
Explore architecting and designing in Microsoft Azure, and begin building foundational Azure design concepts and practices.
Explore how to design Azure architecture across data, identity and security, data solutions, business continuity, deployment and integration, and infrastructure strategy to prepare for the AZ-300 and AZ-301 exams.
Identify workload-driven requirements, including security, compliance, accessibility, availability, and sizing, and use the Azure Architecture Center’s reference architectures and serverless patterns to guide design and deployment.
Estimate total cost of ownership for a two-tier web app: two virtual machines behind a load balancer, a PaaS database, and storage using the Azure pricing calculator.
Learn to optimize Azure compute costs by using virtual machine scale sets with auto scaling, low-priority instances, and eviction policies to balance capacity, utilization, and storage costs.
Estimate total cost of ownership for Azure deployments in Asia with the pricing calculator and cost analysis, and optimize by analyzing current consumption and regional costs.
Use Azure reserved virtual machine instances to cut long-term costs for production deployments; pay-as-you-go suits development and testing, and 1-year or 3-year reservations save 18% to 32% via the portal.
Explore Azure Active Directory editions—free, basic, premium P1, and premium P2—comparing features, limits, and cost considerations for enterprise identity management.
Optimize network costs by understanding Azure data transfer: inbound is free, outbound costs apply after the first 5 GB, and regional or peering traffic incurs per-GB charges.
Explore strategies to reduce Azure storage costs by selecting disk types and hot, cool, archive storage tiers, implementing lifecycle and retention policies, managing backups, and deleting unattached disks.
Learn how to design and audit a monitoring strategy for data mining workload requirements using Azure tools, techniques, and technologies, and implement them in practice.
Understand monitoring in Azure, contrast it with auditing and compliance, and use Azure Monitor to collect metrics, logs, traces, and respond to events across applications, networks, and infrastructure.
Explore audit and compliance in Azure solutions, emphasizing non-technical requirements like data sovereignty, regional hosting rules, tagging, and policy enforcement to meet legal and industry standards.
Explore how Azure Monitor provides a unified platform for logs, metrics, and diagnostics, including activity logs, log analytics, service health, and alerts for Azure resources.
Explore application insights, a powerful Azure Monitor tool for advanced analytics, performance introspection, and integration with other applications, with application map and availability for decoupled apps.
Explore how Azure Monitor handles scenarios for storing and routing information with log analytics, diagnostic settings, and archiving, then configure alerts and action groups to protect resources like virtual machines.
Organize Azure environments by structuring subscriptions, resource groups, and resources, and use tagging for cost management, isolation, and automation across subscriptions.
Azure policy audits and enforces corporate requirements, prevents noncompliant resource creation, and uses definitions, assignments, and initiatives to govern tagging, encryption, region, and VM settings.
Discover why identity and access management is the core of enterprise security, and how federation, directory services, provisioning, and MFA secure access across on-premises and cloud resources.
Explore access controls in Microsoft Azure architecture, including mandatory, discretionary, rule-based, dynamic, and history-based models, and learn how labels, permissions, and conditional access shape resource security.
Explore Azure Active Directory as a cloud-based identity and access management solution, covering single sign-on, B2B collaboration, self-service, groups, enterprise apps, and RBAC across multiple subscriptions.
Azure Active Directory B2B enables inviting external users as guests and granting access via federated identity. Enforce terms of use, multi-factor authentication, and conditional access for partner collaboration.
Explore Azure Active Directory B2C for business-to-consumer scenarios, create and link a B2C tenant, and configure identity providers and user flows to manage external app identities.
Explore Azure Active Directory Domain Services as a fully managed cloud domain with domain join, group policy, and DNS management, noting sync limitations.
Explore how Azure Active Directory secures access to enterprise applications by managing users and groups, enabling single sign-on, and applying conditional access and multi-factor authentication.
Explore how to enable self-service in Azure Active Directory by configuring group management, application access, and password reset, including access panel, gallery apps, naming policies, and MFA considerations.
Explore authentication and authorization in Azure Active Directory, including multi-factor authentication, Azure Active Directory Connect, single sign-on, and managed identities, and learn scenarios for choosing each service.
Explore authentication, authorization, and the protocols that enable them, including OAuth 2.0 and OpenID Connect. Learn how SAML and WS-Federation support sign-on with Azure AD using access and ID tokens.
Understand federated authentication in Azure AD, comparing cloud-native accounts with hybrid identities using password hash sync, pass-through authentication, or ADFS. Assess features, limitations, and when to choose each method.
Discover identity delegation in Azure Active Directory, enabling a web app to act on a user’s behalf via consent and token-based authentication to access a web API.
Explore Azure API Management, create subscriptions, issue API keys and client certificates, and configure policies and a gateway to secure and govern API access.
Configure single sign-on for Google suite with Azure AD, using SAML as the preferred method and open connect options, exchanging sign-in and sign-out URLs, and enabling provisioning and testing.
Discover how Azure managed identities authenticate to services via Azure Active Directory, enabling system or user assigned identities on a VM access resource groups and key vault with read-only permissions.
Use Azure Key Vault to securely store and retrieve secrets, keys, and certificates; manage access policies for secret, key, and certificate operations, enabling compliant encryption and secure domain joins.
Secure identities across devices with multi factor authentication, requiring two or more factors like password, a trusted device, or biometrics, and enable via conditional access in Azure Active Directory.
Register a new Azure AD application, enable OpenID Connect and OAuth 2.0 authentication, configure redirect and localhost settings, and run a Microsoft sample to demonstrate login and authorization.
Explore the risk prevention for identity agenda within design for identity and security, covering azure active directory licensing, pricing factors, and feature limitations for an azure active directory solutions architect.
