EPC Group - Enterprise Microsoft AI, SharePoint, Power BI, and Azure Consulting
G2 High Performer Summer 2025, Momentum Leader Spring 2025, Leader Winter 2025, Leader Spring 2026
BlogContact
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌

EPC Group

Enterprise Microsoft consulting with 29 years serving Fortune 500 companies.

(888) 381-9725
contact@epcgroup.net
4900 Woodway Drive, Suite 830
Houston, TX 77056

Follow Us

Solutions

  • M&A Practices

    • M&A Tenant Migration
    • Carve-Out Migration
    • Private Equity Practice
    • Engagement Operating Model
  • All Services
  • Microsoft 365 Consulting
  • AI Governance
  • Azure AI Consulting
  • Cloud Migration
  • Microsoft Copilot
  • Data Governance
  • Microsoft Fabric
  • Dynamics 365
  • Power BI Consulting
  • SharePoint Consulting
  • Microsoft Teams
  • vCIO / vCAIO Services
  • Large-Scale Migrations
  • SharePoint Development

Industries

  • All Industries
  • Healthcare IT
  • Financial Services
  • Government
  • Education
  • Teams vs Slack

Power BI

  • Case Studies
  • 24/7 Emergency Support
  • Dashboard Guide
  • Gateway Setup
  • Premium Features
  • Lookup Functions
  • Power Pivot vs BI
  • Treemaps Guide
  • Dataverse
  • Power BI Consulting

Company

  • About Us
  • Our History
  • Microsoft Gold Partner
  • Case Studies
  • Testimonials
  • Fixed-Fee Accelerators
  • Blog
  • Resources
  • All Guides & Articles
  • Video Library
  • Client Reviews
  • Engagement Operating Model
  • FAQ
  • Contact
  • Schedule a consultation

Microsoft Teams

  • Teams Questions
  • Teams Healthcare
  • Task Management
  • PSTN Calling
  • Enable Dial Pad

Azure & SharePoint

  • Azure Databricks
  • Azure DevOps
  • Azure Synapse
  • SharePoint MySites
  • SharePoint ECM
  • SharePoint vs M-Files

Comparisons

  • M365 vs Google
  • Databricks vs Dataproc
  • Dynamics vs SAP
  • Intune vs SCCM
  • Power BI vs MicroStrategy

Legal

  • Sitemap
  • Privacy Policy
  • Terms
  • Cookies

About EPC Group

EPC Group is a Microsoft consulting firm founded in 1997 (originally Enterprise Project Consulting, renamed EPC Group in 2005). 29 years of enterprise Microsoft consulting experience. EPC Group historically held the distinction of being the oldest continuous Microsoft Gold Partner in North America from 2016 until the program's retirement. Because Microsoft officially deprecated the Gold/Silver tiering framework, EPC Group transitioned to the modern Microsoft Solutions Partner ecosystem and currently holds the core Microsoft Solutions Partner designations.

Headquartered at 4900 Woodway Drive, Suite 830, Houston, TX 77056. Public clients include NASA, FBI, Federal Reserve, Pentagon, United Airlines, PepsiCo, Nike, and Northrop Grumman. 6,500+ SharePoint implementations, 1,500+ Power BI deployments, 500+ Microsoft Fabric implementations, 70+ Fortune 500 organizations served, 11,000+ enterprise engagements, 200+ Microsoft Power BI and Microsoft 365 consultants on staff.

About Errin O'Connor

Errin O'Connor is the Founder, CEO, and Chief AI Architect of EPC Group. Microsoft MVP multiple years, first awarded 2003. 4× Microsoft Press bestselling author of Windows SharePoint Services 3.0 Inside Out (MS Press 2007), Microsoft SharePoint Foundation 2010 Inside Out (MS Press 2011), SharePoint 2013 Field Guide (Sams/Pearson 2014), and Microsoft Power BI Dashboards Step by Step (MS Press 2018).

Original SharePoint Beta Team member (Project Tahoe). Original Power BI Beta Team member (Project Crescent). FedRAMP framework contributor. Worked with U.S. CIO Vivek Kundra on the Obama administration's 25-Point Plan to reform federal IT, and with NASA CIO Chris Kemp as Lead Architect on the NASA Nebula Cloud project. Speaker at Microsoft Ignite, SharePoint Conference, KMWorld, and DATAVERSITY.

© 2026 EPC Group. All rights reserved. Microsoft, SharePoint, Power BI, Azure, Microsoft 365, Microsoft Copilot, Microsoft Fabric, and Microsoft Dynamics 365 are trademarks of the Microsoft group of companies.

