Macquarie Government has launched a dedicated Microsoft Azure practice for Australian federal and state agencies, extending its long-established sovereign cloud and cybersecurity business into managed public cloud for the first time. Announced on July 22, 2026, the move gives agencies a locally operated option for managing Azure, Microsoft security services, virtual desktops, hybrid infrastructure, data platforms and emerging artificial intelligence workloads while retaining direct oversight of their environments. The significance is not simply that another Microsoft partner has entered government contracting; Macquarie is attempting to connect hyperscale Azure services with Australian ownership, security-cleared personnel, PROTECTED-ready architecture and two decades of public-sector operational experience.

Cybersecurity operations center visualizing protected Australian cloud infrastructure and data centers.Background​

Macquarie Government is the public-sector arm of Macquarie Technology Group, an Australian-owned company spanning telecommunications, cloud services, cybersecurity and data centres. Its government business has spent more than 20 years building relationships with agencies that handle sensitive information, and the company says it currently provides cybersecurity services to 42 percent of Australian federal government agencies.
Until now, Macquarie Government’s cloud proposition has focused heavily on private infrastructure, secure hosting, sovereign data centres and managed cyber defence. Its sister division, Macquarie Cloud Services, established a commercial Azure practice through a strategic Microsoft agreement in February 2020 and has since spent approximately seven years developing the delivery model now being adapted for government.

From private hosting to hybrid government cloud​

That history matters because Australian government cloud adoption has not followed a simple path from agency data centres to public cloud. Departments frequently operate a mixture of ageing on-premises applications, outsourced infrastructure, private cloud platforms, Microsoft 365 services and workloads distributed across one or more hyperscalers.
The result is a hybrid estate that may be more flexible than the infrastructure it replaced but is not necessarily easier to manage. Agencies must coordinate identity, networking, logging, data classification, procurement, incident response and cost controls across multiple operational boundaries.
Macquarie’s new practice is therefore entering a relatively mature market. Many agencies already have Azure subscriptions and Microsoft enterprise agreements; their problem is increasingly how to govern, secure and extract value from those environments, rather than how to purchase cloud capacity for the first time.

A government-specific adaptation​

The new practice is led by Naran McClung, executive head of Azure at Macquarie Cloud Services, who also led the original commercial Azure operation. Macquarie has adapted that model for government classifications and security obligations, including workloads assessed at the Australian Government’s PROTECTED level.
Former Defence adviser Dr Chris Peiris has also joined the Canberra team as Microsoft Security and Azure lead. That appointment highlights the importance of combining platform engineering with an understanding of government risk management, procurement and accountability.

Why Macquarie Is Launching the Practice Now​

The timing reflects three forces converging across the Australian public sector: legacy modernisation, intensifying cyber risk and the demand to make government data usable for artificial intelligence. Azure sits near the centre of all three because Microsoft already supplies productivity, identity, endpoint management, security and cloud services throughout government.
Agencies consequently face pressure to rationalise overlapping platforms without creating an even larger dependency on a single technology supplier. A managed-services partner can help operate that environment, but it can also become another layer of complexity if responsibilities are not precisely defined.

Cloud adoption has entered its operational phase​

The first wave of public cloud adoption often concentrated on migration. Teams moved virtual machines, created subscriptions and replicated familiar data-centre architectures inside infrastructure-as-a-service platforms.
The operational phase is more difficult. Cloud resources can be provisioned quickly, billed through multiple accounts and changed continuously, so traditional annual reviews and static security documentation become inadequate.
A serious Azure operating model must continually answer practical questions:
  • Who can create a subscription, resource group or public endpoint?
  • Which regions and services may host each classification of information?
  • How are privileged actions approved and recorded?
  • Who investigates alerts across identity, endpoints, networks and workloads?
  • How does an agency identify resources that are idle, oversized or incorrectly licensed?
  • Who updates controls when Microsoft changes a service or the government changes its policy?
Macquarie is positioning the practice around these day-two responsibilities. That is a more credible proposition than treating cloud migration as a one-off infrastructure project.

