Skip to main content
Microsoft Solutions Partner — Azure VMware Solution · 11,000+ engagements

Azure VMware Solution Migration Enterprise Guide (2026)

Lift-and-shift the on-premises VMware datacenter into Azure — vSphere, vSAN, NSX-T, HCX, and the AV36/AV52/AV64 host SKUs delivered as a first-party Microsoft service. Senior-architect-led by a Microsoft Solutions Partner founded in 1997.

What is Azure VMware Solution and how do enterprises use it? Azure VMware Solution (AVS) is a first-party Microsoft service that runs a dedicated, fully-managed VMware Cloud Foundation SDDC — vSphere, vSAN, NSX-T, and HCX — on bare-metal Azure hosts inside an Azure region. Enterprises use AVS to lift-and-shift on-premises VMware datacenters into Azure without rewriting application networking, identity, or storage assumptions. Workloads keep their IP addresses through HCX Network Extension, the NSX-T security policy carries across, and the modernization roadmap to Azure-native PaaS runs on cloud time instead of datacenter-lease time. EPC Group ships AVS through a five-phase Assess, Foundation, Migrate, Govern, Modernize accelerator priced fixed-fee between $300K and $1.5M.

Azure VMware Solution (AVS) is a first-party Microsoft service running dedicated VMware Cloud Foundation SDDCs on Azure bare-metal hosts. Three host SKUs — AV36 (general), AV52 (memory-heavy), AV64 (consolidation). HCX delivers live migration with Layer-2 network extension so workloads keep IP addresses. ExpressRoute Global Reach connects on-prem to AVS over private Layer-3. Reserved Instances + Azure Hybrid Benefit drive the cost model. EPC Group AVS Migration Accelerator: fixed-fee, scoped after discovery.

Key Facts

  • AVS is a first-party Microsoft service co-engineered with VMware (now Broadcom) — dedicated VCF SDDC per customer
  • Three host SKUs: AV36 (576 GB RAM / 36 cores), AV52 (1.5 TB RAM / 52 cores), AV64 (1 TB RAM / 64 cores)
  • HCX delivers vMotion, RAV, Bulk Migration, Cold Migration, and Network Extension — workloads keep IP addresses across the move
  • ExpressRoute Global Reach creates a private Layer-3 path between on-prem and AVS, bypassing the public internet
  • Reserved Instance 1-year or 3-year commitments deliver 25-50% discount vs PAYG — anchor production with RIs
  • Azure Hybrid Benefit applies Software Assurance-backed Windows Server and SQL Server licenses to AVS workloads
  • AVS holds HIPAA, FedRAMP High (Commercial + Gov), SOC 2 Type II, PCI DSS, and CMMC 2.0 Level 2 boundaries (Azure Government)
  • EPC Group five-phase AVS Migration Accelerator delivers full activation in 14 to 30 weeks, fixed-fee $300K to $1.5M
  • Microsoft Solutions Partner founded in 1997, 70+ Fortune 500 clients, 216+ M&A tenant consolidations

AVS architecture — what Microsoft actually delivers

Azure VMware Solution is a dedicated, fully-managed VMware Cloud Foundation SDDC running on Azure bare-metal hardware. Five components carry across from on-prem VMware almost unchanged — the SDDC envelope, vSphere with vCenter and vSAN, NSX-T network virtualization, HCX workload mobility, and the bare-metal host SKU layer.

Dedicated Software-Defined Datacenter (SDDC)

Azure VMware Solution provisions a fully-managed, dedicated VMware Cloud Foundation SDDC inside an Azure region — bare-metal hosts running the customer-isolated vSphere, vSAN, NSX-T, and HCX stack as a first-party Azure service, billed through the Azure subscription with Microsoft Customer Agreement or Enterprise Agreement vehicles.

  • Dedicated bare-metal Azure hosts — single-tenant isolation, no noisy-neighbor risk, full hardware control
  • Microsoft-operated VMware Cloud Foundation — Azure SREs handle host firmware, vCenter patching, and vSAN health
  • Native Azure resource — AVS private cloud lives in a customer subscription, in a customer resource group, governed by Azure RBAC and Azure Policy
  • Stretched Cluster topology for AV36 across availability zones — synchronous vSAN replication for 99.99% workload SLA
  • BYOL or PAYG for guest Windows Server and SQL Server through Azure Hybrid Benefit

Note: AVS is a first-party Microsoft service co-engineered with VMware. The vSphere, vSAN, and NSX-T stack inside the SDDC is identical to on-premises VMware Cloud Foundation — VMs, templates, snapshots, and tooling carry over without code changes.

vSphere + vCenter + vSAN

Each AVS private cloud ships with a dedicated vCenter Server appliance, ESXi hypervisor running on Azure bare-metal hosts, and vSAN for distributed storage. The vSphere environment is operationally identical to on-premises — the same Web Client, the same APIs, the same automation hooks.

