โ† Azure Fundamentals AZ 900 Level Two ยท Lesson 2 of 5

Module One

๐Ÿ“– Every lesson in this course is free to read right here, no account needed. Create a free account to track your progress, take the exam, and earn your certificate.
1

Course Outline

Microsoft Azure Fundamentals โ€“ Intermediate Course Outline

โ˜๏ธ Microsoft Azure Fundamentals โ€“ Intermediate

Practical skills ยท Security ยท Governance ยท Cost optimization ยท Automation
๐Ÿ“˜ 5 modules โฑ๏ธ 42โ€“52 hours ๐ŸŽฏ Hands-on labs ๐Ÿ† Capstone project ๐Ÿ“‹ Prerequisite: AZ-900
5Modules
42โ€“52hTotal effort
15+Hands-on labs
1Capstone project
1

Deeper Dive into Core Services

10โ€“12h
  • Advanced Compute VM sizing, managed disks, extensions App Service โ€“ deployment slots, custom domains Container Instances & AKS overview Azure Functions โ€“ triggers, bindings, Durable
  • Advanced Networking VNet, subnets, NSGs, peering Load Balancer, Application Gateway, Front Door VPN Gateway & ExpressRoute
  • Advanced Storage Storage accounts, redundancy, tiers Blob lifecycle, object replication Azure Files, File Sync, SAS tokens
2

Identity, Security & Compliance

8โ€“10h
  • Microsoft Entra ID Tenants, users, groups, guest access SSO, MFA, Conditional Access
  • RBAC Built-in vs. custom roles Least privilege best practices
  • Azure Security Security Center, Secure Score, JIT Azure Defender, threat protection Key Vault โ€“ secrets, keys, managed identities
  • Governance Azure Policy โ€“ definitions, initiatives Resource locks, tags, Blueprints
3

Cost Management & Optimization

6โ€“8h
  • Pricing & TCO Pricing Calculator, TCO Calculator Factors: region, tier, usage
  • Cost Management Tools Cost Management + Billing Budgets, spending alerts, cost analysis
  • Optimization Strategies Right-sizing, Azure Advisor Reserved Instances & Savings Plans Azure Hybrid Benefit Idle resource management, automation
4

Management, Monitoring & Automation

8โ€“10h
  • Management Tools Portal, CLI, PowerShell, Cloud Shell ARM templates & Bicep (IaC)
  • Monitoring Azure Monitor โ€“ metrics & logs Application Insights, Log Analytics KQL basics, dashboards Alerts & Action Groups Service Health
  • Automation Azure Automation โ€“ runbooks, DSC Logic Apps, Functions for workflows
5

Real-world Scenarios & Hands-on

10โ€“12h
  • Hybrid & Multicloud Azure Arc, Azure Stack
  • Disaster Recovery & HA Azure Site Recovery, Azure Backup Availability Zones, region pairs, SLAs
  • DevOps & CI/CD Azure DevOps (Repos, Pipelines) GitHub Actions integration IaC with ARM/Bicep/Terraform
  • Capstone Project Multiโ€‘tier secure application Load balancing, autoโ€‘scaling Managed identities, Key Vault Monitoring, alerting, cost optimization

๐Ÿ“Œ Learning Outcomes

  • Design & implement Azure solutions confidently
  • Apply security with Entra ID & RBAC
  • Enforce governance using Policy & locks
  • Optimize costs with calculators & reserved instances
  • Monitor & troubleshoot with Azure Monitor & Log Analytics
  • Automate deployments with ARM & Bicep
  • Implement hybrid & disaster recovery solutions

๐Ÿ“‹ Prerequisites

  • AZ-900 or equivalent foundational knowledge
  • Familiarity with basic IT concepts (networking, storage, compute)
  • Some experience with the Azure Portal
  • Recommended: free Azure account for labs
๐Ÿ’ก This course is designed for learners who have completed the AZ-900 fundamentals.

๐Ÿ—๏ธ Capstone Project โ€“ Design a Complete Azure Solution

  • Secure VNet with subnets and NSGs
  • Multiโ€‘tier application (web + database)
  • Load balancing and autoโ€‘scaling
  • Managed identities and Key Vault integration
  • Monitoring, alerting, and dashboards
  • Cost optimization recommendations
๐ŸŽฏ Present your design and get feedback

๐Ÿ“Š Course Structure Summary

Module Title Hours
1Deeper Dive into Core Services10โ€“12
2Identity, Security & Compliance8โ€“10
3Cost Management & Optimization6โ€“8
4Management, Monitoring & Automation8โ€“10
5Real-world Scenarios & Hands-on10โ€“12
Total42โ€“52 hours
2

Module One

Module 1 ยท Azure Core Services (Intermediate) ยท AZ-900

๐Ÿ“˜ Module 1: Deeper Dive into Azure Core Services (Intermediate)

Welcome back, cloud explorer! ๐ŸŒŸ In this module, we will go deeper into Azure's most important services. We already know the basics โ€“ now we will learn how to use them like a pro. Think of this as moving from riding a bicycle ๐Ÿšฒ to driving a car ๐Ÿš— โ€“ more power, more control!

๐ŸŽฏ Learning Objectives

  • Understand virtual machine sizing, managed disks, and extensions.
  • Deploy web apps using App Service with deployment slots.
  • Learn about containers: Azure Container Instances and AKS.
  • Use Azure Functions with triggers and bindings.
  • Design advanced networks with VNet, peering, and load balancers.
  • Master Azure Storage with lifecycle management and SAS tokens.

๐Ÿ“– Warm-up Story: The Bigger Workshop

Remember our workshop from the beginner course? Now it's time to upgrade it!

Imagine you have a workshop with many rooms. But now you have:

  • More powerful machines (like bigger VMs).
  • Smart shelves that organise themselves (lifecycle management).
  • Magic doors that connect rooms automatically (VNet peering).
  • A robot that builds things on demand (Azure Functions).

In this module, you will learn how to use these advanced tools to build amazing things!

๐Ÿ“˜ Main Lessons

1. Virtual Machine Sizing โ€“ Choosing the right power

Definition: VM sizing is about choosing the right amount of CPU, memory, and storage for your virtual machine.

Why important: If you choose a small VM, your app will be slow. If you choose a huge VM, you waste money.

Simple: Like buying shoes โ€“ you need the right size!

Real-life: A video editing company needs a large VM with lots of memory.

School: A small school website can use a tiny VM.

Home: A Minecraft server needs a medium VM.

Nigerian: A fintech in Lagos uses a large VM for transaction processing.

VM SeriesUse Case
B-series (burstable)Websites with low traffic
D-series (general purpose)Most applications
E-series (memory optimized)Databases, analytics
N-series (GPU)AI, video rendering

โœ… Summary: Choose the VM size that fits your needs โ€“ not too big, not too small.


2. Managed Disks โ€“ Smart storage for VMs

Definition: Managed disks are Azure's storage for VM hard drives. They are easier to manage than unmanaged disks.

Why important: They handle backups, scaling, and security automatically.

Simple: Like having a housekeeper for your hard drives!

Real-life: A company uses managed disks so they don't worry about disk failures.

School: The school's VM uses a managed disk for safety.

Home: You use a managed disk for your personal VM.

Nigerian: A hospital uses managed disks for patient records.

    Unmanaged Disk = You manage everything (hard work!)
    Managed Disk  = Azure manages it (easy!)
    

โœ… Summary: Managed disks are easier and safer for your VMs.


3. VM Extensions โ€“ Add superpowers to your VM

Definition: VM extensions are small programs that run on your VM to add features, like installing software or configuring settings.

Why important: You can automate tasks without logging into the VM.

Simple: Like adding a new app to your phone with one tap.

Real-life: A company uses an extension to install antivirus software on all VMs.

School: The IT teacher uses an extension to install Python on all VMs.

