
Discover plan-and-assess foundations for Azure solutions, covering networking, storage, identity, management, security, containers, migrations, backups, and exam alignment for the AZ-305 architect track.
Learn how to fix blurred Udemy videos by setting the Udemy player to 720p using the gear icon at the bottom right. This quick adjustment ensures clear playback across courses.
Experiment with playback speed in the udemy player to optimize your learning cadence. Start with the recommended 1.25 x, but adjust to the speed that sounds best to you.
Create your own Azure account with a $200 credit for 30 days, verify your identity with a credit card, and explore free services while learning Azure fundamentals.
Download the courseware PDF to access the content we will cover in this AZ-305 course.
Explore the renaming of Azure Active Directory to Microsoft Entra ID as part of the Entra product family, noting no capability changes and the ongoing need to update documentation.
Explore Azure governance fundamentals, including management group design, subscription strategy, resource group planning, resource tagging, and cost management, illustrated through practical configurations and case studies to design effective solutions.
Plan and enforce governance by defining a structure with management groups, subscriptions, resource groups, and resources before provisioning Azure assets.
Assign RBAC roles at management group levels to apply across subscriptions, using inheritance and a flat hierarchy. Design considers organizational, departmental, geographic, production, sandbox, and security needs to guide structure.
Explore how to create and manage Azure management groups, move subscriptions between groups, and apply policies at the group level while understanding potential access changes and hierarchical structure.
Align subscriptions with business needs, forecast spend, and apply policies at the management group level for centralized control, with scale limits for IoT and SAP and shared services.
Explore practical reasons to use multiple subscriptions, including applying Azure policies and RBAC for compliance, dedicated subscriptions for specialized workloads, and isolating development, test, and production environments.
Group resources by lifecycle into resource groups, managing them as a single entity. Deleting a group removes all contained resources; use role-based access control and locks at the group level.
Learn to apply consistent resource tagging to organize Azure resources, enabling cost management, governance, and regulatory compliance, with searchable tags for production, function, classification, and ownership.
Demonstrates tagging Azure resources by creating a storage account and resource group, applying confidentiality as private and region as issues, and using PowerShell to query and filter tag data.
Tag resources with tag names and values to enable searches by web server, environment, and classification. Use multiple tags for department and region to keep resources organized and searchable.
Analyze, monitor, and optimize Azure costs with cost management plus billing, set spending thresholds, review itemized usage, and identify cost-saving opportunities across virtual machines and resources.
Leverage Microsoft docs for cost analysis and optimization, explore enterprise agreements with up to 45% savings, fast track planning, software assurance, and detailed invoice management.
Outline an Azure hierarchy with management groups and subscriptions that align business units: web development and infrastructure management, with sales, marketing, and engineering departments for cost tracking under enterprise agreement.
Analyze a flexible Azure management group design for artists, with tenant, arts management group, and department subscriptions. Grasp cost management and aggregated billing across units, and compare subscriptions versus tagging.
Learn how Azure landing zones define a foundation of design principles that isolate and scale platform and application resources, with shared services, policy inheritance through management groups, and automated provisioning.
Explore the two Azure landing zone design areas: environment design with billing and Azure Active Directory tenants. Grasp the compliance design area covering security, management, governance, auditing, and automation.
Explore planning and implementing virtual networking in Azure, compare technologies, and configure traffic flows between networks and on premise networks using gateways, Vnet peering, ExpressRoute, filtering, and network security groups.
Plan and standardize vnet design by enforcing naming conventions, region-aligned address spaces and subnets, and choosing peering or gateways to manage traffic and connectivity.
Master virtual networks as the foundation for Azure resources, learning to design subnets, manage IP addresses, and enable secure connections via VPN, express routes, and network security groups.
Explore Azure vnet components, including address space and subnets, with vnet peering across regions and subscriptions, while preventing overlapping address space and applying network security groups to control traffic.
Learn how resources in Azure virtual networks communicate. Explore inbound and outbound internet access with public IPs and load balancers, private addresses, VNet peering, and on-premises connectivity options.
Explore VNet peering within the same region and global VNet peering across regions for full connectivity, and learn about ExpressRoute with redundant on-prem connections via providers like Verizon and AT&T.