  • Dedicated vCenter Server appliance per AVS private cloud — cloudadmin role for customer with delegated permissions, restricted root access for Microsoft SRE operations
  • ESXi hypervisor on AV36, AV52, or AV64 hardware SKUs with cluster sizing from 3 hosts to 16 hosts per cluster, up to 12 clusters per private cloud
  • vSAN distributed storage — RAID-1, RAID-5, or RAID-6 erasure-coded protection with compression and deduplication
  • vRealize Operations, vRealize Log Insight, and vRealize Network Insight integrate with the AVS SDDC for advanced operations visibility
  • Workload domain isolation through vSphere resource pools, folders, and tag-based RBAC

Note: Customer admins receive the cloudadmin role — broad but not root. Day-two operations the cloudadmin role does not cover (host firmware, vCenter patching) are handled by Microsoft SRE.

NSX-T network virtualization

NSX-T delivers the software-defined network plane inside every AVS SDDC — distributed routing, micro-segmentation, distributed firewall, load balancing, and overlay transport across the AVS cluster fabric. The NSX-T plane is operationally identical to on-premises and integrates with Azure native networking through ExpressRoute.

  • Distributed logical routing — Tier-0 and Tier-1 gateways with BGP peering to Azure ExpressRoute Global Reach
  • Distributed firewall and micro-segmentation enforced at the vNIC — security policy follows the workload through vMotion
  • NSX Advanced Load Balancer for Layer-4 and Layer-7 services inside the SDDC
  • Overlay segments stretched across multiple AVS clusters within a private cloud
  • Integration with Azure Firewall, Azure Application Gateway, and third-party NVAs through ExpressRoute and the Microsoft Enterprise Edge

Note: NSX-T is the differentiator versus running VMs in native Azure. On-prem network design assumptions — distributed firewall, micro-segmentation, NSX security tags — carry across without rebuild.

VMware HCX — workload mobility plane

HCX is the VMware-native workload mobility and migration plane bundled with every AVS deployment. HCX delivers live vMotion across the public internet or ExpressRoute, bulk migration with replication, cold migration for offline workloads, and Layer-2 network extension so workloads keep their IP addresses across the move.

  • HCX vMotion for live migration of running VMs from on-prem to AVS with zero downtime
  • HCX Bulk Migration using replication for cutover-style mass migration windows
  • HCX Replication Assisted vMotion (RAV) for live migration of large or warm-data workloads with replication pre-seeding
  • HCX Cold Migration for powered-off workloads in scheduled cutover waves
  • HCX Network Extension — stretched Layer-2 segments so workloads retain IP addresses, MAC addresses, and DNS records across the migration
  • HCX Mobility Optimized Networking (MON) for traffic-flow optimization after cutover

Note: HCX is the single biggest reason enterprises pick AVS over rebuilding workloads in native Azure VMs. Layer-2 extension eliminates the IP renumbering project that derails most native rebuilds.

AV36, AV52, AV64 host SKUs

AVS offers three bare-metal host SKUs — AV36 (general purpose), AV52 (compute and memory intensive), and AV64 (large-scale consolidation). Host selection drives cost, density, and workload-fit. Most customers blend SKUs across clusters to optimize for the workload portfolio.

  • AV36: dual Intel Xeon Gold 6240 (36 physical cores), 576 GB RAM, 15.36 TB NVMe cache + 19.2 TB raw vSAN — general-purpose enterprise workloads
  • AV52: dual Intel Xeon Platinum 8270 (52 physical cores), 1.5 TB RAM, 38.4 TB raw vSAN — memory-heavy SQL, SAP, Oracle, large VDI consolidation
  • AV64: dual Intel Xeon Platinum 8370C (64 physical cores), 1 TB RAM, 15.36 TB cache + 30.72 TB raw NVMe vSAN — high-density VM consolidation
  • Reserved Instance pricing — 1-year and 3-year terms with 25-50% discount versus pay-as-you-go
  • Azure Hybrid Benefit applies guest Windows Server and SQL Server license rights to the AVS workload, reducing per-host effective cost

Note: Right-sizing host count is the single largest cost lever. EPC Group AVS assessment models the customer VM portfolio against AV36 / AV52 / AV64 capacity to land on a minimum-viable host footprint.

Six enterprise patterns where AVS wins

Every AVS engagement composes from one or more of these patterns. EPC Group sequences the rollout against the business and regulatory priority list — datacenter lease exits, M&A close timelines, DR maturity, and regulatory boundary attestation.