Home: You use an extension to set up a web server.

Nigerian: A startup uses an extension to install Node.js on its VMs.

    VM Extension = Small program that runs on the VM
    Example: Install Chrome, update Windows, etc.
    

โœ… Summary: Extensions let you automate tasks on your VMs.


4. App Service โ€“ Deploy web apps easily

Definition: App Service is a PaaS service that hosts web applications. You just upload your code, and Azure runs it.

Why important: No need to manage servers โ€“ just focus on your app.

Simple: Like uploading a video to YouTube โ€“ you don't need to build the video player!

Real-life: A company hosts its e-commerce website on App Service.

School: The school's website is on App Service.

Home: You can host a blog on App Service.

Nigerian: A restaurant in Abuja uses App Service for its online menu.

โœ… Summary: App Service lets you host web apps without managing servers.


5. Deployment Slots โ€“ Test before you go live

Definition: Deployment slots are separate environments in App Service where you can test your code before swapping it to the main (production) slot.

Why important: You can test changes without affecting real users.

Simple: Like trying on clothes in a dressing room before buying them.

Real-life: A company tests a new feature in a staging slot before going live.

School: The school tests a new homework portal in a staging slot.

Home: You test a new blog design in a staging slot.

Nigerian: A fintech tests payment updates in a staging slot.

    Production slot = live website (real users)
    Staging slot   = test version (only you see it)
    Swap = make staging the new production!
    

โœ… Summary: Deployment slots let you test changes safely.


6. Custom Domains and SSL โ€“ Your own website address

Definition: Custom domains let you use your own website name (like mywebsite.com) instead of the Azure default. SSL makes it secure (https://).

Why important: It looks professional and builds trust.

Simple: Like having a personalised number plate on your car.

Real-life: Every company uses a custom domain for its website.

School: The school uses myschool.edu.ng.

Home: You can buy a domain for your personal blog.

Nigerian: A business uses mybusiness.com.ng.

โœ… Summary: Custom domains and SSL make your website look professional.


7. Azure Container Instances (ACI) โ€“ Lightweight containers

Definition: ACI lets you run containers (lightweight packages of code) in Azure without managing any servers.

Why important: It's fast and cheap for small applications.

Simple: Like a microwave meal โ€“ quick and easy!

Real-life: A company runs a small reporting tool in ACI.

School: A teacher runs a quiz app in ACI.

Home: You run a fun game in ACI.

Nigerian: A startup runs a prototype in ACI.

    Container = small package of code + environment
    ACI = run containers without managing servers
    

โœ… Summary: ACI lets you run containers easily and cheaply.


8. Azure Kubernetes Service (AKS) โ€“ Managing many containers

Definition: AKS is a service that helps you manage a large group of containers โ€“ it's like a traffic controller for containers.

Why important: When you have many containers, you need a system to manage them.

Simple: Like a school principal who manages many classrooms.

Real-life: A big company runs hundreds of containers with AKS.

School: Not used in schools โ€“ it's for big companies.

Home: Not used at home.

Nigerian: A large bank uses AKS to manage its microservices.

โœ… Summary: AKS helps you manage many containers.


9. Azure Functions โ€“ Run code on demand

Definition: Azure Functions is a serverless service โ€“ you write code that runs only when triggered.

Why important: You pay only when the code runs, not for idle time.

Simple: Like a vending machine โ€“ it only works when you press a button.

Real-life: A photo app uses a function to resize images when you upload them.

School: A function could send a notification when a teacher posts homework.

Home: A function could turn on your smart lights when you arrive home.

Nigerian: A delivery app uses a function to calculate shipping costs.

    Trigger (e.g., upload photo) โ†’ Function runs โ†’ Done (resized photo)
    

โœ… Summary: Functions run code only when needed, saving money.


10. Triggers and Bindings โ€“ When and how functions run

Definition: A trigger is what starts a function (like a timer or a file upload). Bindings are connections to data (like reading from a database).

Why important: They make functions very flexible.

Simple: A trigger is like an alarm clock; bindings are like a phone line.

Real-life: A function triggers when an email arrives and saves it to storage.

School: A function triggers when a new student is added.

Home: A function triggers when a new photo is uploaded.

Nigerian: A function triggers when a transaction is made.

Trigger TypeExample
TimerRun every 5 minutes
HTTPCall function via a URL
BlobRun when a file is uploaded
QueueRun when a message arrives

โœ… Summary: Triggers start functions; bindings connect to data.


11. Virtual Network (VNet) โ€“ Your private cloud network

Definition: VNet is a private network inside Azure, just like your home Wi-Fi.

Why important: It keeps your resources safe and connected.

Simple: A VNet is like a private road system for your cloud resources.

Real-life: A company uses VNet to connect its web server to its database securely.

School: The school network connects all computers โ€“ VNet does the same in Azure.

Home: Your home Wi-Fi connects your phone, laptop, and TV.

Nigerian: A healthcare provider uses VNet to connect patient records safely.

    VNet = private cloud network
    โ”œโ”€โ”€ Subnet A (Web servers)
    โ”œโ”€โ”€ Subnet B (Database servers)
    โ””โ”€โ”€ Subnet C (Application servers)
    

โœ… Summary: VNet creates a private network for your Azure resources.


12. VNet Peering โ€“ Connect two VNets

Definition: VNet peering lets you connect two VNets so they can communicate as if they were one network.

Why important: You can connect resources in different regions.

Simple: Like building a bridge between two islands.

Real-life: A company has VNets in Lagos and Europe and peers them.

School: Two school buildings connected by a walkway.

Home: Two routers connected to share internet.

Nigerian: A bank peers VNets in South Africa and Nigeria.

โœ… Summary: VNet peering connects two VNets.


13. Azure Load Balancer โ€“ Share the work

Definition: A load balancer distributes incoming traffic across multiple VMs so no single VM gets overloaded.

Why important: It makes your app reliable and fast.

Simple: Like a receptionist who sends visitors to different offices.

Real-life: A popular website uses a load balancer to handle millions of users.

School: The school office sends students to different classrooms.

Home: Not used at home.

Nigerian: An e-commerce site uses a load balancer during sales.

    User requests โ†’ Load Balancer โ†’ VM1, VM2, VM3 (spread evenly)
    

โœ… Summary: A load balancer distributes traffic to keep your app running smoothly.


14. Storage Lifecycle Management โ€“ Auto-archive old files

Definition: Lifecycle management is a rule that automatically moves files to cheaper storage tiers when they become old.

Why important: It saves money.

Simple: Like moving winter clothes to the attic when summer comes.

Real-life: A company moves old project files to Archive after 2 years.

School: Old student records are archived.

Home: Old photos are moved to Archive.

Nigerian: A bank archives old transaction records.

    New file โ†’ Hot tier (fast, expensive)
    After 30 days โ†’ Cool tier (cheaper)
    After 1 year โ†’ Archive tier (cheapest)
    

โœ… Summary: Lifecycle management moves old data to cheaper storage.


15. Shared Access Signatures (SAS) โ€“ Safe sharing

Definition: A SAS is a secure link that gives temporary access to a storage file or container.

Why important: You can share files without giving away your storage keys.

Simple: Like a temporary key to your house for a friend.

Real-life: A company shares a large file with a client via a SAS link.

School: The teacher shares a PDF with students via a SAS link.

Home: You share a family video with a relative.

Nigerian: A lawyer shares a contract file with a client.

    SAS URL = https://storage...?sp=r&se=2025-12-31...
    (expires on 2025-12-31)
    

โœ… Summary: SAS lets you share files securely and temporarily.


