The instinct in most cloud migrations is to move the easiest workload first to build momentum. That's often the wrong call. The first migration should be complex enough to surface the governance, networking and identity gaps that would otherwise appear later, at a worse time.
Landing zone design comes before any workload migration — networking, identity and governance guardrails need to exist first, or every subsequent migration inherits whatever gaps were left in the foundation.
Cost visibility has to be built in from the start. Tagging and budget alerts configured after the first surprise invoice are configured too late. Set them up as part of the landing zone, not as a reaction.
Migration success is measured by what happens after cutover, not during it. A workload that moves cleanly but has no one who understands its new environment isn't a successful migration — it's a delayed incident.
