
Master AZ-305 exam design with hands-on, learn-by-doing practice across advanced networking, compute, and storage, with AZ-104 as the prerequisite for expert certification.
Navigate the AZ-305 exam requirements, review the four design objectives—identity governance and monitoring, data storage, business continuity, and infrastructure solutions—and understand topics, updates, and exam logistics.
Discover how to use the Udemy video player to adjust playback speed, toggle captions and transcripts, and participate in course reviews and Q&A to enhance your learning.
Discover how the Azure free account works: 30 days with a $200 credit, 12 months of free services, and always free options, with no automatic charges after the period.
Design identity governance and monitoring solutions with logging guidance, authentication via Azure Active Directory and Azure Key Vault RBAC, and governance across management groups, subscriptions, resource tagging, and Azure Policy.
Explore how Azure collects metrics and logs from resources, including Windows and Linux, and routes them to Log Analytics, storage, or Event Hub with retention and regional considerations.
Discover Azure Monitor as the centralized repository for diagnostics and logs, sending data to Log Analytics workspace, and use queries, alerts, and dashboards to monitor virtual machines, apps, and more.
Learn how to enable Application Insights on an Azure App Service Web App, leverage autoinstrumentation and manual instrumentation, and use Azure Monitor and live metrics to diagnose performance and failures.
Enable the Azure Monitor Agent on a Windows VM running IIS to collect VM Insights and Application Insights data, view performance metrics, and configure data collection rules.
Monitor storage accounts with Azure Monitor insights, tracking ingress and egress, latency, requests, and client errors. View failures, set alerts, analyze logs, and spot misbehaving accounts.
Select a resource, view vm metrics, and configure an alert rule to notify when vm cpu exceeds 80% for five minutes, using an action group that emails John.
Explore how Azure Monitor logs collect data from resources, use the query editor and Kusto to analyze heartbeats, availability, time ranges, and charts across scopes.
Discover Microsoft Sentinel, a SIEM service that connects to a log analytics workspace to detect, investigate, and respond to threats using hunting and 290+ data connectors.
Explore how role-based access control assigns users to roles with scoped permissions in Azure Active Directory tenants, contrasting with claims-based access, to streamline directory and resource management.
Explore how Azure Active Directory enables identity management for cloud-based applications through authentication flows, B2B and B2C collaboration, and AD Connect synchronization with on-premises AD.
Learn identity management with Azure Active Directory, compare it to on-premises Active Directory, create tenants and users, assign permissions, and switch between multiple tenants (Entra ID future).
Create a new Azure AD tenant as a global administrator, choose Azure AD (not B2C), set a unique onmicrosoft.com domain with Europe data residency.
Learn the difference between authentication and authorization, and how Azure Active Directory enforces password policies, multi-factor authentication, single sign-on, external federation, and role-based access control for users and partners.
Enable single sign-on by synchronizing on-premises Active Directory with Azure Active Directory using AD Connect, so corporate users log in with their passwords across cloud and on-premises apps.
Azure AD Connect Cloud Sync is a cloud-hosted alternative that centralizes synchronization for multiple on-prem forests using a lightweight agent, handling users, groups, and contacts, not devices or pass-through authentication.
Explore how IPSec encrypts data at the IP layer with authentication header signing to secure traffic and enable site-to-site and remote VPNs, not limited to HTTP.
Enable self-service password reset in Azure AD for all users on premium plans, allowing password changes from any device while enforcing two authentication methods for admins, with optional on-premises write-back.
Explore how authorization determines what a user or app can do after authentication, comparing role-based and claims-based models, with granular permissions, batch jobs, and third-party access in Azure Active Directory.
Explore the design-focused approach to authorization in azure. Use Azure AD to register apps, assign roles, implement conditional access and MFA, and protect secrets with Azure Key Vault.
Explore how Azure Active Directory uses groups to grant application access, including on-premises sync, self-registration, dynamic groups, and RBAC with built-in and custom roles.
enable just-in-time access for virtual machines by temporarily opening RDP or SSH ports via azure defender, using RBAC checks and dynamic firewall and NSG changes to limit exposure.
Explore the Azure Resource Graph to query resources in your subscription with kql, using Resource Graph Explorer and programmatic access via PowerShell, CLI, and REST APIs.
Explore how governance becomes code with Azure policy, using JSON policy definitions to enforce secure transfer and encryption on storage accounts via built-in and custom policies.
Assign a secure transfer of data policy to a scope such as a subscription, management group, or resource group, and enforce https only for storage accounts with optional overrides.
Azure blueprints are deprecated; adopt template specs and deployment stacks to standardize and share ARM templates and Bicep files, grouping them for subscription provisioning.
Design data store solutions by evaluating relational options (SQL Server in VM or managed instance), semi-structured data (Cosmos DB), and unstructured blob, balancing features, performance, costs, protection, and data integration.
Design a data platform by choosing between managed and unmanaged data solutions, highlighting built-in high availability, auto scaling, threat detection, and auto tuning in managed options.
Explore relational versus non-relational databases, detailing SQL, primary and foreign keys, normalization, and joins, then contrast with NoSQL document, key-value, and graph stores for scalable, flexible data.
Explore data auditing and caching strategies for SQL Database, leveraging transactional and event logs, server- or database-level auditing, and Azure Monitor integration to power alerts, reports, and Power BI visuals.
Explore Azure SQL Database pricing by comparing vcore and DTU models; DTUs, or database transaction units, provide a relative performance measure while you forgo hardware controls.
