAP-supported Database Migration Option (DMO) for ECC-to-S/4 + Azure move, classical SUM + heterogeneous system copy for in-place ECC moves, and SAP RISE on Azure for customers electing the SAP-managed S/4HANA Cloud Private Edition. EPC Group ships SAP on Azure architectures with HA via Pacemaker + Azure Fence Agent, DR via Azure Site Recovery or HANA System Replication, and the full SAP Solution Manager + Azure Monitor for SAP Solutions integration. Microsoft and SAP have a joint go-to-market for RISE on Azure that converts the spend through the Microsoft Customer Agreement.

Pattern 5 — Mainframe and midrange modernization (z/OS, AS/400, AIX)

Enterprises with legacy IBM z/OS mainframes, IBM i (AS/400) midrange systems, or AIX UNIX environments use Azure as the modernization destination via three credible paths. Astadia automates COBOL, PL/I, and JCL translation into modern Java or .NET running on Azure App Service and Azure SQL — emulation-style replatform that preserves business logic without a full rewrite. TmaxSoft OpenFrame provides mainframe rehosting onto Azure VMs that emulate the z/OS runtime so existing CICS, IMS, and DB2 workloads run with minimal code change. Asysco AMT delivers Unisys and Burroughs mainframe replatforming onto Azure SQL and .NET. Microsoft maintains an Azure Mainframe Migration program with named ISV partners; EPC Group sequences the partner choice against the source platform, the modernization appetite, and the regulatory boundary requirements. Mainframe modernization is typically a 12-to-24-month program with phased application cutover and a parallel-run period for production validation.

Pattern 6 — M&A consolidation + cross-cloud migration

A Microsoft-strategic acquirer closes a deal and inherits an AWS-anchored or Google Cloud-anchored estate from the target. Standing up duplicate operational planes for years while applications rationalize is unacceptable. Azure Migrate Server Migration handles agent-based migration of AWS EC2 and Google Compute Engine instances directly into Azure — the Mobility Service runs in-guest on the source instances and replicates into Azure storage over the public internet or a dedicated ExpressRoute. Cross-cloud database migration runs through DMS for the SQL and PostgreSQL workloads, Azure Data Factory for the data-warehouse and analytics workloads, and direct service-to-service mapping for the AWS-native services (RDS to Azure SQL, S3 to Azure Blob, Lambda to Azure Functions, DynamoDB to Cosmos DB). EPC Group has executed 216+ M&A tenant migrations and routinely consolidates cross-cloud estates into a single Azure landing zone inside the close-period operational handoff calendar.

Discovery patterns — appliance, agent-based, agentless, Movere

Discovery patterns — how Azure Migrate sees the estate

The Azure Migrate discovery layer is the foundation of every credible migration program. Get the discovery right and the rest of the program runs on accurate telemetry. Get it wrong and the entire wave plan, TCO model, and Reserved Instance commitment are built on bad data. EPC Group blends the four discovery approaches against the customer source platform mix.

Azure Migrate appliance (VMware + Hyper-V + physical)

The Azure Migrate appliance is a lightweight Windows VM (or physical server) that runs inside the customer datacenter and acts as the discovery and assessment data-collection point. For VMware estates the appliance connects to vCenter through the VMware API and continuously polls performance counters, configuration, and dependency telemetry. For Hyper-V estates the appliance connects to System Center Virtual Machine Manager or directly to Hyper-V hosts. For physical Windows and Linux servers the appliance runs an agentless discovery via WMI, SSH, or installed agents. The appliance ships data into the Azure Migrate project hourly with minute-level performance granularity over a 30-day collection window.

Agent-based dependency analysis

Agent-based dependency analysis uses the Microsoft Dependency Agent installed inside each workload plus a Log Analytics workspace to capture process-level inbound and outbound network connections, port-level traffic flows, and service-to-service dependency maps across the estate. The output is a per-workload dependency graph that the migration architects use to sequence the wave plan — workloads with tightly-coupled dependencies migrate in the same wave, loosely-coupled workloads migrate independently. Agent-based discovery is the most accurate dependency-mapping approach and is the recommended path for Hyper-V, physical, and cross-cloud workloads.

