
Kick off the AZ-305 Microsoft Azure architect design certification prep with an overview of course goals, structure, and key topics.
Prepare for the az-305 exam by mastering monitoring, identity and security, data storage, business continuity, and infrastructure design across computing, networking, and app deployment in azure.
Explore the module on cost optimization and monitoring in Azure, using Azure Monitor, Azure Policy, and Azure Sentinel to manage budgets and minimize expenses across compute, network, storage, and identities.
Estimate total cost of ownership with the Azure cost calculator, analyze current usage, and optimize region-aware compute and storage costs via cost analysis, cost management, and Azure advisor.
Explore cost management in Azure by using virtual machine scale sets, low-priority instances, and dynamic scaling policies to match CPU and memory utilization while optimizing storage costs.
Minimize compute costs by using Azure reserved virtual machine instances to lock in 1-year or 3-year terms, achieving about 18% and up to 32% savings, via the Azure portal.
Navigate Azure Active Directory editions—free, basic, premium P1, and premium P2—covering self-service password reset, multifactor authentication, on-premises synchronization, 500,000 object limit, and pricing.
Minimize Azure storage costs by selecting appropriate disk types, choosing hot/cool/archive blob tiers, and implementing lifecycle policies, backups, and retention rules to manage snapshots and unused disks.
Explore cost-minimization methods across compute, identity, network, and storage, and learn how Azure monitoring, Azure Application Insights, Azure Policy, and Azure Sentinel with events, routing, and escalation reduce costs.
Compare monitoring with auditing and compliance, and craft a strategy using Azure Monitor's unified platform for metrics, logs, application traces, and identity and security across apps, data, and infrastructure.
Explore audit and non-technical compliance requirements for Azure solutions, including policy enforcement, tagging, data sovereignty, and regional compliance offerings to meet legal and industry standards.
Explore how Azure Monitor provides a unified platform for logs, metrics, and traces, comparing application insights with native monitoring, and covering activity log, service health, alerts, and log analytics.
Explore how Azure Application Insights analyzes performance, usage, and availability, visualizes component interactions with application map, and exports diagnostic data to Azure Monitor or Event Hub.
Explore Azure Monitor use cases for storing and routing information, archiving logs to Log Analytics or storage, and configuring resource-specific diagnostic settings and alerts.
Audit and enforce resource compliance with Azure Policy by applying definitions, assignments, tags, scope, and initiatives to meet corporate requirements.
Understand how azure sentinel enables cloud-native log aggregation and correlation across on-prem and multi-cloud sources to detect threats and support forensics with automated responses.
Connect Azure Sentinel to a Log Analytics workspace, configure data connectors such as Azure Active Directory and AWS CloudTrail, and create alerts, playbooks, and incidents for threat hunting and automation.
Explore multifactor authentication, Azure AD B2B and B2C, and how privileged identity management, self-service password reset, and self-service group management secure identities and guide Azure resource access.
Explore why identity sits at the core of modern security, covering identity and access management, federation, directory services, and an identity-centric model with multifactor authentication and single sign-on.
Explore access control models—mandatory, discretionary, rule-based, and role-based—along with history-based and attribute-based dynamic security groups, including Azure conditional access and identity protection.
Learn how on-premises identities synchronize to Azure Active Directory using AD Connect to enable secure access to cloud-based apps with conditional access, MFA, and RBAC.
Discover Azure Active Directory as a cloud-based identity and access management solution, covering user and group management, B2B collaboration, single sign-on, and enterprise applications for RBAC.
Explore authentication and authorization with Azure products such as multifactor authentication, Azure Active Directory Connect, and service identity management; learn when to choose each in real-world solutions.
Explains authentication and authorization concepts and how protocols like OpenID Connect, SAML, and Deblieux Federation enable single sign-on and token-based access with Azure Active Directory.
Explore cloud-only and hybrid Azure AD authentication options, including password hash sync, pass-through authentication, and federation, along with their features, limitations, and decision guidance for hybrid identities.
Explore single sign-on methods for Azure AD, including OpenID Connect, SAML, and password-based options, with centralized identity management. Choose on-premises options like integrated Windows authentication and header-based SSO.
Configure single sign-on for a G Suite app in Azure, using Salmo as the preferred method, exchange sign-in and sign-out URLs and entity IDs, and enable provisioning and user sync.
Discover how multifactor authentication strengthens identity security in azure through two or more factors—password, a device, or biometrics—applied via conditional access for strong, user-friendly protection.
Register a new app in the azure portal, configure OpenID Connect and OAuth2, set redirect URLs, tenant and client IDs, and test local authentication with Microsoft samples.
Explore how conditional access policies protect identities by evaluating risk, location, device, and user attributes, then configure policies with groups, applications, and MFA requirements.
