Macquarie Government, the public-sector arm of ASX-listed Macquarie Technology Group, launched a dedicated Microsoft Azure practice on July 22, targeting Australian federal and state agencies. The move comes three weeks after the Commonwealth’s Whole-of-Government Cloud Computing Policy took effect on July 1, 2026, making cloud the default choice for new digital investments.

What the new Azure practice delivers

The practice combines managed Azure infrastructure, Microsoft security tooling, data platforms, Azure Virtual Desktop, and hybrid cloud capabilities. It is designed to cover the full lifecycle—from architecture and migration through continuous cost optimisation and security monitoring—and supports workloads classified up to the Australian Government’s PROTECTED level.

Naran McClung, Executive Head of Azure at sister company Macquarie Cloud Services, is leading the expansion. The group brings seven years of commercial Azure managed-services experience, and this government-focused launch leverages engineering processes, certifications, and cost-management disciplines already proven with private-sector customers.

The offering is structured around several interconnected layers:
- Managed Azure: architecture, migration, subscription governance, performance management, and cost oversight.
- Microsoft Security: monitoring and response across Sentinel, Defender, and extended detection and response (XDR) tooling.
- Managed data platforms: governed analytics and reporting using Microsoft Fabric.
- Azure Virtual Desktop: centralised application and desktop access for distributed workforces.
- Hybrid cloud: connecting Azure with existing private infrastructure and on-premises workloads.
- PROTECTED-level monitoring: elevated security operations for sensitive government information systems.

Macquarie promotes “zero migration and professional-services fees” in parts of its offering and advertises average savings of 26 percent on cloud spend through rightsizing and optimisation. For security operations, it claims a three-minute mean time to response and seven-minute mean time to containment for managed services.

Why this launch matters now

The timing is critical. On July 1, the Digital Transformation Agency’s Whole-of-Government Cloud Computing Policy came into force, applying to non-corporate Commonwealth entities and encouraging other bodies to follow. Under the policy, agencies must prioritise cloud solutions for new digital initiatives and technology upgrades—unless they can justify an alternative. Cloud planning must be integrated into broader digital investment strategies, and legacy systems are expected to be retired in a timely manner.

This shifts procurement conversations. Technology leaders now have to explain why a workload should not use cloud, rather than making the positive case for it. The policy creates immediate demand for operational discipline: agencies that provision cloud resources quickly often struggle with ownership tracking, cost control, consistent security policy, and audit evidence. A managed Azure practice that provides structured governance, automated controls, and continuous optimisation is positioned to fill that gap.

What the new service means for government IT teams

For agency CIOs and technology planners

You gain another option for closing capability gaps. Recruiting cloud-security architects, platform engineers, and FinOps specialists is tough in the public sector. This service can supply those skills across multiple agencies and introduce standardised patterns—reducing duplicated effort and improving consistency.

But outsourcing specialist tasks does not remove the need for in-house expertise. Agencies must remain capable of challenging architectural decisions, reviewing risk, understanding expenditure, and switching providers if needed. Macquarie’s co-managed model aims to “co-exist” with internal staff and existing suppliers, rather than replace them entirely. That can reduce institutional resistance, but only if boundaries are clearly defined—otherwise, shared responsibility can blur.

For security and compliance officers

The practice offers IRAP-assessed Azure services suitable for PROTECTED workloads, with landing zones aligned to the Australian Government Information Security Manual (ISM), the Essential Eight, and Center for Internet Security (CIS) benchmarks. Automated guardrails, identity governance via Microsoft Entra ID, and continuous monitoring are central to the proposal. But an IRAP assessment does not automatically make every customer deployment compliant. Each agency remains responsible for evaluating its own risk profile, compensating controls, and authority to operate.

Configuration drift is a major cloud risk. Macquarie’s continuous management aims to keep settings from straying after deployment, and centralised logging should help produce audit evidence. However, dashboards showing green status do not capture flawed business logic, inappropriate data use, or risks from connected systems. Agencies should still conduct independent assurance.

