
Master the essentials of Azure files and blob storage by creating and configuring storage accounts, setting access, enabling encryption, and applying lifecycle, soft delete, and versioning for cloud data.
Navigate the Microsoft Applied Skills: Azure Files and Azure Blob Storage Udemy course with play, pause, speed, volume, and subtitles; access content, resources, notes, Q&A, announcements, and your certificate.
Learn how to secure storage for Azure files and Azure blob storage by creating and configuring storage accounts, containers, and applying encryption, secure transfer, TLS versions, and data protection.
Sign up for a free Azure account, claim 200 U.S. dollars credit and 12 months of free services, and explore the Azure portal to manage storage accounts.
Learn to quickly create a storage account by selecting a subscription, creating or using a resource group, naming the account, selecting a region, and reviewing deployment before viewing results.
Create a storage container, upload an image, and manage resources by deleting the container or the resource group while navigating Azure and understanding blob storage.
Create a storage account named StorageAcc914 in a new resource group RG914, add a container called container2, upload Photo2, then delete the container and the resource group RG914.
Compare standard general purpose v2 and premium storage in Azure. Learn when to use block blobs versus file shares for latency-sensitive workloads, noting premium's lower latency from solid-state drives.
Explore data redundancy options in Azure Files and Blob Storage, including LRS, ZRS, GRS, GZRS, and read-access variants, with distinctions across standard and premium tiers and regional coverage.
Explore the Azure storage security settings in the Advanced tab, including transport layer security, TLS 1.2, anonymous access controls, storage account key access, and SAS expiry options.
Explore the blob access tiers—hot, cool, cold, and archive—and compare their storage and read costs, minimum storage durations, and read-time implications, including rehydration delays and lifecycle management.
Examine networking and data protection for Azure storage, focusing on public access, virtual networks, and private endpoints, plus features like Azure Backup for blobs, point-in-time restore, soft delete, and versioning.
Explore azure storage encryption options, including Microsoft-managed and customer-managed keys via Azure Key Vault or HSM, with user-assigned identity and encryption scopes.
Practice configuring an azure storage account with settings, choosing geo-redundant storage, enabling anonymous container access, enabling infrastructure encryption, setting blob soft delete to 21 days, and restricting access through networks.
Explore blob access tiers in a storage account, set a default tier, override per blob, and switch among hot, cool, cold, and archive while noting rehydration and charges.
Discover how data management lifecycle management automates blob tier changes by applying rules to all blobs or specific containers, moving items to cool, cold, archive, or delete after set days.
Explore blob soft delete and permanent delete for soft deleted items within a seven-day retention, and note that permanent deletion isn’t available in the GUI, requiring code.
Learn blob versioning in Azure storage, preserve previous versions, and apply lifecycle rules to move or delete them. View, restore, and download versions, including making a previous version current.
Guides you through creating an Azure storage account in a new resource group, uploading and managing a blob, enabling versioning and soft delete, and applying a 90-day lifecycle rule.
Object replication copies blobs asynchronously from a source storage account to a destination account using a replication rule that maps source to destination containers.
Set up container level data retention policies in Azure blob storage, using time-based retention or legal hold to prevent modifications or deletions, with optional version-level immutability and append rights.
Create and manage a file share in Azure storage by selecting a tier, configuring directories, uploading files, and using snapshots and backups.
Learn how Azure storage encrypts data at rest with 256-bit AES, using Microsoft managed or customer managed keys via key vaults and identity types.
Enable infrastructure encryption as a second layer at the container level via an encryption scope, using Microsoft-managed or customer-managed keys; apply per container, not at the account level.
Create two storage accounts in RG921, establish containers and replication, enable time-based retention with version level immutability, set up a file share backup, apply infrastructure encryption, and clean up.
Enable blob anonymous access at the storage account, then change container access level to blob to allow anonymous reads of blobs while container data remains inaccessible.
Learn why storage account access keys grant full access, see key rotation in action, and explore connecting with Azure Storage Explorer before SAS is introduced.
Learn to create and use shared access signatures (sas) for blob, container, and account levels, with permissions, start and end times, IP restrictions, and https only.
Switch storage authentication from access key and SAS to Microsoft Entra ID via IAM. Assign Storage Blob Data Owner, Reader, or Contributor roles to users or managed identities for containers.
Create a virtual network, add a Microsoft.Storage service endpoint, and enable access from selected virtual networks and IP addresses to secure storage.
Configure a private endpoint to access Azure Storage from your virtual network using a private IP, eliminating public internet exposure and enhancing security beyond service endpoints.
Create a storage account and container, enable anonymous access, rotate keys, generate a SAS, grant read access with Microsoft Entra, restrict to a virtual network, then delete the resource group.
Build and validate storage skills for Azure Files and Azure Blob Storage by taking Applied Skills assessments, practicing with guided projects and interactive labs, and reviewing encryption and networking configurations.
Review how to create and configure a storage account, blob storage, and Azure files, with encryption and networking, then practice to sit the exam and earn Microsoft Applied Skills credential.
This course goes through all of the skills required for the Microsoft Applied Skills: Secure storage for Azure Files and Azure Blob Storage.
This can also help with AZ-104 Microsoft Azure Administrator exam, with "Configure access to storage" and "Configure Azure Files and Azure Blob Storage".
This course has been updated in line with the expanded Study Guide (updated in January 2025).
Please note: This course is not affiliated with, endorsed by, or sponsored by Microsoft.
What do people like you say about this course?
Grant says: "This course gave me the foundational knowledge to pass the applied skills credential. Everything was explained in a way that really clicked for me. In the applied skills assessment, I felt confident in knowing what I was being asked to configure. Definitely recommend this course!"
Selim says: "I had the opportunity to get detailed information about Azure Files and Azure Blob Storage. By going through the examples, I did not become confused. Everyone's learning method is different, I learn more easily by first learning with examples and then building on what I have learned by listening to the topics explained in detail in different videos. It was a good explanation, thank you. I can go over the practical activities one more time and now I can take the exam. Thanx"
Sanjeev says: "Very good introduction to azure storage!"
In this 2½ hour course we’ll cover the skills that you need for the APL-1003 Microsoft Applied Skills credential for Power Automate.
The tasks that you need to perform to get this skill are:
Create and configure a storage account. We'll quickly creating a storage account and a container and upload a file. Then we'll look in some detail at storage account configuration, both when creating the storage account and after it has been created.
Create and configure Blob Storage. We'll look at blob access tiers, lifecycle management, soft delete and versioning for blobs, together with Shared Access Signatures.
Create and configure Azure Files. This allows you to create directories and putting your files into these folders.
Configure encryption. We'll look at how you can change the encryption key, and configure infrastructure encryption and encryption scopes.
Configure networking for storage. We'll look at how your storage account can interact with Virtual Networks.
We’ll go through several practical examples, so you can see how you can secure your own containers
By the end of the course, you'll be much more confident about using securing Azure Files and Blob Storage and perhaps even take the official Microsoft assessment. That would look great on your CV or resume.