๐Ÿ“š Key Vocabulary

  • VM Sizing: Choosing the right CPU, memory, and storage.
  • Managed Disk: Azure-managed storage for VMs.
  • Extension: A program that adds features to a VM.
  • App Service: A platform to host web apps.
  • Deployment Slot: A test environment before production.
  • Custom Domain: Your own website address.
  • SSL: A security certificate for websites.
  • Container: A lightweight package of code.
  • ACI: Azure Container Instances.
  • AKS: Azure Kubernetes Service.
  • Function: Code that runs on demand.
  • Trigger: What starts a function.
  • Binding: Connection to data.
  • VNet: Virtual Network.
  • Peering: Connecting two VNets.
  • Load Balancer: Distributes traffic.
  • Lifecycle Management: Auto-move data to cheaper storage.
  • SAS: Shared Access Signature.

๐Ÿง  Important Concepts

  • Right-sizing: Choose the right VM size for your workload.
  • Automation: Use extensions, functions, and lifecycle rules to save time.
  • Security: Use managed disks, SSL, and SAS for safety.
  • Scalability: Load balancers and deployment slots help you grow.
  • Cost optimization: Lifecycle management and right-sizing save money.

๐Ÿ”ข Step-by-step: Deploy a Web App with a Staging Slot

  1. Go to Azure Portal.
  2. Create a new App Service (Web App).
  3. In the App Service, go to "Deployment slots".
  4. Add a new slot named "staging".
  5. Deploy your code to the "staging" slot (use FTP or GitHub).
  6. Test the staging site using its URL (staging.azurewebsites.net).
  7. When ready, click "Swap" to move staging to production.
  8. Your website is now live with the new code!

๐ŸŒ Real-life Examples

  • Netflix: Uses VMs, load balancers, and containers for streaming.
  • Spotify: Uses App Service for its website.
  • Adobe: Uses Functions for image processing.
  • E-Trade: Uses VNet for secure banking.
  • Nike: Uses storage lifecycle management for product images.

๐Ÿ‡ณ๐Ÿ‡ฌ Nigerian Examples

  • Flutterwave: Uses VMs and load balancers for payment processing.
  • Paystack: Uses App Service for its developer portal.
  • Kuda Bank: Uses Functions for transaction notifications.
  • Chipper Cash: Uses VNet for secure connections.
  • Farmcrowdy: Uses lifecycle management for farmer data.

๐ŸŽˆ Fun Examples for Kids

  • Roblox: Uses VMs to host game servers.
  • Minecraft: You can use a VM to host your own world.
  • TikTok: Uses storage for all the videos.
  • Zoom: Uses App Service for the website.
  • Google Classroom: Uses functions to send notifications.

๐Ÿ  Everyday Examples

  • Backing up photos: Using Azure Blob Storage.
  • Hosting a blog: Using Azure App Service.
  • Family calendar: Using Azure Functions to send reminders.
  • Smart home: Connecting devices via VNet.
  • Online shopping: Using storage for product images.

๐Ÿ‘ฉโ€๐Ÿซ Teacher Notes

  • Emphasise that this module is about going deeper โ€“ we already know the basics.
  • Use the workshop analogy to explain advanced concepts.
  • Relate to Nigerian context: use local examples like Flutterwave, Paystack.
  • Encourage students to try hands-on labs in Azure (free account).
  • Show the Azure Portal in a live demo.

๐Ÿง‘โ€๐Ÿคโ€๐Ÿง‘ Parent Tips

  • Discuss with your child how businesses use advanced cloud services.
  • Explain that right-sizing saves money โ€“ like buying only what you need.
  • Talk about how load balancers help handle many users.
  • Encourage them to think about how they would design a cloud app.
  • Ask: "Which service would you use to build a game?"

๐Ÿ’ก Interesting Facts

  • Azure has over 60 regions worldwide.
  • Azure Functions can scale to handle millions of requests per second.
  • Azure App Service supports .NET, Java, Python, Node.js, and more.
  • Containers run more efficiently than VMs.
  • Azure Load Balancer can handle billions of requests per day.

๐Ÿค” Did You Know?

  • You can run a supercomputer in Azure for research.
  • Azure has a service for AI and machine learning.
  • You can use Azure to build a blockchain network.
  • Azure has a service called "Cosmos DB" for global databases.
  • Microsoft has underwater data centres to cool servers.

๐Ÿงพ Remember This

  • Choose the right VM size for your workload.
  • Managed disks are easier and safer than unmanaged disks.
  • Use extensions to automate VM tasks.
  • App Service hosts web apps without managing servers.
  • Deployment slots let you test changes safely.
  • Containers are lightweight and efficient.
  • Functions run code on demand, saving money.
  • VNet is a private network; peering connects two VNets.
  • A load balancer distributes traffic.
  • Lifecycle management moves old data to cheaper storage.
  • SAS lets you share files securely and temporarily.

โš ๏ธ Common Mistakes

  • Mistake: Choosing a VM that is too small, causing slowness.
    Fix: Monitor CPU/memory and resize if needed.
  • Mistake: Using unmanaged disks when managed disks are better.
    Fix: Always use managed disks.
  • Mistake: Forgetting to test in a staging slot.
    Fix: Always test in staging before swapping.
  • Mistake: Not securing storage with SAS tokens.
    Fix: Use SAS for temporary sharing.
  • Mistake: Not using lifecycle management, wasting money.
    Fix: Set up lifecycle rules for old data.

๐ŸŒŸ Best Practices

  • Use managed disks for all VMs.
  • Use deployment slots for all App Service apps.
  • Monitor your VMs and resize when needed.
  • Use lifecycle management to save money.
  • Secure storage with SAS tokens.
  • Use VNet to isolate your resources.
  • Use load balancers for high availability.
  • Automate tasks with extensions and functions.

๐Ÿ“Š ASCII Illustrations

VM Sizing

    Small VM (B1s)   โ†’  Web apps, low traffic
    Medium (D2s)     โ†’  General purpose
    Large (E4s)      โ†’  Databases, analytics
    

Load Balancer

    Users โ†’ Load Balancer
                โ”œโ”€โ”€ VM1
                โ”œโ”€โ”€ VM2
                โ””โ”€โ”€ VM3
    

Lifecycle Management

    New file โ†’ Hot tier (0โ€“30 days)
    After 30 days โ†’ Cool tier
    After 365 days โ†’ Archive tier
    

๐Ÿ“‹ Comparison tables

Compute services comparison

ServiceTypeUse case
Virtual MachinesIaaSFull control, custom OS
App ServicePaaSWeb apps, APIs
FunctionsServerlessEvent-driven, short tasks
ACIContainerSimple container workloads
AKSContainer orchestrationComplex container management

Storage tiers comparison

TierAccess frequencyCost
HotFrequentHigh
CoolInfrequentMedium
ArchiveRareLow

๐Ÿ“Œ End-of-module Summary

In this module, we took a deeper dive into Azure's core services. We learned:

  • Compute: VM sizing, managed disks, extensions, App Service, deployment slots, containers (ACI, AKS), and Functions.
  • Networking: VNet, peering, and load balancers.
  • Storage: Lifecycle management and SAS tokens.
  • Security: Custom domains, SSL, and SAS.
  • Nigerian examples: How local companies use these services.

You now have a solid understanding of Azure's core services at an intermediate level. In the next module, we will learn about Identity, Security, and Compliance.

โ“ Frequently Asked Questions

  1. What is the difference between App Service and Functions? โ€“ App Service hosts full web apps; Functions run small pieces of code on demand.
  2. When should I use containers instead of VMs? โ€“ Containers are lighter and faster for small apps.
  3. What is a deployment slot? โ€“ A test environment for your App Service.
  4. How do I choose the right VM size? โ€“ Monitor your CPU and memory usage.
  5. What is a managed disk? โ€“ A storage disk that Azure manages for you.
  6. What is a SAS token? โ€“ A secure link to access storage temporarily.
  7. What is VNet peering? โ€“ Connecting two VNets.
  8. What does a load balancer do? โ€“ It distributes traffic across multiple VMs.
  9. What is lifecycle management? โ€“ Automatically moving old data to cheaper storage.
  10. What is a function trigger? โ€“ What starts a function (e.g., a timer or file upload).