Demonstrate VNet peering by connecting two isolated virtual networks with distinct address spaces and subnets, enabling direct remote desktop between VMs across regions without routing changes.
In the Azure portal, create two VNets and two resource groups. VNet one in West Central US uses 10.0.0.0/16 with subnet 10.1.0.0/16; VNet two uses 172.0.0.0/8 with subnet 172.16.0.0/16.
Create and configure two virtual machines across two resource groups and regions, selecting virtual networks and subnets, and enabling RDP access with controlled network settings.
Verify connectivity between two virtual machines across two vnets by configuring VNet peering, then test remote desktop connectivity from vm1 to vm2, noting default bidirectional access and optional forwarded traffic.
Discover how to configure Azure ExpressRoute circuits for a fast private connection from on premise infrastructure to Microsoft cloud services, with port type, bandwidth, and billing options.
Explore express route fundamentals, bandwidth alignment with VPN connections, and bursting behavior. Learn how VNets are advertised over express route private peering and how remote gateway affects traffic.
Learn to filter VNet traffic with NSGs, applying inbound and outbound rules at subnet or NIC level to control VM access and ports like 80 and 3389.
Azure routes traffic between subnets and connected networks; override defaults with a custom route table or propagate on-prem BGP routes via VPN gateway or ExpressRoute for unified routing.
Compare vnet peering and vpn gateway in azure, highlighting global peering, private Microsoft backbone routing, lower latency, and when to use gateway transit for centralized on-prem connectivity.
Compare vnet peering and the vpn gateway across regions, tenants, and subscriptions. See how both connect virtual networks and work with a mix of modern and classic deployment models.
Demonstrates creating two Azure virtual networks and virtual machines, configuring subnets and storage, and deploying a VPN gateway to enable connectivity between VNets.
Create and configure a VPN gateway to connect two virtual networks, choosing route-based vnet-to-vnet connections, assign a public IP, set a pre-shared key, verify connectivity, and clean up when finished.
Learn how gateway transit connects peered VNets to on-prem networks via a hub VNet, using VPN or express route. Leverage this hub-and-spoke model to simplify configuration.
Explore Azure vnet peering and cross-subscription connectivity. Compare vnet peering's private backbone routing with VPN gateway's encrypted internet connections and variable throughput.
Create and maintain a VNet documentation spreadsheet to capture virtual networks, resource groups, regions, DNS settings, VNet peering, VPN gateway, address space, subnets, such as bastion, ddos protection, and firewall.
Access the latest virtual networking guidance on Microsoft Docs, including quickstart guides, how-to guides, vnet concepts, sample configurations, and PDF downloads; stay current with updates.
Discover how to plan and implement virtual machines, using a downloadable checklist and spreadsheet to standardize deployments, documentation, and administrator visibility, including high availability and scale sets.
Plan virtual machine deployments by creating your own virtual network to control the address space, and choose the VM and computer names, Azure location, size, pricing, storage, security, and OS.
Design an Azure virtual network with an address space and subnets, enforce traffic via network security groups, and plan non overlapping addresses for VNets and on-prem connections.
Learn practical vm naming conventions that reflect location, environment, and role, ensuring the Azure resource name matches its purpose and enables consistent monitoring and alerts.
Select a region when creating a virtual machine to balance redundancy, data sovereignty, and cost, noting regional hardware availability, rolling upgrades, and price differences.
Select the right Azure VM size by balancing compute, memory, and storage for workload needs and cost, with scalable options from general purpose to high performance compute.
Master Azure VM pricing concepts, including separate compute and storage costs, per-minute billing, and the choice between pay-as-you-go and reserved instances for cost savings.
Adopt managed disks to simplify storage and scale beyond 20,000 iops. Use premium ssd for high-performance workloads, with hdd/ssd for development and testing, and ultra disk for highest performance.
Learn to select a virtual machine operating system, from stock images to marketplace presets, and deploy custom in-house images that run across on-premises and Azure with 64-bit requirements.
Understand how Azure cost seems perplexing with in-use vs idle, using the pricing calculator to model virtual machine configurations, os options, and storage, then compare reserved pricing and upfront costs.