Agentless dependency analysis (VMware)

For VMware estates Azure Migrate supports agentless dependency analysis through the vCenter API — no software runs inside the guest VMs. Dependency data is sampled hourly and aggregated over the discovery window. Agentless analysis is lower-fidelity than agent-based but eliminates the operational friction of installing the Dependency Agent across hundreds or thousands of VMs. EPC Group typically blends both approaches — agentless for the bulk of the VMware estate, agent-based for the tier-1 production workloads where the dependency map needs to be highly accurate.

Movere (deeper discovery — selective use)

Movere is Microsoft-acquired discovery tooling that delivers deeper, agentless, point-in-time discovery across the estate — including configuration drift detection, software inventory, license consumption, and security posture. Movere is appropriate when the customer needs a one-time, comprehensive estate snapshot rather than the continuous performance telemetry that Azure Migrate appliance delivers. EPC Group runs Movere selectively for customers with deep license-rationalization needs alongside the Azure Migrate appliance for the migration assessment proper.

TCO + cost optimization

TCO calculator, Reserved Instances, Hybrid Benefit, and wave planning

Four levers control the migrated Azure bill. The built-in Azure Migrate TCO calculator anchors the pre-migration business case. Reserved Instance commitments lock the steady-state discount at 25% to 72% off PAYG. Azure Hybrid Benefit carries the Software Assurance-backed Windows Server and SQL Server license rights across. Dependency-driven wave planning sequences the program against the actual workload dependency graph, not against a wish-list ordering. EPC Group locks all four at the assessment-phase deliverable.

Five-year TCO modeling inside Azure Migrate

Azure Migrate ships a built-in TCO calculator that projects five-year on-premises cost (hardware refresh, licensing, datacenter operations, power, cooling, network) against five-year Azure cost (Reserved Instance commitments, Azure Hybrid Benefit, dev/test pricing, storage and network egress). The output is the costed business case the executive sponsor takes to the board. EPC Group augments the built-in TCO with the customer-specific cost-of-capital assumptions, datacenter exit savings, headcount-redirect assumptions, and risk-adjusted modernization tail to produce the final financial model.

Reserved Instance shape — anchor steady-state with 1y + 3y commitments

Reserved Instances at 1-year or 3-year terms deliver 25% to 72% discount versus pay-as-you-go pricing on Azure VM compute, with the deeper discounts on 3-year terms. Most production migrations lock the steady-state compute footprint to 3-year RIs and reserve PAYG capacity for migration-wave headroom and burst. Azure Reservations are fungible across SKUs in the same instance family in the same region — switching VM SKU mid-term does not break the reservation. The assessment-phase deliverable always includes the recommended RI commitment shape.

Azure Hybrid Benefit — Windows Server + SQL Server license carry

Azure Hybrid Benefit applies Software Assurance-backed Windows Server and SQL Server license rights to Azure VMs, Azure SQL Managed Instance, and Azure SQL Database, effectively eliminating the per-VM and per-DB license cost premium. For SQL-heavy estates this often saves 35% to 55% of the total bill of materials. AHB is per-workload, not per-host or per-subscription — customers blend AHB-covered workloads with consumption-billed workloads in the same Reserved Instance pool.

Wave planning — dependency-driven sequencing

Migration velocity is bounded by dependency complexity, not by Azure capacity. The Azure Migrate dependency map drives the wave plan — workloads with tightly-coupled dependencies move in the same wave, loosely-coupled workloads move independently. Typical enterprise wave plans run 8 to 16 weeks per wave with 20 to 200 workloads per wave. EPC Group sequences waves by business unit, application criticality, and dependency cluster — production cutover criteria, rollback procedures, and named owners are documented per wave before execution begins.