For procurement and finance officers

Cloud spending shifts from periodic capital purchases to continuous consumption. An Azure bill can balloon if teams leave test environments running or oversize resources. Macquarie’s FinOps focus—resource tagging, budgets, anomaly alerts, reserved capacity, and automatic shutdown of non-production resources—aims to curb waste. The advertised 26% savings is an average, though; actual results depend on the starting environment and commercial terms.

The zero migration-fee offer lowers the initial barrier, but examine how costs are recovered through ongoing commitments. Migration is not transformation: application remediation, testing, integration redesign, and decommissioning can cost more than moving infrastructure itself. Agencies should calculate total lifecycle and exit costs, including what happens if they later switch providers or return a workload on-premises.

How we got here: Australia’s shift toward a cloud-first government

Macquarie Government itself is not new to the public sector. It secures 42 percent of Australian federal government agencies and has operated sovereign hosting, private cloud, and cybersecurity services for over two decades. The introduction of a formal Azure practice adds a public-cloud layer to that existing hybrid capability.

The broader policy landscape has been building for years. The Australian Cyber Security Centre’s Essential Eight became mandatory for non-corporate Commonwealth entities in 2024. Microsoft’s Azure platform already had IRAP assessments for services up to PROTECTED. And the government’s Digital Transformation Strategy has been pushing modernisation. The new cloud policy—published in late 2025 and effective July 1, 2026—solidifies cloud as the default.

Macquarie’s sister company, Macquarie Cloud Services, has been delivering managed Azure to commercial customers for about seven years. That experience transfers critical capabilities: understanding Azure landing zones, identity policy, subscription governance, billing controls, and Microsoft’s fast-changing service catalogue. Naran McClung’s leadership brings continuity from that commercial practice to government.

What to do now: practical steps for government agencies

If you’re evaluating Macquarie Government’s Azure practice—or any managed cloud service in light of the new policy—consider these actions:

  1. Assess your current cloud posture. Identify existing Azure subscriptions, their ownership, cost patterns, and security configurations. Many agencies already have fragmented, inconsistent deployments that need retrofitted governance.
  2. Map your workload classification and compliance needs. Not everything belongs in public cloud. Determine which systems are candidates for Azure under the policy and which must stay on private infrastructure or require hybrid setups.
  3. Define co-management boundaries explicitly. If you consider a co-managed model, document who owns alerts, policy changes, privileged access, patching, and incident escalation. Ambiguity here leads to operational risk.
  4. Scrutinise the commercial model. Look beyond “zero migration fees.” Understand minimum terms, pricing for ongoing management, data egress costs, and exit provisions. Model total cost over three to five years, including internal staffing.
  5. Test the provider’s land-zone alignment. Ask for a demonstration of how they implement Azure Policy, Entra ID conditional access, and logging in line with ISM and Essential Eight. Ensure you retain visibility and the ability to review exceptions.
  6. Plan for identity-first security. Review your Entra ID governance, privileged identity management, and authentication policies. The provider’s identity approach must integrate with your existing Microsoft 365 and security operations.
  7. Prepare for AI governance before rushing in. Establishing identity, data governance, and cost controls should precede AI workloads. Ensure data classification, lineage, and access rights are solid before adopting Microsoft Fabric or AI services.
  8. Build exit options from the start. Retain configuration documentation, export logs in open formats, and test data recovery. Know which services would need re-architecting if you switch platforms.

Outlook

Macquarie Government’s Azure launch is a direct response to Australia’s cloud-first policy, but its real impact will emerge as agencies sign contracts and deploy workloads at scale. The practice’s success depends on whether it can help agencies retain sovereignty, accountability, and financial control—not just migrate servers.

Five indicators will signal momentum: named agency customers; PROTECTED workload deployments passing assurance; verifiable cost savings after management fees; real-world AI and analytics projects built on governed data foundations; and hybrid-cloud deals that integrate Macquarie’s private infrastructure with Azure. The DTA’s enforcement of the cloud policy will also shape demand. If implementation is rigorous, managed governance services like this one become essential. If policy enforcement is lax, cloud adoption may grow without the operational discipline the framework intends.

For government technology leaders, the arrival of this practice adds a local, experienced option at a moment when cloud is no longer optional.