Explore Cosmos DB pricing by storage and provisioned throughput, measured in ru/s, and learn how reserving capacity affects performance for different data models and APIs.
Explore SQL database data retention, using automatic geo-redundant backups and point-in-time restores from seven to thirty-five days, plus long-term retention up to ten years for governance and cross-region restoration.
Explore availability, consistency, and durability in databases, including regional replication, latency trade-offs, and business critical SQL tiers promising five seconds of data loss and 30-second failover.
Use a data warehouse for analytical and reporting needs by consolidating data from multiple sources into a single, read-only dataset optimized for analysis; avoid transactional workloads and enable Power BI.
Geo-replication enables global data distribution across Azure SQL Database and Cosmos DB, with multi-master replication and active-standby failover managed by Traffic Manager.
Learn data protection through encryption strategies, including transparent data encryption for Azure SQL Database and Cosmos DB, data in transit via https, and key management with Azure Key Vault.
Learn how to scale Azure SQL Database and Cosmos DB, comparing DTU and vCores pricing, perform manual scaling, implement read scale-out with geo-redundant replicas, and use sharding to distribute data.
Secure Azure data by using network isolation and firewalls to restrict access. Implement virtual network service endpoints and Azure AD authentication to control access to SQL databases and Cosmos DB.
Identify sensitive data in your data catalog, apply data loss prevention policies, and enforce least privilege and temporary access via Azure AD and Azure Information Protection.
Explore Azure database monitoring in the portal, using metrics, query performance insight, and advisor recommendations; enable intelligent insights and diagnostic logs, and analyze results in Azure Monitor with SQL Analytics.
Design resilient business continuity solutions by implementing backup and recovery and high availability to withstand disasters and ransomware threats, including Azure Site Recovery, failovers, redundancy, scalability, and availability zones.
Plan for business continuity with Azure Site Recovery to back up, replicate, and fail over to a standby region like Central US using a Recovery Services vault.
Explore Azure site recovery failover strategies, including test failover with no data loss, actual failover, and planned failover, using recovery services vault to switch between East US and Central US.
Azure Site Recovery supports disaster recovery across multiple environments, including Azure regions, on-premises VMware, Hyper-V, and physical servers, with testing and failover and cloud-based replication between two on-premises sites.
Explore how geography shapes azure site recovery and business continuity through paired regions that enable fast data synchronization, while considering migration, backup strategies, and cross-region pricing.
Complete preparation for the Azure AZ-305 exam.
COURSE BONUS: Free study guide PDF available for download inside the course.
Microsoft Azure is a skill in high demand in today's large business marketplace.
According to Microsoft, Azure is being used by 85% of the Fortune 500 companies, particularly with their hot Office 365 suite
Use of Azure has grown 51% year-over-year
Salary survey sites report that Azure Architects earn up to US$170,000 per year across the United States
Microsoft has more than 100 data centers, across 60+ regions and 10 geos, making it one of the largest data centers in the world.
This course also goes through the requirements of the Azure AZ-305 exam: Designing Microsoft Azure Infrastructure Solutions, section by section.
I'm quite confident that this is the most complete training course targeted specifically at the exam.
While the technology world is full of "buzzwords" and "flavors of the month", the cloud is a real paradigm shift in the way solutions are designed and architected. There are now so many reasons why you should include Azure cloud technology in the design of your solution that there are almost no reasons why not to do it.
Cost savings is the one that catches the attention of businesses. Some companies are spending millions of dollars per month of their IT infrastructure, and every few years that hardware needs to be repaired and upgraded. Being able to reduce capital investment and essentially rent powerful equipment on demand is quite a lot of upfront savings.
If you add in the scalability, flexibility, and worldwide reach of the cloud and the technology group sees the potential as well. You can truly do more with less.
This course goes through all of the requirements of the Microsoft exam AZ-305 exam: Designing Microsoft Azure Infrastructure Solutions. Multiple videos are devoted to each sub-objective, and we cover the topic thoroughly.
Most of the courses and content you find online assume you already have expert knowledge of Azure and just tells you what to study, spending only seconds covering entire objectives. I can confidently say this course goes deep on everything you need to know.
If you ARE already an expert at many Azure topics, you can easily skip the sections that you already know and focus on the ones you have not yet had much exposure also. This is the benefit of having the complete course.
Each section has additional web-based resources for you to do further research and expand your knowledge beyond the requirements of the exam.
Enroll today!
Version history
V1.0 Launched Aug 2019
V1.1 OCT 2019 - Updates to audio quality. English closed captions added.
V1.2 DEC 2019 - Review of exam updates. Course updated for the latest requirements.
V2.0 SEP 2020 - AZ-304 updates have started. New and updated videos being added.
V2.1 JAN 2021 - New videos added - JIT access, Azure Policy, Azure Blueprint, Resource Graph, Storage Migration Service.
V2.2 MAY 2021 - Course update with new content - Cost Optimization, Storage Management, Maintainability.
V3.0 NOV 2021 - Updated with AZ-305 content.
V3.1 JUN 2022 - Updated
V3.2 AUG 2023 - Updated
V3.3 SEP 2023 - Updated
Microsoft, Windows, and Microsoft Azure are either registered trademarks or trademarks of Microsoft Corporation in the United States and/or other countries. This course is not certified, accredited, affiliated with, nor endorsed by Microsoft Corporation.