๐Ÿ“ Review Questions

  1. What is VM sizing?
  2. Why are managed disks better than unmanaged disks?
  3. What is an extension?
  4. What is App Service used for?
  5. What is a deployment slot?
  6. What is a custom domain?
  7. What is the difference between ACI and AKS?
  8. What is a function trigger?
  9. What is a VNet?
  10. What is VNet peering?
  11. What does a load balancer do?
  12. What is lifecycle management?
  13. What is a SAS token?
  14. Give a Nigerian example of using App Service.
  15. Why is right-sizing important?

โœ๏ธ Fill-in-the-Blank

  1. ___________ is choosing the right CPU and memory for a VM. (Sizing)
  2. ___________ disks are managed by Azure. (Managed)
  3. ___________ are programs that add features to a VM. (Extensions)
  4. ___________ is a service for hosting web apps. (App Service)
  5. A ___________ slot is a test environment. (deployment)
  6. ___________ is a security certificate for websites. (SSL)
  7. ___________ are lightweight packages of code. (Containers)
  8. ___________ runs code on demand. (Azure Functions)
  9. A ___________ starts a function. (trigger)
  10. ___________ is a private network in Azure. (VNet)

โœ… True or False

  1. Managed disks require you to manage backups. (False)
  2. Deployment slots let you test changes safely. (True)
  3. Containers are heavier than VMs. (False)
  4. Azure Functions run only when triggered. (True)
  5. VNet peering connects two VNets. (True)
  6. A load balancer sends all traffic to one VM. (False)
  7. Lifecycle management moves old data to cheaper storage. (True)
  8. A SAS token is a permanent access key. (False)
  9. App Service requires you to manage the server. (False)
  10. AKS is used for managing many containers. (True)

๐Ÿงช Multiple Choice Questions

  1. Which VM series is best for databases?
    a) B-series b) D-series c) E-series d) N-series
    Answer: c
  2. Which is a managed disk?
    a) Unmanaged b) Standard SSD c) Both d) None
    Answer: b
  3. What does App Service provide?
    a) Virtual machines b) Web hosting c) Storage d) Networking
    Answer: b
  4. What is a deployment slot?
    a) A VM b) A test environment c) A storage account d) A network
    Answer: b
  5. Which service runs containers without managing servers?
    a) AKS b) ACI c) VMs d) App Service
    Answer: b
  6. What is a trigger in Azure Functions?
    a) A connection to data b) What starts the function c) A VM d) A storage account
    Answer: b
  7. What is VNet peering?
    a) Connecting two VNets b) A load balancer c) A storage service d) A VM
    Answer: a
  8. What does a load balancer do?
    a) Stores data b) Distributes traffic c) Hosts web apps d) Manages disks
    Answer: b
  9. Which tier is best for frequently accessed data?
    a) Hot b) Cool c) Archive d) Frozen
    Answer: a
  10. What is a SAS token?
    a) A permanent key b) A temporary secure link c) A VM d) A storage account
    Answer: b
  11. Which service manages many containers?
    a) ACI b) AKS c) App Service d) Functions
    Answer: b
  12. What is an extension?
    a) A storage service b) A program that adds features to a VM c) A network d) A web app
    Answer: b
  13. What is a custom domain?
    a) Your own website address b) A VM c) A storage account d) A network
    Answer: a
  14. Which Nigerian company uses Azure VMs?
    a) Dangote b) Flutterwave c) NNPC d) Airtel
    Answer: b
  15. What is lifecycle management?
    a) Moving data to cheaper storage automatically b) A VM c) A network d) A web app
    Answer: a

๐Ÿ”— Matching Exercises

Match the service with its description.

ServiceDescription
App ServiceHost web apps
FunctionsRun code on demand
ACIRun containers without servers
AKSManage many containers
VNetPrivate network
Load BalancerDistribute traffic
SASTemporary secure link

โœ๏ธ Short Answer Questions

  1. Explain why VM sizing is important.
  2. What are the benefits of using managed disks?
  3. Describe how deployment slots work.
  4. What is the difference between ACI and AKS?
  5. How does lifecycle management save money?

๐Ÿงฉ Scenario-based Exercises

Scenario 1: A company in Lagos wants to host a web app that gets 50,000 visitors per day. They want to test changes before going live. Which services should they use?

Scenario 2: A school wants to store old student records for 10 years. They don't need fast access. Which storage tier should they use?

Scenario 3: A fintech company needs to run a small piece of code when a transaction is made. Which service should they use?

๐Ÿ‘ฅ Group Activity

In groups, design a simple architecture for a Nigerian e-commerce website. Include:

  • A web app (App Service).
  • A database (use a VM or Azure SQL).
  • A load balancer.
  • Storage for product images.
  • A function to send order confirmations.

๐Ÿง‘ Individual Activity

Draw a diagram of a VNet with two subnets: one for web servers and one for database servers. Label the components.

๐Ÿ’ฌ Classroom Discussion Questions

  1. Which Azure service do you think is most useful? Why?
  2. How would you design a cloud solution for a Nigerian bank?
  3. What are the benefits of using containers?
  4. Why is it important to test changes in a staging slot?
  5. How can Nigerian businesses save money with lifecycle management?

๐Ÿ› ๏ธ Mini Project

Cloud Architecture Design: Design a cloud architecture for a mobile app that lets users upload and share photos. Specify which Azure services you would use for compute, storage, and networking. Draw a diagram and explain your choices.

๐Ÿ’ป Practical Assignment

If you have an Azure free account, do the following:

  1. Create a VM with a managed disk.
  2. Install a web server using a VM extension.
  3. Deploy a simple web app to App Service with a staging slot.
  4. Create a storage account with a lifecycle management rule.

๐Ÿ† Challenge Exercise

Research how to create an Azure Function that triggers when a file is uploaded to storage. Write a simple guide on how to set it up.

๐Ÿ”‘ Quiz Answers (Multiple Choice)

  1. c
  2. b
  3. b
  4. b
  5. b
  6. b
  7. a
  8. b
  9. a
  10. b
  11. b
  12. b
  13. a
  14. b
  15. a

๐ŸŽ Key Takeaways

  • Choose the right VM size to balance cost and performance.
  • Managed disks are easier and safer.
  • Extensions automate VM tasks.
  • App Service hosts web apps without server management.
  • Deployment slots allow safe testing.
  • Containers (ACI, AKS) are lightweight and efficient.
  • Functions run code on demand, saving money.
  • VNet and peering create secure networks.
  • Load balancers improve reliability.
  • Lifecycle management and SAS tokens save money and secure data.

๐Ÿš€ Preparation for Module 2

In the next module, we will learn about Identity, Security, and Compliance. We'll cover:

  • Microsoft Entra ID (Azure AD) โ€“ users, groups, and access.
  • RBAC โ€“ Role-Based Access Control.
  • Azure Security Center and Azure Defender.
  • Governance with Azure Policy and Blueprints.
  • Resource locks and tags.

Review the concepts of subscriptions and resource groups โ€“ they will be very important in Module 2.


๐ŸŽ‰ Congratulations! You have completed Module 1 (Intermediate). Keep going! ๐Ÿš€

3

Module Two

Module 2 ยท Identity, Security & Compliance (Intermediate) ยท AZ-900

๐Ÿ” Module 2: Identity, Security & Compliance (Intermediate)

Welcome to the world of security! ๐ŸŒ Now that we know how to build things in Azure, we need to learn how to protect them. In this module, we will learn about identities (who you are), security (keeping bad guys out), and compliance (following the rules). Think of it like a castle โ€“ you build walls, guard towers, and only let trusted people inside.

