The ticket
Twelve minutes. Whiteboard: dc01 10.20.30.10, fgt-hq 203.0.113.10, pay-api 10.20.30.40, Azure hub 10.40.0.0/16, AWS hub 10.50.0.0/16. They will ask if hybrid is a failure. It is not. An accidental hybrid with two password islands is.
Name the decision (R, landing, identity, path, control, rollback) → name the object (MG, tunnel, A record, NSG vs Firewall) → name the proof (IKE list, nslookup, POST /v1/pay, Sentinel hit) → name the trap. Weak: “we will lift and then see.” Strong: “wave-1 is pay-api rehost into sub-spoke-app after Connect sync and vpn-azure; success is POST /v1/pay; on-prem stays read-only.”
On-prem DC dc01 10.20.30.10 · FortiGate fgt-hq 203.0.113.10 · same Azure landing as the Azure series and same AWS landing as the AWS series. Wave-1 app pay-api today on VM 10.20.30.40.
Hybrid forever vs exit
| Hybrid forever | Exit | |
|---|---|---|
| Meaning | On-prem stays a site. Cloud is another site. | A program to empty the DC, last thing is identity/data. |
| This lab | Valid — dc01 retain, SQL may stay, pay-api rehost | Valid — but not wave-1, and not this weekend |
| Identity | Connect / Cloud Sync stays | Cutover directory only after apps do not need Kerberos |
| Network | VPN then maybe ER/DX | Same, until the last subnet leaves |
| Failure mode | Two password islands, two writers | Deleting on-prem before soak / before identity exit |
Hybrid is the default for wave-1. Exit is a portfolio, not a cutover step.
What they score
Landing zone · identity · network · control map · rollback. If your answer skips those five, it is a feature dump.
16 questions
Q1 · Lift the DC this weekend?
PM wants every VM on 10.20.30.0/24 moved.
Q2 · What is a landing zone?
They point at a subscription with one VM.
Q3 · Where does pay-api land?
Junior used his personal subscription.
Q4 · New Entra passwords for everyone?
Cloud team sent welcome mail.
Q5 · Connect vs Cloud Sync?
One forest, no federation yet.
Q6 · AWS humans with access keys?
Someone created IAM users.
Q7 · ExpressRoute first?
Circuit is eight weeks out.
Q8 · VPN up, app dead?
IKE green. Users still on the old box.
Q9 · Overlapping CIDR?
Someone wants the spoke to be 10.20.30.0/24.
Q10 · Lift or rebuild?
OS is supportable, app is a black box.
Q11 · IP + DNS + auth tonight?
Junior wants one big change.
Q12 · NSG equals FortiGate?
Checklist says “NSG allow 443.”
Q13 · Drop WAF because cloud is secure?
Budget slide.
Q14 · VM running — are we done?
Portal is green.
Q15 · Delete on-prem at flip?
License saving.
Q16 · Hybrid forever or exit?
The closer.
Weak vs strong
| Weak | Strong |
|---|---|
| Lift everything / reboot the VM | 6 Rs, wave-1 = pay-api |
| We have a subscription | MG/OU, hub 10.40 or 10.50, logs first |
| Cloud-only accounts | Connect / Cloud Sync + IAM Identity Center |
| Wait for ExpressRoute | VPN now, ER/DX later |
| NSG is the firewall | Control map including IPS/WAF/SIEM |
| VM is running | POST /v1/pay + rollback DNS |
How to prove it
You can walk Q1, Q8, Q12, Q14, Q16 in 90 seconds each with dummy IPs and one proof command each (IKE list, nslookup, control-map row, curl POST, DNS revert).
Traps
Memorising “6 Rs” without a wave-1 sentence still fails. Hybrid forever is allowed. Two writers and two password islands are not.
Knowledge check
Judgment items. One best answer. Reasons send you back to the matching section.
On-prem to cloud migration class series: 6 Rs · Landing zone first · Identity first · VPN / ER / DX · Lift vs rebuild · Map controls · Cutover + rollback · Hybrid interview
Sources
- This series lessons 1–7 — 6 Rs, landing zone, identity, VPN/ER/DX, lift vs rebuild, control map, cutover.
- AWS 6 Rs.
- Azure CAF Migrate.
- Entra Connect.
- ExpressRoute · Direct Connect.
- Azure hub-spoke · AWS TGW.
Related: Azure landing zone · AWS Org / OU.