AI has raised the stakes​

Artificial intelligence has increased the urgency because agencies cannot safely deploy advanced models on top of poorly governed data. Before generative AI can assist with case management, policy analysis, citizen services or internal workflows, an agency needs reliable identity controls, classified data pathways, defensible access rules and auditable model operations.
Macquarie’s offer links Managed Azure with Microsoft Fabric, hybrid infrastructure and security tooling. The underlying pitch is that AI readiness begins with cloud governance, not with purchasing a chatbot.

What the Azure Practice Will Deliver​

Macquarie Government’s portfolio includes Managed Azure, Microsoft Sentinel, Microsoft extended detection and response services, Azure Virtual Desktop, Azure Local and managed Microsoft Fabric capabilities. These components cover the major layers of a modern Microsoft government environment: infrastructure, identity, endpoint access, security operations, data engineering and hybrid deployment.
That breadth could help agencies reduce fragmentation, although the practical value will depend on how well Macquarie integrates the services rather than selling them as separate products.

Managed Azure and landing zones​

The foundation is a managed Azure service built around standardised landing zones. A landing zone establishes the subscription structure, network topology, identity model, policy assignments, logging, naming standards and deployment controls within which agency applications operate.
Macquarie says its government landing zones are designed to support PROTECTED workloads from the outset. The architecture incorporates Microsoft’s Cloud Adoption Framework, Information Security Manual-aligned guardrails, Center for Internet Security benchmarks, Essential Eight controls and Microsoft Entra governance.
A well-designed landing zone does not make every application compliant automatically. It reduces the number of architectural decisions each project must repeat and makes unsafe configurations more difficult to introduce.

Microsoft Sentinel and extended detection and response​

Microsoft Sentinel provides cloud-native security information and event management, while Microsoft’s broader extended detection and response stack correlates activity across identities, endpoints, email, applications and cloud resources. Macquarie will combine these products with managed monitoring and response services.
For government customers, the important question is not whether the tools can produce more alerts. Most security teams already have an abundance of telemetry. The issue is whether an operator can convert those signals into timely investigations, containment actions and evidence suitable for agency reporting.
Macquarie’s existing government security operations provide a potentially valuable base. The new practice can connect Azure platform management with incident response instead of forcing an agency to mediate between unrelated cloud and security suppliers.

Azure Virtual Desktop​

Azure Virtual Desktop can provide managed Windows workspaces and applications without placing all data on the user’s physical PC. This is useful for distributed workforces, contractors, temporary project teams and access to specialised applications.
However, virtual desktops are not inherently secure simply because they run in Azure. Agencies still need conditional access, strong authentication, endpoint validation, session controls, application management, data-loss protections and suitable capacity planning.
Macquarie is marketing a government-oriented implementation with classification-aware controls and predictable management. Success will depend on whether it can deliver a responsive Windows experience while avoiding the cost and profile sprawl that have undermined some earlier virtual desktop deployments.

A Co-Managed Model Rather Than Full Outsourcing​

One of the most consequential aspects of the launch is Macquarie’s emphasis on co-management. The company says it intends to work alongside agency personnel and existing suppliers rather than replace the department’s internal technology function.
This aligns with a broader shift away from outsourcing contracts in which the provider controls nearly every operational detail. Government buyers increasingly want access to specialised expertise without losing institutional knowledge, architectural authority or the ability to change suppliers.

How responsibilities could be divided​

A co-managed Azure model normally works best when duties are divided by control plane rather than through vague promises of collaboration. A practical implementation could follow this sequence:
  1. The agency defines policy, risk appetite and information ownership. Senior officials remain accountable for classification, business continuity and acceptance of residual risk.
  2. Macquarie establishes reusable technical guardrails. These may include policy-as-code, landing zones, identity protections, network templates and automated compliance checks.
  3. Application teams deploy within approved boundaries. Internal developers and other contractors retain the flexibility to build services without redesigning the platform.
  4. Macquarie monitors platform health, security and expenditure. Engineers investigate deviations, optimise resources and maintain evidence of control performance.
  5. The parties jointly approve high-risk changes. Privileged operations, exceptions and architectural departures receive explicit scrutiny.
  6. The agency retains access to data and operational records. This supports accountability, transition planning and independent assurance.
This structure can preserve government control while giving internal teams access to Azure specialists. It also creates the possibility of continuous skills transfer rather than permanent dependence on an outsourcer.

