
This course aligns with the AZ-104 exam, outlining five sections: identities, storage, compute, networking, and resources. It covers labs, ARM templates and Bicep, diagrams, PDFs, quizzes, and practice tests.
Shows how to create an Azure free account using Gmail or GitHub signup, verify identity by email and phone, enable multi-factor authentication, and note the $1 verification charge.
Explore the Azure portal through an initial tour, learn to navigate resources, subscriptions, and costing, and get familiar with Azure services like SQL Database, Azure Cosmos DB, and virtual machines.
Learn to deploy and connect to an Azure virtual machine, inspect deployment details and linked resources, and resize hardware to enable stable remote access.
Consult Microsoft documentation to troubleshoot remote desktop connections to Azure VMs. Verify VM size and image, credentials, and firewall restrictions; also check usage and quotas by region.
Install a web server on a Windows Server by using server manager to add the Internet Information Services role, then open inbound port 80 via a network security group rule.
Deploy a Linux virtual machine in Azure using Ubuntu Server 24.04 LTS, on an existing East US virtual network and subnet, with a new public IP.
Connect to a Linux-based Azure VM via Secure Shell using its public IP, private IP, and port 22, on Ubuntu with a command-line interface.
Connect to a Linux machine from macOS using SSH, obtain the public IP address, and access the Linux web VM via the Azure portal with your username and password.
Learn to deploy a linux VM on Azure using ssh keys, generate a key pair with public and private keys, download and secure the private key, and connect via ssh.
Learn how to add data disks to Azure VMs, choose among standard hdd, standard ssd, premium ssd, and ultra disk, and understand iops and throughput for production workloads.
Learn how server side encryption protects data on Azure managed disks, including OS and data disks, using platform keys by default and optional customer managed keys, with no extra cost.
Discover how to use customer managed keys in Azure Key Vault to enable server-side encryption for data disks, including creating an encryption key and configuring RBAC.
Create a disk encryption set in Azure, apply a customer managed key from Key Vault to enable encryption at rest on the OS disk, with RBAC permissions.
Learn to automate post deployment with custom script extensions on Azure VMs, installing IIS on Windows or nginx on Linux during VM creation.
Deploy a Windows VM and apply a custom script extension that downloads a PowerShell script from an Azure storage container, installs IIS, and serves a simple HTML page.
Explore cloud-init, an industry-standard tool for post-installation automation on Linux VMs. See Ubuntu Server 24.04 VM update package indexes, install nginx, and create an index.html with cloud-init.
Understand how Azure Boot Diagnostics captures console output for Linux and screenshots for Windows during VM boot, helping administrators diagnose boot and kernel failures.
Learn how availability sets isolate virtual machines across fault and update domains to maintain application availability during hardware failures and software updates, without extra cost.
Deploy VMs across availability zones in Azure to maintain uptime when a data center fails. Zones group data centers in a region with fast links; cross-zone transfers incur charges.
Create an Azure virtual machine scale set with uniform orchestration, using Ubuntu Server 24.0 and standard_b-1s, and configure per-VM networking and public IPs.
Explore configuring and scaling an Azure virtual machine scale set, adding manual and automatic rules based on CPU metrics, with min and max instance counts and monitoring integration.
Configure scale-in alongside scale-out for an Azure virtual machine scale set using CPU percentage metrics, with a 5-minute window to adjust instances and then tear down resources.
Learn to create an Azure virtual machine scale set with flexible orchestration mode, apply allocation strategies (lowest price, capacity optimization, prioritizing size), and manage individual VMs alongside the scale set.
Deploy a simple html file to an Azure web app and host it on an IIS web server with dotnet eight, using the App Service Editor.
Upgrade your Azure App Service plan to standard to enable deployment slots, create a staging slot, deploy a new version, and swap traffic between production and staging with rollback capability.
Explore container-based applications, understanding Docker containers and packaging, isolated containers on a VM, and how this approach solves dev and prod differences and OS-level conflicts, with Azure hosting options forthcoming.
Containerize a simple php app on an Azure VM by building a Docker image from a Dockerfile and running a container with port 80 exposed.
Build a MySQL Docker image from a base image on Docker Hub using a Dockerfile and an init folder with schema and data scripts, then deploy to Azure Container Instance.
Build and deploy a PHP application in a custom Docker image that connects to a MySQL container, then publish to Azure Container Registry and deploy in a container group.
