
Discover how to create an Azure free account with a Microsoft or GitHub login and a credit card on file. $200 credit for 30 days and convert to pay-as-you-go afterward.
Explore storage accounts, virtual machines, templates, and networking, plus Azure Active Directory. Learn to implement network security groups, application security groups, and the bastion host, with monitoring considerations.
Learn to use the blob service by creating a container, uploading objects like files and images, and understanding access levels, edits, and viewing limits in a fully managed storage service.
Explore a practical use case of the blob service in azure storage accounts, uploading videos as objects into a container, each with a unique URL and isolated storage.
Explore the Azure storage file service and how file shares store files as normal files accessible via SMB, contrasting with the block service where each object has a unique URL.
Create and manage Azure storage file shares, set quotas, organize directories, and access files via SMB, then connect from Windows, Linux, or Mac using PowerShell or mapped drives.
Explore the Azure storage table service as a schema-less NoSQL option within storage accounts, using entities with PartitionKey and RowKey to store and query course and order data efficiently.
Discover how to download, install, and sign in to Azure Storage Explorer, then view subscriptions and storage accounts to manage blobs, file shares, queues, and tables.
learn how to generate and configure shared access signatures for blob-level access, or storage account level access, in Azure storage, controlling permissions, start and expiry times, and IP restrictions.
Explore the archive access tier, the lowest-cost blob storage option, and learn why objects must be rehydrated to hot or cool before access, with standard priority up to 15 hours.
Deploy machines with the virtual machine service, spin up app and database workloads, delete resources when done, and let Azure manage infrastructure while you pay only for what you use.
Create an Azure virtual machine using the guided wizard. Configure subscription, resource group, region North Europe, image Windows Server 2019, and size standard_D2_V2 with RDP access and cost review.
Allocate an OS disk for the VM and attach data disks as needed, with Azure managed disks providing high availability. Use the temporary disk only for temporary data.
Explore how restarting, shutting down, and stopping an Azure virtual machine affects temporary storage, data on the D drive, public IP addresses, static IP addressing, and compute charges.
Learn how to terminate resources in Azure to avoid extra costs, and delete not just the virtual machine but its network interface and disks by using all resources.
Learn how to attach a secondary network interface to an Azure virtual machine, enabling private IP routing between subnets for enhanced security.
Deploy an Azure virtual machine in a virtual network with subnet-a and subnet-b, then attach a secondary network interface after stopping the VM; enable routing between interfaces with software.
Explore azure virtual machine availability and service level agreements, from 99.9% baseline to 99.95% with availability sets and 99.99% with availability zones, including multiple VMs and multi-zone deployment.
Explore availability sets to protect your applications by distributing virtual machines across fault domains and update domains. Learn how this setup reduces downtime during updates and improves the SLA.
Understand Azure virtual machine scale sets scale out or in, install apps on virtual machines with script extensions or a custom image, and use Azure load balancer to distribute load.
Learn to deploy virtual machines and a virtual machine scale set across multiple availability zones to improve availability in the Central US region.
Explore Azure watcher networking to securely connect resources and define subnets. Understand public and private IPs, compare basic and standard public IP SKUs, and note region scope and zone redundancy.
Explore how network security groups restrict inbound traffic to a Windows virtual machine in a virtual network. Learn about inbound and outbound rules and attaching NSGs to NICs or subnets.
Explore applying application security groups and network security groups to deploy SQL Server on an Azure virtual machine. Includes subnet association, firewall rules, and TCP/IP configuration.
Implement a secure jump server setup by creating a dedicated jump subnet and two Windows servers, assign no public IP to the target VM, and enforce port 3389 NSG rules.
Explore how service endpoints secure access to a storage account by restricting networks, enabling a virtual network and subnet, and verifying access via Azure Storage Explorer.
Set up two Azure virtual machines in staging and test networks, install IIS on the staging machine, and establish virtual network peering to enable cross-network access via port 80.
Demonstrates how to establish a point-to-site virtual private network from another Windows 10 machine by exporting and installing the client certificate, connecting, and managing resources to control costs.
Configure a site-to-site vpn by creating a local network gateway with the company vm public ip and on-premise address range, then link to a higher sku virtual network gateway.
Learn to implement a site-to-site VPN between Azure staging and on-prem networks by configuring gateways, a pre-shared key, and Windows routing with demand-dial, then verify access to the staging VM.
Learn how Azure Resource Manager templates enable infrastructure as code with JSON, define resources, and deploy items like watcher machines and storage accounts, using resource, variable, parameter, and output sections.
Enable and manage Azure backup for Azure virtual machines by selecting or creating a Recovery Services vault, applying policies, and performing file or VM restores from application consistent restore points.
Learn how the MARS Azure Recovery Services agent enables selective backups of files and folders from Windows VMs, through a Recovery Services vault, with on-premise and cloud options.
Explore Azure Active Directory, including managing users and groups, MFA, self-service password reset, and Identity Protection, and learn how Azure AD Connect syncs on-premise directory with Azure AD.
Learn how Azure AD tenants map to directories, how subscriptions trust a single directory, and how to create or switch directories and tenants.