Explore how azure availability zones use separate power, network, and cooling to create fault domains and update domains, delivering zero downtime during failures and updates.
Discover Azure virtual machine scale sets that auto scale a load balanced group of VMs to meet demand with high availability across update and fault domains.
Group VMs into an availability set within a single data center, using fault and update domains; two or more VMs yield 99.95% SLA, while availability zones provide cross-region resilience.
Create a virtual machine scale set with resource group, region, Windows Server 2016 image, networking, and optional load balancer, and enable auto scaling with CPU-based rules.
Explore Azure dedicated hosts, a dedicated physical server that hosts your own virtual machines within a single subscription, delivering hardware isolation and user-controlled maintenance events.
Create dedicated hosts in Azure with exclusive hardware, group them in the same location, and enable high availability with availability zones and automatic replacement.
Azure storage encryption service protects data at rest with 256-bit encryption, while Azure disk encryption uses bitlocker and dm crypt to encrypt VM disks, with key vault integration.
Document a comprehensive virtual machine template that uses environment prefixes, clear naming like P-SQL-01, and standardized settings for image, size, discs, encryption, networking, and management.
Explore creating and configuring Azure virtual machines in the portal, including resource groups, availability sets and zones, OS images, authentication, networking, management diagnostics, and extensions.
Demonstrates creating a Linux virtual machine in Azure with Ubuntu and a new SSH key pair, then converting the key for PuTTY and connecting via SSH.
Explore Azure automation with resource manager templates, quickstart templates, virtual machine templates, and runbooks to automate repetitive tasks, and learn how a template deploys a virtual machine with common settings.
Learn how Azure Resource Manager templates simplify deploying resources into resource groups and enable modular, nested templates with a master template for real-world deployments.
Explore how to accelerate deployments with Azure Quickstart templates, selecting and mutating ready-made JSON templates from the GitHub-hosted catalog to deploy resources such as virtual machines, networks, and storage.
Demonstrates creating a virtual machine from a reusable Azure template, capturing repeatable configurations with template.json and parameters.json. Learn to download, edit, and deploy the template in the portal.
Sysprep and generalize a VHD, upload it to a storage account, then create an image to deploy an Azure virtual machine from that image.
Azure runbooks automate routine tasks by executing defined logic as jobs on a schedule or on demand, accessing both Azure and on-prem resources via secure connections.
Create an automation account and a simple PowerShell runbook to output the current date. Publish, test, and run it, then link a schedule to automate future tasks.
Explore high availability and traffic management with Azure Firewall security, covering Azure Load Balancer, Application Gateway, Traffic Manager, Network Security Groups, Application Security Groups, and Azure Bastion for secure remote connections.
Explore how the Azure load balancer delivers high availability by evenly distributing traffic with a five-tuple hash and session affinity, routing requests to the same or different VMs.
Learn how availability sets isolate virtual machines within a single data center, distributing them across two fault domains—different servers, racks, storage, switches, and cooling—to achieve high availability.
Discover how Azure availability zones provide isolated data centers within a region with independent power, cooling, and networking to keep VMs online during failures, while data residency rules may apply.
Explore the two Azure load balancer types—public (external) and internal—and learn how they distribute traffic from clients to resources, with internal load balancers accepting traffic only from Azure resources.
Configure a public load balancer to distribute internet requests on port 80 across three internet-accessible VMs, while routing to private back-end apps through an internal load balancer for high availability.
Compare basic and standard Azure load balancers, covering health probes, port forwarding, SNAT outbound rules, availability sets, zones, and the 99.99% SLA.
Builds web servers and demonstrates load balancing with an external public Azure load balancer, creating a new resource group, public IP, and zone-redundant configuration.
Demonstrates configuring an Azure load balancer with two Windows Server 2016 VMs behind a backend pool, using a custom script extension to install IIS and a health probe.
Learn how an application gateway performs application layer routing based on the URL to a pool of web servers, with a web application firewall, front-end IP/FQDN, and hybrid on-premises integration.
Create an application gateway with a resource group and virtual network, public IP, front end, back end, routing rules, and http settings with cookie-based affinity and connection draining.