The Azure Migrate Hub workflow — discover, assess, migrate, modernize

The Azure Migrate Hub is the single Azure portal blade that orchestrates discovery, assessment, replication, cutover, and post-migration modernization. EPC Group operates the Hub on behalf of the customer migration program — provisioning the appliance, configuring Server Migration projects, standing up DMS instances, running the App Service Migration Assistant scans, and coordinating the App Containerization workflows. The Hub is the single pane of glass that the program manager and the executive sponsor both check daily through the migration window.

  • Step 1 — Project provisioning: Azure Migrate project provisioned in the destination subscription with the source platform discovery tool selected (Server Migration, DMS, Web App Migration, App Containerization).
  • Step 2 — Discovery: Azure Migrate appliance deployed on-prem, vCenter / SCVMM / physical inventoried, 30 days of performance and dependency telemetry captured.
  • Step 3 — Assessment: Workloads scored for rehost / replatform / refactor / repurchase / retire / retain, Azure SKU recommended per workload, five-year TCO produced.
  • Step 4 — Wave planning: Dependency graph drives wave sequencing, cutover criteria documented per wave, rollback procedures defined, named owners staffed.
  • Step 5 — Replication: Server Migration replicates VM disks continuously into the Azure replication storage account, DMS replicates database transactions, App Service Migration Assistant prepares the IIS workloads.
  • Step 6 — Test migration: Test failover into an isolated Azure VNet validates each workload end-to-end before production cutover — no impact on the production replication stream.
  • Step 7 — Cutover: Final delta sync, source shutdown, target boot, DNS cutover, validation, decommission. Cutover windows measured in seconds to minutes per workload.
  • Step 8 — Modernize: Post-migration modernization roadmap from rehosted IaaS onto AKS, App Service, Azure SQL Managed Instance, Cosmos DB, and Azure Functions on the customer-funded pace.

The EPC Group Cloud Migration Accelerator — five phases, fixed fee

The accelerator anchors on The EPC Group Lifecycle — Assess, Foundation, Migrate, Govern, Modernize. Fixed-scope between $300,000 and $2,000,000 depending on workload count, multi-region scope, regulatory complexity, SAP or mainframe inclusion, and the modernization tail. Senior architect on-record from kickoff through go-live, no offshore handoff, no T&M overrun.

Phase 1 — Assess

Azure Migrate discovery + costed migration plan in 4 to 6 weeks

Phase one is a fixed-fee assessment that deploys the Azure Migrate appliance into the customer datacenter, runs 30 days of performance and dependency telemetry collection, scores every workload against rehost / replatform / refactor / repurchase / retire / retain (the 6 Rs), produces the dependency-driven wave plan, and ships a costed five-year TCO with Reserved Instance shape, Azure Hybrid Benefit application, and modernization tail. The output is the board-ready business case the executive sponsor uses to fund the program.

  • Azure Migrate appliance deployed across every customer datacenter — VMware, Hyper-V, and physical inventoried
  • 30-day performance + dependency telemetry collection with minute-level granularity
  • 6 Rs disposition per workload — rehost, replatform, refactor, repurchase, retire, retain
  • Dependency-driven wave plan with per-wave size, sequence, and named-owner staffing
  • Five-year TCO with Reserved Instance commitment shape, Azure Hybrid Benefit, and AVS-vs-native comparison

Phase 2 — Foundation

Azure landing zone, identity, and Migration Hub stood up

Phase two builds the destination landing zone — management groups, subscriptions, RBAC, Azure Policy initiatives, the hub-and-spoke VNet topology, ExpressRoute or VPN connectivity, Microsoft Entra ID integration, and Azure Monitor + Defender for Cloud at the management-group scope. The Azure Migrate Server Migration replication environment is provisioned, DMS instances stood up for the database tier, and the pilot workload is migrated end-to-end through the platform to validate the destination operationally.

