Automated vs Manual vs Consultant: Three Ways to Run an Azure Architecture Assessment

Automated, manual self-assessment, and consultant-led: three ways to run an Azure architecture assessment compared on time, cost, depth, and currency. For CTOs and VPs of Engineering.

Marc Dekeyser |

Automated vs Manual vs Consultant: Three Ways to Run an Azure Architecture Assessment

There are three honest ways to run an Azure architecture assessment: an automated assessment that produces findings in hours, a manual self-assessment using the free Microsoft Azure Well-Architected Review, and a consultant-led engagement. They differ most in speed, cost, and how current the result stays — and a senior consultant brings contextual judgment that automation does not.

The choice is usually framed as automation versus humans. That framing is wrong. The real question is which method fits the decision you are making, the budget you have, and how often the answer needs refreshing. Each method is genuinely best at something.

Key takeaways

  • An automated Azure architecture assessment produces findings in hours and stays current with continuous re-runs; depth is bounded by what tooling can observe.
  • The Microsoft Azure Well-Architected Review is free and structured but manual and self-reported — its accuracy depends entirely on the honesty and knowledge of the person filling it in.
  • A consultant-led assessment brings the deepest contextual judgment and strategic interpretation, at the highest cost, as a point-in-time snapshot.
  • Currency over time is where they diverge most: automation re-runs cheaply; manual and consultant assessments go stale the moment the architecture changes.
  • The methods complement each other. Automation handles breadth and drift; a senior architect handles judgment.

What are the three ways to assess an Azure architecture?

The three methods are automated assessment, manual self-assessment, and consultant-led review, and they sit at different points on a cost-speed-depth curve. Automated assessment uses tooling to read the environment or its definition and generate findings against the Microsoft Azure Well-Architected Framework. Manual self-assessment means a team works through a structured questionnaire — most commonly the free Well-Architected Review, roughly 60 questions across the five pillars. Consultant-led means a human expert, or a team, examines the architecture, interviews stakeholders, and writes findings.

Each produces a different kind of output. Automation produces consistent, repeatable findings. The questionnaire produces a self-scored snapshot. A consultant produces interpreted, contextual recommendations. None is strictly better; they answer different questions.

How do the three methods compare?

The table compares the three methods on the dimensions that determine which one fits a given decision. The honest summary is below it.

DimensionAutomated assessment (e.g. PAA)Manual self-assessment (Well-Architected Review)Consultant-led engagement
Time to first outputHoursDays (a workshop)Weeks
Typical costLow, transparent (EUR 99–799/mo)FreeHigh, contact-us (often five figures)
Currency over timeContinuous; re-runs cheaplyStale once architecture changesPoint-in-time snapshot
Depth of judgmentBounded by what tooling observesBounded by the team’s own knowledgeDeepest; contextual and strategic
ConsistencyDeterministic, repeatableVaries with who answersVaries with the consultant
Compliance mappingPer-finding to NIS2/DORA/ISO/SOC 2Not built inYes, if scoped (and priced)
Remediation outputGenerated Terraform / BicepGuidance onlyTailored recommendations
Best atBreadth, currency, drift detectionFree structured starting pointContext, strategy, hard trade-offs

The honest reading. A senior consultant is the only one of the three that can weigh a business context — a planned acquisition, a regulatory deadline, a team’s actual operational maturity — and tell you which of ten findings actually matters this quarter. Automation cannot do that. What automation does that a consultant cannot is run again next week, and the week after, for the same low cost, catching the drift that makes any point-in-time assessment stale.

When should you choose each method?

Choose the method that matches how often the answer needs to be right, not just how deep you want it once. Three patterns cover most situations.

  1. Choose automated assessment when you need findings fast, repeatedly, and mapped to compliance frameworks — for example, before a board update, during due diligence, or to monitor an actively changing platform. Strength: speed and currency. Limitation: it surfaces what tooling can observe; it will not infer your unstated business strategy.

  2. Choose the manual Well-Architected Review when you want a free, structured way to start a conversation inside the team. Strength: zero cost, first-party framing, good for building shared understanding. Limitation: self-reported. A team that does not know what it does not know will score itself generously, and the result ages immediately.

  3. Choose a consultant when the decision is high-stakes and context-heavy — a re-platforming, a major architectural bet, a contested trade-off between cost and resilience. Strength: judgment and strategic interpretation. Limitation: cost, lead time, and the fact that the report describes the architecture as it was on the day, not as it is six months later.

For a structured framing of what an assessment should cover, see our Azure architecture governance checklist, and for one pillar in depth, the Well-Architected security pillar walkthrough.

Do these methods compete or complement?

They complement each other far more than they compete, because each covers the others’ weakest dimension. The most effective pattern we see: run automated assessment continuously to hold the line on breadth and drift, use the free Well-Architected Review to align the team on language and priorities, and bring in a senior consultant for the handful of decisions where contextual judgment changes the outcome. Automation makes the consultant’s time more valuable — the expert spends it on interpretation and trade-offs rather than on inventory and box-ticking the tooling already did.

This is where PAA sits, honestly. It is the automated, continuous option: all-five-pillar Azure and Microsoft 365 review, deterministic compliance mapping, generated Terraform or Bicep remediation you apply, and drift detection between runs. It does not replace a senior architect’s judgment, and it is read-only — it proposes changes rather than making them. It is the layer that keeps the assessment current between the moments a human looks closely.

FAQ

Is an automated Azure architecture assessment as good as a consultant? No, and it is not trying to be. Automation is faster, cheaper, and stays current, but a senior consultant brings contextual judgment and strategic interpretation that tooling cannot. They answer different questions. The strongest approach uses automation for breadth and currency and a consultant for high-stakes, context-heavy decisions.

Is the Microsoft Azure Well-Architected Review free? Yes. The Well-Architected Review is a free, first-party self-assessment of roughly 60 questions across the five pillars. Its weakness is not cost but reliability: it is self-reported, so its accuracy depends on the knowledge and honesty of the people answering, and it goes stale as the architecture changes.

How often should an architecture assessment be refreshed? As often as the architecture changes materially, which for an active platform is continuously. This is the core weakness of manual and consultant assessments: they are point-in-time. Automated assessment with drift detection is the only method that refreshes cheaply enough to stay current between major reviews.

Can automated assessment map findings to NIS2 and DORA? Yes. Automated assessment tools can map each finding to control frameworks deterministically — the same input yields the same mapping every time. Manual self-assessment does not include this, and consultant engagements include it only when scoped and priced for it. Deterministic mapping is what makes findings auditable.

Does automation produce remediation, not just findings? Some automated tools generate remediation as infrastructure-as-code — Terraform or Bicep you review and apply. This is a meaningful difference from the manual review, which gives guidance only. The code still needs human review before it is applied; automation proposes, it does not silently change your environment.

The right answer is rarely one method. It is automation holding the line on breadth and currency, a free questionnaire aligning the team, and a senior architect spending scarce judgment where it actually moves the decision.