Create a virtual machine as a web server, configure a back-end pool with an application gateway, and automate IIS setup using a custom script extension and PowerShell in Azure.
Explain the differences between Azure load balancer and application gateway, covering layer 4 versus layer 7 traffic, pricing, and features like SSL termination, URL-based routing, and web application firewall.
Route requests by url path using the application gateway’s path based routing to video and image pools, with a default pool for unmatched paths at the application layer (layer seven).
Learn how the application gateway hosts up to 100 sites on one port, routing contoso.com and fabrikam.com to separate back end pools and considering express route or vpn connectivity.
Protect your Azure resources with a fully managed Azure firewall that controls traffic, scales across subscriptions, uses a static public IP, and integrates with Azure Monitor for detailed logging.
Set up an Azure firewall in a hub-and-spoke model with dedicated firewall and workload subnets, configure application, network, and DNS rules, and validate access to google.com.
Create a virtual machine named SV-work in the firewall resource group using Windows Server 2016, with no inbound port rules and no public IP to route traffic through the firewall.
Deploy the Azure firewall in the test firewall resource group using an existing virtual network and a new public IP address, then review and create to complete the deployment.
Create a route table and associate it with the firewall workload subnet, then configure a 0.0.0.0/0 route to send all traffic via a virtual appliance using the firewall’s private IP.
Demonstrates configuring a virtual machine to use custom primary and secondary DNS servers, enabling external name resolution by updating the network interface DNS settings and saving.
Demonstrate verifying Azure firewall filters traffic by remote desktop to the firewall public IP, translating to the private VM, and refining app collection rules to allow Google and Microsoft.
Distribute user traffic across global data centers and endpoints using DNS-based routing with priority, performance, geographic, and weighted methods, plus health checks.
Explore Azure traffic manager routing methods - priority, performance, geographic, and weighted - show how health checks affect failover, latency-based selection, and nested profiles combining geographic routing and priority.
Configure Azure traffic manager to balance traffic between two web servers behind public IPs, set DNS names for VMs, and define endpoints with performance routing.
Azure network security groups (NSGs) filter inbound and outbound traffic for resources in a virtual network by applying rules to subnets or individual network interfaces.
Configure network security groups at subnet and NIC levels to control inbound and outbound traffic; subnets are processed first, then NICs, with default internal traffic allowed.
Create and configure a virtual network and subnet, attach a network security group, and set inbound rules for ports 80 and 443, while understanding default rules and propagation delays.
Use application security groups to apply network security group rules to specific groups of virtual machines, enabling per-group inbound and outbound policies without creating many subnets.
Demonstrates configuring an Azure application security group to allow RDP traffic to a web VM and removing the VM from the group to show how remote desktop becomes blocked.
Connect to your virtual machines securely with Azure Bastion, which provides remote desktop access over SSL on port 443 from the internet, keeping RDP traffic off the public internet.
Set up a virtual network and VM in East US, add the Azure Bastion subnet, and connect via Bastion over https to avoid exposing RDP.
Explore Azure storage fundamentals, including data structures (structured, semi-structured, unstructured), storage tiers, account types, costs, and security, with a focus on data redundancy to avoid a single point of failure.
Discover Azure Storage as a durable, highly available cloud solution with cross-region replication, encryption, and scalable access via portal, CLI, PowerShell, and SDKs.
Identify three storage categories in Azure: structured data with schemas and tables; semi-structured data with Json and NoSQL formats; and unstructured data like Word documents, media, and logs.
Explore the two Azure storage tiers: standard with hdd for bulk data, and premium with ssd for low-latency workloads; storage accounts cannot convert between tiers and require a new account.
Explore Azure storage services: blob containers for unstructured data like audio and video, Azure files as cloud file shares, Azure queue for messaging, and Azure tables for key-value structured data.
Explore Azure storage account types from legacy v1 to general purpose v2, including blob, file, queue, and table storage, with encryption across all services.
Explore Azure data redundancy and high availability by comparing locally redundant storage, zone redundant storage, geo redundant storage, and read-access geo redundant, including replication across fault domains and regions.
Understand how storage accounts use unique URLs for blob, table, file, and queue types, with the account name forming the subdomain. Access specific objects by appending container or share paths.