Pattern 1 — VMware datacenter exit (full lift-and-shift)

A regulated enterprise with two on-premises VMware datacenters and 2,400 production VMs is facing a lease expiration in 14 months and does not want to renew. Native Azure rebuild would take three years and require rewriting application networking, identity, and storage assumptions per workload. AVS lift-and-shift moves the entire VMware estate — vCenter inventory, NSX-T security policy, vSAN storage, and HCX network extension — into an AVS private cloud in 14 to 26 weeks. Workloads keep their IP addresses, their security policy, and their operational runbooks. Post-cutover the modernization roadmap to native PaaS runs on cloud time, not on lease-clock time. The customer exits the datacenter on schedule, the application teams hit their refactor milestones over the following 18 months, and the cost model converts from capex datacenter spend to Azure OpEx with Reserved Instance discounting.

Pattern 2 — M&A datacenter consolidation

A Fortune 500 acquirer closes a $1.8B carve-out and inherits three VMware datacenters from the target. The acquirer is Azure-strategic, the target is not. Standing up duplicate operational stacks for three years while applications rationalize is unacceptable. AVS becomes the consolidation target — every target datacenter ships into a dedicated AVS private cloud in the acquirer Azure tenant, the security policy and identity model align to the acquirer governance plane through NSX-T and Microsoft Entra integration, and the application teams modernize on Azure-native PaaS at the pace the program funds. AVS de-risks the close-period operational handoff and gives the IT integration team a unified Azure governance plane without the rebuild cost.

Pattern 3 — Disaster recovery target without a second datacenter

A healthcare delivery organization runs primary VMware in one on-prem datacenter and has historically maintained a second on-prem datacenter solely for DR. The second datacenter is expensive, underutilized, and end-of-life. AVS becomes the new DR target — VMware Site Recovery Manager or Zerto orchestrates failover from on-prem to an AVS private cloud, HCX replication continuously syncs critical workloads, and ExpressRoute Global Reach provides the active-active path. The DR cost model converts from full-datacenter overhead to AVS Reserved Instance hosts plus per-VM replication. Annual DR test failovers run in AVS without the operational drag of maintaining the legacy second site. When the primary datacenter eventually exits, AVS becomes the active production target and the on-prem becomes the DR.

Pattern 4 — Burst capacity and seasonal expansion

A retail enterprise runs steady-state production on-prem VMware and historically over-provisions hardware to handle Black Friday plus holiday seasonal demand spikes. The over-provisioning capex is a recurring board complaint. AVS becomes the elastic capacity layer — base-load production stays on-prem, seasonal expansion VMs spin up in an AVS private cloud, HCX live-migrates workloads in and out as demand shifts, and ExpressRoute Global Reach makes the AVS extension look like another vSphere cluster from the on-prem operations perspective. Reserved Instance hosts cover predictable seasonal baselines, pay-as-you-go hosts cover unforecast spikes, and the over-provisioning capex line disappears from the annual budget.

Pattern 5 — Legacy app modernization staging ground

A financial services enterprise has 600 legacy applications running on VMware that the CIO wants modernized to Azure-native services over the next four years. A full lift-and-shift to native Azure VMs would require IP renumbering, security re-design, and operational retraining across the entire portfolio. AVS becomes the modernization staging ground — HCX moves the entire estate into AVS in three migration waves with zero workload code changes and zero IP renumbering, application teams then modernize at their own pace from the AVS staging environment onto AKS, App Service, Azure SQL, and Azure Functions, and decommissioned workloads release host capacity that gets right-sized down through cluster contraction. The CIO gets a five-year modernization roadmap on a stable AVS platform instead of a chaotic year-one rebuild.

Pattern 6 — Regulated industry on-prem-to-Azure migration

A defense contractor under CMMC 2.0 Level 2 obligation and a healthcare delivery organization under HIPAA Security Rule both run VMware on-prem with deeply customized security stacks — NSX-T micro-segmentation, third-party vTPM and HSM, regulated network zones — that cannot be rebuilt in native Azure without re-certifying the entire security boundary. AVS preserves the existing VMware security stack, including NSX-T policy and third-party vTPM integration, while moving the compute into an Azure-managed environment under the AVS BAA and the AVS FedRAMP authorization (AVS is FedRAMP High authorized in Azure Commercial and available in Azure Government Secret regions). The compliance boundary documentation carries across with the security policy. Recertification effort drops from 18 months of native rebuild to 6 weeks of AVS-on-Azure boundary attestation.

Connectivity — ExpressRoute, native Azure, Stretched Cluster

Connectivity design — AVS to on-prem and AVS to native Azure

The AVS network design has three workstreams — the private path from on-prem to AVS through ExpressRoute Global Reach, the path from AVS to native Azure PaaS through the customer ExpressRoute, and the multi-AZ resilience story through Stretched Cluster. All three lock at the assessment-phase deliverable, before the AVS private cloud gets provisioned. See the Azure Arc hybrid + multicloud guide for the broader hybrid governance plane that surrounds AVS.