Azure AD Connect synchronizes on-premises Active Directory identities to Azure AD, enabling access to cloud apps via a default 30-minute one-way sync and optional password write-back.
Monitor hybrid identities with Azure AD Connect Health and track on-premises to Azure Active Directory synchronization. Configure notifications and licenses for agents, and manage auto update settings.
Learn to monitor Azure Active Directory with security reports, activity reports, and Azure Monitor, identify risky users and risky sign-ins, and leverage log analytics for insights.
Enable self-service capabilities in azure active for group management, application access, and password reset, empowering users to create groups, manage memberships, access gallery apps, and reset passwords securely.
Explore azure ad b2b for secure external collaboration by inviting guest users, federating with partners, and granting access to apps and resources with roles, terms of use, and multifactor authentication.
Explore the purpose of Azure AD B2C for external users, create and link a B2C tenant to your subscription, and configure applications with identity providers and user flows.
Choose between cloud authentication and federated authentication in Azure Active Directory using a decision tree, balancing on-premises security, password hash sync, pass-through, and identity protection features.
Explore the difference between authentication and authorization, how identities sync with Azure Active Directory from on-prem, and how role-based access control enables permissions to resources in Azure.
Organize subscriptions using Azure management groups to apply governance, policies, and budgets across hierarchies; inherit conditions ensure consistent access, compliance, and cost reporting for business units and teams.
Azure subscriptions are billing units linked to your account, supporting production, development, and testing under one umbrella; monitor costs with cost analysis and grant access via IAM roles.
Explore Azure subscription options, including free, pay-as-you-go, enterprise agreement, and student plans, with credits, 12-month free products, always-free offerings, identity verification, and monthly charges.
Master rule-based access control to grant precise access to users, groups, and service principals, by defining actions allowed and denied and applying rules at subscription, resource group, or resource levels.
Learn how RBAC roles control access to Azure resources, with built-in Owner, Contributor, and Reader permissions, and how to assign roles via the Azure portal using Azure Active Directory.
Learn how Azure Active Directory roles and permissions govern access, including global administrator power, role descriptions, and how permissions flow from management groups to subscriptions and resources.
Explore role definitions in Azure Active Directory, detailing how each role's name, id, description, actions, not actions, and assignable scopes govern permissions.
Retrieve azure role definitions with PowerShell, inspect JSON attributes like name, id, description, actions, notActions, and scope, then filter results to show name, description, or actions.
Explore how the Azure resource hierarchy, from root management group to subscriptions, drives RBAC and policy inheritance, and learn to manage top-level permissions carefully to avoid unintended access.
Enable governance with access reviews by allowing reviewers to validate group and resource permissions, ensuring appropriate access and visibility across cloud and premise identities.
Identify, assess, and control identity risks using a framework focused on assets and threats; remediate and mitigate with MFA, least privilege, and centralized azure identity management.
Identify risky identities with Azure Active Directory Identity Protection, using machine learning to flag leaked credentials, impossible travel, and sign-in risks, then enforce remediation via conditional access and MFA.
Explore how Azure Identity Protection and Privileged Identity Management monitor risk, generate alerts, and deliver notifications and weekly digests, with audit history and action links.
Explore Azure privileged identity management (PIM) to enable just-in-time, time-bound access with approvals, MFC enforcement, and audit logs for secure, least-privilege elevation.
Explore Azure AD password protection, focusing on banned passwords and smart lockouts to defend identities, and understand licensing for cloud native, hybrid, and customization using P1 and P2 licenses.
Learn to navigate Azure Active Directory licensing, separating free features from paid options, and map needs to P1 or P2 licenses for conditional access, MFA, and identity protection.
Learn how just-in-time VM access strengthens security by opening port 22 only when requested, using Azure Security Center and Defender to grant temporary access for admins.
Organize an Azure environment by structuring subscriptions, resource groups, and resources, and use tagging to map costs, isolate billing, and manage security across multiple business units.
Learn how Azure Policy helps your organization meet compliance by auditing and enforcing resource configurations, tagging, encryption, backups, and region rules through policy definitions and initiatives.
Learn to automate infrastructure deployment with Azure blueprints by composing repeatable artifacts, including role assignments, policies, and ARM templates, plus resource groups across multiple subscriptions.
Learn how Azure Key Vault enables secret, key, and certificate management with access policies to securely store and retrieve credentials, keys, and certificates.
Discover how system-assigned identities in Azure virtual machines authenticate to Azure AD services, enabling read-only access to resources and Key Vault without embedded credentials.
Explore block, file, and object storage paradigms and when to use each for scalable cloud architectures. Understand access patterns, connectivity, metadata, and design considerations for unstructured data.
Explore azure files as a cloud-based path toward replacing on-prem file servers, using serverless smb file shares, and reviewing authentication and security gaps with access keys and signatures.
