
Prepare for the AZ-700 by exploring core networking infrastructure, managed connectivity, application delivery, network security, and private access in Azure through hands-on labs and knowledge checks.
Explore Azure virtual networks, including ip addressing, subnets, and private ip allocation. Learn to peer networks across regions and connect to on premises or cloud via vpn with security controls.
Configure public IP addresses for Azure virtual networks by choosing the appropriate SKU and setting dynamic or static IPs, and assign them to resources like NICs and load balancers.
Design and implement a virtual network in Azure, creating core services VNets across multiple geographies, configuring subnets and IP ranges, and enabling peering in the Azure portal.
Design name resolution for Azure virtual networks using public and private DNS, Azure DNS zones, and delegation; configure DNS in a VNet with common record types and private zones.
Configure a private dns zone, link virtual networks with auto registration, deploy a test vm, and verify name resolution for contoso.com across the private dns zone.
Explore cross VNet connectivity with Azure network peering, including regional and global peering, gateway transit, service chaining, and hub-and-spoke designs, while planning IP address spaces.
Demonstrates creating two virtual networks and configuring global vnet peering. Verify connectivity with an RDP session between the manufacturing VM and the test VMs and private DNS.
Implement Azure virtual network traffic routing using user defined routes, force tunneling, and Azure Route Server to direct traffic through virtual appliances and VPN gateways, with built-in troubleshooting.
Configure outbound internet access for Azure virtual networks with the Azure Virtual Network NAT gateway, providing a regional static public IP, no per-VM public IPs, and no load balancer.
Design and implement the Azure VPN gateway for hybrid networks, planning the gateway subnet, selecting the right SKU, configuring site-to-site and point-to-site connections, and ensuring redundancy and troubleshooting.
Create and configure a virtual network gateway to connect two VNets with a site-to-site VPN, including gateway subnets. Demonstrate deployment with PowerShell and Cloud Shell, and test connectivity via RDP.
Learn to connect devices to networks with point-to-site VPN in Azure using OpenVPN, SSTP, or IKEv2, and authenticate with Azure certificate, on-prem AD, or Azure AD, configuring private address pools.
Explore Azure Virtual WANs to centralize hybrid networking with a hub-and-spoke model. Connect cross-tenant VNets, manage hub routing, and ensure non-overlapping private address spaces.
Demonstrates creating a virtual WAN in the Azure portal, configuring a West US hub, provisioning a VNet connection, and managing site-to-site and ExpressRoute routing.
Deploy a network virtual appliance (NVA) in a virtual hub to support hybrid networking. Configure infrastructure units and select an NVA provider from the Azure marketplace for scalable bandwidth.
Explore Azure ExpressRoute design and deployment, including private peering and VPN integration, various connectivity models from cloud exchange to direct, with high bandwidth, redundancy, and global reach.
Design and deploy Azure ExpressRoute by selecting SKUs and tiers, choosing peering locations and circuits, and sizing bandwidth and billing models for data transfer.
Configure an Azure ExpressRoute gateway by creating a virtual network (VNet) and a gateway subnet, then set up the VNet gateway for ExpressRoute with a new public IP.
Provision an express route by creating and configuring an express route circuit, resource group, and gateway, then review service keys, peering options, and deletion to avoid charges.
Explore configuring private and Microsoft peering for Azure ExpressRoute, using BGP with ASN and MD5, and applying route filters to govern on-premises and Azure resource traffic.
Learn how to connect an Azure ExpressRoute circuit to a VNet by adding a virtual network connection, configuring the gateway, and validating the peering.
Connect geographically dispersed networks using ExpressRoute Global Reach to link multiple ExpressRoute circuits across geopolitical regions. Configure private peering, enable global reach, and connect on-premises networks via the Azure backbone.
Explore expressroute fastpath to improve data path performance between on premises networks and virtual networks by bypassing the gateway, increasing packets per second and connections per second.
Diagnose ExpressRoute connectivity by verifying circuit provisioning and peering status in the Azure portal, validate ARP mappings, and troubleshoot performance using Network Watcher and the Azure Connectivity Toolkit.
Explore Azure load balancing options in portal, including layer four balancer, traffic manager, application gateway, and Azure front door, and learn how health probes and TLS boost security and availability.
Design and implement Azure load balancer in the portal, selecting public or private types, basic and standard skews, zones, health probes, front-end and back-end pools, and NAT for outbound traffic.
Create and configure an internal load balancer in the Azure portal. Configure a virtual network with front-end and back-end subnets, Azure Bastion access, health probes, and a load balancer rule.
Discover how Azure Traffic Manager uses DNS routing to direct users to optimal endpoints, configure profiles and health checks, and implement global routing with various methods.
Set up a traffic manager profile with primary East US and secondary West Europe app service endpoints, configure priority routing and health checks over https on 443, and validate failover.
Learn to design and configure Azure application gateway for HTTPS load balancing, with path-based and multi-site routing, choosing the SKU, and setting up front end, listener, and back end pools.
Configure the Azure application gateway with front-end IP, listeners, routing rules and back-end pools; implement URL-based routing, rewrite policies, health probes, and redirects.
Demonstrate deploying an Azure application gateway, creating a resource group and VNet, configuring front-end public IP, backend pool, routing rule, and two IIS web servers behind the gateway.