ExpressRoute + ExpressRoute Global Reach

Every AVS private cloud lands behind a Microsoft-managed ExpressRoute circuit that connects the SDDC to the customer Azure virtual network. ExpressRoute Global Reach then peers the AVS ExpressRoute circuit to the customer on-prem ExpressRoute, creating a private Layer-3 path from on-prem datacenter to AVS that bypasses the public internet. Typical end-to-end latency between on-prem and a same-region AVS private cloud is 5 to 20 ms depending on circuit termination. HCX vMotion, replication, and network extension ride on this private path.

AVS to native Azure connectivity

AVS connects to native Azure services — Azure SQL, Azure Files, Azure Blob, Microsoft Entra ID, Azure Key Vault — through the same ExpressRoute circuit that anchors the SDDC. Workloads inside AVS reach Azure PaaS over private endpoint, Azure DNS Private Resolver handles the hybrid name resolution, and Microsoft Entra Domain Services projects identity into the AVS environment. The modernization on-ramp from AVS-hosted VM to Azure-native service is one ExpressRoute hop, not a rebuild.

Stretched Cluster — multi-AZ resilience

AVS Stretched Cluster on AV36 distributes a single vSAN datastore synchronously across two Azure availability zones with a third zone hosting the vSAN witness. The customer gets 99.99% workload SLA, automatic vSphere HA failover across zones, and zero data-loss recovery — meaningful for production tier-1 workloads where the cost of a regional outage exceeds the cost premium of stretched clustering. Stretched Cluster is configured at cluster creation time and cannot be retro-fit; AVS architectures with tier-1 workloads should be designed Stretched from day zero.

Cost optimization

Cost optimization — Reserved Instances, Hybrid Benefit, host right-sizing

Four levers control the AVS bill. Reserved Instance commitments anchor production at 25-50% off pay-as-you-go. Azure Hybrid Benefit applies the customer Software Assurance-backed Windows Server and SQL Server license rights to AVS workloads. Host-count and SKU-mix right-sizing prevents the 20-35% over-provisioning that most customer initial estimates carry. Consumption tiering blends Reserved + PAYG + scaled non-production. EPC Group locks all four at the assessment-phase deliverable.

Reserved Instance discounting (1-year and 3-year terms)

Reserved Instance commitments on AVS hosts deliver 25% to 50% discount versus pay-as-you-go pricing, with deeper discounts on 3-year terms. Most production AVS deployments lock the steady-state host footprint to 3-year Reserved Instances and reserve PAYG capacity for burst and migration-wave headroom. The financial model becomes predictable, the board sees flat OpEx, and the Reserved Instance is fungible across the AVS hardware SKUs in the same region — switching from AV36 to AV52 mid-term does not break the reservation.

Azure Hybrid Benefit — Windows Server + SQL Server license carry

Azure Hybrid Benefit lets the customer apply existing Software Assurance-backed Windows Server and SQL Server license rights to workloads running inside AVS, effectively eliminating the per-host guest OS and database license cost premium. For SQL-heavy AVS deployments this often saves 30% to 40% of the total bill of materials. The AHB application is per-workload, not per-host, so customers blend AHB-covered workloads with consumption-billed workloads on the same AVS cluster.

Right-sizing host count and SKU mix

The single largest cost lever in AVS is host-count right-sizing. AV36 hosts provide 576 GB RAM and 36 cores; AV52 provides 1.5 TB RAM and 52 cores; AV64 provides 1 TB RAM and 64 cores at higher density. EPC Group AVS assessment runs the customer VM portfolio against each SKU capacity model and recommends the minimum-viable host count plus SKU mix to fit the workload profile with realistic headroom. Most assessments find 20% to 35% lower host counts than the customer initial estimate because production on-prem VMware over-provisioning rarely transfers cleanly into the AVS density model.

Consumption tiering — Reserved + PAYG + spot for non-production

Reserved Instances anchor production. Pay-as-you-go covers migration-wave headroom and unforecast burst. Non-production environments (dev, test, sandbox) can live in PAYG clusters that scale down nightly and over weekends. The blended host-hour cost lands meaningfully below an all-Reserved or all-PAYG model. EPC Group ships the host-tier mix recommendation as part of the AVS assessment and revisits it quarterly through the operate-phase managed-service tail.

Migration patterns — HCX vMotion, replication, cold, dual-region

The HCX service mesh delivers four migration patterns plus a global dual-region pattern that EPC Group blends against the customer VM portfolio. Tier-1 production gets live vMotion or Replication Assisted vMotion. The mid-tier mass-migration waves use HCX Bulk Migration with replication pre-seeding. Non-production and legacy long-tail use Cold Migration. Global enterprises run dual-region from day zero.

