AZ-104: Microsoft Azure Administrator – LIVE Training
-
Introduction
-
Microsoft Entra Users & GroupsMicrosoft Entra Identity & Access ManagementMicrosoft Entra Product FamilyMicrosoft Entra ID – OverviewMicrosoft Entra ID – DemoManaging Microsoft Entra ID TenantsCompare Identity Providers for External IdentitiesManage licenses in Microsoft Entra IDManage external users – DemoSelf-service password reset (SSPR) – DemoCreate, Manage User and Group Properties – DemoManage Resource Groups – Demo
-
Manage Access to Azure ResourcesRole based access control (RBAC) – OverviewMicrosoft Entra Role based access controlRBAC – Users and Management GroupsAssign Microsoft Entra roles at different scopes – DemoManage Built-in Azure rolesMicrosoft Entra joined devicesInterpret access assignments in AzureActive Directory and Microsoft Entra ID for Identity ManagementIAM Fundamentals Users, Roles, Permissions
-
Azure Subscriptions & GovernanceAzure Subscriptions and Governance OverviewUse Cost Alerts to Monitor Usage and SpendingDemo : Azure resource locksLab – Creating Azure resource locksDemo: Azure resource tagsLab – Working with resource tagsDemo: Azure PoliciesLab – Creating Azure PoliciesAzure Advisor and Azure Service HealthDemo: Azure Advisor
-
Implement & Manage Azure Storage ServicesAzure Storage Accounts and Services – OverviewDemo: Create an Azure Storage AccountLab – Create a Storage AccountAzure Storage RedundancyDemo: Azure Storage EncryptionLab – Encrypt a Windows VM with Azure PortalDemo: Azure Blob Storage Client Library for .NETAzure Blob Storage Policy & Data Lifecycle Management – OverviewDemo: Configure a Lifecycle Management PolicyLab – Understanding Azure Blob Storage TiersAzure Key Vault – OverviewLab – Understanding Azure Key VaultAzure FirewallDemo: Azure Firewall – Part 1 [Creating Vnet and VM]Demo: Azure Firewall – Part 2 [Creating Routes and Firewall Rules]Demo: Azure Firewall – Part 3 [Testing Azure Firewall]Lab – Deploy and configure Azure Firewall and policy using the Azure portalAzure Migration Services – OverviewAzure File Movement OptionsDemo: AzCopyShared Access Signature (SAS) – DemoLab – Working with Shared Access SignaturesLab – Network Access to Storage AccountsAzure Files [Snapshots & Soft Delete] – DemoAzure Storage Firewalls and Virtual NetworksAzure Blob Object Replication and Blob Versioning – DemoAzure Files Identity-based AuthenticationAzure Stored Access Policies – DemoAzure Storage Explorer, and File Sync OverviewAzure File Sync
-
Azure Virtual MachinesAzure Virtual Machines OverviewCreate an Azure Virtual MachineLab – Create a Virtual MachineAzure Availability Sets – OverviewLab – Creating Availability SetAzure Availability Zones – OverviewAzure Regions – OverviewLab – Adding Data Disks to the VM Using CLILab – Create a SQL Server on a Windows VM using Azure portalAzure Virtual Machine Scale Sets (VMSS) – OverivewDemo: Creating Virtual Machine Scale Sets – Part 1Demo Creating Virtual Machine Scale Sets – Part 2Azure Disk Encryption – DemoExport a deployment as an Azure Resource Manager Template – DemoLab – Install and Test a Web Server on Virtual MachineLab – Resizing of Virtual Machine
-
ARM Templates & Biceps Files
-
Azure Containers – Services & ManagementAzure Container Services – OverviewAzure Container Apps – OverviewCreate solutions by using Azure Container AppsLab – Deploy your first container app using the Azure portalAzure Container Services [ACI vs AKS]Demo: Azure Container InstancesLab – Deploy Azure Container InstancesDemo: Azure Container Registry – Build and Publish Docker image – Part IDemo: Azure Container Registry – Build and Publish Docker image – Part IILab – Azure Container Registry
-
Azure App ServiceAzure App Service OverviewDemo: Create and Configure Azure App ServiceLab – Azure app serviceConfigure scaling for an App Service planConfigure certificates and Transport Layer Security (TLS) for an App ServiceMap an existing custom DNS name to an App ServiceLab – Implement DNS name resolution in AzureConfigure backup for an App ServiceConfigure networking settings for an App ServiceConfigure deployment slots for an App ServiceLab – Hands-On Azure App Service Deployment Slot SwappingLab – Containerizing Web Apps on Azure App Service
-
Azure Virtual Networking: Service Managing & Secure AccessAzure Networking Services – OverviewDemo: Azure Virtual NetworkLab – Create a Virtual NetworkDemo: Network Security GroupsLab – Understand Network Security Group rulesDemo Applicaiton Security GroupsAzure NAT Gateway – OverviewAzure VPN Gateway – OverviewDemo: Azure VPN GatewayLab – VPN Gateway ChallengeAzure DDoS and Bastion Service – OverviewLab – Azure Bastion ServiceUser Defined Routes – OverviewNetwork Connectivity Troubleshooting – OverviewLab – Troubleshoot routing, traffic control and load balancing in Microsoft AzureService Endpoints for Azure platform as a service (PaaS)Lab – Service Endpoints and Securing StoragePrivate endpoints for Azure PaaS – DemoLab – Creating a private endpoint using Bicep
-
Azure Virtual Networking: DNS & Load Balancer ServiceAzure DNS – OverviewCreate a DNS zone and alias recordAzure Load Balancing Services – OverviewDemo: Azure Load Balancer – Part1 [Creating Vnet and NAT Gateway]Demo: Azure Load Balancer – Part2 [Backend Pool Deployment]Demo: Azure Load Balancer – Part3 [Connecting to VM, ISS and Testing LB]Lab – Create an internal load balancer to load balance VMsLab – Creating a Basic Load Balancer
-