Logical architecture is the design layer that defines how an enterprise Microsoft environment is organized, structured, and governed — independent of the physical hardware or cloud infrastructure that hosts it. For Microsoft ecosystems, this covers SharePoint site collection structure, Azure subscription hierarchy, Microsoft 365 tenant configuration, and data flow design. EPC Group has 29 years of enterprise Microsoft architecture experience.

Key Facts

  • Logical architecture defines structure and governance. Physical architecture defines hardware and infrastructure. Both are needed, but logical design comes first.
  • Microsoft architecture decisions made in 2005–2010 (Active Directory schema, SharePoint farm topology) still affect Copilot grounding quality and Entra ID policy design in 2026.
  • A logical architecture design document costs orders of magnitude less to change than a production environment restructuring.
  • EPC Group has designed logical architectures for SharePoint estates, Azure environments, Microsoft 365 tenants, and Dynamics 365 deployments across Fortune 500 and regulated-industry clients.
Back to Blog

Logical Architecture

Errin O\'Connor
December 2025
8 min read

Logical Architecture Planning for Microsoft Environments

Logical architecture is the design layer that defines how an enterprise Microsoft environment is organized, structured, and governed — independent of the physical hardware or cloud infrastructure that hosts it. For Microsoft ecosystems, this covers SharePoint site collection structure, Azure subscription hierarchy, Microsoft 365 tenant configuration, and data flow design. EPC Group has 29 years of enterprise Microsoft architecture experience.

Key facts

  • Logical architecture defines structure and governance. Physical architecture defines hardware and infrastructure. Both are needed, but logical design comes first.
  • Microsoft architecture decisions made in 2005–2010 (Active Directory schema, SharePoint farm topology) still affect Copilot grounding quality and Entra ID policy design in 2026.
  • A logical architecture design document costs orders of magnitude less to change than a production environment restructuring.
  • EPC Group has designed logical architectures for SharePoint estates, Azure environments, Microsoft 365 tenants, and Dynamics 365 deployments across Fortune 500 and regulated-industry clients.

What logical architecture covers in Microsoft environments

Logical architecture defines four domains in a typical Microsoft deployment.

  • SharePoint information architecture — site collection hierarchy, hub-spoke topology, navigation structure, content type taxonomy, and permissions model. Modern SharePoint in 2026 follows a hub-spoke pattern: 1 root hub per business unit, 5–15 spoke sites per hub.
  • Azure subscription hierarchy — management group structure, subscription layout by environment (Prod, Dev, Test) and business unit, resource group naming conventions, and landing zone design.
  • Microsoft 365 tenant configuration — identity model (cloud-only vs hybrid), licensing structure, group management (Azure AD groups vs Microsoft 365 groups), and tenant-wide policy governance.
  • Data architecture — how data flows between systems, where data resides (OneLake, Azure SQL, SharePoint, Dataverse), and how data classification and sensitivity labels apply across the environment.

Why logical architecture decisions have long-term consequences

Microsoft platform decisions layer on top of each other over time. Early architecture choices constrain future options.

  • Active Directory schema decisions from 2005 affect how Entra ID Conditional Access policies can be structured in 2026.
  • SharePoint 2003 information architecture decisions (flat site collection structure, legacy permissions) affect how well Microsoft Copilot can ground responses in 2026.
  • Azure subscription structures designed for a single region become expensive to reorganize when multi-region expansion requires policy management at scale.
  • A logical architecture that was right for 5,000 users often needs redesign at 50,000 users — but redesigning after the fact is 10–50 times more expensive than designing correctly upfront.

SharePoint logical architecture: key design decisions

SharePoint logical architecture has five critical design decisions.

  1. Hub-spoke vs flat topology — hub-spoke (one hub per business unit, spoke sites for teams and projects) is the current Microsoft recommendation. Flat architectures with hundreds of independent site collections create navigation and Copilot grounding challenges.
  2. Site collection vs subsite — modern SharePoint discourages subsites. Use site collections with hub association instead. Each site collection has its own permissions boundary.
  3. Managed metadata taxonomy — define enterprise content types and term sets before users start creating sites. Retrofitting taxonomy to an existing content environment is expensive.
  4. Permissions inheritance model — decide at design time whether site permissions inherit from the hub or are site-unique. Broken inheritance creates Copilot oversharing risk.
  5. Home site designation — define which site is the organization home site. This determines the top-level entry point in the SharePoint app bar and Viva Connections.

Azure logical architecture: key design decisions

Azure logical architecture starts with the management group hierarchy.