HCX vMotion — live migration with zero downtime

HCX vMotion live-migrates a running VM from on-prem vSphere to AVS over the HCX service mesh — across the public internet or, preferably, over ExpressRoute. The workload keeps its IP address through HCX Network Extension, the application stays online, and the cutover window per VM is measured in seconds for the memory-state copy phase. HCX vMotion is the right pattern for tier-1 production workloads where any downtime is unacceptable but the VM footprint is small enough that per-VM migration is operationally feasible.

HCX Replication Assisted vMotion + Bulk Migration

For larger workloads or larger waves, HCX replicates the VM disks to AVS over hours or days while the source keeps running, then performs a final delta sync and switchover in a brief maintenance window. Replication Assisted vMotion (RAV) cuts the switchover to live-vMotion seconds; Bulk Migration accepts a longer scheduled cutover window in exchange for simpler operational handling. Most enterprise mass migrations use HCX Bulk Migration for the high-volume mid-tier and RAV for the latency-sensitive tier-1 subset.

HCX Cold Migration — scheduled cutover for offline workloads

Cold Migration powers off the source VM, copies the disks to AVS, and powers it on in the target — appropriate for non-production environments, batch workloads with defined maintenance windows, and legacy systems where the operations team accepts a longer downtime in exchange for migration simplicity. Cold Migration is the lowest-risk and lowest-cost option per VM. EPC Group typically reserves Cold Migration for the long-tail and uses RAV or Bulk for the production majority.

Dual-region migration pattern for global enterprises

Global enterprises with VMware datacenters on multiple continents typically deploy AVS into two Azure regions and migrate continent-by-continent. ExpressRoute Global Reach interconnects the AVS regions, HCX service meshes are anchored per region, and the migration wave plan aligns to the regional datacenter exit calendar. Identity, security policy, and operational tooling are designed for the eventual dual-region steady state from day zero so the program does not have to refactor the global topology mid-stream.

Broadcom licensing aftermath

Broadcom acquired VMware — what that means for AVS pricing and value

The Broadcom acquisition of VMware in November 2023 disrupted the on-prem VMware licensing market — perpetual licenses ended, subscription pricing spiked 2x to 10x at renewal for many customers, and partners were dropped from the channel. AVS sits in an insulated position because Microsoft bundles the VMware Cloud Foundation license inside the AVS host SKU pricing, billed through the Azure subscription. Four points of analysis below.

Broadcom acquired VMware in November 2023 — what changed

Broadcom completed the VMware acquisition in November 2023, immediately transitioned VMware from a perpetual-license model to subscription-only, consolidated the product portfolio into VMware Cloud Foundation (VCF) and vSphere Foundation (VVF) bundles, and ended many of the standalone product SKUs that enterprises had standardized on. Renewal prices for on-prem VMware spiked between 2x and 10x for many customers, channel partners were dropped, and the perpetual-license-plus-support model that anchored two decades of VMware deployments disappeared. Enterprises with on-prem VMware are now structurally re-evaluating the platform every renewal cycle.

How Broadcom licensing impacts AVS pricing

AVS is a first-party Microsoft service co-engineered with VMware (now Broadcom) — Microsoft bundles the VMware Cloud Foundation license inside the AVS host SKU pricing, billed through the Azure subscription, and the customer never holds a direct Broadcom VMware license for the workloads running inside AVS. This insulates AVS pricing from the volatile on-prem Broadcom renewal market. AVS host prices have been comparatively stable since the Broadcom transition; customers who feared AVS would become a Broadcom-pricing pass-through have not seen that materialize as of mid-2026.

AVS vs greenfield Azure VMs — the Broadcom-era decision

The Broadcom transition has tilted some enterprise decision-making toward leaving VMware entirely and rebuilding workloads on native Azure VMs. The right answer depends on workload count, modernization appetite, and time pressure. Enterprises with hundreds of VMware-anchored workloads under datacenter-lease pressure typically still pick AVS because the lift-and-shift is faster than a parallel rebuild, the security and network design carry across, and the modernization-on-AVS roadmap runs at the pace the program can fund. Enterprises with smaller VMware footprints, longer migration runways, and high modernization appetite increasingly skip AVS and rebuild directly on Azure VMs, AKS, App Service, and PaaS. EPC Group sizes the decision against the customer portfolio in the assessment phase.

Bring-your-own VMware license — still possible but rare

AVS does support a bring-your-own VMware license model for customers who already own Software Assurance-backed VMware entitlements they want to apply. In practice, the post-Broadcom VMware contract structure has made BYO meaningfully less attractive than the bundled AVS host pricing for most enterprises. Customers with deeply discounted legacy enterprise license agreements should run the math both ways during the assessment; most newer or smaller customers default to the bundled AVS pricing because the operational simplicity outweighs the residual license-arbitrage opportunity.

The EPC Group AVS Migration Accelerator — five phases, fixed fee

The accelerator anchors on The EPC Group Lifecycle — Assess, Foundation, Migrate, Govern, Modernize. Fixed-scope between $300,000 and $1,500,000 depending on workload count, multi-region scope, regulatory complexity, and the modernization tail. Senior architect on-record from kickoff through go-live, no offshore handoff, no T&M overrun.