Co-management introduces its own complications​

Shared responsibility can become blurred responsibility. An incident may expose disagreement over whether the managed provider, application developer, security operations centre or agency owner was expected to act.
Contracts must therefore specify response times, authority to isolate compromised resources, escalation procedures and responsibility for cloud configuration. Agencies should also test these arrangements through exercises instead of assuming that a responsibility matrix will survive contact with a live incident.

PROTECTED Workloads and the Meaning of Sovereignty​

Macquarie’s focus on PROTECTED-ready Azure is central to its government strategy. PROTECTED information can cause damage to the national interest, organisations or individuals if compromised, so agencies must apply controls proportionate to that potential harm.
Microsoft Azure provides services assessed under Australia’s Information Security Registered Assessors Program, commonly known as IRAP. An IRAP assessment supplies evidence about a system’s controls, but it does not grant universal accreditation to every customer configuration or transfer an agency’s accountability to Microsoft.

Assessment is not automatic compliance​

An agency still has to determine whether its specific architecture, data flows, operating practices and residual risks are acceptable. Misconfigured identities, excessive privileges or poorly protected application interfaces can undermine a deployment even when the underlying cloud service has been independently assessed.
Macquarie’s value proposition is that it can turn assurance requirements into repeatable engineering. Its published approach includes PROTECTED-ready landing zones, identity governance, secure networking, automated policies and support for high-risk operations requiring additional elevation.
The distinction is important: compliance must be sustained as an operational condition, not treated as a certificate obtained before launch.

Sovereignty is multidimensional​

Data residency is only one component of sovereignty. Agencies also need to consider who administers the environment, which laws apply to the provider, where support personnel are located, how encryption keys are controlled and whether operations can continue during a geopolitical or commercial disruption.
Macquarie offers Australian ownership, locally based personnel and experience running security-cleared facilities. Yet Azure remains a global Microsoft platform, with a software supply chain and strategic roadmap controlled by a multinational vendor.
The new practice consequently represents a hybrid form of sovereignty. It combines locally governed operations and Australian infrastructure expertise with the scale and product portfolio of a global hyperscaler. That will satisfy some government use cases, while especially sensitive workloads may continue to require isolated, private or dedicated infrastructure.

Azure Local and Isolated AI Hosting​

Macquarie is presenting Azure Local as a bridge between Microsoft’s public cloud ecosystem and infrastructure operated inside an agency-controlled environment. Formerly associated with the Azure Stack HCI product family, Azure Local extends Azure management and selected services to distributed or on-premises hardware.
The approach is particularly relevant to agencies that want cloud-style management but cannot send certain data to public endpoints. It can also support workloads in locations with limited connectivity or strict latency requirements.

Private models within the agency perimeter​

Macquarie says Azure Local can support isolated AI hosting using dedicated infrastructure and graphics processors. An agency could run a private language model within its own security boundary rather than sending prompts and documents to an externally hosted frontier model.
This can reduce several risks:
  • Sensitive prompts do not need to traverse a public model endpoint.
  • The agency can exercise greater control over model versions and updates.
  • Retrieval systems can remain close to classified or operational data.
  • Logging and access records can stay within the agency’s monitoring boundary.
  • The system may continue operating when an external service is unavailable.
Isolation does not eliminate AI risk. A private model can still leak information between users, produce fabricated answers, process data beyond its intended purpose or become vulnerable through its supporting software.

Hybrid AI requires disciplined engineering​

Running AI locally also introduces hardware, energy, cooling and lifecycle costs that public cloud services normally absorb. GPU capacity must be sized for peak demand, and agencies need specialist skills to maintain model-serving infrastructure.
The strongest use cases are therefore likely to involve information that genuinely cannot be processed through an ordinary public cloud service, or workloads requiring predictable performance and tight operational control. Using dedicated infrastructure merely to claim that a project is “sovereign” could leave taxpayers funding expensive capacity with low utilisation.