Explore identity security and risk management in cloud environments, learning about MFA, SSL, centralized identity, risk assessment, remediation, and controls like least privilege and auditing.
Explore Azure Active Directory identity protection, which detects risky sign-ins using machine learning and integrates with conditional access and MFA to mitigate risks.
Enforce access control with conditional access policies that evaluate groups and users (including guests), device platforms, locations, risk levels, and user actions, granting or denying access with multifactorial authentication.
Explore how Azure AD PIM enforces least privilege with just-in-time access, elevating permissions through approvals, audits, and notifications to protect identities and Azure resources.
Azure AD password protection provides banned passwords and smart lockouts to block common passwords and detect brute force sign-in attempts, with licensing varying by cloud native vs hybrid identities.
Understand Azure Active Directory licensing, distinguishing free features from P1 or P2, and map conditional access, multi-factor authentication, identity protection, and group access management to the correct license.
Explore monitoring for identity and security using Azure Monitor and Active Directory, and configure notifications, alerts, and schedules to monitor on a regular basis.
Learn to monitor Azure Active Directory using security, activity, and log analytics reports, identify risky users and sign-ins, and leverage audit logs and MFA insights for proactive protection.
Monitor azure ad identity protection and privilege identity management, configuring alerts, weekly digests, and email notifications for at-risk users, elevations, and approvals, with audit history for action trails.
Learn how Azure AD Connect Health monitors hybrid identities by tracking synchronization of objects from on-premises Active Directory to Azure AD, diagnosing sync errors, and configuring notifications and agent management.
Explore how databases evolved from relational systems to non-relational models, and how data warehouses and data lakes enable analytics across structured and unstructured data in the cloud.
Explore Azure SQL Database as a relational database service for app backends and migrations. Compare three options: Azure SQL Database, managed instance, and virtual machine, with v core pricing.
Explore elastic pools for cost-effective scaling, enable automatic tuning and read scale out for read-only workloads, and compare Azure SQL Database and managed instances, including SSIS and Data Factory options.
Explore Cosmos DB, a multi-model globally distributed database supporting multiple APIs and geo-replication, with throughput considerations and the five consistency models: strong, bounded staleness, session, consistent prefix, and eventual.
Learn about Azure data warehousing with massively parallel processing, scale units, compute-storage separation, and pausing compute to power analytics, reporting, and business intelligence across multiple data sources.
Discover Azure data lake storage Gen 2 for unstructured data from diverse sources, enabling petabyte-scale ingestion and high throughput, with hot, cool, and archive pricing and external networking considerations.
Understand data flow and data movement fundamentals. Explore data flow architecture concepts and technologies to move data, including data management platforms and data movement frequencies.
Explore data flow fundamentals across data warehouses and data lakes, learning ingestion, transformation, and the ETL versus LTE approaches, batch versus streaming processing, and on-demand frequencies.
Learn to use Azure Data Factory to connect on-premise and cloud sources, migrate SSIS packages, and design pipelines and data sets that copy and transform data with triggers.
Explore how Azure Databricks provides a scalable analytics platform built on Apache Spark, enabling data scientists to analyze diverse data with notebooks, clusters, and Python or Scala workflows.
Design a data protection strategy for Azure data platforms by exploring their availability and security features to ensure rapid disaster recovery.
Design data platforms for availability and recovery using data replication and zone redundancy. Secure data at rest, in transit, and in use with encryption, networking, and access controls.
Discover how Azure SQL data protection provides data backups, high availability, and disaster recovery for Azure SQL databases across managed instances and virtual machines, including geo replication and failover groups.
Secure Azure SQL data by configuring network security and firewalls, enabling Azure Active Directory integration, and applying Always Encrypted, Dynamic Data Masking, and Transparent Data Encryption.
Explore how Azure data warehouse ensures inherent availability via massively parallel processing and shards, with 99.9% SLA, plus snapshots and restore points, seven-day retention, geo backups, and encryption options.
Protect Azure Cosmos DB by enabling multi-region replication for global availability, automated four-hour backups and snapshots with geo-redundant storage, and robust security using firewalls, access controls, and resource tokens.
Explore designing data solutions for monitoring, alerting, and notification using Azure Monitor to gain insights into metrics such as write operations and database reads across Azure services.
Configure integrated monitoring for data management platforms using azure monitor with log analytics, event hub, and storage accounts, and set up diagnostic settings to enable alerts, analytics, and auditing.
NOTE : There is a overlap between Az 300 and Az 301 . Az 304 is now upgraded to Az 305.
Candidates for this exam are Azure Solution Architects who advise stakeholders and translate business requirements into secure, scalable, and reliable solutions. Candidates should have advanced experience and knowledge across various aspects of IT operations, including networking, virtualization, identity, security, business continuity, disaster recovery, data management, budgeting, and governance. This role requires managing how decisions in each area affects an overall solution. Candidates must be proficient in Azure administration, Azure development, and DevOps, and have expert-level skills in at least one of those domains.
The AZ-305 exam is targeted at experienced IT experts, the exam covers a variety of subjects and services, all of which are covered in this course. In order to understand core architect technologies, This course will lead you through a series of sections, modules, and demos to prepare you for taking, and ultimately passing, the Microsoft Azure AZ-301 exam.
Please download the Skills measured document below to see what changed.
Determine workload requirements (10-15%)
Design for identity and security (20-25%)
Design a data platform solution (15-20%)
Design a business continuity strategy (15-20%)
Design for deployment, migration, and integration (10-15%)
Design an infrastructure strategy (15-20%)
This exam measures your ability to accomplish the following technical tasks: determine workload requirements; design for identity and security; design a data platform solution; design a business continuity strategy; design for deployment, migration, and integration; and design an infrastructure strategy.