Learn to deploy a two-container Azure container group with PHP and MySQL using a deployment.yaml in Azure container registry, exposed via a public IP on port 80.
Explore Azure container apps, a managed Kubernetes abstraction for running multiple containers without provisioning infrastructure, with terms like environment, revisions, and replicas.
Explore deploying a PHP and MySQL app on Azure Container Apps, using an Azure Container Registry, in East US, with port 80 and HTTP traffic enabled, and review pay-as-you-go pricing.
Deploy a PHP app container to Azure Web App Service from the Azure Container Registry, using the latest tag on Linux, port 80, and connect to a remote database.
Explore Azure fundamentals, including regions, subscriptions, resource groups, and RBAC, then deploy and manage virtual machines, containers, web apps, and container services.
Explore the fundamentals of networks, devices, and IP addresses, then see how switches and routers route traffic and how the home router acts as the default gateway to the internet.
Learn how IP addresses identify devices on a network, distinguish the network and host portions, and use CIDR blocks to allocate ranges for IPv4 and IPv6.
Carve a large IP space into smaller, routable blocks using CIDR blocks and subnet masks, and learn how 32-bit masks split network and host portions.
Learn to create an Azure virtual network from the wizard, define a private IP address space like 10.0.0.0/16, create a subnet 10.0.0.0/24, and understand network and subnet basics.
Understand how subnets divide an Azure virtual network into smaller CIDR blocks, enabling workload segregation, security rules, and tiered architectures with web, app, and database subnets.
Deploy a new Ubuntu Server VM on a dedicated 10.0.1.0/24 subnet within the virtual network, assign a private IP, and omit a public IP to secure the database workload.
Explore the distinction between private IP addresses, not routable over the public internet, and public IP addresses, routable on the global internet, including subnet ranges and static IP lifecycles.
Install nginx on a web server and configure an NSG inbound rule to allow port 80 from the internet to the private VM, illustrating Azure NAT and default deny behavior.
Learn how network security groups evaluate inbound and outbound rules by priority, where the first matching rule denies traffic such as port 80, and default rules have fixed priorities.
Explore inter-VM communication within a virtual network using private IPs. See how default VNet rules enable internal access between database and web servers on port 80 via NAT.
Demonstrates outbound security rules in a network security group, including a deny all outbound rule, and the stateful nature that allows inbound responses.
Install the MySQL server on the database machine, bind to the private IP, restart the service, and configure a DB admin user with network security groups for secure two-tier connectivity.
Implement and test NSG rules to secure a two-tier setup by denying internet access to the database while allowing web server to reach MySQL, using service tags and priority-based rules.
Create a single network security group to control web and database subnet traffic, attach it to both subnets, and define inbound and outbound rules for internet and mysql access.
Configure NSG rules at both subnet and network interface layers to permit web traffic. Attach NSG to the web VM and ensure inbound port 80 is allowed on both layers.
Learn how to use application security groups to replace hard-coded IP rules in network security groups, tagging web and database servers for scalable, maintainable access control.
Connect isolated virtual networks with virtual network peering to enable traffic across networks via the Microsoft backbone, using a simple two-way wizard to link dev and test.
Create an empty Azure Bastion subnet in dev network and deploy Azure Bastion in basic tier to securely connect internal VMs via portal without public IPs; delete Bastion when finished.
Set up a continuous connection monitor in Network Watcher between two endpoints, configuring a test group with source, destination, 30-second tcp/http/icmp checks on port 80 and round trip time thresholds.
Demonstrates using the IP flow verify tool to check inbound tcp connectivity to a web server on a virtual machine, based on network security group rules.
Explore the NSG diagnostic utility to understand and debug network security group rules, using a database server example to check TCP traffic on port 3306 and view additional details.
Learn to configure NSG flow logs and virtual network flow logs for a subnet, store data in an Azure storage account, and analyze it with a Log Analytics workspace.
Create a user defined route in a route table to send traffic via the central zero one VM, enabling IP forwarding on the NIC and OS, and verify with curl.
Set up two Ubuntu VMs with Nginx behind an Azure standard load balancer, no public IPs, sharing a subnet NSG, and verify web pages on both backends.
Learn how inbound NAT rules on an Azure load balancer map a public front end port to each VM's ssh port, enabling admin access with two rules per VM.
Master outbound rules for the Azure load balancer to enable virtual machines to access the internet via NAT, using a front-end IP address, a back-end pool, and allocated outbound ports.