๐ŸŽฏ Learning Objectives

  • Understand Microsoft Entra ID (Azure AD) and how it manages users.
  • Learn about Single Sign-On (SSO) and Multi-Factor Authentication (MFA).
  • Use Role-Based Access Control (RBAC) to give the right permissions.
  • Secure your resources with Azure Security Center and Azure Defender.
  • Protect secrets with Azure Key Vault.
  • Enforce rules with Azure Policy and Azure Blueprints.

๐Ÿ“– Warm-up Story: The Secure Castle

Imagine you are the king or queen of a big castle ๐Ÿฐ. Inside the castle, you have treasure, important documents, and many rooms.

You need to make sure that:

  • Only the right people can enter the castle (Identity).
  • Guards check IDs at the gate (Authentication).
  • Some rooms are off-limits to most people (RBAC).
  • You have security cameras to watch everything (Azure Security Center).
  • You have rules that everyone must follow (Azure Policy).

In this module, you will learn how to build your own secure castle in Azure!

๐Ÿ“˜ Main Lessons

1. Microsoft Entra ID โ€“ The Identity Service

Definition: Microsoft Entra ID (formerly Azure AD) is a cloud-based service that manages users and their access to resources.

Why important: It is the central place where you control who can access your Azure resources.

Simple: Like a school register โ€“ it has the names of all students and who can enter which classroom.

Real-life: A company uses Entra ID to manage employee logins to all their apps.

School: The school uses a system to manage student and teacher logins.

Home: Your Microsoft account is an Entra ID identity.

Nigerian: A Lagos bank uses Entra ID to manage employee access to banking apps.

    Entra ID = Master list of users and their permissions
    โ”œโ”€โ”€ Users (people)
    โ”œโ”€โ”€ Groups (teams)
    โ””โ”€โ”€ Applications (apps they can use)
    

โœ… Summary: Entra ID is the service that manages identities in Azure.


2. Tenants โ€“ Your own space in Azure

Definition: A tenant is a dedicated instance of Entra ID for your organisation. It is like your own private copy of the service.

Why important: It keeps your users and data separate from other organisations.

Simple: Like having your own locker at school โ€“ only you have the key.

Real-life: Each company has its own tenant.

School: The school has its own tenant for all teachers and students.

Home: Not used at home.

Nigerian: A fintech has its own tenant for its employees.

    Tenant = Your private directory in Entra ID
    

โœ… Summary: A tenant is your organisation's private space in Entra ID.


3. Users and Groups โ€“ Who are you?

Definition: A user is a person (or application) that needs access. A group is a collection of users.

Why important: Groups make it easy to give permissions to many people at once.

Simple: A user is like a student; a group is like a class.

Real-life: A company has users (employees) and groups (Marketing, Sales, IT).

School: Students are users; a class is a group.

Home: Family members are users; the "family" is a group.

Nigerian: A startup has users (employees) and groups (Developers, Managers).

    User = Individual person
    Group = Collection of users (e.g., "Finance Team")
    

โœ… Summary: Users are individuals; groups are collections of users.


4. Single Sign-On (SSO) โ€“ One login for everything

Definition: SSO lets you log in once with one set of credentials to access multiple apps.

Why important: You don't need to remember many passwords.

Simple: Like a master key that opens all doors in your house.

Real-life: Employees log in once to access email, HR system, and cloud apps.

School: Students use one login for the school portal and online library.

Home: You use your Google account to log in to YouTube, Gmail, and Drive.

Nigerian: A bank uses SSO for employees to access multiple internal apps.

    Login once โ†’ Access all apps (no need to re-enter passwords)
    

โœ… Summary: SSO means one login for many apps.


5. Multi-Factor Authentication (MFA) โ€“ Extra security

Definition: MFA requires two or more verification methods to log in. For example, a password + a code sent to your phone.

Why important: It makes it much harder for hackers to break in.

Simple: Like a bank vault that needs a key and a combination.

Real-life: Your online banking uses MFA.

School: Teachers use MFA to access student records.

Home: You can enable MFA on your Microsoft account.

Nigerian: Many Nigerian banks use MFA for online banking.

    Step 1: Enter password
    Step 2: Enter code from phone
    โœ… Access granted!
    

โœ… Summary: MFA adds an extra layer of security to your login.


6. Role-Based Access Control (RBAC) โ€“ Who can do what?

Definition: RBAC assigns permissions to users, groups, or applications based on their roles.

Why important: You give people only the permissions they need.

Simple: Like a school where teachers can grade, but students can only view.

Real-life: An admin can create VMs, a reader can only view them.

School: The principal can change settings, but the librarian can only view.

Home: Parents have full control, children have limited access.

Nigerian: A company gives developers "contributor" rights but not "owner".

RolePermissions
OwnerCan do everything
ContributorCan create/manage resources but not give access
ReaderCan only view resources

โœ… Summary: RBAC gives permissions based on roles.


7. Azure Security Center โ€“ Your security guard

Definition: Azure Security Center is a tool that helps you monitor and improve your security posture.

Why important: It alerts you to threats and gives recommendations.

Simple: Like a security guard who watches cameras and tells you if something is wrong.

Real-life: A company uses Security Center to monitor its VMs for threats.

School: The school uses it to protect student data.

Home: Not used at home.

Nigerian: A hospital uses Security Center to protect patient records.

    Security Center
    โ”œโ”€โ”€ Monitors for threats
    โ”œโ”€โ”€ Gives security recommendations
    โ””โ”€โ”€ Shows Secure Score (how secure you are)
    

โœ… Summary: Security Center monitors your Azure resources for security issues.


8. Azure Defender โ€“ Advanced threat protection

Definition: Azure Defender is a service that provides advanced threat protection for your resources, like VMs, databases, and storage.

Why important: It detects sophisticated attacks that basic tools might miss.

Simple: Like a detective who investigates suspicious activities.

Real-life: A bank uses Azure Defender to detect unusual transactions.

School: Not used in schools.

Home: Not used at home.

Nigerian: A fintech uses Azure Defender to protect against fraud.

    Azure Defender = Advanced security for VMs, databases, storage, etc.
    

โœ… Summary: Azure Defender provides advanced threat protection.


9. Azure Key Vault โ€“ Keep secrets safe

Definition: Key Vault is a service that securely stores secrets, keys, and certificates.

Why important: You don't want to hard-code passwords in your code.

Simple: Like a safe where you keep your most valuable items.

Real-life: A company stores database passwords in Key Vault.

School: The school stores API keys in Key Vault.

Home: Not used at home.

Nigerian: A startup stores payment gateway keys in Key Vault.

    Key Vault = Secure storage for:
    โ”œโ”€โ”€ Secrets (passwords, keys)
    โ”œโ”€โ”€ Keys (encryption keys)
    โ””โ”€โ”€ Certificates (SSL/TLS)
    

โœ… Summary: Key Vault securely stores your secrets.


10. Managed Identities โ€“ Automatic identity for Azure services

Definition: A managed identity is an identity that Azure creates for a service (like a VM or Function) so it can authenticate to other Azure services.

Why important: You don't need to store credentials โ€“ Azure handles it.

Simple: Like a security badge that is automatically given to a robot.

Real-life: A VM uses a managed identity to access Key Vault.

School: Not used in schools.

Home: Not used at home.

Nigerian: A function app uses a managed identity to access storage.

    Managed Identity = Automatic identity for Azure services
    No need to store passwords!
    

โœ… Summary: Managed identities let Azure services authenticate automatically.


11. Azure Policy โ€“ Enforce rules

Definition: Azure Policy is a service that lets you create rules to enforce standards across your resources.

Why important: It prevents people from making mistakes, like creating VMs in the wrong region.

Simple: Like school rules โ€“ you can't run in the hallway.

Real-life: A company uses a policy to only allow VMs in a specific region.