Phase 1 — Assess

VMware estate inventory + AVS sizing in three weeks

Phase one is a fixed-fee assessment that inventories every vCenter, every cluster, every VM, every NSX-T policy, and every storage policy across the customer VMware estate. EPC Group runs the portfolio against AV36, AV52, and AV64 capacity models to land on a minimum-viable host count, builds the AVS network and identity design, and ships a costed five-year financial model with Reserved Instance, Hybrid Benefit, and consumption-tiering recommendations.

  • vCenter and cluster inventory across every customer datacenter, including over-provisioning analysis
  • VM portfolio classification by tier, by criticality, by HCX migration pattern, and by AVS host SKU fit
  • NSX-T policy inventory and translation plan for the AVS-side rebuild or extension
  • AVS network design — ExpressRoute, Global Reach, Azure native VNet integration, AVS-to-PaaS connectivity
  • Five-year TCO model with Reserved Instance commitment shape, Hybrid Benefit application, and PAYG tail

Phase 2 — Foundation

AVS private cloud, ExpressRoute, and identity plane stood up

Phase two provisions the AVS private cloud in the target Azure region, lights up ExpressRoute and Global Reach, stands up the NSX-T network design, integrates Microsoft Entra and Active Directory Domain Services into the AVS environment, and connects AVS to the customer landing zones and native Azure PaaS. The HCX service mesh is configured between on-prem and AVS, and the first pilot workload is migrated end-to-end to validate the platform.

  • AVS private cloud provisioned with the assessment-recommended cluster count and host SKU mix
  • ExpressRoute and ExpressRoute Global Reach lit between on-prem and AVS with private-path Layer 3
  • NSX-T Tier-0 and Tier-1 topology built out with BGP peering to the Azure network plane
  • Microsoft Entra ID and Active Directory Domain Services integrated into AVS for identity and DNS
  • HCX service mesh configured between on-prem vCenter and AVS vCenter, end-to-end validated through a pilot workload

Phase 3 — Migrate

HCX wave migration of the production VMware estate

Phase three executes the migration waves. EPC Group sequences workloads by criticality, dependency, and HCX migration-pattern fit — Cold Migration for the long-tail, Bulk Migration for the mid-tier, RAV and live vMotion for the tier-1 production workloads. Each wave runs through a documented runbook with named owners, validated rollback procedures, and signed-off cutover criteria. Migration velocity ramps from 20 to 50 VMs per week in the early waves to 150 to 300 VMs per week at peak cadence.

  • Wave plan sequenced by business unit, application dependency, and HCX migration pattern
  • Cold Migration for batch and non-production, Bulk Migration for the production mid-tier, RAV for tier-1
  • Per-wave runbook with cutover criteria, rollback procedures, and named owners across infrastructure and application teams
  • HCX Network Extension active during the wave so workloads keep IP addresses across the cutover
  • Post-wave validation — connectivity, identity, dependency, monitoring, and performance baselines per workload

Phase 4 — Govern

Azure Policy, Defender, and operational tooling on AVS

Phase four projects the customer governance model onto the AVS environment. Azure Policy initiatives apply at the AVS resource scope, Microsoft Defender for Cloud covers the AVS hosts and the workloads running inside, Azure Monitor captures the operational telemetry, and the customer ITSM and change-control plane integrates with the AVS administrative surface. The vCenter-side operational tooling — vRealize Operations, Log Insight, Network Insight — runs alongside the Azure-native governance plane.

  • Azure Policy initiatives applied at the AVS subscription and resource group scope for tag taxonomy, encryption, and configuration baselines
  • Microsoft Defender for Cloud — Defender for Servers Plan 2 on Windows + Linux workloads inside AVS, with Arc projection for unified posture
  • Azure Monitor + Log Analytics ingestion of AVS workload telemetry, integrated with the broader Azure governance plane
  • vRealize Operations and Log Insight stood up for VMware-native operational visibility
  • ITSM integration — ServiceNow, Jira Service Management, or Cherwell wired to the AVS change and incident workflows

Phase 5 — Modernize

AVS-to-PaaS modernization roadmap on cloud time

Phase five hands the customer a costed multi-year modernization roadmap from AVS-hosted VMs onto Azure-native PaaS — AKS for the containerizable workloads, Azure SQL Database and Managed Instance for the relational tier, App Service and Functions for the web and integration workloads, Azure Files for the unstructured-data workloads. AVS is the staging ground; native Azure is the destination. The modernization runs at the pace the program funds, on a stable platform, with no datacenter-clock pressure.