Provision a Ubuntu Server scale set in East US behind an Azure Load Balancer, install nginx and a default index.html, and apply a custom script extension to the two instances.
Provision a standard regional Azure load balancer with a public ip and a vm scale set backend pool, configure a tcp port 80 health probe, and test the front-end ip.
Learn fundamentals of the domain name system, including mapping domain names to IP addresses, DNS query flow, and the role of authoritative name servers, in preparation for Azure DNS services.
Map a domain to an Azure VM by configuring DNS A records to point the domain to the VM's public IP, enabling access to nginx.
Discover how Azure public DNS hosts DNS zones, map domains to public IP addresses with A records, and configure external registrars to use Azure name servers for centralized DNS management.
Design a private dns foundation in Azure VNets by building a 3-machine setup with Windows Server 2025, including a domain controller, DNS server, and a web server running IIS.
Install the Active Directory Domain Services role on a domain controller VM, promote it to a domain controller, and configure a private Cloud Hub Learning.com DNS forest.
Configure an internal private domain by setting a domain controller as the vnet dns server, joining machines to cloud learning.com, and managing forward lookup zones and A records.
Enable private communication from an Azure Web App to resources in a virtual network via Virtual Network Integration, requiring a basic App Service plan and same-region deployment with dedicated subnet.
Configure a MySQL database on a VM in an Azure virtual network, enable private connectivity from an Azure web app, and deploy a PHP application that connects securely.
Enable private communication between an Azure web app and its database by implementing virtual network integration. Create an empty subnet, delegate it, connect the app, and verify domain access.
Configure a custom domain for Azure web apps on the paid App Service tier, validate ownership with DNS A and TXT records, and enable https with a managed certificate.
Explore Azure virtual networks as private, isolated cloud networks with subnets, IP addressing, and security. Learn about VNet peering, private endpoints, NAT gateway, NSGs, load balancer, Bastion, and DNS options.
Explore Azure storage accounts as the secure, scalable storage layer, using blob service for unstructured data, file shares for user files, and queue and table services.
Explore the types of storage accounts in Azure, including standard general purpose v2 with access to blob, table, queue, and file share services, and premium block blob storage.
Create an Azure storage account via the wizard, set resource group and location, choose locally redundant storage, enable encryption with Microsoft managed keys, and access blob, file, and queue services.
Learn to use Azure blob storage to store unstructured data like images and videos as objects by creating a container in a v2 storage account, uploading files as block blobs.
Upload files to Azure blob service by creating a storage container and using virtual folders like code, images, and CSV; store everything as binary blobs for flexible, scalable object storage.
Learn how the blob service stores binary objects with unique URLs and configure access with anonymous blob read permissions, and see private, blob, or container levels.
Explore Azure storage authorization techniques for blob service access, from anonymous access to storage account keys, and learn how shared access signatures provide temporary, fine-grained permissions.
Use the Azure Storage Explorer to securely connect to storage accounts, browse containers, upload, download, rename, delete, and generate shared access signatures.
Learn to use azure storage explorer on macOS to connect to a storage account with account key, then manage containers, upload and download objects, and file shares, queues, and tables.
Grant blob-level access with shared access signatures by generating tokens to provide time-bound, IP-restricted read permissions for specific blobs.
Learn to generate and use a container-level shared access signature to grant read and list permissions for blobs, test via URL and Azure Storage Explorer, and understand credential limits.
Create a storage account level shared access signature to grant blob service, containers, and objects with read and list permissions, start and expiry times, and IP restrictions.
Define a central stored access policy at the container level to control shared access signatures, assign read and list permissions, and revoke access by updating the policy.
Explore access tiers in Azure blob storage, including hot, cool, cold, and archive, and learn how to optimize costs by moving objects over time and managing minimum storage durations.
Set a default access tier for the storage account, and apply per-object changes to hot, cool, cold, or archive, with rehydration when needed.
Define JSON-based lifecycle policies in Azure Blob storage to automatically move blobs between hot, cool, and archive tiers and delete older snapshots or versions.
Define json-based lifecycle rules for Azure blob storage to move between cool, cold, archive or delete, using days after creation, modification, or last access, with access tracking and rule precedence.
Explore blob snapshots in Azure storage accounts to capture read-only, point-in-time copies for backup and restoration, and promote a snapshot to the current blob version when needed.
