On July 22, 2026, Macquarie Government launched a dedicated Microsoft Azure practice for Australian federal and state agencies, its first foray into managed public cloud for the country's public sector. The move brings a locally operated, co-managed option that promises average cost reductions of 26 percent through continuous rightsizing, licensing optimization, and governance.

That 26 percent figure, which Macquarie says it has already delivered to commercial customers, anchors a broader pitch: By taking over the operational burden of Azure—including security monitoring, virtual desktops, hybrid infrastructure, and data engineering—agencies can redirect scarce internal talent toward mission outcomes rather than managing cloud subscriptions and firefighting alerts.

A Managed Azure Portfolio Tailored for Government

The new practice, led by Naran McClung, executive head of Azure at Macquarie Cloud Services, will bundle several Microsoft services under a single managed umbrella. The core components include:

  • Managed Azure – Standardized landing zones designed from the ground up for PROTECTED-level workloads, incorporating the Microsoft Cloud Adoption Framework, Information Security Manual-aligned guardrails, CIS benchmarks, and Essential Eight controls.
  • Microsoft Sentinel and Extended Detection and Response (XDR) – Managed security operations that aggregate signals across identity, endpoints, email, and cloud workloads.
  • Azure Virtual Desktop – Government-appropriate implementations with classification-aware controls and predictable cost management.
  • Azure Local – Hybrid infrastructure that extends Azure management to on-premises or agency-controlled hardware, with the option to run isolated AI workloads on dedicated GPUs.
  • Microsoft Fabric – Managed data analytics and engineering capabilities aimed at building AI-ready foundations.

Macquarie is not a newcomer to government IT. Its parent, Macquarie Technology Group, has spent more than 20 years building cybersecurity relationships across the Australian public sector, currently claiming to protect 42 percent of all federal agencies. The government practice has historically focused on private cloud, secure hosting, and managed cyber defense. The Azure launch represents the first time those sovereign, security-cleared operations are being extended to hyperscale public cloud services.

Co-Management: Shared Responsibility, Not Outsourcing

Perhaps the most important strategic choice baked into the offering is its co-management model. Macquarie says it intends to work alongside agency IT staff and existing suppliers, not replace them. That distinction matters in an era where governments increasingly want to retain institutional knowledge, architectural authority, and the capacity to switch providers if necessary.

In practice, co-management would typically divide duties along these lines:

  • The agency defines policy, risk appetite, and information ownership. Senior leaders remain accountable for classification, business continuity, and acceptance of residual risk.
  • Macquarie establishes reusable technical guardrails—policy-as-code, identity protections, network templates—and monitors platform health, security, and expenditure.
  • Application teams (internal or other contractors) deploy services within the approved boundaries without redesigning the platform each time.
  • Both parties jointly approve high-risk changes, and the agency retains full access to data and operational records.

This structure aims to preserve government control while giving internal teams access to deep Azure specialists. But as Macquarie itself acknowledges, shared responsibility can slide into blurred responsibility if contracts do not spell out response times, incident isolation authority, exception handling, and who is expected to act in a crisis. Agencies will need to stress-test these arrangements through live-fire exercises, not just rely on a tidy responsibility matrix.

The Windows Connection: Identity, Desktops, and Security

For Windows-heavy agencies, the Azure practice will be particularly relevant because Microsoft's cloud identity, endpoint, and server products increasingly function as an integrated security fabric. Entra ID, Defender, Sentinel, Intune, Windows 11, and Windows Server can share policy and telemetry across a hybrid environment. Managed well, this integration improves detection and cuts down on tool clutter. Managed poorly, a single compromised administrative account can cascade across multiple services.

Macquarie's model includes Entra governance and additional protections for privileged actions. Agencies should expect controls like phishing-resistant multifactor authentication, just-in-time elevation, separate admin accounts, and automated access reviews. Azure Policy and infrastructure-as-code templates can also prevent prohibited configurations before deployment—a vital capability when manual checklists no longer scale across dozens of subscriptions.