Explore Azure Store Simple, a hybrid cloud storage platform using SSD and HDD tiers, auto tiering, on-prem appliance, encryption at rest, and geo-replication for secure backups and archival storage.
Explore how databases evolved from relational systems to non-relational stores, and how data lakes and warehouses enable analytics and business insights in the cloud.
Explore Azure SQL Database as a service for relational data, covering SQL Database, managed instance, and virtual machines options, with v-core pricing, performance tiers, backups, security, and cloud-native deployment.
Explore elastic pools for cost-effective scaling across multiple databases on a single server, and enable automatic tuning and read scale out to boost performance for read-heavy workloads.
Leverage Cosmos DB, Microsoft's flagship multimodal, globally distributed non-relational database, to power planet-scale apps with multi-region read and write across geographies and APIs for MongoDB, Cassandra, and Gremlin.
Explore Azure Synapse Analytics, its big data pipeline and Spark engine, to build data warehouses and big data analytics with a unified studio pool and parallel processing.
Discover Azure data lake storage for unstructured data at petabyte scale with high throughput, and configure storage accounts, containers, pricing tiers, and network considerations for scalable data ingestion.
Explore data flow fundamentals, when to move data, and key data flow architectural concepts. Learn technologies for data movement, integrating data management platforms, data movement frequencies, and orchestration options.
Learn how Azure Data Factory enables hybrid data integration by connecting on-premise and cloud sources, building pipelines with datasets to copy and transform data via triggers or schedules.
Explore Azure Databricks, a spark-based analytics platform for data science and machine learning. Set up a workspace, clusters, and notebooks to analyze data and visualize results with Power BI.
Discover Azure storage as a Microsoft cloud storage solution for websites, apps, and cloud services, covering vm storage (disks and files), unstructured blobs, and structured data (tables and Cosmos DB).
Explore Azure Blob storage for unstructured data, Azure Files for shared file access via SMB and SAS tokens, queues for asynchronous messaging, and Cosmos DB tables for global, scalable throughput.
Choose between standard and premium storage: standard uses magnetic drives for bulk storage at low cost, premium uses solid state drives for low latency; conversions between types aren't supported.
Choose between general-purpose v1, v2, and blob storage. Provide general-purpose v2 as the latest, offering the lowest costs and supporting blob, files, disks, and tables, including block and append blobs.
Learn to provision a storage account within a resource group using GUI, PowerShell, and Azure CLI, specifying name, location West US, replication type local storage, and storage v2.
Learn to create a resource group and a storage account in PowerShell, declare and reuse variables, add inline comments, and verify resources with get commands.
Explore how to use Azure Storage Explorer to connect to multiple subscriptions, manage blob storage, tables, queues, and file storage, and access data lake across Windows, Linux, and Mac.
Learn how a storage account hosts containers that organize unlimited blobs, with naming rules using lowercase letters, numbers, and hyphens, and the relationship among storage accounts, containers, and blobs.
Learn how to tailor Azure storage using hot, cool, and archive tiers to match data access patterns, balancing IOPS, retrieval latency, and cost from days to months.
Identify block, append, and page blobs, and understand their creation and limitations; learn to upload data with easy copy and Azure Data Factory.
Stored access policies add a security layer by controlling shared access signatures, setting start and expiry times, permissions, enabling revocation after issuance, and binding to containers, blobs, or file shares.
Evaluate when to use Azure file shares versus blobs or disks, noting that file shares offer SMB access and cross-platform mounting, with caching and pricing considerations.
Explore Azure storage security, focusing on encryption and access control with RBAC and shared access signatures, and securing data in transit.
Explore authorization options for Azure storage resources, including access keys, encrypted signatures in the authorization header, delegated access with time-limited signatures, and anonymous public containers or blobs for customer-facing apps.
Explore shared access signatures that grant granular, time-limited access to Azure storage (blobs, tables, queues) with start and expiry, permissions, and IP and protocol restrictions using Q1 or Q2 keys.
Learn SAS best practices for secure shared access signatures, mitigating leakage risks, using stored access policies, setting short lived expirations, renewing timely, and validating data written via SAS.
Understand how blob and container access levels control permissions in storage. Configure private and public read access to support web apps.
Explore Azure Site Recovery to design fault-tolerant business continuity solutions, recover from major disasters, and use Traffic Manager to keep services online with minimal business impact.
Explore disaster recovery and business continuity concepts, including replication, backups, and recovery objectives, and learn how Azure Site Recovery enables high availability and rapid failover.
Learn how azure site recovery replicates from a primary to a secondary site, enabling disaster recovery with automated replication, application consistent backups, vss, and recovery plans for azure-to-azure or on-premise-to-azure.