Enable blob versioning in your storage account to maintain read-only blob versions, recover prior versions after edits or deletions, and delete versions older than seven days.
Learn how Azure storage object replication copies block blobs asynchronously from source to destination storage account. Enable change feed and blob versioning on both accounts, and create replication rules.
Create a managed Azure file share with no server to manage and use access tiers like transaction optimized, hot, and cool to map the share to drive via a script.
Learn how to connect to an Azure storage file share from macOS by copying a script, mounting the share via terminal, and accessing images and scripts folders.
Take snapshots of the entire Azure file share to create a read-only copy. Restore a deleted file from the snapshot with options to copy and rename or overwrite.
Enable soft delete for Azure file shares to recover accidentally deleted shares within a seven-day retention window, with soft deleted items retained until permanent removal.
Learn to use the AzCopy command line tool to copy blobs and files to and from an Azure storage account, create containers with SAS authentication, and perform recursive transfers.
Learn how premium base storage accounts for the blob service deliver low latency and better performance with lower transaction costs, with options for block blobs and file shares.
Explore secure Azure storage accounts for blob, file, queue, and table data, with general purpose v2 and premium options, plus access tiers, data redundancy, lifecycle, snapshots, and versioning.
Learn to manage Azure resources using PowerShell and the Azure CLI. Install the latest PowerShell on Windows with MSI, and run commands in Azure Cloud Shell if installation is restricted.
Create a simple PowerShell script in Visual Studio Code to define and deploy an Azure resource group using variables, and authenticate with a device code before running the New-AzResourceGroup command.
Create an Azure virtual network with PowerShell by defining name, resource group, location, and address space 10.0.0.0/16 using New-Azure Virtual Network, run the VNet.ps1 script, and verify in the portal.
Explore Azure cloud shell, a browser-based terminal authenticated with Azure credentials to run PowerShell and Azure CLI commands without local installs, and manage files via Azure file share.
Learn to add a subnet to an existing Azure virtual network using PowerShell by retrieving the VNet, configuring a subnet, and pushing the update with set Azure virtual network.
Create a network interface in Azure using PowerShell by defining the name, resource group, location, and IP configuration, then place it in a subnet of the existing virtual network.
Create and configure an Azure network security group with PowerShell, add inbound rules for port 80 and SSH, attach the NSG to a subnet, and persist the changes.
Create an Azure VM via a PowerShell script, configuring Ubuntu Server 24.04 with a resource group, location, VM size standard_b1s, and attaching the network interface.
Deploy an Azure web app with PowerShell by creating a free-tier app service plan and a Linux-based web app in a resource group located in Central US, using PHP 8.3.
Explore how the Azure CLI interacts with Azure services. Install the Azure CLI on Windows, Linux, or macOS, using the Windows MSI, and learn its cross-platform commands.
Use the Azure CLI to create a resource group, log in with az login, and run az group create in a VS Code PowerShell wrapper, exploring parameter forms.
Learn to deploy a virtual network using Azure CLI with a PowerShell wrapper to define resource group, location, VNet name, address space, and subnets.
Create a public IP address using Azure CLI in a PowerShell script by specifying resource group name, location, name, SKU standard, allocation method static, and IP version 4.
Create a network interface with Azure CLI, attach a public IP, and assign it to a subnet in a VNet.
Create an Azure storage account with the Azure CLI by specifying the resource group, location, account name, kind general purpose v2, and sku standard locally redundant storage.
Deploy an Ubuntu server 24.04 VM with a dedicated network interface in a virtual network, add an availability set and a 16 GB data disk, and configure SSH access.
Set up Visual Studio Code with the Azure Resource Manager extension, create a local templates folder, and begin building ARM templates in JSON with the ARM language server.
Build a simple ARM template in VS Code to deploy an Azure resource group, exploring the resources section, name, location, and API version, with a hands-on RG 104 example.
Deploy a resource group via a simple arm template using Azure PowerShell. Sign in with device code, deploy from VS Code in East US, and confirm provisioning succeeded.
Deploy an Azure storage account with an ARM template, using JSON in VS Code, configuring API version, location, kind, and sku, then deploy via the portal template deployment.
Learn how to deploy multiple storage accounts in a single arm template using a resource copy loop, with copy index-based dynamic naming and string functions like concat.
Deploy a public IP address with an ARM template by editing public IP.json, using resource group location, static allocation, and standard skew, and validate deployment through Azure.