Configure trusted IPs to skip multifactor authentication in a hybrid setup with on premise active directory and Azure AD via ADFS, using a /32 IP example and saving changes.
Azure AD identity protection automates remediation of identity risks with inbuilt intelligence. It detects risky sign-ins from anonymous IPs or unusual locations and applies policies.
Create a security group and users in Azure Active Directory, then set up an access review in Identity Governance to evaluate group membership with a reviewer and recurring schedules.
Set up an active directory domain in azure virtual network by deploying a windows server 2019 machine, installing AD DS, promoting a domain controller, and configuring dns and static ip.
Install azure ad connect on a new Windows Server VM joined to the domain to sync on-premises ad with Azure ad, using express settings, and sql express installed.
Shows signing in with the same local Active Directory user to both a domain-joined Windows 10 client and Azure AD after syncing with Azure AD Connect.
Learn how Azure AD Connect synchronizes on-premises users to Azure AD, view current settings, enable password hash synchronization, staging mode for testing, and sign-in options.
Learn to filter Azure AD Connect by selecting specific domains and organizational units, and verify that only the chosen resource OU synchronizes to Azure AD.
Monitor sync status, password hash sync, pass through authentication, and single sign on with Azure AD Connect Health, and explore health data from the ADDS agent.
Explore how the Azure Migrate service assesses on-premise workloads and migrates them to Azure virtual machines, supporting Hyper-V, VMware, or physical servers through replication, testing, and final migration.
Explore Azure Site Recovery to replicate a Windows Server virtual machine across regions, perform a test failover, and prepare for a real failover with network and recovery services vault setup.
Review Azure Migrate assessment demo, showing how to spin up a Hyper-V virtual machine, create a nat network, attach a virtual hard disk, restore Azure Migrate appliance, and run discovery.
Learn how to perform a test migration in azure migrate, clean up the test resources, stop and disable replication, and delete the azure migrate project and hyper-v server registrations.
Use Azure site recovery to replicate Hyper-V virtual machines to Azure, registering the Hyper-V host with a Recovery Services vault. Create a replication policy and target virtual network for migration.
Distribute user traffic across multiple virtual machines in an Azure virtual network with a load balancer, using a backend pool, front end IP, a health probe, and load balancing rules.
Compare the basic and standard azure load balancers, noting standard's multi-vm backend pools and 99.99% SLA, plus the distinction between internal and external load balancers.
Deploy two Windows Server 2019 VMs with IIS in an availability set hosting default.html. Configure a basic Azure load balancer with a backend pool, health probe, and load balancing rule.
Create a standard Azure load balancer, configure the backend pool, and deploy IIS with default.html on each VM, then configure health probes and a load balancing rule.
Provision two Windows Server VMs with IIS, create default pages, and set up Azure Application Gateway with URL path-based routing to the backend pool.
Enable the WAF v2 on an Azure application gateway, create a custom policy with IP-based rules, and apply it to block requests from matching sources.
Compare Azure load balancer at layer 4 with Azure application gateway at layer 7. Explore how OSI layers and transport vs application data drive routing decisions.
Explore how Azure Front Door routes traffic at layer seven using URL-based routing to the fastest and most available backend pools, with multi-site hosting and SSL termination.
Learn how to create and manage custom roles in Azure at the resource group level, including starting from scratch or JSON, adding permissions, and assigning roles.
Explore how to create and link an app service plan to a web app, compare free, shared, and basic plans, and scale across compute instances to balance load.
Learn to run background tasks inside the Azure Web App service with Azure Web Jobs, supporting PowerShell, Python, or .NET scripts. Choose continuous or triggered with scheduling.
Explore the Azure Web App Diagnostics and App Service logs, enabling application, web server, and deployment logging, with FTP access to log directories and detailed error tracing.
Explore deployment slots in Azure web apps to test new versions in a staging slot with its own DNS name, and swap with production to minimize downtime and enable rollback.
Explore application insights, an application performance management service for web apps that helps monitor, detect anomalies, diagnose issues, and analyze user behavior to improve performance and usability.
Explore azure functions to run code pieces in a serverless environment, billed by execution time. Develop in C#, Java, JavaScript, PowerShell, or Python, and trigger with timer or storage events.
Create an Azure functions app with a unique function name, configure runtime stack .NET 3.1, set region and storage, publish code or a docker container, and enable Application Insights.
Explore hosting azure functions on a consumption plan versus an app service plan, and how to link a function app to a plan while noting backups and scale differences.
Azure functions provide a serverless way to run code without managing infrastructure, offloading modules like email processing to keep your app lean, and using triggers with bindings across languages.
This chapter looks at a lab on Azure Logic Apps
This chapter looks at the Azure Service Bus
This chapter looks at a lab on Azure Service Bus queues
This chapter looks at Azure Service Bus Topics
Deploy the Docker runtime on a Linux virtual machine in Azure, install the Docker engine, pull the EngineX image, run a container exposing port 80, and view the EngineX homepage.
Learn how to deploy containers in isolation with Azure Container Instances, manage underlying infrastructure, and persist data via Azure File Shares while exposing port 5000.