  • AKS rollout for the containerizable application tier, with Arc projection back into the central governance plane
  • Azure SQL Managed Instance migration plan for the SQL Server estate inside AVS
  • App Service and Azure Functions rollout for the web tier and integration workloads
  • Azure Files and Azure NetApp Files for the unstructured-data workloads currently on vSAN
  • AVS cluster contraction as workloads modernize off — Reserved Instance commitment re-shaped against the trailing footprint

Why EPC Group leads enterprise Azure VMware Solution migrations

1997
Founded · Microsoft consulting
70+
Fortune 500 clients
216+
M&A tenant consolidations
1.83 million
Users migrated

Microsoft Solutions Partner — Infrastructure

Microsoft Solutions Partner with the Infrastructure (Azure), Security, Modern Work, Data & AI, Digital & App Innovation, and Business Applications designations. Senior architects average two decades of VMware and Azure platform delivery experience.

Four-time author for Microsoft Press and Sams

Founder Errin O’Connor has nearly three decades of Microsoft consulting leadership and is a four-time author for Microsoft Press and Sams across Power BI and SharePoint.

Fixed-fee AVS engagements

Every AVS Migration Accelerator is fixed-fee with a costed five-year financial model and a named senior architect on-record from kickoff through go-live. No T&M overruns, no offshore handoff, no junior-analyst-led production cutover.

Compliance-native

EPC Group is compliance-native across HIPAA, SOC 2, FedRAMP, FINRA, CMMC, and GxP. AVS deployments ship with auditor-ready control matrices, Defender for Cloud regulatory dashboards, and Microsoft Sentinel detection content.

HIPAA
SOC 2
FedRAMP
FINRA
CMMC
GxP

Frequently asked questions — Azure VMware Solution

AVS vs native Azure VMs vs Oracle Cloud VMware Solution — which one wins for a VMware-anchored enterprise?

Azure VMware Solution, native Azure VMs, and Oracle Cloud VMware Solution (OCVS) are the three credible destinations for an on-prem VMware estate that needs to leave the datacenter. AVS wins for Microsoft-anchored enterprises because the SDDC sits inside the Azure governance plane, ExpressRoute lights up native Azure PaaS as a one-hop modernization on-ramp, Microsoft Entra and Azure Policy apply directly, and the Microsoft Customer Agreement vehicle covers the spend. Native Azure VMs wins when the customer has small VMware footprints, long modernization runways, and high modernization appetite — the rebuild cost is real but the result is a cleaner native-PaaS posture. OCVS wins primarily for Oracle-database-anchored enterprises where keeping the database tier physically adjacent to Oracle Exadata Cloud Service is the dominant requirement. EPC Group sizes the decision against the customer workload portfolio in the AVS assessment phase. For Microsoft-strategic enterprises with 200+ VMware-anchored workloads under datacenter pressure, AVS is almost always the right answer.

How do enterprises plan AVS host capacity — how many AV36, AV52, or AV64 hosts do I need?

Host count is the single largest cost lever in AVS, and on-prem VMware over-provisioning rarely transfers cleanly into the AVS density model. EPC Group runs the customer VM portfolio — CPU, memory, storage, IOPS, and growth headroom — against each SKU capacity model. AV36 fits general-purpose enterprise workloads with 576 GB RAM and 36 cores per host. AV52 fits memory-heavy workloads (SQL, SAP, Oracle, large VDI consolidation) with 1.5 TB RAM and 52 cores. AV64 fits high-density VM consolidation with 1 TB RAM and 64 cores. Most enterprise AVS deployments blend SKUs across clusters — AV36 for general production, AV52 for the database tier, AV64 for consolidation density. Realistic host counts for typical enterprise VMware estates land between 12 and 64 hosts across 2 to 6 clusters per region. The assessment-phase capacity model usually recommends 20% to 35% fewer hosts than the customer initial estimate.

What does a typical AVS network design look like?

Every AVS private cloud lands behind a Microsoft-managed ExpressRoute circuit that terminates inside Azure. ExpressRoute Global Reach peers the AVS ExpressRoute to the customer on-prem ExpressRoute, creating a private Layer-3 path from on-prem datacenter to AVS that bypasses the public internet. NSX-T Tier-0 and Tier-1 gateways inside the AVS SDDC handle the workload-side routing, distributed firewall, and micro-segmentation. Native Azure services — Azure SQL, Key Vault, Blob, Entra ID — reach the AVS workloads through the same ExpressRoute circuit using private endpoint. HCX rides the same path for migration and for ongoing Layer-2 network extension. For tier-1 workloads with multi-AZ resilience requirements, Stretched Cluster on AV36 distributes a vSAN datastore synchronously across two Azure availability zones. The full network design lands in the assessment phase deliverable.

Can I bring my own VMware license to AVS — and does that save money in the post-Broadcom era?