Build a network interface in a virtual network using a JSON-based ARM template, configuring a dynamic private IP and linking to a subnet and public IP.
Link a pre-existing network security group to subnets in an Azure VNet using an ARM template, updating subnets incrementally without recreating the virtual network, and validate with Microsoft docs.
Learn to deploy an Azure virtual machine using a single arm template, including storage account for boot diagnostics, vnet, nsg, public ip, network interface, and Ubuntu 24.04 virtual machine.
Learn to use parameters in an arm template to inject runtime values like vm name and admin username, and understand defaults and contrast with variables.
Create a secure string parameter for admin password in an ARM template, then deploy via PowerShell script to pass the password securely.
Learn how to pass parameter values from a separate JSON parameters file during an ARM template deployment, enabling environment-specific configurations like dev and staging.
Deploy a VM as part of an availability set using an ARM template, creating the set with update and fault domains and linking the VM via resource ID.
Create and attach a new data disk to an existing VM using an ARM template, defining disk size, LUN, and dependencies, then verify the disk is attached.
Deploy custom script extensions with ARM to automatically install nginx on a VM after deployment, using an Azure storage blob and a shared access signature.
Deploy an Azure web app using ARM templates by creating a Linux-based app service plan and a PHP 8.3 web app in central US, configuring site settings and verifying deployment.
Learn to build Azure infrastructure with Bicep, a human readable language that compiles to ARM JSON, and use Visual Studio Code with the Microsoft Bicep extension for streamlined templates.
Create a resource group in your subscription with a simple bicep file in VSCode, specifying name, East US location, and subscription scope, then deploy and verify the resource group.
Create three copies of a resource in Bicep by defining an array of resources with a for loop and range, using string interpolation to ensure unique storage account names.
Learn to deploy a virtual network with Bicep for an Azure VM, defining the address space and subnets (including a database subnet), saving and running the file in the terminal.
Learn to deploy a public IP address in Azure using a Bicep file, specifying name, location, standard SKU, and static allocation, with VS Code formatting.
Define a network interface using bicep, contrast it with arm for flexibility, and reference existing public ip and subnet resources to configure ip configurations and ids.
Verify the completed deployment by confirming the network interface links to public IP and private subnet, then define a Bicep network security group with ssh rules for an ubuntu server.
Attach an existing network security group to subnets in an existing virtual network using a new Bicep file, referencing the NSG by ID and updating subnet configurations.
Deploy an Azure virtual machine with Bicep by wiring together an existing network interface, storage account, and boot diagnostics, and reference blob endpoints for diagnostics.
Learn to deploy an availability set with two fault domains and five update domains using a Bicep file and attach a VM to the set.
Create and attach a new data disk to an Azure VM within an availability set using Bicep, specifying empty create option, 16 gig disk, and implicit resource dependencies.
Apply custom script extensions to an Azure VM with a Bicep file, reference a script in a storage container, generate a SAS URL, and verify nginx is running.
Learn to design Azure infrastructure with Bicep, deploying virtual networks, subnets, and virtual machines while securing access with Azure Bastion, internal load balancers, and private endpoints.
Explore infrastructure with Bicep, deploying virtual networks, storage, subnets, and modules. Build Windows Server VMs, use Azure Key Vault and Bastion, with private IPs, internal load balancer, VNet peering.
Build infrastructure with bicep modules by creating a virtual network and subnets in VS Code, using parameters and modules to enable infrastructure as code.
Learn to build a virtual network with bicep modules and a dev parameters file, structuring vnet as an object with name, address prefixes, and subnets for environment deployments.
Deploy a virtual network using Bicep with PowerShell deployment. Pass parameters from dev dot parameters dot JSON to main dot Bicep and VNet dot Bicep, defining location and subnets.
Deploy a storage account using a Bicep module, define name and location, call the storage module from main Bicep, and deploy incrementally via Azure Resource Manager.
Deploy a network security group with a bicep module by parameterizing name, location, and rules, using a for loop to process remote desktop and port 80.
Attach a network security group to multiple subnets using a generic bicep module, employing a for loop and subnet blocks to link the NSG to two subnets in virtual network.
Deploy Windows Server 2025 VMs with bicep into existing Azure network and subnets, without public IPs, using key vault secrets for admin passwords, and scale with a count parameter.
Define outputs in Bicep modules to pass subnet ids back to main.bicep, using an output block and the subnet id function.
