
In this Chapter I have covered What is Microsoft Azure and its advantages
A tenant represents your organization and houses subscriptions, which provision resources like virtual machines and Office 365 apps in Azure, and you can change the subscription's directory.
Discover how Azure VM service provides on-demand, scalable compute with usage-based pricing and flexible VM series choices for your workloads, including availability sets and zones for uptime.
Learn to create and manage Azure disks, attach data disks, and resize the operating system disk on an Azure VM, choosing premium or standard options.
Create a network security group in the Azure portal, bind it to a production subnet, and review inbound and outbound rules. Configure default allow within the virtual network, add deny all rules at priority 3000, and create specific allow rules for necessary traffic.
Establish vnet peering to connect virtual networks across subscriptions and regions, with traffic routed over Azure backbone for low latency. Ensure ip ranges do not overlap to enable seamless connectivity.
Explain Azure virtual network routing, including default system routes, user-defined routes, and BGP, and show how to route traffic via firewall, VPN gateways, peering, and service endpoints.
Learn how Azure Active Directory provides cloud-based authentication and identity and access management for services like Office 365 and Azure Virtual Desktop, including cloud, on-premises, and hybrid scenarios.
Learn to buy a domain and register it in Azure Active Directory, configure DNS for verification, and add the custom domain to enable single identity across on-premises and Azure services.
Learn how Azure AD Connect links on-premises identity to Azure, enabling a unified single identity for access to cloud and on-premises apps, via password hash synchronization, pass-through authentication, or federation.
Explore how Azure DNS provides default name resolution with internal.cloudapp.net and configure custom DNS to use your own DNS servers for VM name resolution and domain joining.
Explore Azure public dns zone for hosting public dns records. Create a zone, add an a record to the public IP, and delegate to Azure name servers.
Configure a site-to-site VPN between Azure and on-premise by provisioning a VPN gateway and local network gateway, installing routing and remote access on Windows Server, and validating connectivity with ping.
Explore how Azure NAT gateway provides outbound internet access for private VMs without public IPs, enabling scalable access via a single NAT IP.
Highlight Azure Virtual Desktop advantages over other VDI solutions: Office 365 licenses include AVD at no extra cost, Microsoft-managed services, and Windows 10/11 multi-session for scalable, cost-effective access in Azure.
Explain Azure Virtual Desktop architecture, contrasting customer-managed resources (networks, Active Directory, domain services, session hosts, workspace) with Microsoft-managed services (web access, gateway, connection broker, diagnostics) in a PaaS model.
Meet the prerequisites for Azure virtual desktop: an active subscription, identity providers, domain join via domain services, suitable images, a license, plus proper network, DNS, and remote desktop access.
Learn to plan and design an Azure virtual desktop, covering identity and access management, network and connectivity, compute sizing, storage options, and backup and disaster recovery best practices.
Learn how Azure Shared Image Gallery centralizes and replicates VM images across regions, using image sources, definitions, and versions to enable rapid disaster recovery for Azure Virtual Desktop.
Assign hybrid, on-premises-synced users to the application group by clicking add, selecting FS Test1 and FS Test2, and then logging in to access the Azure virtual desktop.
Explore Azure Virtual Desktop host pool, application group, and workspace settings, including properties, session behavior, device redirection, access control, diagnostics, and scaling options.
Learners configure a storage private endpoint to force traffic through a private IP on a storage account, block public internet access, and set up private DNS for secure access.
Configure a FSLogix profile disk alert with group policy and a logon script to notify users at 70% usage, using registry to set a 30-second message duration with loopback processing.
Apply azure policy to enforce location-based deployment, achieve organization-wide resource governance, and centrally track compliance and noncompliance by defining rules with scope at subscription, resource group, or management group.
Learn to configure and test AppLocker in Azure Virtual Desktop by whitelisting and blacklisting applications and scripts on Windows 10.
Configure Azure virtual desktop alerts by creating action groups and alert rules for virtual machines, storage, and disks, then set memory, cpu, and storage thresholds and test notifications.
Explore the microsoft endpoint management (Intune) portal to manage devices across Windows, Android, iOS, and Mac, covering Windows enrollment, compliance policies, configuration profiles, and PowerShell script deployment.
Deploy Office 365 apps to an Azure Virtual Desktop via Intune. Publish Word and Teams, configure 64-bit, current channel, and shared activation for multi-session.
Package and deploy a Win32 app to Azure Virtual Desktop using the Intune content preparation tool and Intune portal, with 64-bit deployment and a manual detection rule.
Create a security dynamic device group in Intune by using a dynamic query that includes devices whose display name starts with a prefix, enabling automatic inclusion for applying compliance policies.