Discover Azure storage security: automatic encryption at rest, rbac-based access via Azure ad, data in transit protection with https and smb, disk encryption, optional key vault management, and sas-based access.
Create a storage account in Azure by setting up a new resource group, choosing a unique name, storage v2, geo-redundant replication, hot tier, and default public networking with secure transfer.
Demonstrates creating a private Azure blob container, uploading a PDF, and inspecting blob properties with versioning. Shows generating a SAS token and URL with start and expiry, plus access policies.
Create and map an Azure file share in a storage account, upload documents, and organize with directories like sales and marketing using SMB 3.0 for secure access.
Implement immutable storage policies to prevent modification or deletion during the policy duration, including time-based and legal hold options, with audit logs tracking policy application and attempted writes or deletes.
Learn how to migrate on-prem data to Azure using data box options - disk, box, heavy - for blobs, files, and managed disks, including shipping, unlocking, and validation steps.
Explore identity management fundamentals, manage users and groups, and implement multifactor authentication and conditional access. Configure password strategies and custom domain names for your environment.
Explore identity management in Azure, integrating on-premises Active Directory with Azure AD Connect, creating accounts in Azure AD, and managing users, devices, and permissions to thousands of enterprise apps.
Manage Azure Active Directory users, guest accounts, and group permissions, using the Azure portal or PowerShell; implement security and Office 365 groups with dynamic membership.
Create two new users in Azure Active Directory, assign manual passwords, and leave them out of groups to use for upcoming labs and course references.
Create a security group in Azure Active Directory named London Users and eliminate manual adds by enabling dynamic user membership with a city equals London rule.
Set days-to-live expiration for Office 365 groups in Azure Active Directory. Renew the group to avoid deletion; otherwise, its content across Outlook, SharePoint, Teams, and Power BI is deleted permanently.
Learn how Azure access reviews enable recertification of guest users, group membership, and application access under identity governance, with reviewers, duration, and recurrence to support compliance.
Explore how multi-factor authentication strengthens Azure and Office 365 security by requiring two of the three factors (know, possess, or are) via Azure MFA cloud service.
Learn to configure multi-factor authentication in the Azure portal using security defaults, conditional access, and policy decisions for all users or specific groups.
Explore Azure Active Directory MFA configuration, including account lockout rules, fraud alerts, one-time passwords and authenticator app software tokens, and how trusted locations and intranet IP ranges affect MFA.
Enable and manage multi-factor authentication in Azure Active Directory, enforce multi-factor authentication for users, configure contact methods, reset app passwords, and handle remembered devices with bulk updates and authentication methods.
Demonstrates configuring multifactor authentication via a conditional access policy for a user administrator in Azure Active Directory, enabling multifactor authentication for the Azure portal and validating sign-in.
Enable self-service password reset in Azure Active Directory, decide which groups can reset, and choose authentication methods including email, text, and predefined or custom security questions.
Conditional access applies risk-based controls to specific apps. Unlike identity protection, it targets a specific application rather than the whole user account.
Learn to configure conditional access in Azure Active Directory, including trusted locations, IP ranges, user and cloud app assignments, conditions, and grant or block controls with MFA and Intune integration.
Azure identity protection monitors sign-ins, detects impossible travel, unfamiliar locations, and suspicious IPs, checks dark web credentials, and enforces risk-based actions like MFA or password changes.
Configure Azure Identity Protection in Azure Active Directory, defining user and sign-in risk policies by group and risk level. View reporting on risky sign-ins and users.
Learn how Azure creates a bootstrapping domain ending in onmicrosoft.com and how to add and verify a custom, globally unique domain via DNS records (MX or TXT) for sign-in.
Learn to apply role based access control across Azure by examining defined locations and role types, then implement Azure policies and Azure blueprints.
Explore how role-based access control in Azure Resource Manager grants users exact access and how scope inheritance from subscription to resource groups shapes permissions, including Azure AD roles.
Enable just-in-time privileged access with privileged identity management to activate user administrator or virtual machine administrator roles only when needed, with time-bound activations and approval, multi-factor authentication, and audit reviews.