Deploy Windows VMs with Bicep, using for loops and module outputs to configure VNet subnets and NICs, while fetching admin passwords from Azure Key Vault.
Learn how to deploy custom script extensions with bicep to install a web server on Windows VMs, using a PowerShell script stored in a storage container and a SAS URL.
Deploy an internal load balancer with Bicep, using a private front-end IP, a back-end pool of VM NICs, a health probe, and load balancing rules.
Build a test network using bicep modules to deploy a virtual network and an Ubuntu Server VM, configure a private load balancer with http health checks, and enable vnet peering.
Learn to establish virtual network peering with Bicep modules, linking local and remote VNets to enable Bastion access and private IP address connectivity for an Ubuntu Linux VM.
Explore Azure private DNS zones by creating a zone, linking virtual networks with auto registration, and configuring A records to resolve private IPs through a load balancer.
Enable private access from your virtual network to an Azure storage account using service endpoints over the Azure backbone by adding the endpoint and attaching a subnet.
Learn how to create and apply service endpoint policies to limit access to specific storage accounts, associating them with a subnet in a virtual network, and validate access restrictions.
Explore private endpoints that bring the storage blob service into your virtual network, assign a private IP, and use a private DNS zone for secure connectivity.
Azure storage encryption at rest uses server-side encryption by default with Microsoft managed keys, and supports customer managed keys from Azure Key Vault for blobs and files, plus encryption scopes.
Explore Microsoft Enter ID, a cloud identity and access management service formerly known as Azure Active Directory, handling authentication and authorization to secure Azure subscriptions, Microsoft 365, and SaaS apps.
Assign a role at the resource level using Azure RBAC, exploring resource group and subscription scopes and inheritance, with a hands-on example using the reader role on a virtual machine.
Explore assigning the contributor role at the resource group level to grant broad resource management, observe actions allowed and restricted, and see how adding multiple roles expands permissions across resources.
Master the user access administrator role to read the control plane, manage authorization, and delegate permissions by assigning roles to other users using fine-grained RBAC.
Explore Azure attribute based access control on top of role based access control to enforce fine grained permissions for storage blob data readers with conditional authorizations.
Deploy a Windows Server virtual machine in Azure, configure role-based access control, enable login with Microsoft Entra ID, and provision a system-assigned managed identity for VM authentication.
Explore assigning built-in Azure vm roles—vm user login, vm administrator login, and vm contributor—and manage access with Azure AD credentials and temporary access passes for secure login and vm management.
Create and assign custom roles in Azure to grant start and stop permissions for vms within a resource group. Learn about role-based access control, permissions, and scope for vm management.
This chapter looks into Microsoft Entra ID Roles
Discover how to use Microsoft Entra ID roles by assigning the user administrator role at the directory scope, enabling user creation and enforcing necessary permissions.
Learn to create Microsoft Entra ID custom roles by starting from scratch or cloning a custom role, with permissions set under roles and administrators, note this requires a premium license.
Invite external identities into Microsoft Entra ID, grant temporary access to resources using role-based access control, and manage invitations and acceptance across tenants.
Understand Microsoft Entra ID licenses, including P1 and P2, and how licensing enhances security with conditional access. Learn to define users and assign licenses via the admin portal.
Explore how to assign licenses to a security group in Azure AD, allocate Microsoft Fabric licenses to group members, and apply group-based licensing with optional PowerShell steps.
Discover how to assign licenses to groups in Entra ID for group-based licensing, require P1+ subscriptions, and toggle service plans; nested groups do not grant licenses to their members.
Learn how to enable self-service password reset in Microsoft Entra, letting non administrator users change or reset passwords without helpdesk assistance, with Entra ID P1 licenses.
Enable self-service password reset in Microsoft Entra ID by creating a security group, assigning Microsoft Entra ID User Premium base license, and enabling group-based reset with email or mobile verification.
Explore resource tagging with key-value pairs added to resources, resource groups, and subscriptions to add business context. Filter costs by tags like environment and cost center.
Move resources across resource groups in Azure using the move operation, which locks both groups and keeps the resource location unchanged while updating to new resource IDs.
This chapter looks into Locking resources
Learn how management groups sit above multiple subscriptions to define a governance hierarchy, enable RBAC and policy inheritance to subscriptions, and manage costing and budgets per subscription.