Explore how Azure Site Recovery protects Azure Virtual Desktop personal host pools by replicating disks to a secondary region, using crash and application consistency snapshots, and performing failover.
Configure FSLogix profile for Azure AD joined session hosts with Azure Kerberos, including creating an Azure premium file share and enabling Kerberos ticket access for hybrid users.
Azure virtual desktop custom image templates automate master image customization, installing language packs and apps during image creation and publishing as a managed image or compute gallery.
In this Course you will learn about how to plan, design, implement and monitor Azure cloud services and Azure Virtual Desktop Infrastructure.
This Course does not require prior azure knowledge and we will cover from the basics of azure to deploy the AVD Infrastructure
This training course is a combination of Azure Architect (AZ-305) and AZ-140 where I have included topics from Azure compute, network, storage and Identity and Access management as well as Azure Virtual Desktop so such mix and match you would not find anywhere.
All concepts covered in this course are aligned to the following Exam Objectives
Plan an Azure Virtual Desktop Architecture
Implement an Azure Virtual Desktop Infrastructure
Manage Access and Security
Manage User Environments and Apps
Monitor and Maintain an Azure Virtual Desktop Infrastructure
In this course, you will learn about below Azure cloud and Azure Virtual Desktop services .
Design the Azure Virtual Desktop architecture
* assess existing physical and virtual desktop environments
* assess network capacity and speed requirements for Azure Virtual Desktop
* recommend an operating system for an Azure Virtual Desktop implementation
* plan and configure name resolution for Active Directory (AD) and Azure Active Directory Domain Services (Azure AD DS)
* plan a host pools architecture
* recommend resource groups, subscriptions, and management groups
* configure a location for the Azure Virtual Desktop metadata
* calculate and recommend a configuration for Azure Virtual Machine capacity requirements
Design for user identities and profiles
* Select an appropriate licensing model for Azure Virtual Desktop based on requirements
* recommend an appropriate storage solution (including Azure NetApp Files versus Azure Files)
* plan for Azure Virtual Desktop client deployment
* plan for user profiles
* recommend a solution for network connectivity
* plan for Azure AD Connect for user identities
Implement and manage networking for Azure Virtual Desktop
* implement Azure virtual network connectivity
* manage connectivity to the internet and on-premises networks
* implement and manage network security
* secure Azure Virtual Desktop session hosts by using Azure Bastion
* monitor and troubleshoot network connectivity
Implement and manage storage for Azure Virtual Desktop
* configure storage for FSLogix components
* configure storage accounts
* configure disks
* create file shares
Create and configure host pools and session hosts
* create a host pool by using the Azure portal
* create a host pool based on Windows client or Windows Server session hosts and configure host pool settings
* manage licensing for session hosts that run Windows client or Windows Server
* assign users to host pools
* apply security and compliance settings to session hosts
Create and manage session host images
* create a gold image
* modify a session host image
* deploy a session host by using a custom image
* plan for image update and management
* create and use a Shared Image Gallery
* troubleshoot OS issues related to Azure Virtual Desktop
Manage access
* plan and implement Azure roles and role-based access control (RBAC) for Azure Virtual Desktop
* manage roles, groups and rights assignment on Azure Virtual Desktop session hosts
* configure user restrictions by using AD group policies and Azure policies
Manage security
* plan and implement Conditional Access policies for connections to Azure Virtual Desktop
* plan and implement multifactor authentication in Azure Virtual Desktop
* manage security by using Azure Security Center
* configure Microsoft Defender Antivirus for session hosts
Implement and manage FSLogix
* plan for FSLogix
* install and configure FSLogix
* configure Profile Containers
* configure Cloud Cache
* migrate user profiles to FSLogix
Configure user experience settings
* configure persistent and non-persistent desktop environments
* configure Remote Desktop Protocol (RDP) properties on a host pool
* configure session timeout properties
* troubleshoot user profile issues
* troubleshoot Azure Virtual Desktop client
Install and configure apps on a session host
* implement application masking
* deploy an application as a RemoteApp
* implement and manage OneDrive for Business for a multi-session environment
* implement and manage Microsoft Teams AV Redirect
* create and configure an application group
* troubleshoot application issues related to Azure Virtual Desktop
Plan and implement business continuity and disaster recovery
* plan and implement a disaster recovery plan for Azure Virtual Desktop
* design a backup strategy for Azure Virtual Desktop
* configure backup and restore for FSLogix user profiles
* implement autoscaling in host pools
Monitor and manage performance and health
* monitor Azure Virtual Desktop by using Azure Monitor
* customize Azure Monitor workbooks for Azure Virtual Desktop monitoring
* optimize session host capacity and performance
* manage active sessions and application groups
* monitor and optimize autoscaling result