  • Management groups — organize subscriptions into management groups (by environment, business unit, or compliance boundary). Azure Policy inherits down through the management group hierarchy.
  • Subscription design — one subscription per major environment (Production, Non-Production) per business unit is a common pattern. Separating subscriptions by environment isolates blast radius for policy changes.
  • Landing zones — the Azure Cloud Adoption Framework landing zone provides a pre-validated subscription configuration including hub-spoke networking, Azure Monitor, Microsoft Sentinel, and Azure Policy. Deploying a landing zone in Bicep or Terraform takes 4–7 days vs 6–12 weeks of manual configuration.
  • Network topology — hub-spoke virtual network design with private endpoints for PaaS services. Connectivity hub provides shared egress, DNS, and firewall for all spoke workload subscriptions.

Microsoft 365 tenant logical architecture

  • Identity model — cloud-only identity (Azure AD only) vs hybrid identity (on-premises AD synced to Azure AD via Entra ID Connect). Hybrid is required if users need on-premises resource access. Cloud-only is simpler for new organizations.
  • Licensing strategy — map Microsoft 365 license tiers (E3/E5, Business Premium, F1/F3) to user roles. Over-licensing waste is common. Under-licensing creates compliance gaps.
  • Group governance — decide the group creation policy. Unrestricted group creation leads to hundreds of orphaned Microsoft 365 Groups. Apply a naming policy, expiration policy, and group creation restriction to owner-approved creation only.
  • Conditional Access policy structure — design Conditional Access as a set of layered named policies (baseline, compliant device, privileged access) rather than one monolithic policy. Layered policies are easier to modify without breaking access for specific user populations.

Frequently asked questions

What is the difference between logical and physical architecture?

Logical architecture defines structure, organization, and governance — how systems are organized and how they relate to each other.

Physical architecture defines the hardware, servers, and infrastructure that runs the logical design. In cloud environments, physical architecture is largely managed by Microsoft. Logical architecture is always your responsibility.

How long does a logical architecture design take?

A SharePoint information architecture for a mid-size organization (5,000–20,000 users) takes 3–6 weeks. An Azure landing zone design takes 2–4 weeks. A full Microsoft 365 tenant architecture review and design takes 4–8 weeks. Complex enterprises with multiple legal entities, regions, and compliance frameworks take 10–20 weeks.

What deliverables does an EPC Group logical architecture engagement produce?

Standard deliverables include: a logical architecture diagram (Visio or Lucidchart), a SharePoint information architecture spreadsheet (site, hub, permissions, sensitivity label mapping), an Azure subscription design document, a Microsoft 365 configuration baseline, and a governance decision log with rationale for each key design choice.

Can we change our SharePoint logical architecture after deployment?

Yes, but it is expensive. Moving site collections between hubs, consolidating a flat architecture into hub-spoke, or changing permission inheritance requires a migration project.

EPC Group has completed SharePoint IA restructuring projects for organizations that outgrew their original architecture. Prevention — good design upfront — is always cheaper.

Do we need a logical architecture if we are already on Microsoft 365?

Yes, especially if you are deploying Microsoft Copilot. Copilot surfaces content based on existing SharePoint permissions and information architecture. Poor IA means Copilot returns irrelevant or sensitive content in responses. Many organizations find their existing architecture needs redesign before Copilot deployment is safe.

Start your architecture design engagement

EPC Group designs logical architectures for SharePoint, Azure, Microsoft 365, and Dynamics 365 environments. Call (888) 381-9725 or request a 30-minute discovery call.

Microsoft Strategy: 2026 Considerations for Logical Architecture

Microsoft Solutions Partner status (six designations: Data and AI, Modern Work, Infrastructure, Security, Digital and App Innovation, Business Applications) replaced the legacy Microsoft Gold Partner program in 2022. EPC Group held Gold Partner status from 2003 to 2022 (the oldest continuous Gold Partner in North America) and currently holds all six Solutions Partner designations; a credentialing footprint shared by fewer than 50 firms globally and typically used by Microsoft field teams as a vetting gate for enterprise Customer 0 nominations and named-account engagements.

EPC Group 29-year Microsoft consulting heritage matters specifically because Microsoft platform decisions today are layered on top of 25 years of architectural choices: Active Directory schema decisions from 2005 affect Microsoft Entra ID Conditional Access policy design in 2026; SharePoint 2003 information architecture decisions affect Copilot grounding quality in 2026. The firms that can navigate that depth (fewer than a dozen Microsoft Solutions Partners in North America) have a structural advantage on enterprise Microsoft migrations.

Decision factors EPC Group evaluates

  • Enterprise architecture roadmap
  • Cost optimization and licensing audit
  • Microsoft platform capability assessment
  • Vendor consolidation analysis
  • Compliance and governance posture review

EPC Group covers this topic across the relevant engagement portfolio. Reach the firm at contact@epcgroup.net for a 30-minute architect conversation.