Learn how management groups organize subscriptions under a tenant root group, create an information technology group, and apply the user access administrator role to all subscriptions.
This chapter looks into Azure policies
Assign a policy to restrict not allowed resource types, such as virtual networks, and observe noncompliance when a disallowed resource exists; unassign the policy.
Release v10.0 - October 2025
An entire course refresh for the AZ-104 course. This is being done to align the course with what are the most recent exam objectives.
All of the videos will be up-to date with the latest User Interface and feature changes to the Azure services. This will provide a more seamless experience for the student and make it easier to follow along to practice on the Azure platform.
An entire refresh also carried out for the Practice Tests - All Practice Test questions updated.
Quizzes also added and updated for each section
Videos added at the end of each section to summarize all important aspects discussed during the section.
An entire project - What you’ll build in the Project
Networking: Two VNets (dev & test), subnets for web/app/DB, VNet peering
Security: NSGs/ASGs, Key Vault for admin secrets
Access: Azure Bastion for RDP/SSH—no public IPs on VMs
Traffic: Internal Load Balancer (backend pools, health probes, persistence)
Storage Connectivity: Service Endpoints vs Private Endpoints, plus Private DNS
Automation: Bicep modules for VNets, NSGs, VMs, ILB—deploy with param files
Release v9.0 - September 2024
An entire course refresh for the AZ-104 course. This is being done to align the course with what are the most recent exam objectives.
All of the videos will be up-to date with the latest User Interface and feature changes to the Azure services. This will provide a more seamless experience for the student and make it easier to follow along to practice on the Azure platform.
Azure services go through several updates and we need to ensure we align our learning with the most recent updates.
Release v8.1 - July 2023
To keep in line with the exam objective changes on 28th July , the following topics have been added to the course
Azure file shares - Snapshots , soft-delete, identity-based authentication
Azure Container Apps
An entire section on how to use Bicep to deploy Azure resources
Release v8.0 - April 2023
Carried out a complete revision of the Azure Administrator course. Refreshed all videos and ensured course is aligned with the most recent course objectives.
Release v7.0 - January 2022
Created new sections with revised videos on
Monitor and back up Azure resources
Azure PowerShell and Azure CLI
Azure Resource Manager Templates
Have introduced a lot of chapters on how you can create ARM templates.
Created around 180 new practice test questions
Release v6.0 - March 2021
Refreshed videos on various chapters which includes the following
Point-to-Site VPN connections
Site-to-Site VPN connections
Network Security Groups
Azure Standard Load Balancer
Azure Backup and Restore for Azure Virtual Machines
Azure Firewall
Azure Storage Accounts
Added new videos which includes the following
Azure Kubernetes - Adding disks and file shares
Azure Web Apps - Backup, Custom domains, SSL
Azure Application Gateway - Working with multiple sites
Azure Storage Accounts - Object replication, Private Endpoints
Release v5.0 - December 2020
Added new contents including the following
Creating VM's with Premium Disks
Lab on using an Azure Load Balancer with Virtual Machine Scale sets
Deployment slots for Azure Web Apps
Integration of Azure Web Apps with Azure Virtual Network
Usage of various tools available with Network Watcher
Refreshed chapters to reflect changes in Azure services
Release v4.0 - April
Added contents based on AZ-104 skills outline
Students can use this course to pass either the AZ-103 or the AZ-104 exam
Release v3.0 - February
Released newer version of section "Deploy and manage virtual machines (VMs)"
Released newer version of section "Configure and manage virtual networks"
Released newer version of section "Implement and manage storage"
Updated section "Manage Azure subscriptions and resources"
Updated section "Manage identities"
Release - v2.0 - July 2019
Fresh new look to chapters that explain key concepts on the Azure platform
Added more chapters on concepts - Resource tagging , storage accounts , Virtual Machine SLA
Mention on new az PowerShell
Added chapter on Availability Zones
Added chapter on implementation of the Azure Standard Load Balancer
Release - v1.1 - June 2019
Added optional chapters for students who are new to the Azure platform
Added chapter on Azure subscriptions based on students request
Release - v1.0 - May 2019
Course contents updated to align with AZ-103 objectives
This course is designed for students who would like to attain the Microsoft Azure Administration Certification
This course has contents for the Exam AZ-104
The objectives covered in this course are
Manage Azure identities and governance
Implement and manage storage
Deploy and manage Azure compute resources
Configure and manage virtual networking
Monitor and back up Azure resources