Explore how Kubernetes manages containerized workloads with DNS names, load balancing, restarts, and secret storage, and see how Azure Kubernetes provides a fully managed service on Azure.
Create an Azure Kubernetes Service cluster using the wizard or Azure CLI, configuring resource group, cluster name, region, version, and node pools. Enable authentication, monitoring, kubectl, and cluster connectivity.
Deploy an Nginx container on a Kubernetes cluster using deployment and service yaml files, kubectl commands, and a load balancer to expose Nginx via a public ip.
Explore elastic or server-side transactions that span one or more azure sql databases, ensuring end-to-end rollback on failure and seamless cross-server coordination via .NET libraries.
Explore active geo-replication in Azure SQL databases, enabling a readable secondary on the same or a different server for reports and manual failover; not supported on Azure SQL managed instance.
Explore why NoSQL databases emerged to offer flexible, schema-less data stores beyond relational models, including key-value, document (JSON), and graph options, with Cosmos DB as a NoSQL example.
Explore how Azure Cosmos DB replicates data across read regions and supports multi-region writes with failover for disaster recovery, while noting data integrity considerations.
Explore Azure Cosmos DB consistency levels, from strong to eventual, including bounded staleness, session, and consistent prefix, and how replication across regions affects reads and latency.
Create an Azure Cosmos DB account with the Graph or Gremlin API, set city as the partition key, add vertices and edges, and use Gremlin queries to visualize employee-department relationships.
Learn to create an Azure Key Vault by selecting resource, naming, region, and pricing tier, then set an access policy to manage keys, secrets, and certificates, and review and create.
Explore Azure disk encryption: enable server-side encryption with platform-managed or customer-managed keys, create a disk encryption set, and apply it to OS and data disks.
Learn to implement Azure Disk Encryption using a key vault to encrypt OS and data disks with BitLocker on Windows and dm-crypt on Linux, via portal or Azure CLI.
Learn how managed identities on an Azure virtual machine enable secure access to Azure Key Vault without embedding client IDs or secrets, by obtaining an authentication token via the VM.
Enable a system-assigned managed identity on the Azure VM and grant it Key Vault get and list permissions; the app uses the identity to fetch secrets without embedded credentials.
Create a log analytics workspace and route logs from existing virtual machines to it, considering regional placement to minimize data transfer costs.
Connect Windows and Linux virtual machines to a log analytics workspace by installing the Microsoft Monitoring Agent and sending metrics to a central repository.
Manually install the log analytics agent on virtual machines in on-premises or Azure environments to collect logs by providing the workspace ID and primary key.
Learn to create alerts from Log Analytics queries. Monitor available megabytes when the counter drops below 6,000, configure alert rules and action groups, and review monthly cost estimates.
Configure custom logs to stream Engine X access logs from a Linux VM into a log analytics workspace, creating the Linux_seal table and verifying data in the workspace.
Enable update management for Windows and Linux VMs by linking Azure Automation with a Log Analytics workspace and adding VMs across regions.
Discover how Azure diagnostics stream resource logs to destinations such as a Log Analytics workspace, Azure Storage accounts, and Azure Event Hubs, with data movement via Azure Data Factory.
Enable diagnostics for Azure storage accounts by capturing metrics and logs via diagnostic settings, selecting blob, files, tables, and queues, with 1.0 or 2.0 formats and retention options.
Identify and monitor Azure Function metrics, including response time, memory working set, data in, data out, and function execution count, with setup guidance for Application Insights and Azure Monitor.
Explore how Azure resource tags use name-value pairs to organize resources by department or call center and map costs to billing.
This chapter looks at a lab on working with tags
This chapter looks at costing in Azure
Right here! Avail special discount coupon links for all of my Al Azure and AWS Courses
v 5.0 - March 2021
Added several new videos that includes
Azure Storage accounts - Working with the File and Table service
Azure Storage accounts - Access tiers
Azure AD - Self-service password reset
Azure Blueprints
Azure SQL Managed Instance
Azure SQL - High Availability
v 4.0 - August 2020
Updated course to cover objectives for both AZ-300 and AZ-303
v 3.1 - May 2020
Refreshed multiple chapters including Azure Webs , Azure Functions, Azure Key Vault.
Added more chapters on Azure Cosmos DB
v 3.0 - Apr 2020
Core chapters on Virtual Machines , Virtual Networks and Storage accounts updated to reflect newer features in Azure
Added new chapters on working with Virtual Machines , Virtual Networks and Storage accounts
v2.1 - Sep 2019
Added chapters on Docker , containerizing .Net applications and working with Kubernetes
Added chapters on Managed Service Identity
Added chapters on Azure Event Grid, Azure Event Hub, Notification Hub and Azure Service Bus
v1.0 - Course released - June 2019
"There is a huge demand for cloud based architects. Being an Azure Architect will propel you to the top of the chain"
This course will make students be prepared to take on the following exam
Exam AZ-300: Microsoft Azure Architect Technologies
All concepts covered in this course are aligned to the following Exam Objectives
Deploy and configure infrastructure
Implement workloads and security
Create and deploy apps
Implement authentication and secure data
Develop for the cloud and for Azure storage