Configure Azure AD Privileged Identity Management to grant eligible access for the User Administrator role, require MFA and justification, set duration, and activate on demand for controlled elevation.
enables enforcing organizational standards with Azure policy, shows compliance via a dashboard, and enables bulk remediation and reporting to ensure resources meet location, encryption, and threat detection requirements.
Create and enforce Azure policies to constrain resources by region, assign policies to subscriptions and resource groups, and monitor compliance with remediation options and definitions.
Azure blueprints define repeatable resource deployments and role assignments (like user and global administrators) within resource groups, policies, and template deployments for integrated, standards-based infrastructure.
Create Azure blueprint definitions and artifacts to automate role assignments—virtual machine administrator login and virtual machine contributor—and publish and assign the blueprint to enforce them.
The AZ-305: Azure Solutions Architect Expert course is for students that are becoming subject matter experts in designing cloud and hybrid solutions that run on Microsoft Azure, including compute, network, storage, monitoring, and security.
Responsibilities for this role include advising stakeholders and translating business requirements into designs for secure, scalable, and reliable Azure solutions.
An Azure solutions architect partners with developers, administrators, and other roles responsible for implementing solutions on Azure.
Course topics include:
Planning and Assessments
You will learn about Azure Governance and Planning
Lessons
Landing Zones
Azure Assessments
Governance
Management Groups
Managing Multiple Subscriptions
Resource Groups
Resource Tagging
Resource Tagging and Naming Conventions
Implement VMs for Windows and Linux
You will learn about Azure virtual machines including planning, creating, availability and extensions.
Lessons
Select Virtual Machine Size
Configure High Availability
Implement Azure Dedicated Hosts
Deploy and Configure Scale Sets
Configure Azure Disk Encryption
After completing this module, students will be able to:
Plan for virtual machine implementations.
Create virtual machines.
Configure virtual machine availability, including scale sets.
Understand High Availability options for VMs in Azure
Automate Deployment and Configuration of Resources
You will learn about the tools an Azure Administrator uses to manage their infrastructure.
Lessons
Azure Resource Manager Templates
Save a Template for a VM
Evaluate Location of New Resources
Configure a Virtual Hard Disk Template
Deploy from a Template
Create and Execute an Automation Runbook
After completing this module, students will be able to:
Leverage Azure Resource Manager to organize resources.
Use ARM Templates to deploy resources.
Create and Execute an Automation Runbook
Deploy an Azure VM from a VHD
Understand Azure encryption technologies
Implement Virtual Networking
You will learn about basic virtual networking concepts like virtual networks and subnetting, IP addressing, network security groups, Azure Firewall, and Azure DNS.
Lessons
Virtual Network Peering
Implement VNet Peering
After completing this module, students will be able to:
Connect services with Virtual Network Peering
Configure VNet Peering
Modify or delete VNet Peering
Implement Load Balancing and Network Security
You will learn about network traffic strategies including network routing and service endpoints, Azure Load Balancer, Azure Application Gateway, and Traffic Manager.
Lessons
Implement Azure Load Balancer
Implement an Application Gateway
Understand Web Application Firewall
Implement Azure Firewall
Implementing Azure Traffic Manager
Implement Network Security Groups and Application Security Group
Implement Azure Bastion
After completing this module, students will be able to:
Select a Load Balancer solution
Configure Application Gateway
Implement Azure Firewall
Understand Traffic Manager routing methods
Configure Network Security Groups (NSGs)
Implement Storage Accounts
You will learn about basic storage features including storage accounts, blob storage, Azure files and File Sync, storage security, and storage tools.
Lessons
Storage Accounts
Blob Storage
Storage Security
Managing Storage
Accessing Blobs
Configure Azure Storage Firewalls and Virtual Networks
After completing this module, students will be able to:
Understand Storage Account services and types
Configure Blob storage, accounts, containers, and access tiers
Implement Shared Access Signatures
Understand Azure Storage firewalls and virtual networks
Implement Azure Active Directory
You will learn how to secure identities with Azure Active Directory, and implement users and groups.