Design and configure Azure Front Door as a global, edge-cached entry point with URL path routing, health probes, and TLS in transit, choosing standard or premium for advanced security.
Deploy an Azure front door to deliver a highly available web app across central US and East US by routing app services through origin groups, reducing latency via load balancing.
Learn to design and implement network security in Azure with Microsoft Defender for Cloud, applying the Microsoft cloud security benchmark and network security controls across multi-cloud and on-premises environments.
Deploy Azure DDoS protection via Azure portal to defend against volumetric, protocol, and application-layer attacks. Explore standard, network, and IP protection levels, telemetry, logs, and testing in a hands-on lab.
Configure DDoS protection on a virtual network in azure, create a DDoS protection plan, enable telemetry, and set up diagnostic logs and monitoring for insights.
Deploy and configure Azure network security groups to control inbound and outbound traffic for VNet subnets and interfaces, using default rules, priorities, and application security groups.
Explore designing and implementing Azure Bastion to securely connect to virtual machines via the portal, without exposing port 3389, using a bastion subnet, TLS tunneling, and role-based access control.
Design and implement Azure firewall in a hub-and-spoke topology with stateful rules, NAT and application rules, compare to network security groups, and leverage threat intelligence and Azure Monitor logging.
Deploy and configure Azure firewall in the Azure portal by creating a firewall, policy, and route table within a virtual network, then implement application and network rules.
Azure Firewall Manager centralizes policies and routing for hub virtual networks and secure virtual hubs, enabling hierarchical policies, third-party security integration, and automated connectivity to virtual WANs and express routes.
Deploy and configure Azure Firewall Manager to secure a virtual hub and spoke networks, establish a firewall manager hub, create policies, and route traffic through Azure Firewall.
Implement a web application firewall with Azure Application Gateway and Front Door for centralized OWASP protection. Configure WAF policies, switch between detection and prevention, and create custom and managed rules.
Discover how virtual network service endpoints secure and direct connectivity to Azure services over the backbone. Add endpoints to a subnet to access storage accounts directly.
Explore private link services and private endpoints to securely connect on-premises to Azure services, with traffic staying on the Microsoft network and no public internet exposure via DNS records.
Learn how to integrate private endpoints with DNS by configuring private DNS zones, mapping A records for private links, and using Azure DNS private resolver and forwarders for hybrid environments.
Demonstrates restricting network access to a storage account via a private virtual network, service endpoints, network security groups, and a private subnet, using the Azure portal and virtual machine access.
Learn how to create an Azure private endpoint using Azure PowerShell, set up a DNS zone, and test connectivity via a bastion host within a configured VNet.
Explore how Azure Monitor collects metrics and logs from Azure and multi-cloud resources, and use Metrics Explorer and Network Insights to monitor health, connectivity, and traffic with alerts and diagnostics.
Learn to monitor an internal load balancer with Azure Monitor, configure front and back end, health probes, and logging, using deployment files and a test virtual machine in a lab.
Azure Network Watcher provides regional diagnostics and monitoring tools. It verifies IP flow, checks next hops, diagnoses VPN gateways, and analyzes NSG rules and connections.
Prepare for the AZ-700 exam by using Microsoft Learn to schedule the exam, take the practice assessment, and study the module-by-module guide; review labs to cover the five network areas.
Discover how to design, implement, and optimize secure and scalable network solutions with Azure. This comprehensive certification course covers networking fundamentals, hybrid connectivity, network security, and traffic management. Learn how to build resilient cloud networking architectures using Azure services while ensuring performance, security, and compliance.
Course Format
This course features interactive video lectures, hands-on labs, and real-world networking scenarios. Delivered online, it offers a mix of self-paced learning, guided demos, and practice exams. Most students complete the course in 3-4 weeks, depending on their pace and prior experience.
Designing and Implementing Azure Networking Solutions
Gain expertise in designing, implementing, and managing secure and scalable networking solutions on Azure. Learn how to configure virtual networks, implement hybrid connectivity, and optimize network performance for enterprise workloads.
Securing and Monitoring Network Infrastructure
Master network security by implementing Azure Firewall, DDoS protection, and Network Security Groups (NSGs). Learn how to monitor and troubleshoot network performance using Azure Monitor, Network Watcher, and other diagnostic tools to ensure high availability and resilience.
Hybrid Networking and Load Balancing
Understand how to integrate on-premises networks with Azure using VPNs, ExpressRoute, and virtual WAN solutions. Learn how to optimize application delivery with Azure Load Balancer, Application Gateway, and Traffic Manager for high availability and performance.
Join the Refactored Community
Connect with fellow students and industry professionals through the Refactored community, where you can share insights, collaborate on challenges, and expand your Azure expertise.
Certification
Upon successful completion of the course and passing the AZ-700 exam at a Microsoft Testing Center, participants will earn the Microsoft Certified: Azure Network Engineer Associate certification. This certification validates their ability to design, implement, and manage Azure networking solutions.
Lectures will introduce you to essential Azure networking principles, while demos provide hands-on experience with real-world scenarios.
Welcome to Refactored and the AZ-700 course—let’s build secure, scalable cloud networking solutions together!