  • Cloud Adoption Framework landing zone — management groups, subscription topology, RBAC, Azure Policy
  • Hub-and-spoke VNet topology with ExpressRoute or VPN Gateway connectivity to on-prem
  • Microsoft Entra ID integration with hybrid identity if the customer remains AD DS-anchored
  • Azure Migrate Server Migration replication environment provisioned per source platform
  • Database Migration Service instances provisioned for the planned SQL and PostgreSQL workloads

Phase 3 — Migrate

Wave execution through Server Migration, DMS, App Service, and AKS

Phase three executes the migration waves. EPC Group sequences workloads through Server Migration for the VM tier, DMS for the database tier, App Service Migration Assistant for the IIS web tier, and App Containerization plus AKS for the containerizable workloads. Each wave runs through a documented runbook with cutover criteria, rollback procedures, and named owners across infrastructure and application teams. Migration velocity ramps from 20 to 50 workloads per week in the early waves to 150 to 300 workloads per week at peak cadence.

  • Server Migration for VMware, Hyper-V, physical, AWS EC2, and Google Compute Engine sources
  • DMS for SQL Server, PostgreSQL, MySQL, Oracle, and MongoDB targets
  • App Service Migration Assistant for the IIS web tier with direct PaaS landing
  • App Containerization for AKS-bound workloads with automated Dockerfile + Helm generation
  • AVS lift-and-shift for the VMware estate where native rebuild does not fit the calendar

Phase 4 — Govern

Azure Policy, Defender for Cloud, and FinOps operational baseline

Phase four projects the customer governance model onto the migrated estate. Azure Policy initiatives apply at the management-group scope. Microsoft Defender for Cloud covers the Server, SQL, App Service, AKS, and Key Vault plans with regulatory dashboards mapped to the customer compliance framework. FinOps tagging and cost-management dashboards land in Cost Management + Billing with chargeback to the business units. ITSM integration wires the new Azure environment into ServiceNow, Jira Service Management, or Cherwell. Microsoft Sentinel detection content lands for the migrated workloads.

  • Azure Policy initiatives applied at management-group scope for encryption, tagging, and configuration baselines
  • Microsoft Defender for Cloud — Defender for Servers Plan 2, SQL, App Service, AKS, Key Vault, and Storage
  • Cost Management + Billing dashboards with FinOps chargeback to business units
  • Microsoft Sentinel deployed with analytics rules mapped to the migrated workload portfolio
  • ITSM integration — ServiceNow, Jira Service Management, or Cherwell wired to the Azure change-control plane

Phase 5 — Modernize

Post-migration modernization roadmap on Azure-native PaaS

Phase five hands the customer a costed multi-year modernization roadmap from rehosted IaaS onto Azure-native PaaS — AKS for the containerizable workloads, Azure SQL Database and Managed Instance for the relational tier, App Service and Functions for the web and integration workloads, Azure Files and Azure NetApp Files for the unstructured-data workloads, Cosmos DB for the NoSQL tier. The Reserved Instance commitment shape is re-modeled against the trailing footprint as workloads modernize off IaaS. The modernization runs at the pace the program funds, on a stable platform, with no datacenter-clock pressure.

  • AKS rollout for the containerizable application tier with Arc projection back into central governance
  • Azure SQL Managed Instance and Database migration plan for the SQL Server estate
  • App Service and Azure Functions rollout for the web tier and integration workloads
  • Cosmos DB rollout for the NoSQL and globally-distributed workloads
  • Reserved Instance re-shape against the modernized footprint with savings reinvested into the next wave

Why EPC Group leads enterprise Azure Migrate + modernization programs

1997
Founded · Microsoft consulting
70+
Fortune 500 clients
216+
M&A tenant consolidations
1.83 million
Users migrated

Microsoft Solutions Partner — Infrastructure

Microsoft Solutions Partner with the Infrastructure (Azure), Security, Modern Work, Data & AI, Digital & App Innovation, and Business Applications designations. Senior architects average two decades of Azure platform and large-scale migration delivery experience.

Four-time author for Microsoft Press and Sams

Founder Errin O’Connor has nearly three decades of Microsoft consulting leadership and is a four-time author for Microsoft Press and Sams across Power BI and SharePoint.

Fixed-fee migration engagements

Every Cloud Migration Accelerator is fixed-fee with a costed five-year financial model and a named senior architect on-record from kickoff through go-live. No T&M overruns, no offshore handoff, no junior-analyst-led production cutover.