Monitor & Maintain Azure ResourcesAzure Monitoring services – OverviewDemo: Azure MonitorDemo: Implement Application Insights web tests and alertsAzure Monitor Insights OverviewAzure Network Watcher and Connection Monitor OverviewAzure Backup and Recovery Service Vault OverviewBackup and Restore operations by using Azure Backup – DemoLab – Azure Key Vault Backup
-
Course Ending
Introduction
-
Welcome to the course
-
Understanding the Microsoft Environment
-
Having a Solid Foundation of Active Directory Domains
-
Having a Solid Foundation of RAS, DMZ, and Virtualization
-
Having a Solid Foundation of the Microsoft Cloud Services
-
Order of concepts covered in the course
Setting up for hands on
-
Using Assignments in the course
-
Creating a free Azure Account
-
Activating an Entra ID P2 license
Manage Entra (formerly Azure AD) users and groups
-
Creating users, guest accounts, and bulk updates
-
Creating groups
-
Manage licenses in Azure AD
-
Create administrative units
-
Manage user and group properties
-
Manage device settings and device identity
-
Configure self-service password reset (SSPR)
Manage Azure using command line tools
-
Basic concepts of PowerShell
-
Installing PowerShell modules and Connecting to Azure
-
Interacting with Azure AD using PowerShell
-
Using Cloudshell
-
Using Azure CLI / Bash
-
Installing Azure CLI locally
Manage access to Azure resources
-
Understanding the assignment of roles in Azure
-
Create custom role-based access control (RBAC) and Azure AD roles
-
Provide access to Azure resources by assigning roles at different scopes
-
Interpret access assignments
Manage Azure subscriptions and governance
-
Configure management groups
-
Manage subscriptions
-
Manage costs by using alerts, budgets, and recommendations
-
Manage resource groups
-
Apply and manage tags on resources
-
Configure and manage Azure Policy
-
Configure resource locks
Configure access to storage
-
Understanding storage accounts
-
Create and configure storage accounts
-
Configure Azure Storage firewalls and virtual networks
-
Configure Azure AD authentication for a storage account
-
Manage access keys
-
Generate shared access signature tokens
-
Configure stored access policies
-
Configure storage encryption
Configure and manage storage accounts
-
Create import and export jobs
-
Manage data by using Azure Storage Explorer and AzCopy
-
Understanding Azure Storage redundancy
-
Implement Azure Storage redundancy
-
Configure object replication
Configure Azure Files and Azure Blob Storage
-
Create an Azure file share and Configuring storage tiers
-
Configure Azure Blob Storage
-
Configure blob lifecycle management
-
Configure blob versioning
Automate deployment of resources by using ARM templates or Bicep files
-
Interpret an ARM template or a Bicep file
-
Modify an ARM template
-
Deploy a template
-
Create or modify an existing Bicep file
-
Deploy virtual machine (VM) extensions
Create and configure virtual machines
-
Create a VM
-
Create a VM using PowerShell
-
Manage images by using the Azure Compute Gallery
-
Configure Azure Disk Encryption
-
Move VMs from one resource group to another
-
Manage VM sizes
-
Add data disks
-
Configure VM network settings
-
Configure VM availability options
-
Deploy and configure VM scale sets
Provision and manage containers in the Azure portal
-
Understanding Azure Containers
-
Configure sizing and scaling for Azure Container Instances
-
Understanding container groups for Azure Container Instances
Create and configure an Azure App Service
-
Understanding App Service Plans
-
Create an App Service plan
-
Configure scaling settings in an App Service plan
-
Create an App Service
-
Secure an App Service
-
Configure custom domain names
-
Configure backup for an App Service
-
Configure networking settings
-
Configure deployment settings
Configure and manage virtual networks in Azure
-
Visualizing virtual networks and subnets in Azure
-
Create and configure virtual networks and subnets
-
Creating virtual networks with PowerShell
-
Create and configure virtual network peering
-
Configure private and public IP addresses
-
Configure user-defined network routes
Configure secure access to virtual networks
-
Create and configure network security groups (NSGs) and ASGs
-
Evaluate effective security rules
-
Implement Azure Bastion
-
Visualizing service endpoints and private endpoints
-
Configure service endpoints and private endpoints
Configure name resolution and load balancing
-
Configure Azure DNS
-
Visualizing Azure load balancing
-
Setting up two VMs for load balancing
-
Configure an internal or public load balancer
-
Configure load balancing rules for two VMs
-
Configure inbound NAT rules
-
Configure SNAT outbound rules
-
Removing the Load Balancer before moving on
-
Start creating an Azure Application Gateway
-
Specifying a back-end pool while creating an Application Gateway
-
Setting the routing rules while creating an Application Gateway
-
Finalizing the gateway creation
-
Removing resources no longer needed
Monitor resources in Azure
-
Configure and interpret metrics
-
Configure Azure Monitor Logs
-
Query and analyze logs
-
Set up alerts and actions
-
Configure monitoring of VMs, storage accounts, and networks by using VM insights
-
Configure and use Azure Monitor for networks and on-premise connectivity
-
Use Azure Network Watcher
-
Troubleshoot external networking
-
Troubleshoot virtual network connectivity
Implement backup and recovery
-
Create an Azure Recovery Services vault
-
Create and configure backup policy
-
Perform backup and restore operations by using Azure Backup
-
Configure Azure Site Recovery for Azure resources
-
Configure and review backup reports
Finishing Up
-
Where do I go from here?