School: A policy ensures all school resources use the same naming convention.

Home: Not used at home.

Nigerian: A bank uses policies to ensure all VMs are in South Africa.

    Policy: Allowed locations = South Africa, Europe
    If VM created in US โ†’ Policy denies it
    

โœ… Summary: Azure Policy enforces rules to keep things consistent.


12. Azure Blueprints โ€“ Create compliant environments

Definition: Azure Blueprints is a service that lets you define a set of resources, policies, and roles to create a repeatable environment.

Why important: You can deploy a whole set of resources with one click.

Simple: Like a recipe โ€“ follow it to bake the same cake every time.

Real-life: A company uses Blueprints to create new development environments.

School: The school uses Blueprints to set up new labs.

Home: Not used at home.

Nigerian: A startup uses Blueprints to deploy its app to multiple regions.

    Blueprint = Pre-packaged environment (resources + policies + roles)
    

โœ… Summary: Blueprints help you deploy compliant environments quickly.


13. Resource Locks โ€“ Prevent deletion

Definition: A lock prevents a resource from being deleted or changed accidentally.

Why important: You don't want someone to delete your important VM.

Simple: Like putting a child-proof lock on a cabinet.

Real-life: A company locks its production database so no one can delete it.

School: The school locks the server that stores exam results.

Home: You lock your diary so no one reads it.

Nigerian: A hospital locks patient records to prevent accidental deletion.

    Lock Types:
    - CanNotDelete (prevents deletion)
    - ReadOnly (prevents changes)
    

โœ… Summary: Resource locks protect important resources from being deleted or changed.


14. Tags โ€“ Labels for organisation

Definition: Tags are key-value pairs (like "Project: Website" or "CostCenter: Marketing") that you add to resources.

Why important: They help you organise, track costs, and manage resources.

Simple: Like putting sticky notes on your belongings to know what they are for.

Real-life: A company tags resources by project, department, and environment (Dev/Prod).

School: Tags can show which class uses which resource.

Home: You might tag photos with names and dates.

Nigerian: A startup tags resources by region (Lagos, Abuja).

    Tag: Environment = Production
    Tag: Department = Finance
    Tag: Project = PayrollApp
    

โœ… Summary: Tags are labels that help you organise and track resources.


15. Defense in Depth โ€“ Multi-layered security

Definition: Defense in depth is a strategy that uses multiple layers of security to protect your resources. If one layer fails, another layer stops the attack.

Why important: It's like having multiple doors โ€“ if a thief breaks one, there is still another locked door.

Simple: Like a castle with walls, a moat, and guards.

Real-life: A company uses network firewalls, MFA, and encryption.

School: The school has locks on doors, security cameras, and passwords.

Home: Your home has a gate, a door lock, and an alarm.

Nigerian: A bank uses firewalls, encryption, and MFA.

    Defense in Depth:
    Layer 1: Network (firewall, NSG)
    Layer 2: Identity (MFA, RBAC)
    Layer 3: Data (encryption)
    Layer 4: Applications (secure code)
    

โœ… Summary: Defense in depth uses multiple security layers.


๐Ÿ“š Key Vocabulary

  • Entra ID: Identity service in Azure.
  • Tenant: Your organisation's private Entra ID instance.
  • User: An individual person.
  • Group: A collection of users.
  • SSO: Single Sign-On.
  • MFA: Multi-Factor Authentication.
  • RBAC: Role-Based Access Control.
  • Security Center: Monitors security.
  • Azure Defender: Advanced threat protection.
  • Key Vault: Secure storage for secrets.
  • Managed Identity: Automatic identity for Azure services.
  • Azure Policy: Enforces rules.
  • Blueprint: Pre-packaged environment.
  • Resource Lock: Prevents deletion.
  • Tag: Label for organisation.
  • Defense in Depth: Multi-layered security.

๐Ÿง  Important Concepts

  • Identity is the first line of defence: Entra ID, SSO, and MFA protect who can access your resources.
  • Access control: RBAC gives the least privilege needed.
  • Monitoring: Security Center and Defender alert you to threats.
  • Governance: Policy and Blueprints enforce rules.
  • Protection: Key Vault, locks, and tags keep data safe and organised.

๐Ÿ”ข Step-by-step: Enable MFA for a user

  1. Go to Entra ID in the Azure Portal.
  2. Select "Users" and choose a user.
  3. Go to "Authentication methods".
  4. Click "Add authentication method".
  5. Choose "Microsoft Authenticator" or "Phone".
  6. Follow the steps to set up MFA.
  7. The user will now need a second factor to log in.

๐ŸŒ Real-life Examples

  • Microsoft: Uses Entra ID for all employee logins.
  • Adobe: Uses Key Vault for storing API keys.
  • E-Trade: Uses MFA for customer accounts.
  • BP: Uses Azure Policy to enforce security standards.
  • Nike: Uses RBAC to manage access to product data.

๐Ÿ‡ณ๐Ÿ‡ฌ Nigerian Examples

  • Flutterwave: Uses Entra ID for employee access.
  • Paystack: Uses Key Vault for payment keys.
  • Kuda Bank: Uses MFA for customer logins.
  • Chipper Cash: Uses Azure Policy for compliance.
  • Farmcrowdy: Uses RBAC to manage farmer data.

๐ŸŽˆ Fun Examples for Kids

  • Roblox: Uses MFA to protect player accounts.
  • Minecraft: Uses login systems (like Entra ID).
  • Zoom: Uses SSO for schools.
  • Google Classroom: Uses MFA for teachers.
  • Fortnite: Uses security measures to prevent hacking.

๐Ÿ  Everyday Examples

  • Email: Gmail uses MFA and SSO.
  • Banking: Online banking uses MFA.
  • School portal: Uses a login system (Entra ID).
  • Family sharing: Tags help organise photos.
  • Smart home: Uses passwords and locks.

๐Ÿ‘ฉโ€๐Ÿซ Teacher Notes

  • Emphasise that security is everyone's responsibility.
  • Use the castle analogy to explain defense in depth.
  • Relate to Nigerian context: use local examples like banks and fintech.
  • Encourage students to enable MFA on their personal accounts.
  • Discuss real-world security breaches to show why these tools matter.

๐Ÿง‘โ€๐Ÿคโ€๐Ÿง‘ Parent Tips

  • Discuss with your child why passwords and MFA are important.
  • Explain that Azure Key Vault is like a digital safe.
  • Talk about online safety and how companies protect data.
  • Encourage them to think about security in their daily digital life.
  • Ask: "What would you do to keep your online accounts safe?"

๐Ÿ’ก Interesting Facts

  • Microsoft Entra ID has over 500 million active users.
  • MFA can block over 99.9% of account attacks.
  • Azure Security Center scans millions of resources daily.
  • Key Vault can be used to store secrets for thousands of apps.
  • Azure Policy can be applied to entire subscriptions.

๐Ÿค” Did You Know?

  • You can use your own custom roles in RBAC.
  • Azure Defender can detect ransomware attacks.
  • Blueprints can include policy definitions and role assignments.
  • Managed identities are free!
  • Tags can be used to track costs down to the cent.

๐Ÿงพ Remember This

  • Entra ID manages identities.
  • SSO and MFA make logins secure and easy.
  • RBAC gives the right permissions.
  • Security Center and Defender monitor threats.
  • Key Vault stores secrets securely.
  • Policies and Blueprints enforce rules.
  • Locks protect resources.
  • Tags organise resources.
  • Defense in depth uses multiple layers.

โš ๏ธ Common Mistakes

  • Mistake: Using default passwords for Entra ID accounts.
    Fix: Enforce strong passwords and MFA.
  • Mistake: Giving too many permissions (e.g., Owner).
    Fix: Use the least privilege โ€“ give only what is needed.
  • Mistake: Not enabling MFA.
    Fix: Enable MFA for all users.
  • Mistake: Hard-coding secrets in code.
    Fix: Use Key Vault.
  • Mistake: Not applying locks to critical resources.
    Fix: Apply locks to prevent accidental deletion.

