
Gain hands-on mastery of Azure IT administration with interactive simulations, real-world demos, and comprehensive topics from subscriptions and cost to Azure AD, firewall, virtual networks, VMs, storage, and monitoring.
Develop a solid foundation by reviewing on-premise Active Directory and domain services, RAR and DMZ, and virtualization, while contrasting Microsoft 365 and Azure with IaaS, PaaS, and SaaS.
Trace the evolution of Microsoft domains from peer-to-peer networks to Active Directory domains, covering domain controllers, replication, Kerberos, NTLM, DNS, and GPOs, with notes on cloud shifts and virtualization.
Learn secure remote access with routing and remote access services and VPN, and explore DMZ perimeter networks with dual firewalls alongside virtualization with Hyper-V and elasticity.
Explore the foundations of Microsoft cloud services, including IaaS, PaaS, and SaaS, with Azure and Microsoft 365, directory services, and on premise to cloud integration.
Discover how Microsoft renames portals, from Azure Active Directory to IntraID, and access updated links like admin.microsoft.com, defender.microsoft.com, purview.microsoft.com, and intune.microsoft.com via a dedicated portals page.
John Christopher guides Azure IT administration learners to find official Microsoft guidance quickly via docs.microsoft.com, using targeted search, exam lab practice, and patient, proactive questions.
Earn a certificate of completion by watching all course videos; assignments don’t count, and a final video explains how to obtain your certificate.
Complete simulations by reading instructions, opening the external link in a new tab, and submitting after finishing; the certificate does not require assignment check-off, but all videos must be checked.
Create a free Azure account to get $200 credit for 30 days and access free services for 12 months, then switch to pay-as-you-go when ready, and log in at portal.azure.com.
Convert your Azure account name to a business account by updating the user principal name in Microsoft Entra ID, linking Azure with Microsoft 365.
Activate a Microsoft Entra ID premium 2 license to access advanced features; learn to obtain a free trial via admin.microsoft.com or portal.azure.com, noting regional availability and activation timing.
Explore Microsoft's official shared responsibility model across on-premises, IaaS, PaaS, and SaaS for Azure and Microsoft 365, clarifying what Microsoft manages and what you handle.
Navigate portal.azure.com to manage azure subscriptions, add pay-as-you-go or azure student offers, set budgets and alerts, and assign contributor roles for controlled access.
Organize Azure subscriptions with management groups to containerize production, development, and testing across regions; create a root group name with no spaces, then attach subscriptions under each group.
Use the Azure pricing calculator to estimate costs for virtual machines and storage by region and operating system. Create cost alerts and budgets in cost management to monitor Azure spending.
Explore use cases for IaaS, PaaS, and SaaS, detailing when to manage operating systems and hardware (IaaS), run web apps with platform management (PaaS), or license ready-to-use software (SaaS).
Understand resource groups as logical containers for Azure resources like virtual machines, storage, and networks, and manage their lifecycle, access, and cross-region communication.
Tag resources in Azure with key value pairs to organize, control costs, enable automation, and enforce governance using tags like environment, owner, project, and application for searchability.
See how to create and apply read-only and delete locks, then observe how the locks block deleting a storage account and its resource group in the Azure portal.
Explore Azure policies to enforce rules and settings across resources, including allowed locations, tagging, encryption, and remediation, with policy definitions, initiatives, and a managed identity.
Learn to redo course simulations quickly by navigating to summary, returning to the assignment, and opening the instructions to access the simulation link anytime.
Understand how Microsoft Entra ID centralizes identities, including user identities, service principals, and managed identities, with on-premises Active Directory sync and device identities like joined, hybrid joined, and registered.
Explore creating user identities in Microsoft Entra ID across portals, including Azure portal, admin.microsoft.com, and the Entra portal, covering user principal names, display names, passwords, licenses, groups, and roles.
Learn to bulk create users in Entra ID using the GraphQL portal, download and fill the CSV template, upload it, and view the new users.
Master Azure and intra id group concepts, including Microsoft 365 groups, distribution groups, mail-enabled security groups, and security groups; compare dynamic versus assigned memberships and resource access.
Create and manage Microsoft 365 groups in the admin center, including Microsoft 365 groups, distribution lists, security groups, and teams, with owners, members, a group email, and private settings.
Learn to create and manage groups in Microsoft Intra ID via the Azure portal, including dynamic user and device groups, Microsoft 365 and security groups, and building dynamic queries.
Explore administrative units in Microsoft Entra ID as departmentally scoped containers that delegate admin control for users and devices, not groups, and are not used for access control.