Compliance-native

EPC Group is compliance-native across HIPAA, SOC 2, FedRAMP-aligned engagements, FINRA, CMMC, and GxP. Azure Migrate deployments ship with auditor-ready control matrices, Defender for Cloud regulatory dashboards, and Microsoft Sentinel detection content.

HIPAA
SOC 2
FedRAMP
FINRA
CMMC
GxP

Frequently asked questions — Azure Migrate + modernization

Azure Migrate vs AWS CloudEndure Migration / Application Migration Service — which one wins for cross-cloud or net-new migrations?

Azure Migrate is the first-party Microsoft hub for inventorying, assessing, and migrating workloads into Azure from VMware, Hyper-V, physical servers, AWS EC2, and Google Compute Engine. AWS Application Migration Service (the rebranded CloudEndure) does the same job in the opposite direction — into AWS. For Microsoft-strategic enterprises, Azure Migrate wins because it is integrated with the Azure portal, Reserved Instances, Azure Hybrid Benefit, Defender for Cloud, and the broader Microsoft governance plane. The Server Migration agent inside Azure Migrate also replicates from AWS EC2 and Google Compute Engine sources directly into Azure, so cross-cloud migration does not require dual tooling. EPC Group has executed 216+ M&A tenant migrations including cross-cloud consolidations from AWS and GCP into Azure.

Azure Migrate TCO vs CloudHealth / Apptio Cloudability / Flexera — when do enterprises need a third-party FinOps tool?

The Azure Migrate built-in TCO calculator is fine for the pre-migration business case — five-year on-prem cost vs five-year Azure cost with Reserved Instance and Hybrid Benefit modeling. CloudHealth (VMware/Broadcom), Apptio Cloudability, and Flexera One are the multi-cloud FinOps platforms that take over after migration when the customer needs continuous cost optimization, chargeback to business units across Azure + AWS + GCP, and commitment-management automation across cloud providers. Single-cloud Azure customers usually find Microsoft Cost Management + Billing sufficient. Multi-cloud enterprises with mature FinOps practices typically layer CloudHealth or Cloudability on top. EPC Group ships the FinOps tooling recommendation in the Govern phase based on the customer cloud footprint and operating model maturity.

Azure Migrate vs Carbonite / Cloudbase Solutions Coriolis / Rivermeadow — when do enterprises bring in a third-party migration tool?

Azure Migrate Server Migration covers VMware, Hyper-V, physical, AWS EC2, and Google Compute Engine. For sources outside that list — KVM, OpenStack, Xen, IBM Power, certain niche Linux distributions — third-party tools like Carbonite Migrate, Cloudbase Coriolis, and Rivermeadow extend the source coverage. These tools are also occasionally chosen when the customer has very large workloads with constrained migration windows where the third-party replication engines outperform agent-based Server Migration. EPC Group recommends Azure Migrate as the default and reaches for third-party tooling only when source-coverage or performance requirements explicitly justify the additional cost and operational complexity.

How does SAP RISE on Azure compare to running customer-managed S/4HANA on Azure?

SAP RISE on Azure is SAP-managed S/4HANA Cloud Private Edition with the Azure infrastructure layer underneath, sold through SAP with a Microsoft-SAP joint go-to-market. The customer pays SAP for the S/4HANA platform and SAP operates the SAP layer; Microsoft provides the Azure compute, storage, and network underneath. Customer-managed S/4HANA on Azure means the customer (often with a partner like EPC Group) provisions HANA Large Instances or M-series VMs, installs the SAP NetWeaver and S/4HANA stack, and operates it themselves under their Microsoft Customer Agreement spend. RISE wins when the customer wants SAP-managed simplicity, predictable subscription pricing, and a faster S/4HANA adoption path. Customer-managed wins when the customer has mature in-house SAP Basis capability, wants deeper Azure-native integration with Power BI, Synapse, and Fabric, and prefers to retain control of the SAP stack. The decision is rarely platform — it is operating model.

What does a typical mainframe modernization to Azure cost and how long does it take?