Cost Control and FinOps for Government​

Cloud cost has become a major concern as agencies accumulate subscriptions, duplicated resources and long-running virtual machines. The pay-as-you-go model creates transparency at the resource level, but it can also obscure total programme costs when teams deploy services independently.
Macquarie claims its managed approach can produce average Azure savings of 26 percent through rightsizing, licensing optimisation, governance and predictable billing. That figure should be viewed as a vendor-reported average rather than a guaranteed outcome for every agency.

Where savings usually come from​

Azure cost optimisation rarely depends on a single dramatic change. It generally comes from many smaller controls applied continuously:
  • Idle virtual machines and unattached storage are identified and removed.
  • Oversized compute resources are matched to observed demand.
  • Development environments are shut down outside working hours.
  • Reserved capacity or savings mechanisms are used for stable workloads.
  • Data transfer paths are redesigned to avoid unnecessary egress charges.
  • Duplicate security, backup and monitoring products are consolidated.
  • Licensing entitlements are reconciled with actual consumption.
  • Application owners receive budgets and alerts before expenditure escalates.
These measures sound straightforward, yet they require accurate tagging, ownership records and the authority to challenge application teams. Automated recommendations alone are insufficient because a technically idle resource may still have a legitimate continuity or emergency purpose.

Migration incentives need scrutiny​

Macquarie advertises zero migration or professional-services fees for some Azure engagements. This can lower the initial barrier to changing provider or modernising an environment, but agencies should examine how those costs are recovered through recurring charges, contract duration or consumption commitments.
A free migration is not necessarily a poor deal. It simply shifts the economic analysis from upfront project fees to the total cost over the contract’s life, including transition-out assistance.

Security Implications for Windows Environments​

The Azure practice will be especially relevant to Windows-heavy agencies because Microsoft’s cloud identity, endpoint and server products increasingly operate as an integrated security platform. Entra ID, Defender, Sentinel, Azure Arc, Intune, Windows 11 and Windows Server can share policy and telemetry across a hybrid environment.
That integration can improve detection and reduce tool fragmentation. It can also magnify the impact of a weak identity configuration because one compromised administrative account may reach multiple services.

Identity becomes the primary perimeter​

Traditional government networks often relied heavily on physical locations and network segmentation. In cloud environments, access decisions increasingly depend on user identity, device condition, risk signals and the sensitivity of the requested operation.
Macquarie’s model includes Entra governance and additional protections for privileged actions. Agencies should expect controls such as phishing-resistant multifactor authentication, just-in-time elevation, separate administrative accounts, access reviews and restrictions on emergency credentials.
Privileged access workstations remain relevant even when the controlled service is in Azure. A secure cloud control plane can still be compromised from an infected administrator’s Windows device.

Automation can strengthen consistency​

Azure Policy and infrastructure-as-code can stop prohibited configurations before deployment. They can require diagnostic logging, approved regions, private networking, encryption and designated security settings across large estates.
Automation is particularly valuable in government because it produces consistent evidence and reduces reliance on manual checklists. However, policy definitions must be tested carefully: an overly broad rule can break legitimate services, while an incomplete rule can create false confidence.

Competitive Impact on Australia’s Cloud Market​

Macquarie’s expansion intensifies competition among systems integrators, telecommunications providers, cybersecurity firms and cloud specialists seeking government Azure work. The contest is no longer limited to migrating virtual machines; it now encompasses cloud operations, security, data platforms and AI governance.
Large multinational consultancies bring global resources and transformation experience. Local providers counter with Australian ownership, lower organisational distance and a sharper sovereignty narrative.

A specialist rather than multicloud strategy​

Macquarie says it specialises in Azure rather than spreading its public cloud expertise across every hyperscaler. This can support deeper engineering capability and closer Microsoft alignment.
The trade-off is that agencies may receive advice framed through the Azure ecosystem even when another platform, private cloud or conventional hosting would be more appropriate. A strong specialist must be willing to recommend that some workloads remain elsewhere.