Create and manage administrative units across portal.azure.com and admin.microsoft.com, using restricted management administrative units to limit roles from the whole tenant.
Explore how Microsoft Entra ID licensing works, from free tier to P1 and P2, and learn to view, compare, and manage licenses in Azure portal and admin center, including entitlements.
Enable self-service password reset (SSPR) in Azure AD, configure authentication methods and password write-back for synced users in a hybrid environment, and test the reset flow.
Explore how Azure RBAC and Entra ID roles control who can access and manage resources, apply least privilege, and leverage PIM for just-in-time administration.
Explore how to implement role-based access control in Azure Entra ID, define roles and permissions, assign users, and use activation and MFA with privileged identity management.
Explore how Azure resource scope and role based access control apply across a hierarchical structure of management groups, subscriptions, resource groups, and resources, with IAM blades governing downwards permissions.
Learn how to use role-based access control to create custom roles in Azure, assign permissions, and manage resource group access with IAM across the control plane and data plane.
Master foundational PowerShell concepts for admin tasks across Azure and Microsoft 365 environments, including the verb-noun syntax, intellisense, parameters and piping, remote management, and scripting policies.
Install the AZ module from the PowerShell Gallery and connect to Azure to manage resources, including virtual machines, resource groups, storage, load balancers, and virtual networks.
Microsoft Graph provides a unified API endpoint to access Microsoft 365 and Azure services. It enables cross-platform automation and bulk operations with token-based auth and OAuth 2.0, replacing legacy PowerShell.
Install Microsoft Graph modules for PowerShell, set execution policy to bypass, and connect to Microsoft Graph with scopes like group.readwrite.all and user.readwrite.all, handling tenant ID and login prompts.
Learn to use PowerShell with Graph to manage Microsoft Entra ID: connect, view and create users (including bulk imports), assign licenses, and create groups.
Explore Cloud Shell in Azure, using PowerShell and Azure CLI in the web browser, manage storage accounts, switch between PowerShell and Bash, and access it via mobile apps.
Use azure cli in powershell or bash to create azure ad users with az ad user create, including display name, user principal name, and password change at sign-in (json output).
download and install Azure CLI on Windows (or Mac), then use PowerShell to run az commands and log in with az login for browser-based authentication, enabling local Azure management.
Create Azure virtual machines to run Windows or Linux in the cloud, enabling on demand, scalable computing for deploying applications, web hosting, development and testing, disaster recovery, labs, and databases.
Explore how to create Azure virtual networks with PowerShell by importing the AZ module, authenticating, defining a VNet and subnet within a resource group, and verifying in the portal.
Configure azure disk encryption for a Windows VM using platform managed or customer managed keys with a disk encryption set and Azure Key Vault, including managed identities.
Move resources between resource groups in the azure portal, including virtual machines, to a new resource group, subscription, or region, with validation and updates for new resource IDs.
Learn how to resize an Azure virtual machine to adjust virtual CPUs, memory, and IOPs for cost or performance, including shutting down, selecting a new size, and verifying the update.
Add a second data disk to an Azure VM and learn how to configure host caching (none, read only, read write) to optimize performance for OS and data drives.
Explore Azure virtual machine availability options, including availability sets and availability zones, configured at VM creation, with fault domains, update domains, and zone-based redundancy.
Learn how Azure virtual machine scale sets deploy and auto scale a uniform, load-balanced group of identical VMs for high availability, with CPU-based and scheduled autoscale rules.
Explore Azure Resource Manager templates and Bicep for declarative, repeatable resource deployment; compare JSON-based ARM templates to Bicep, covering parameters, VNet, storage, and orchestration.
Learn how ARM templates automate Azure deployments by using the Azure Resource Manager, JSON schemas, and parameters to define storage accounts, virtual machines, and networks.
Learn to deploy a virtual machine using an Azure Resource Manager template by exporting and editing the template in portal.azure.com, including parameters, admin password, and resource group management.
Export arm templates from resources, compare them with bicep, and convert json templates to bicep in Visual Studio Code for easier Azure deployments.
Deploy Azure Bastion to securely access VMs over https 443, avoiding exposure of RDP 3389. Compare basic, standard, and premium SKUs and their costs.
Configure Azure virtual networks and subnets in a guided walkthrough, covering address spaces like 10.1.0.0/16, private subnets, NAT gateway, network security groups, service endpoints, and Azure Bastion.
Learn how to create an Azure vNet and its subnet using PowerShell, including importing the AZ module, connecting to Azure, selecting a resource group, and defining an address prefix.
Configure Azure VNet peering to enable cross-VNet traffic in a hub-and-spoke layout, linking VNet one with VNet two, three, and four, with bidirectional communication.
