What You Get with MCF
Every capability maps to concrete, versioned Terraform modules — maintained by Netcloud. See what's included, what's available as an add-on, and what's on the roadmap.
25
Purpose-built Terraform modules
68+
Releases shipped
~15
Phase I capabilities
~8
Phase II capabilities
~5
Phase III capabilities
100%
Infrastructure as Code
Infrastructure
18 modules · 37 releases
Infrastructure
18 modules · 37 releases
Automation & Infrastructure as Code (IaC)
Every infrastructure change is versioned, tested, and deployed through CI/CD pipelines.
12 releases shipped
Network & Connectivity Services
Hub-spoke topology, DNS, and SD-WAN integration deployed and maintained as code.
17 releases shipped
Workload Isolation
Each workload gets its own subscription and network segment with enforced boundaries.
4 releases shipped
Workload Orchestration
Production-ready Kubernetes clusters with integrated networking and security policies.
2 releases shipped
Security Incident Response
Centralized firewall with policy-driven traffic control and logging.
2 releases shipped
Vulnerability & Threat Management
Planned: advanced threat detection and vulnerability scanning.
Coming soon
Governance & Compliance
7 modules · 27 releases
Governance & Compliance
7 modules · 27 releases
Compliance Monitoring (CIS / Cloud Best Practices)
200+ policies covering CIS, ISO 27001, and DSGVO — continuously updated.
8 releases shipped
Least Privilege Monitoring
Just-in-time, just-enough access with Privileged Identity Management.
1 release shipped
Service Onboarding
New subscriptions provisioned with full governance baseline in minutes.
1 release shipped
Account Activity Logging
All activity logged to Log Analytics — full audit trail from day one.
1 release shipped
Workload-specific Region & Service Availability
Policies restrict deployments to approved regions and services only.
8 releases shipped
Tagging Policy & Enforcement
Required tags enforced — cost allocation and ownership always tracked.
8 releases shipped
Security Assessments & Audits
Planned: automated security assessment reports and audit support.
Coming soon
Security
4 modules · 16 releases
Security
4 modules · 16 releases
Identity Management, Access Control & Monitoring
Entra ID, custom RBAC roles, PIM, and conditional access — fully automated.
7 releases shipped
Security Reporting & Optimization Recommendations
Defender Secure Score tracked continuously with actionable recommendations.
9 releases shipped
Encryption & Data Leak Monitoring
Planned: automated encryption enforcement and DLP monitoring.
Coming soon
Finance
2 modules · 2 releases
Finance
2 modules · 2 releases
Cost & Usage Reports
Budget alerts on every subscription — no surprise bills.
1 release shipped
Workload-specific Budget Alerts
Per-workload budget thresholds with automated notifications.
1 release shipped
Business Continuity
0 modules · 0 releases
Business Continuity
0 modules · 0 releases
Backup Management
Planned: automated backup policies and recovery testing.
Coming soon
Patch Management
Planned: automated OS and application patching.
Coming soon
Container Registry
Planned: managed container registry with vulnerability scanning.
Coming soon
Self-Service Products
Planned: self-service tools for your teams — built on your secure foundation.
Coming soon
Simplified Developer Experience & Tools
Planned: developer-friendly tools that abstract infrastructure complexity.
Coming soon
Organizational Readiness
4 modules · 11 releases
Organizational Readiness
4 modules · 11 releases
Cloud Readiness & Migration Assessments
Expert-led assessment of your cloud readiness and migration strategy.
Consulting — not a module
Naming Conventions
Consistent, automated resource naming across your entire Azure estate.
5 releases shipped
IaC & Automation Enablement
Your teams get pre-built module templates and CI/CD pipelines to build on the foundation.
6 releases shipped
Monitoring
1 modules · 1 releases
Monitoring
1 modules · 1 releases
Service Health Monitoring
Azure service health alerts configured and routed to your operations team.
1 release shipped
What's Coming Next
Current release: MCF 26.02 — these capabilities are planned for upcoming releases.
Backup Management
Phase IBusiness Continuity
Planned: automated backup policies and recovery testing.
Patch Management
Phase IBusiness Continuity
Planned: automated OS and application patching.
Vulnerability & Threat Management
Phase IIInfrastructure
Planned: advanced threat detection and vulnerability scanning.
Encryption & Data Leak Monitoring
Phase ISecurity
Planned: automated encryption enforcement and DLP monitoring.
Container Registry
Phase IBusiness Continuity
Planned: managed container registry with vulnerability scanning.
Security Assessments & Audits
Phase IIGovernance & Compliance
Planned: automated security assessment reports and audit support.
Self-Service Products
Phase IIIBusiness Continuity
Planned: self-service tools for your teams — built on your secure foundation.
Simplified Developer Experience & Tools
Phase IIIBusiness Continuity
Planned: developer-friendly tools that abstract infrastructure complexity.