Pressure on incumbent service providers​

Macquarie can combine government cybersecurity relationships with Azure management, potentially expanding existing accounts without beginning as an unknown supplier. That creates cross-selling opportunities and puts pressure on providers offering only infrastructure, consulting or security monitoring.
The challenge for competitors will be to demonstrate an equally coherent operating model. Product certifications alone are unlikely to differentiate suppliers when buyers need evidence of cost control, incident response, automation and public-sector delivery.

Microsoft gains another route into government​

Microsoft benefits because a capable local partner can make Azure more manageable for agencies with constrained internal resources. The practice also extends demand for Sentinel, Defender, Fabric, Azure Virtual Desktop and hybrid Azure services.
Nevertheless, governments should preserve architectural choice. Deep integration across identity, desktops, security, data and AI can make later migration technically and financially difficult, even when each individual purchasing decision appears reasonable.

Impact on Federal and State Agencies​

Federal departments typically operate under extensive protective-security requirements and may manage information with national-security, taxation, health, welfare or law-enforcement implications. State agencies face many of the same technical pressures but differ in procurement frameworks, budgets and internal capability.
Macquarie’s ability to serve both levels of government could enable reusable patterns while still requiring jurisdiction-specific controls.

Federal government opportunities​

Federal agencies may benefit from a supplier already familiar with Canberra’s security expectations and accountability structures. The co-managed model could be attractive to departments that want to strengthen internal cloud capability rather than hand complete operational control to a prime contractor.
The greatest value may emerge in rationalising Azure estates that grew project by project. Consolidated identity, logging, network design and cost allocation can improve assurance without forcing every application through an immediate migration.

State government opportunities​

State agencies often operate large citizen-facing systems across health, education, transport, justice and emergency services. Availability and regional service delivery can matter as much as information classification.
Azure Virtual Desktop, hybrid infrastructure and central security monitoring may support geographically distributed workforces. Yet state agencies must ensure that centralisation does not create a single operational dependency capable of disrupting multiple essential services at once.

Strengths and Opportunities​

Macquarie’s proposition combines capabilities that government buyers have often had to procure separately. The strongest opportunities include:
  • The practice builds on an existing Azure operation rather than starting from scratch. Seven years of commercial delivery should provide reusable engineering, automation and operational lessons.
  • Australian ownership strengthens the sovereignty proposition. Local personnel and governance may simplify assurance for agencies concerned about administrative access and jurisdiction.
  • Macquarie already understands sensitive government environments. Its cybersecurity presence across federal agencies gives it experience with public-sector incident response and reporting.
  • The co-managed model can preserve internal capability. Agencies can retain architectural authority while using specialist engineers for platform operations.
  • Integrated cloud and security operations may reduce gaps between providers. Sentinel alerts, Azure configuration and incident response can be handled within a common service model.
  • Azure Local creates options for hybrid and isolated workloads. Agencies can apply Azure management patterns without placing every application in the public cloud.
  • Microsoft Fabric support connects infrastructure modernisation with data readiness. This could help agencies create governed foundations for analytics and AI.
  • Continuous optimisation addresses a growing financial problem. FinOps controls can expose waste that remains hidden in decentralised cloud accounts.
These strengths are meaningful, but they depend on execution. Government customers should demand measurable evidence rather than accepting broad claims about sovereignty, optimisation or AI readiness.

Risks and Concerns​

The practice also introduces strategic and operational concerns that agencies should address during procurement and design:
  • Microsoft concentration could increase. Using one ecosystem for identity, desktops, security, data and AI may create a broad dependency that is difficult to unwind.
  • Co-management can blur accountability. Incident authority, patching duties and exception management must be explicit.
  • PROTECTED-ready does not mean universally compliant. Each workload still requires risk assessment, correct configuration and ongoing assurance.
  • Savings estimates may not transfer between customers. Agencies should validate baselines and include transparent measurement in contracts.
  • Local management does not make the entire technology supply chain sovereign. Azure remains a globally developed and operated platform.
  • Hybrid environments can become more complex than either public or private cloud alone. Consistent identity, monitoring and lifecycle management are essential.
  • AI infrastructure can become expensive and underused. Dedicated GPUs need a defensible operational requirement and realistic utilisation plan.
  • Provider dependence can survive even when the underlying platform remains unchanged. Agencies need documentation, automation ownership and tested transition arrangements.
  • Automated guardrails can create false assurance. Policies must be audited against actual threats and business processes.
  • Migration incentives may obscure long-term costs. Whole-of-life pricing should include support, consumption, licensing and exit services.
None of these risks invalidates the managed-services model. They demonstrate why government cloud must be treated as a governance transformation rather than a conventional hosting contract.