Learn to create and attach public IP addresses in Azure, covering IPv4, standard SKU, static assignment, Microsoft network routing, DNS label options, and usage with VMs or load balancers.
Explore how network security groups and application security groups filter traffic with priority rules, where the first matching rule or most restrictive NSG governs, and traffic is denied by default.
Learn how to use Azure UDRs to route traffic through a network virtual appliance, Azure Firewall, by creating a route table and applying it to subnets in a hub-and-spoke VNet.
Understand service endpoints enable virtual machines to reach storage accounts directly in Azure, avoiding internet routing. Private endpoints offer a 1-to-1 private connection to a storage account inside the VNet.
Set up a service endpoint from the VM subnet to an Azure storage account in the portal, enabling private connectivity without routing through the internet.
Learn to create a private endpoint in Azure, linking a storage account to a VM's VNet with IP allocation and optional private DNS, then test in the VM's networking settings.
Explore how NSG and ASG rules control inbound traffic in Azure, using priority and explicit versus implicit deny.
Learn Azure load balancing concepts, comparing the standard layer 4 load balancer with the layer 7 application gateway, covering public and internal setups, health probes, and URL-based routing.
Configure two Windows Server 2022 virtual machines in a load balancing VNet, install IIS, host simple web pages, and enable HTTP port 80 via NSG rules for testing load balancing.
Set up a public standard load balancer in Azure to distribute traffic to two virtual machines, configure a front-end public IP, and define a back-end NIC-based pool.
Configure an Azure load balancer to distribute TCP traffic on port 80 across two VMs with a front-end IP, back-end pool, health probes, and session persistence and SNAT options.
Configure inbound NAT rules in Azure to forward remote desktop traffic from a public IP on port 3389 to a specific VM, migrating from NAT rules v1 to v2.
Learn how outbound rules govern internet access for virtual machines in an Azure load balancer back end pool, with snat and port allocation concepts.
Delete the load balancer to conserve Azure credits, then navigate to portal.azure.com, open all services, search load balancer, and confirm deletion to move on.
Create and configure a route table to direct traffic through the Azure firewall, adding a route with a virtual appliance next hop and associating subnets across VNets.
Learn to set up an Azure firewall, choose standard, premium, and basic SKUs, create a firewall policy and rule collections, and configure network, destination net, and application rules.
Centralize management of multiple Azure firewalls, VNets, and policies using Azure Firewall Manager in a single portal.
Understand Azure storage accounts as scalable, highly available cloud storage with a unique namespace for blobs, files, queues, tables, and disks, plus redundancy, endpoints, and billing options.
Learn to create and configure an Azure storage account, choose a unique name and region, select blob or data lake, and apply security and encryption options.
Configure Azure storage account access by choosing firewall and virtual network settings, control public network access, and select Microsoft or internet routing with corresponding endpoints.
Understand how shared access signatures (SAS) tokens grant time-limited, permissioned access to Azure storage resources, generated via access keys, with configurable permissions, expiry, and https-only enforcement.
Learn how to use stored access policies for container level SAS tokens, create a temp policy with permissions and dates, and edit it on the fly, including immutable blob storage.
Explore how access keys grant admin access to an Azure storage account, how rotation works to prevent downtime, and why keys should be protected or replaced with shared access signatures.
Enable identity based access for file shares in a storage account by choosing Active Directory domain services, Microsoft intra domain services, or intra Kerberos, with permissions for all authenticated identities.
Explain Azure storage redundancy options—lrs, zrs, grs, gzrs—and read access (ra), and compare synchronous and asynchronous replication across primary and secondary regions for high availability.
Learn to configure and switch storage redundancy in Azure storage accounts, using LRS and GRS via the portal, and apply redundancy when creating new accounts.
Learn to configure object replication between Azure storage accounts, including creating containers, selecting source and destination, and applying prefix filters and cross-tenant replication.
Explore storage account encryption in Azure, including data-at-rest protection, automatic decryption, and options for Microsoft managed keys or customer managed keys via Azure Key Vault.
Explore how to manage Azure storage accounts with Storage Explorer and AzCopy, including uploading to blob containers, authenticating with Azure, and using SAS tokens for transfers.
We really hope you'll agree, this training is way more than the average course on Udemy!