๐ŸŒŸ Best Practices

  • Enable MFA for all users.
  • Use RBAC to give the least privilege.
  • Store all secrets in Key Vault.
  • Use managed identities instead of hard-coded credentials.
  • Apply Azure Policy to enforce standards.
  • Use locks on critical resources.
  • Tag resources for organisation and cost tracking.
  • Monitor security with Security Center.
  • Apply defense in depth.

๐Ÿ“Š ASCII Illustrations

Defense in Depth

    Layer 1: Network (firewalls, NSGs)
    Layer 2: Identity (MFA, RBAC)
    Layer 3: Data (encryption)
    Layer 4: Applications (secure code)
    

RBAC roles

    Owner     โ†’  Full control
    Contributor โ†’  Can create/update resources
    Reader    โ†’  Can only view
    

MFA flow

    Enter password โ†’ Enter code from phone โ†’ Access granted โœ…
    

๐Ÿ“‹ Comparison tables

Security services comparison

ServicePurpose
Security CenterMonitoring and recommendations
Azure DefenderAdvanced threat protection
Key VaultStore secrets
PolicyEnforce rules
BlueprintsDeploy compliant environments

RBAC roles comparison

RoleCan create resources?Can assign roles?
OwnerYesYes
ContributorYesNo
ReaderNoNo

๐Ÿ“Œ End-of-module Summary

In this module, we learned about identity, security, and compliance in Azure. We covered:

  • Identity: Entra ID, tenants, users, groups, SSO, and MFA.
  • Access Control: RBAC roles (Owner, Contributor, Reader).
  • Security: Security Center, Azure Defender, and Key Vault.
  • Governance: Azure Policy, Blueprints, resource locks, and tags.
  • Defense in Depth: Multi-layered security.
  • Nigerian examples: How local companies use these services.

You now have a strong understanding of how to secure and govern your Azure resources. In the next module, we will learn about Cost Management and Optimization.

โ“ Frequently Asked Questions

  1. What is Entra ID? โ€“ Azure's identity service.
  2. What is SSO? โ€“ One login for many apps.
  3. What is MFA? โ€“ Extra security layer.
  4. What is RBAC? โ€“ Role-Based Access Control.
  5. What does Security Center do? โ€“ Monitors security and gives recommendations.
  6. What is Azure Defender? โ€“ Advanced threat protection.
  7. What is Key Vault? โ€“ Secure storage for secrets.
  8. What is Azure Policy? โ€“ Enforces rules.
  9. What is a Blueprint? โ€“ Pre-packaged environment.
  10. What is a resource lock? โ€“ Prevents deletion.

๐Ÿ“ Review Questions

  1. What is Microsoft Entra ID?
  2. What is a tenant?
  3. What is the difference between a user and a group?
  4. What does SSO stand for?
  5. Why is MFA important?
  6. What are the three built-in RBAC roles?
  7. What is Azure Security Center?
  8. What is Azure Defender?
  9. What is Key Vault used for?
  10. What is a managed identity?
  11. What does Azure Policy do?
  12. What is a Blueprint?
  13. What is a resource lock?
  14. What are tags used for?
  15. What is defense in depth?

โœ๏ธ Fill-in-the-Blank

  1. ___________ is the identity service in Azure. (Entra ID)
  2. A ___________ is your organisation's private space in Entra ID. (tenant)
  3. ___________ lets you log in once to many apps. (SSO)
  4. ___________ adds an extra security layer to logins. (MFA)
  5. ___________ gives permissions based on roles. (RBAC)
  6. ___________ is a tool that monitors security. (Security Center)
  7. ___________ stores secrets like passwords and keys. (Key Vault)
  8. ___________ enforces rules on your resources. (Azure Policy)
  9. A ___________ is a pre-packaged environment. (Blueprint)
  10. A ___________ prevents deletion of a resource. (lock)

โœ… True or False

  1. MFA is optional and not recommended. (False)
  2. RBAC gives permissions based on roles. (True)
  3. Key Vault is used to store virtual machines. (False)
  4. Azure Policy can enforce rules. (True)
  5. A resource lock prevents deletion. (True)
  6. Security Center is a threat protection service. (False โ€“ it monitors and recommends)
  7. Azure Defender provides advanced threat protection. (True)
  8. Tags are used to organise resources. (True)
  9. A Blueprint is a type of virtual machine. (False)
  10. Defense in depth uses a single layer of security. (False)

๐Ÿงช Multiple Choice Questions

  1. Which service manages identities in Azure?
    a) Key Vault b) Entra ID c) Security Center d) Policy
    Answer: b
  2. What does SSO allow?
    a) Multiple passwords b) One login for many apps c) Extra security d) Role assignment
    Answer: b
  3. Which adds an extra security layer to logins?
    a) SSO b) MFA c) RBAC d) Policy
    Answer: b
  4. What are the three built-in RBAC roles?
    a) Admin, User, Guest b) Owner, Contributor, Reader c) Creator, Editor, Viewer d) Manager, Developer, Tester
    Answer: b
  5. Which service monitors security and gives recommendations?
    a) Security Center b) Defender c) Key Vault d) Policy
    Answer: a
  6. Which service provides advanced threat protection?
    a) Security Center b) Azure Defender c) Key Vault d) Policy
    Answer: b
  7. What does Key Vault store?
    a) VMs b) Secrets c) Networks d) Storage accounts
    Answer: b
  8. What is a managed identity?
    a) A user b) An automatic identity for Azure services c) A group d) A role
    Answer: b
  9. Which service enforces rules?
    a) Entra ID b) Policy c) Security Center d) Key Vault
    Answer: b
  10. What is a Blueprint?
    a) A VM b) A pre-packaged environment c) A storage account d) A network
    Answer: b
  11. What does a resource lock do?
    a) Prevents deletion b) Enforces a rule c) Monitors performance d) Tags resources
    Answer: a
  12. What are tags used for?
    a) Security b) Organisation c) Performance d) Storage
    Answer: b
  13. What is defense in depth?
    a) A single security layer b) Multi-layered security c) A type of VM d) A storage service
    Answer: b
  14. Which Nigerian company uses Entra ID?
    a) Dangote b) Flutterwave c) NNPC d) Airtel
    Answer: b
  15. What is the purpose of MFA?
    a) To make logins faster b) To add extra security c) To assign roles d) To enforce policies
    Answer: b

๐Ÿ”— Matching Exercises

Match the service with its purpose.

ServicePurpose
Entra IDManage identities
MFAExtra security
RBACAssign permissions
Key VaultStore secrets
Azure PolicyEnforce rules
Resource LockPrevent deletion
TagsOrganise resources

โœ๏ธ Short Answer Questions

  1. Explain the difference between SSO and MFA.
  2. What are the three built-in RBAC roles?
  3. How does Azure Policy help with governance?
  4. What is defense in depth?
  5. Why is Key Vault important for security?

๐Ÿงฉ Scenario-based Exercises

Scenario 1: A Nigerian bank wants to ensure that only IT staff can create VMs. Which Azure service should they use?

Scenario 2: A company wants to store database passwords securely. Which service should they use?

Scenario 3: A hospital wants to monitor its resources for threats. Which service should they use?

๐Ÿ‘ฅ Group Activity

In groups, design a security plan for a Nigerian e-commerce company. Include:

  • Identity management (Entra ID, SSO, MFA).
  • Access control (RBAC).
  • Security monitoring (Security Center, Defender).
  • Governance (Policy, locks, tags).

๐Ÿง‘ Individual Activity

Create a list of tags you would use for a cloud project. Include tags for project, department, environment, and cost centre.