What to Watch Next​

The launch announcement establishes Macquarie’s ambition, but the next phase will reveal whether the practice can convert existing credibility into large-scale Azure delivery. Contract wins, reference architectures and independently measurable outcomes will matter more than the breadth of the initial service catalogue.
Several developments deserve close attention.

First government customers​

Macquarie has not publicly detailed a flagship agency deployment associated with the launch. Early customers will show whether demand centres on full Azure operations, security management, desktop services, data platforms or targeted remediation of troubled cloud estates.
The classification and scale of those workloads will also indicate how far agencies are willing to entrust a co-managed partner with core systems.

Evidence of cost and security outcomes​

Buyers should look for documented changes in cloud expenditure, policy compliance, vulnerability exposure and incident-response times. A claim of percentage savings is most meaningful when it includes the original baseline, implementation cost and duration of measurement.
Likewise, the number of alerts handled is not a strong security metric. Faster containment, fewer repeat misconfigurations and improved recovery performance provide more useful evidence.

Azure Local adoption​

Macquarie’s experience deploying Azure Local in commercial environments may offer an early advantage, but government adoption will depend on whether the platform can meet strict operational requirements without recreating the maintenance burden of conventional on-premises infrastructure.
Watch for deployments involving disconnected operations, sensitive AI, remote facilities or applications with specialised latency needs. Those are more compelling than using hybrid hardware simply to preserve familiar server-management practices.

The path from data platforms to production AI​

Microsoft Fabric and private AI hosting give Macquarie a route into higher-value transformation projects. The difficult step will be moving beyond proofs of concept into systems that agencies can audit, maintain and trust.
Production deployments will need model evaluation, data provenance, human review, access restrictions, monitoring and clear accountability for automated decisions. Cloud infrastructure is only the foundation of that governance stack.

Macquarie’s broader infrastructure expansion​

The Azure launch sits alongside Macquarie Technology Group’s investment in sovereign cloud, cybersecurity and data-centre capacity. The company has also outlined plans for major new Australian infrastructure intended to serve high-performance computing, AI, hyperscale and government demand.
If those investments progress as planned, Macquarie may be able to offer a continuum ranging from public Azure to locally managed hybrid infrastructure and highly controlled sovereign facilities. That breadth could become a differentiator, provided the individual environments operate under a consistent management and security framework.

Looking Ahead​

Macquarie Government’s Azure practice reflects the reality that Australia’s public-sector cloud debate has moved beyond the binary question of public versus private infrastructure. Agencies now need to decide where each workload belongs, who should operate it, how control can be demonstrated continuously and whether the resulting platform will support secure data use and AI.
The company is well placed to address that problem because it brings together government relationships, Australian ownership, cybersecurity operations, data-centre infrastructure and a mature commercial Azure practice. Its decision to use a co-managed model also acknowledges that agencies cannot outsource accountability, institutional knowledge or every aspect of technical judgement.
The real test will be whether Macquarie can deliver measurable cost control, durable security and genuine agency autonomy while operating inside Microsoft’s expanding ecosystem. If it succeeds, the practice could give Australian governments a useful middle path between traditional outsourcing and unmanaged hyperscale consumption: Azure’s breadth and scale, wrapped in locally governed operations designed for the obligations of public service.

References​

  1. Primary source: CRN Australia
    Published: Wed, 22 Jul 2026 06:28:07 GMT
  2. Independent coverage: Telecompaper
    Published: 2026-07-22T05:33:00+00:00
  3. Official source: news.microsoft.com
  4. Related coverage: itbrief.com.au
  5. Official source: learn.microsoft.com