Have access to the following:
Training from an instructor of over 20 years who has trained thousands of people and also a Microsoft Certified Trainer
Lecture that explains the concepts in an easy to learn method for someone that is just starting out with this material
Instructor led hands on and simulations to practice that can be followed even if you have little to no experience
TOPICS COVERED INCLUDING HANDS ON LECTURE AND PRACTICE TUTORIALS:
Introduction
Welcome to the course
Understanding the Microsoft Environment
Having a Solid Foundation of Active Directory Domains
Having a Solid Foundation of RAS, DMZ, and Virtualization
Having a Solid Foundation of the Microsoft Cloud Services
Questions for John Christopher
Setting up for hands on
IMPORTANT Using Assignments in the course
Creating a free Azure Account
Activating an Entra ID P2 license
Understanding Azure Subscriptions, Costs and Resources
The Azure Shared responsibility model
Subscriptions in Azure
Using management groups in Azure
Learning to manage costs with alerts and budgets in Azure
Use cases for IaaS, PaaS, and SAAS
Using resource groups in Azure
Tagging resources in Azure
Adding locks to resources in Azure
Using Azure Policies to control Azure Resources
Understanding Azure Active Directory (Azure AD) management and access control
User identity creation in Azure Active Directory (Azure AD)
Group creation and management in Azure AD
Properties involved in Users and Groups
Device settings in Azure AD
Using administrative units in Azure AD
License management in Azure AD
Implementing self-service password reset (SSPR) in Azure AD
Assigning Roles in Azure AD
Using role-based access control (RBAC) to create custom roles
Assigning roles at different scopes
Understanding access assignments
Understanding Azure PowerShell and Cloudshell
Foundational concepts of PowerShell
Connecting PowerShell to Azure
Using PowerShell with Azure AD
Azure Cloudshell
Azure CLI / Bash
Azure CLI installed locally
Understanding Virtual Networks (vNets) and Virtual Subnets in Azure
Concepts of using virtual networks and subnets in Azure
Azure virtual network and subnet creation
Using PowerShell to create vNets
Peering virtual networks in Azure
Private and public IP addresses in Azure
Azure DNS management
Using network security groups (NSGs) and ASGs in Azure
Using User Defined Routes (UDRs) in Azure
Understanding the concepts of service endpoints and private endpoints
Using service endpoints in Azure
Effective rules in an NSG
Azure Bastion creation in Azure
Understanding Azure Load Balancers
Azure load balancing concepts
Internal vs public load balancing
Azure Application Gateway load balancing
Understanding the Azure Firewall
Using a router table to direct traffice to the Azure Firewall
Setting up an Azure Firewall
Azure Firewall Manager
Understanding virtual networking monitoring and troubleshooting
Using Azure Monitor for monitoring networks
Azure Network Watcher
Virtual network connectivity troubleshooting
External network troubleshooting
Azure DDoS Protection
Understanding storage in Azure
Concepts of working with storage accounts
Storage account creation in Azure
Implementing network access to storage accounts
Configuring a storage account to use Azure AD authentication
Storage account access keys in Azure
Creating shared access signature (SAS) tokens
Using stored access policies
Import and export jobs
Concepts of using storage redundancy in Azure
Using storage redundancy in Azure
Object replication
Azure file share and Configuring storage tiers configuration
Azure Blob storage management
Working with blob lifecycle management
Understanding Virtual Machines (VMs) creation and Azure Resource Manager (ARM) templates
Creating a Virtual Machine (VM) in Azure
Using PowerShell to create a virtual machine in Azure
Managing disk encryption
Moving virtual machines between resource groups
Resizing virtual machines in Azure
Adding data disks
Implementing network settings with virtual machines
Options for virtual machine availability
Using virtual machine scale sets in Azure
Managing Azure Resource Manager (ARM) templates
Azure Resource Manager (ARM) template deployment
How to save an existing deployment as an ARM template
Virtual machine (VM) extensions
Understanding Azure App Services
Concepts of using App Service Plans
App Service plan deployment
App Service plan scaling configuration
App Service creation
Networking settings in App Services
Deployment settings with App Services
Custom domain names
Backups for App Services
App Service Security
Understanding Container and Kubernetes Services
Concepts of working with Azure Containers
Azure Container Instance sizing and scaling
Concepts of container groups
AKS Scaling
Azure Kubernetes Service (AKS) storage
Upgrading an AKS cluster
AKS network connectivity
Understanding basic database management in Azure
Setting up SQL Database/Server and using SSMS to connect
SQL firewall settings for client connections
Using database authentication with Azure AD
SQL database auditing
Understanding backup and recovery in Azure
Azure Recovery Services vault deployment
Backup policies
Azure backup and restoration
Using backup reports
Azure Site Recovery
Understanding Azure Monitor
Using metrics in Azure Monitor
Azure Monitor logs
Azure Monitor alerts and actions
VM, storage accounts, and network monitoring
Using the Azure Advisor
Finishing Up
Where do I go from here?