Explore Azure backups and compare to Azure site recovery, then configure agents and retention policies for Windows, Linux, and on-premises workloads.
Explore data archiving strategies, define archiving and archival storage, and examine Azure archival solutions along with essential considerations for architecting archives.
Explore archiving fundamentals, compare archiving with backup, and design cost-aware archival storage using lifecycle tiers (hot, cool, archive) to meet regulatory retention and compliance requirements.
Design archival solutions using Azure blob storage hot, cool, and archive tiers, compare pricing and access times, and automate data movement with lifecycle management.
Explore fundamentals and strategies for high availability, and learn how to design and connect data centers, services, and connectivity to ensure infrastructure and applications stay highly available.
Learn high availability concepts and how to guard against outages and faults. Design for redundancy with VM skill sets, failover groups, and load balancing, plus traffic manager and monitoring.
Explore how regions, regional pairs, and availability zones enable highly available Azure solutions. Learn to use availability sets with fault and update domains to protect against outages.
Learn Azure storage availability with replication options such as LRS, ZRS, GRS, and GZRS, plus Joselin redundant storage, and apply compute availability sets and VM scale sets for resilience.
Explore high availability for connectivity by comparing load balancer, application gateway, and traffic manager to distribute traffic, ensure health checks, and enable regional and dns level global routing.
Explore deployment fundamentals, Asia-specific deployment approaches, and best practices, then review deployment tools and Azure services to deploy solutions in Azure.
Define a base Azure architecture and governance, including subscriptions, tenant configuration, security policies, connectivity, and configuration management, deploying resources consistently with infrastructure as code and ARM templates.
Explore Azure resource manager templates as infrastructure-as-code, using JSON to describe parameters, variables, resources, and outputs for reliable, repeatable deployments across development, quality, production, and test environments.
Azure automation provides cloud-based process automation and configuration management for deploying and managing resources across hybrid and on-premises environments using runbooks, graphical or powershell/python workflows, and supporting Windows and Linux.
Implement data replication and zone redundancy to maximize availability and recoverability, while securing data at rest, in transit, and in use with encryption and access controls.
Explore Azure Ezekial data protection through backups, high availability, and disaster recovery, including standard and premium architectures, geo-replication, failover groups, and long-term backup retention.
Configure firewall rules and IP access to secure Azure SQL. Integrate Azure Active Directory for access control and enable transparent data encryption, always encrypted, and dynamic data masking.
Discover how azure data warehouse delivers inherent availability via massively parallel architecture and shard-based storage, with snapshots, restore points, and 99.9% SLA, along with security options.
Enable multi-region replication to boost Cosmos DB availability, with automated four-hour backups, snapshots, and export options, while enforcing firewall controls, key-based access, and resource tokens for mobile access.
Explore migration fundamentals for moving solutions to Azure, covering key concepts, considerations, and common steps across frameworks and essential tools for migrating servers and databases.
Identify workloads, assess compatibility, and design the end-state migration from on premise to Azure, applying the four hours—re hosting, refactor, retexture, rebuild—for deployment, cutover, and post-migration maintenance.
Use the Azure Import Export Service for offline data transfer on physical drives, shipping them to Azure data centers to import into blob or file storage, with drives encrypted.
The AZ-305 exam is targeted at experienced IT experts, the exam covers a variety of subjects and services, all of which are covered in this latest course updated as per Microsoft Exam Curriculam. In order to understand core architect technologies, This course will lead you through a series of sections, modules, and demos to prepare you for taking, and ultimately passing, the Microsoft Azure AZ-305 exam.
This course curriculum is as follows:
Design monitoring (10-15%)
Design identity and security (25-30%)
Design data storage (15-20%)
Design business continuity (10-15%)
Design infrastructure (25-30%)
The Lectures will educate you on the fundamental terms and principles of the Azure platform and demos will enable you with a hands-on experience using scenarios to empower you in the real world. This course goes through all of the requirements of the Microsoft exam AZ-305: Microsoft Azure Architect Design. Multiple videos are devoted to each sub-objective, and we cover the topic thoroughly. If you are already an expert at many Azure topics, you can easily skip the sections that you already know and focus on the ones you have not yet had much exposure too. This is the benefit of having the complete course
Welcome to this course! We’re happy you’re joining us! I'm quite confident that this is the most complete training course targeted specifically at the exam.
Note: If you took the AZ-300 course, there will be some overlap. There is a lot to repeat around subjects covered in AZ-300 to make sure you have the basis on core technologies that align with the curriculum. Where possible, I try to make the distinction but you will find that we need to cover core infrastructure topics again before moving onto design elements. Feel free to ignore these videos if you took my AZ-300 course, or watch them again for a good refresh before taking your AZ-301 exam. I continue to update this course based on design examples so you can try to take your hands on knowledge & think about it from an architecture perspective.