AVS supports a bring-your-own VMware license model for customers who already own Software Assurance-backed VMware entitlements. In practice, the post-Broadcom VMware contract structure has made BYO meaningfully less attractive than the bundled AVS host pricing for most enterprises. Microsoft bundles the VMware Cloud Foundation license inside the AVS host SKU pricing — the customer never holds a direct Broadcom VMware license for the AVS workloads — and AVS host prices have been comparatively stable since the Broadcom transition. Customers with deeply discounted legacy enterprise license agreements should run the math both ways during the assessment, but most newer or smaller customers default to the bundled AVS pricing because the operational simplicity outweighs the residual license-arbitrage opportunity. The cost savings most customers actually capture come from Reserved Instance commitments and from Azure Hybrid Benefit on the guest Windows Server and SQL Server licenses, not from BYO VMware.

How does AVS compare to Azure Stack HCI for hybrid VMware-style workloads?

AVS and Azure Stack HCI solve different problems despite both being Microsoft-managed hybrid platforms. AVS is a destination service inside an Azure region — the customer leaves the datacenter and runs the VMware workloads inside Azure with Microsoft operating the underlying VMware Cloud Foundation stack. Azure Stack HCI is on-prem hyperconverged infrastructure that runs Hyper-V-based virtualization on customer-owned hardware in the customer datacenter, with Azure as the governance plane. The decision is about where the workload physically lives. Enterprises exiting the datacenter pick AVS. Enterprises that need to keep compute on-prem for latency, data residency, or regulatory reasons pick Azure Stack HCI. Many enterprises run both — AVS as the cloud destination for the bulk of the VMware estate and Azure Stack HCI at the edge sites that cannot leave physical premises. See the Azure Arc Hybrid + Multicloud guide for the broader hybrid model.

How does HCX Network Extension work and why does it matter for the migration?

HCX Network Extension stretches a Layer-2 segment from the on-prem VMware environment into the AVS SDDC, so workloads migrating from on-prem to AVS keep their IP addresses, MAC addresses, DNS records, and ARP behavior. Without Network Extension every migrated workload would need to be renumbered, every DNS record updated, every firewall rule rewritten, and every application configuration touched — a project-killer at enterprise scale. With Network Extension the migration becomes operationally invisible to the application teams; the workload simply appears in the AVS vCenter with its on-prem IP intact. HCX Mobility Optimized Networking optimizes the post-cutover traffic flow so workloads do not hair-pin through the extension after the migration completes. This is the single biggest reason enterprises pick AVS lift-and-shift over a native Azure VM rebuild — the rebuild requires IP renumbering, AVS does not.

How does AVS handle compliance — HIPAA, FedRAMP, CMMC, FINRA, PCI DSS?

AVS in Azure Commercial holds the standard Azure regulatory certifications including HIPAA, FedRAMP High, SOC 2 Type II, ISO 27001, and PCI DSS. AVS in Azure Government holds the FedRAMP High and DoD IL5 authorizations and is the platform of choice for CMMC 2.0 Level 2 and Level 3 obligated defense contractors. The customer-side compliance work focuses on the workloads inside AVS — applying the NSX-T micro-segmentation, the Defender for Cloud regulatory dashboards, the Microsoft Sentinel detection content, and the Azure Policy compliance initiatives that map to the framework. The AVS BAA covers HIPAA-regulated workloads. EPC Group ships the framework-specific control matrix and the auditor-ready evidence package as part of the AVS Govern phase. The /government-federal-microsoft-consulting-fedramp-cmmc-2026 hub covers the federal-specific story.

What does a typical AVS engagement cost and what is the EPC Group AVS Migration Accelerator fee model?

AVS itself is billed through the Azure subscription — Reserved Instance host commitments anchor the steady-state model, pay-as-you-go covers migration headroom and burst. Azure Hybrid Benefit on Windows Server and SQL Server typically reduces the gross host bill by 25% to 40%. Annual AVS host spend for typical enterprise deployments ranges from $400K (12-host minimum-viable) to $8M+ (large multi-region estate). The EPC Group AVS Migration Accelerator is a fixed-fee professional services engagement priced between $300K and $1.5M depending on workload count, multi-region scope, regulatory complexity, and the modernization tail the customer wants embedded. Pricing is locked at the assessment-phase deliverable so the customer has board-ready numbers before any cluster gets provisioned. Senior architect on-record from kickoff through go-live, no offshore handoff, no T&M overrun.

Continue exploring the EPC Group enterprise Microsoft library

Azure VMware Solution sits inside a broader Microsoft cloud orchestration and datacenter modernization story. These hubs and analyses cover adjacent and complementary territory.

Exit the VMware datacenter on schedule — modernize on cloud time

Book an AVS migration briefing with an EPC Group senior architect. Two-hour working session — VMware estate inventory, AVS host-sizing model, HCX wave plan, five-year financial model. Zero obligation, board-ready output.

AI assistant — not human