What is Azure Managed Applications?
Azure Managed Applications lets software vendors (ISVs), managed service providers (MSPs), and system integrators deploy solutions that run in a dedicated resource group inside the customer’s Azure subscription while remaining manageable by the publisher. This combines the customer’s control over their subscription with the publisher’s expertise for maintenance, support, and updates.
Unlike classic solution templates, a managed application includes a “managed resource group” to which the publisher can optionally be granted defined access. Managed applications are published either to an organization’s internal service catalog or publicly to Azure Marketplace.
Core Features
- Separation of the application resource group (customer) and the managed resource group (publisher access)
- ARM template-based definition of the entire solution (resource type
Microsoft.Solutions) - Multiple permission models: publisher-managed, shared access, locked mode, or fully customer-managed
- Just-in-time access for time-limited publisher permissions
- Marketplace integration for sales and billing through Azure
- Compliance enforcement on the managed resource group via Azure Policy
Typical Use Cases
ISV Solutions: Software vendors distribute their products via Azure Marketplace and take on ongoing operation and support for customers.
Enterprise Templates: Organizations provide standardized, approved application stacks to departments through an internal service catalog.
Partner and MSP Solutions: System integrators and managed service providers offer preconfigured solutions that they operate inside the customer tenant.
Benefits
- Customers keep the subscription and general data sovereignty in their own tenant
- Publishers can centrally maintain, update, and support solutions
- Flexible permission models allow anything from full self-service to fully managed operation
- Billing via Azure Marketplace simplifies procurement and cost control
Frequently Asked Questions
What is a managed resource group?
The managed resource group holds all resources required by the application, such as virtual machines, storage, or networking. Depending on the permission model, the publisher receives defined access to it while the customer manages the separate application resource group.
Can customers modify the resources themselves?
That depends on the chosen permission model. In the default “publisher managed” model, a deny assignment restricts customer access; in “customer managed” mode, the customer has full control and the publisher has no access.
How does billing work?
Customers pay for the Azure resources used plus an optional publisher fee for licensing and support. Billing happens through Azure Marketplace or an existing Enterprise Agreement.
What is the difference from classic solution templates?
Solution templates are fully managed by the customer after deployment and offer no publisher access model. Managed applications, by contrast, enable ongoing management, updates, and support by the publisher.
Integration with innFactory
As a Microsoft Solutions Partner, innFactory supports you in designing and deploying Azure Managed Applications. We help with architecture, permission model design, Marketplace integration, and lifecycle management.
Contact us for a non-binding consultation on Azure Managed Applications.
Note: All product information on this page has been compiled with care, but is provided without guarantee and may be outdated or incomplete. Cloud services evolve rapidly — features, pricing, SLAs, and availability change frequently. Authoritative and up-to-date information can only be found on the official product page of Azure (official documentation). This page does not represent an offer by Azure.