Lessons
Overview of Azure Active Directory
Users and Groups
Domains and Custom Domains
Azure AD Identity Protection
Implement Conditional Access
Configure Fraud Alerts for MFA
Configure Trusted IPs
Configure Guest Users in Azure AD
After completing this module, students will be able to:
Add Guest Users to Azure AD
Configure Location Condition Configuration
Configure Azure MFA settings
Implement Conditional Access Azure MFA
Implement and Manage Azure Governance
You will learn about managing your subscriptions and accounts, implementing Azure policies, and using Role-Based Access Control.
Lessons
Create Management Groups, Subscriptions, and Resource Groups
Overview of Role-Based Access Control (RBAC)
Role-Based Access Control (RBAC) Roles
Azure AD Access Reviews
Implement and Configure an Azure Policy
Azure Blueprints
After completing this module, students will be able to:
Understand Resource Groups
Understand how RBAC works
Create an Azure AD access review
Create and manage policies to enforce compliance
Create a Blueprint
Implement and Manage Hybrid Identities
You will learn how to install and configure Azure AD Connect and implement Azure AD Connect Health.
Lessons
Install and Configure Azure AD Connect
Configure Password Sync and Password Writeback
Configure Azure AD Connect Health
After completing this module, students will be able to:
Implement Azure AD seamless Single Sign-On
Perform an Azure AD Connect installation
Implement Azure AD Connect Health
Manage Workloads in Azure
You will learn how to perform Azure Backup and Azure Site Recovery.
Lessons
Implement Azure Backup
Azure to Azure Site Recovery
Implement Azure Update Management
After completing this module, students will be able to:
Understand Azure VM backup architecture
Manage updates and patches for Azure VMs
Implement Cloud Infrastructure Monitoring
You will learn about Azure Monitor, Azure Workbooks, Azure Alerts, Network Watcher, Azure Service Health, Azure Application Insights.
Lessons
Azure Infrastructure Security Monitoring
Azure Monitor
Azure Workbooks
Azure Alerts
Log Analytics
Network Watcher
Azure Service Health
Monitor Azure Costs
Azure Application Insights
Unified Monitoring in Azure
Manage Security for Applications
You will learn about Azure Key Vault and implementing authentication using Azure Managed Identities.
Lessons
Azure Key Vault
Azure Managed Identity
After completing this module, students will be able to:
Explain Key Vault uses such as secrets, key, and Certificate management
Use Managed Identities with Azure resources
Implement an Application Infrastructure
You will learn how to create an App Service web App for Containers, create and configure an App Service Plan, and create and manage Deployment Slots.
Lessons
Create and Configure Azure App Service
Create an App Service Web App for Containers
Create and Configure an App Service Plan
Configure Networking for an App Service
Create and Manage Deployment Slots
Implement Logic Apps
Implement Azure Functions
After completing this module, students will be able to:
Configure an Azure App Service
Create an App Service Plan
Create a Workflow using Azure Logic Apps
Create a Function App
Implement Container-Based Applications
You will learn how to run Azure Container instances and how to deploy Kubernetes with AKS.
Lessons
Azure Container Instances
Configure Azure Kubernetes Service
After completing this module, students will be able to:
Run Azure Container instances
Deploy Kubernetes with AKS
Implement NoSQL Databases
You will learn about Azure CosmsoDB.
Lessons
Configure CosmosDB APIs
After completing this module, students will be able to:
Understand options for Azure Cosmos DB
Understand high availability using CosmosDB
Implement Azure SQL Databases
You will create an Azure SQL Database single database, create an Azure SQL Database Managed Instance, and review high-availability and Azure SQL database.
Lessons
Configure Azure SQL Database Settings
Implement Azure SQL Database Managed Instances
High-Availability and Azure SQL Database
After completing this module, students will be able to:
Create an Azure SQL Database single database
Create an Azure SQL Database Managed Instance
Recommend high-availability architectural models used in Azure SQL Database
Plan an Azure Migration
You will review the cloud adoption framework, plan a checklist for Azure migrations. You will discover the migration tools available and which is best suited for specific migration tasks.
Lessons
Review the cloud adoption framework checklist
Initial decisions checklist
Determining your migration strategy
Determining what to migrate and Migration tools
After completing this module, students will be able to
Use Microsoft tools to assist in Azure migrations