How Embee Software replaced a single-VM bottleneck with a secure, two-tier Azure architecture eliminating recurring outages on a national quality-certification body’s public certification application.
The Challenge
The customer, a national quality-certification body, runs a public-facing certification application on Microsoft Azure. The platform was hosted on a single virtual machine running both the web application and its database, an architecture that had become a reliability and security liability as data and traffic grew.
The core gaps:
- A single VM hosting both the the certification platform web application and its database, causing performance bottlenecks
- High memory utilization (over 80%), a sign of inefficient sizing and resource contention
- Frequent certification website interruptions affecting availability
- No network segmentation, leaving limited control and a rigid, hard-to-secure environment
- An IIS-based website exposed to security attacks and breaches
The trigger was direct: frequent certification application outages were impacting public user access. The inefficient single-VM design could not keep up with growing data and workload, and the recurring downtime carried a real business cost.
The Solution
Embee Software re-architected the certification platform on Microsoft Azure using a Well-Architected Framework-aligned, two-tier design with security built in from the start, executed end to end, with rollback planning and phased cutover.
What Embee Software delivered:
- A new two-tier Azure architecture separating the web tier and database (Azure SQL Managed Instance)
- Hub-spoke networking with segmentation for control and isolation
- A security-by-design environment: Application Gateway with WAF v2, NSGs, Microsoft Defender for Cloud (CSPM and CWP), and Private Endpoints
- Azure DDoS IP Protection on the Application Gateway’s public IP
- Configured SSL, DNS, RBAC, and Azure Key Vault for secure, governed access
- Right sizing and post-deployment validation to optimize performance
- Identified and fixed IIS application vulnerabilities and misconfigurations alongside the customer’s app-dev team
Microsoft products & services: Azure Virtual Machine, Azure SQL Managed Instance, Azure Files, Microsoft Defender for Cloud, Application Gateway with WAF v2, Azure DDoS IP Protection, Log Analytics Workspace, plus Static Public IP, Azure Private DNS, Private Endpoints, and VNet Peering.
What made Embee Software’s approach different:
- A Microsoft Well-Architected Framework-aligned design (two-tier + hub-spoke), not a like-for-like lift
- End-to-end execution across infrastructure build, security, and validation
- Security-by-design: WAF, Defender, and Private Endpoints integrated upfront, not bolted on
- A structured framework with rollback planning and phased execution
- Optimization-focused delivery, with right-sizing and post-deployment validation
Results & Impact
| Metric | Before → After / Outcome |
| Recurring outage incidents | Daily recurrence → eliminated completely |
| Application uptime | Sub-optimal, frequent interruptions → stable and available |
| Architecture | Single shared VM → two-tier (Web + Azure SQL MI), independently scalable |
| Memory utilization | Over 80% (contention) → healthy headroom after right-sizing |
| Platform availability | ~99.9% post-migration |
| Data footprint | 20+ TB on the new architecture |
| Deployment time | ~10 weeks, design to go-live |
| Downtime business cost | High before → negligible to nil after |
How the certification body operates differently now:
- Stable application availability with no frequent downtime
- A scalable setup — the web and database tiers scale independently
- Improved performance with no resource contention
- Secure access through WAF, Private Endpoints, and controlled traffic
- Better visibility and control via a segmented network and RBAC
The AI & Analytics Readiness Angle
Although this was an infrastructure and security engagement, the outcome is a structured, secure data platform that is now ready to support analytics and AI-driven workloads as a future step.
Why the Certification Body Chose Embee Software
- End-to-end transformation capability across infrastructure, PaaS modernization, and security
- Strong Microsoft alignment with best practices and the Well-Architected Framework
- A consultative, partner-led approach focused on long-term outcomes, not just deployment
Re-Architect for Reliability and Security on Azure
A single oversized VM is a reliability incident waiting to happen. Embee Software re-architects public and business-critical workloads on Microsoft Azure using the Well-Architected Framework, combining cloud consulting and assessment, cloud migration, and application modernization with security designed in from the start.
Our security-by-design approach spans application and API security, cloud security, and ongoing managed security services, with cloud optimization to keep performance and cost in balance. As a Microsoft Frontier Partner, we deliver end to end: architecture, security, and validation. Explore more customer success stories.
Is an ageing architecture putting your uptime at risk? Talk to our Azure architects for a Well-Architected review of your critical workloads.


















