Mainframe modernization is highly bespoke. A typical IBM z/OS mainframe modernization program with Astadia or TmaxSoft runs 12 to 24 months and costs $2M to $20M depending on application count, COBOL line-of-code volume, JCL complexity, regulatory recertification scope, and the parallel-run validation period. The Microsoft Azure Mainframe Migration program partners with named ISVs — Astadia, TmaxSoft, Asysco, Micro Focus, NTT Data, Kyndryl — and EPC Group sequences the partner choice against the source platform. IBM i (AS/400) modernization runs faster, typically 9 to 18 months. AIX UNIX modernization to Azure Linux runs the fastest, typically 6 to 12 months. The assessment-phase deliverable always includes the partner recommendation, the program sequencing, and the costed business case before any modernization commitment is made.

How does Azure Migrate handle regulated industry compliance — HIPAA, FedRAMP, CMMC, FINRA, GxP?

Azure Migrate itself is in scope for the standard Azure regulatory certifications including HIPAA, SOC 2 Type II, ISO 27001, and PCI DSS. Azure Migrate is also available in Azure Government for FedRAMP-authorized and DoD IL5 workloads — the discovery, assessment, and migration tooling all runs inside Azure Government for federal and defense customers. CMMC 2.0 Level 2 and Level 3 obligated defense contractors typically run Azure Migrate inside Azure Government with the destination workloads landing in GCC High or DoD environments. EPC Group ships the framework-specific control matrix and the auditor-ready evidence package as part of the Govern phase. The /government-federal-microsoft-consulting-fedramp-cmmc-2026 hub covers the federal-specific story; the /microsoft-365-gcc-high-dod-migration-consulting-2026 hub covers the GCC High and DoD environment selection.

How does Azure Migrate handle databases beyond SQL Server — Oracle, DB2, PostgreSQL, MySQL, Mongo?

Azure Database Migration Service covers SQL Server, PostgreSQL, MySQL, Oracle, MongoDB, and Cassandra as source platforms with native or near-native target mappings in Azure SQL, Azure Database for PostgreSQL, Azure Database for MySQL, Cosmos DB for MongoDB API, and Cosmos DB for Apache Cassandra. Oracle to Azure SQL Managed Instance migrations use the SQL Server Migration Assistant (SSMA) for schema and stored-procedure translation; Oracle workloads that cannot be refactored land on Oracle Database@Azure (Microsoft and Oracle joint offering) or on Oracle on Azure VMs with Oracle support. DB2 modernization typically goes to Azure SQL via SSMA or to DB2 on Azure VMs. EPC Group runs the database engagement against the source engine, the feature-parity requirements, and the application refactor appetite.

What does a typical Azure Migrate + Modernization engagement cost and what is the EPC Group Cloud Migration Accelerator fee model?

The Azure consumption itself is billed through the Azure subscription — Reserved Instance commitments anchor steady-state production, Azure Hybrid Benefit reduces the gross bill on the Windows Server and SQL Server estate, and PAYG covers migration-wave headroom and burst. Annual Azure spend for typical enterprise migrations ranges from $500K (small lift-and-shift) to $20M+ (large multi-region multi-platform programs). The EPC Group Cloud Migration Accelerator is a fixed-fee professional services engagement priced between $300K and $2M depending on workload count, multi-region scope, regulatory complexity, SAP or mainframe inclusion, and the modernization tail the customer wants embedded. Pricing is locked at the assessment-phase deliverable so the customer has board-ready numbers before any production cutover. Senior architect on-record from kickoff through go-live, no offshore handoff, no T&M overrun.

Continue exploring the EPC Group enterprise Microsoft library

Azure Migrate sits at the center of the Microsoft cloud orchestration and datacenter modernization story. These hubs cover adjacent and complementary territory.

Exit the datacenter on schedule — modernize on cloud time

Book an Azure Migrate + modernization briefing with an EPC Group senior architect. Two-hour working session — estate discovery scope, Azure Migrate assessment plan, wave sequencing, and five-year financial model. Zero obligation, board-ready output.

AI assistant — not human