The Road to Azure Maturity in Australian Government

Australian government cloud adoption has not followed a straight path from legacy data centers to public cloud. Many agencies run a hybrid patchwork: aging on‑premises apps, outsourced infrastructure, private clouds, and workloads scattered across one or more hyperscalers. Microsoft 365 deployments are widespread, and many departments already hold Azure subscriptions and enterprise agreements. The problem is no longer how to buy cloud capacity; it’s how to govern, secure, and extract value from environments that have grown organically.

Macquarie’s launch capitalizes on what McClung calls a “perfect storm”: pressure to modernize, intensifying cyber risk, and the need to prepare data environments for artificial intelligence. “We’re seeing that need to modernise and develop new services including AI while also controlling costs and meeting increasing security expectations,” he told CRN Australia. The Azure practice positions day-two operational governance—subscription management, cost control, compliance automation, and continuous monitoring—as a dedicated service rather than an afterthought to migration.

What Agencies Should Do Before Signing On

For federal and state agencies evaluating Macquarie’s offer, several due-diligence steps stand out:

  1. Validate the cost savings claim. Macquarie’s 26 percent figure is a vendor-reported commercial average. Agencies should request a detailed baseline of their own current Azure spend, including all tagging gaps, waste, and hidden charges, and embed transparent measurement clauses in any contract.
  2. Stress-test the co-management model. Specify who has authority to isolate compromised resources, who patches critical vulnerabilities within what timeframe, and how escalations are handled when the provider and the agency disagree on a severity assessment. Document these in a responsibility matrix that goes beyond generic service descriptions.
  3. Examine PROTECTED readiness thoroughly. An IRAP-assessed platform does not automatically make every customer workload compliant. Ask for the specific guardrails, identity controls, and configuration templates that will govern your environment, and test them against your own risk assessments.
  4. Plan the exit strategy today. Co-management can become dependency if the agency lacks its own documentation, automation scripts, and a clear transition plan to another provider or back to an internal team. Require regular data and configuration exports in usable formats.
  5. Watch for AI infrastructure overcommitment. Azure Local with dedicated GPUs sounds attractive for sensitive AI workloads, but running private models involves hardware, cooling, and lifecycle costs that public cloud services normally absorb. Demand a realistic utilization plan, not just a sovereignty claim.
  6. Check Microsoft dependency breadth. Engaging a single ecosystem for identity, desktops, security, data, and AI can make later migration difficult. Even if Macquarie is the managed partner, the agency must retain architectural choice and ensure that procurement decisions remain contestable.

What to Watch Next

The launch announcement establishes Macquarie’s ambition, but execution will separate marketing from meaningful outcomes. Several coming developments will be telling:

  • First customer workloads. Macquarie has named the Department of Climate Change, Energy, the Environment, and Water as an existing cybersecurity and cloud customer, but no flagship Azure management agency has been disclosed for the new practice. The classification and scale of initial deployments will signal how much trust government buyers are willing to place in a co-managed model for core systems.
  • Measurable impact on cost and security. Beyond headline percentages, look for published case studies that show reduced vulnerability exposure, faster incident containment, and consistent policy compliance over time—not just an increase in alerts handled.
  • Azure Local in the wild. Deployments involving disconnected operations, sensitive AI, or remote facilities with strict latency needs will test whether hybrid infrastructure can meet government demands without recreating the maintenance burden of conventional on-premises hardware.
  • Broader infrastructure plays. Macquarie Technology Group is also investing in new sovereign data-center capacity. If those plans progress, the company could offer a continuum from public Azure to locally managed hybrid infrastructure and highly controlled sovereign facilities—a breadth that few competitors could match.

Macquarie’s government Azure practice is entering a market that has matured from “should we use cloud?” to “how do we run it properly?” The offering’s blend of local ownership, security clearances, and commercial Azure expertise is designed to answer that question for agencies that cannot afford to experiment. The risk is that co-management, in the wrong hands, becomes just another layer of complexity. Getting the contract details right—and testing them under pressure—will determine whether the 26 percent savings materialize in reality, not just in a quotation.