๐Ÿ’ฌ Classroom Discussion Questions

  1. Why is MFA important for online accounts?
  2. How would you explain RBAC to a friend?
  3. What would happen if a company didn't use Azure Policy?
  4. How can Nigerian businesses improve their security with Azure?
  5. Why is defense in depth better than a single security layer?

๐Ÿ› ๏ธ Mini Project

Security Plan: Create a security plan for a fictional Nigerian company. Include identity management, access control, monitoring, governance, and defense in depth. Present your plan to the class.

๐Ÿ’ป Practical Assignment

If you have an Azure account, try the following:

  1. Enable MFA on your account.
  2. Create a user and assign a role.
  3. Create a Key Vault and store a secret.
  4. Apply a resource lock to a resource.

๐Ÿ† Challenge Exercise

Research how to create an Azure Policy that only allows VMs in a specific region. Write a simple guide on how to set it up.

๐Ÿ”‘ Quiz Answers (Multiple Choice)

  1. b
  2. b
  3. b
  4. b
  5. a
  6. b
  7. b
  8. b
  9. b
  10. b
  11. a
  12. b
  13. b
  14. b
  15. b

๐ŸŽ Key Takeaways

  • Entra ID is the identity service.
  • SSO and MFA make logins secure and easy.
  • RBAC gives the right permissions.
  • Security Center and Defender monitor threats.
  • Key Vault stores secrets securely.
  • Policies and Blueprints enforce rules.
  • Locks protect resources.
  • Tags organise resources.
  • Defense in depth uses multiple layers.

๐Ÿš€ Preparation for Module 3

In the next module, we will learn about Cost Management and Optimization. We'll cover:

  • Pricing and TCO calculators.
  • Cost Management + Billing.
  • Budget alerts and cost analysis.
  • Reserved instances and savings plans.
  • Right-sizing and idle resource management.

Review your knowledge of subscriptions and resource groups โ€“ they will be important in Module 3.


๐ŸŽ‰ Congratulations! You have completed Module 2 (Intermediate). Keep going! ๐Ÿš€

4

Module Three

Module 3 ยท Cost Management & Optimization (Intermediate) ยท AZ-900

๐Ÿ’ฐ Module 3: Cost Management & Optimization (Intermediate)

Welcome to the money-saving module! ๐Ÿ’ต In the cloud, you pay for what you use โ€“ but if you are not careful, your bill can be huge! In this module, we will learn how to plan, track, and reduce your Azure costs. Think of it like managing your pocket money โ€“ you need to know how much you have, where it goes, and how to save.

๐ŸŽฏ Learning Objectives

  • Estimate costs using the Pricing Calculator and TCO Calculator.
  • Track spending with Azure Cost Management + Billing.
  • Set budgets and alerts to avoid surprises.
  • Save money with Reserved Instances and Savings Plans.
  • Optimize costs by right-sizing resources and managing idle resources.
  • Use Azure Advisor for cost recommendations.

๐Ÿ“– Warm-up Story: The Lemonade Stand

Imagine you have a lemonade stand ๐Ÿ‹. You need to buy lemons, sugar, and cups. You also need to pay for water and ice.

If you buy too many lemons, they go bad and you waste money. If you buy too few, you run out and lose customers.

You need to plan how much to buy, track what you spend, and optimize to make a profit.

In Azure, it's the same! You plan, track, and optimize your cloud spending to stay within budget.

๐Ÿ“˜ Main Lessons

1. Azure Pricing Model โ€“ How does Azure charge?

Definition: Azure uses a pay-as-you-go model โ€“ you pay only for what you use, and you can stop anytime.

Why important: You don't need to buy expensive hardware upfront.

Simple: Like paying for water โ€“ you pay for what comes out of the tap.

Real-life: A company pays for VMs only when they are running.

School: The school pays for storage only for the term.

Home: You pay for extra iCloud storage only if you need it.

Nigerian: A small business uses cloud services and pays only for what they use each month.

    Pay-as-you-go = pay per unit (like โ‚ฆ per GB or per hour)
    

โœ… Summary: You pay only for what you consume, like a utility bill.


2. Pricing Calculator โ€“ Estimate before you spend

Definition: The Pricing Calculator is a free tool on the Azure website that helps you estimate how much a service will cost.

Why important: You can plan before you spend.

Simple: Like using a calculator to add up your shopping list.

Real-life: A company calculates the cost of running a VM for a year.

School: The IT teacher estimates the cost of hosting the school website.

Home: You can use it to see how much it would cost to store your family photos.

Nigerian: A fintech startup uses the calculator before launching a new service.

    Pricing Calculator
    โ”œโ”€โ”€ Choose service (e.g., VM)
    โ”œโ”€โ”€ Set options (size, region, hours)
    โ””โ”€โ”€ Get estimated cost
    

โœ… Summary: The Pricing Calculator helps you estimate your Azure costs.


3. TCO Calculator โ€“ Compare on-premises vs. cloud

Definition: The TCO (Total Cost of Ownership) calculator compares the cost of running your own servers (on-premises) versus using the cloud.

Why important: It helps you decide if moving to the cloud saves money.

Simple: Like comparing the cost of buying a car vs. renting one.

Real-life: A company uses TCO to decide whether to move to Azure.

School: A school compares the cost of a physical server room vs. cloud.

Home: Not usually used by individuals.

Nigerian: A bank uses the TCO calculator to justify moving to the cloud.

AspectOn-premisesCloud (Azure)
Hardware costHigh upfrontPay as you go
MaintenanceYou manageMicrosoft manages
ElectricityYou payIncluded
ScalabilityHardEasy

โœ… Summary: TCO calculator shows the total cost of on-premises vs. cloud.


4. Cost Management + Billing โ€“ Track your spending

Definition: A tool in the Azure portal that shows you exactly how much you're spending and on what.

Why important: You need to see where your money is going.

Simple: Like a bank statement for your cloud usage.

Real-life: A manager checks Cost Management to see if a project is over budget.

School: The school's finance officer tracks cloud spending monthly.

Home: You can see how much your free trial is using.

Nigerian: A company in Abuja reviews Cost Management every week.

    Cost Management
    โ”œโ”€โ”€ View spending by resource
    โ”œโ”€โ”€ Set budgets & alerts
    โ””โ”€โ”€ Recommendations to save money
    

โœ… Summary: Cost Management + Billing helps you track and control spending.


5. Budgets โ€“ Set spending limits

Definition: A budget is a spending limit you set for a subscription or resource group. You get alerts when you reach a certain percentage.

Why important: It prevents surprise bills.

Simple: Like a weekly allowance โ€“ you can't spend more than you have.

Real-life: A company sets a monthly budget of $10,000 for Azure.

School: The school sets a budget for cloud storage.

Home: You set a budget for your mobile data.

Nigerian: A startup sets a budget of โ‚ฆ500,000 per month.

    Budget: โ‚ฆ500,000/month
    Alert at 80% (โ‚ฆ400,000) โ†’ Get email notification
    

โœ… Summary: Budgets help you limit spending and avoid surprises.


6. Cost Analysis โ€“ Understand your spending

Definition: Cost Analysis is a tool that lets you see your spending over time, by resource, by service, or by tag.

Why important: You can find out which services cost the most.

Simple: Like looking at a pie chart of your spending.

Real-life: A company sees that 60% of their cost is from VMs.

School: The school sees that storage costs the most.

Home: You see which apps use the most data.

Nigerian: A fintech sees that database costs are high.

    Cost Analysis = Detailed view of your spending
    โ”œโ”€โ”€ By service (VMs, storage, etc.)
    โ”œโ”€โ”€ By resource (VM1, VM2, etc.)
    โ””โ”€โ”€ By tag (Project, department)
    

โœ… Summary: Cost Analysis helps you understand where your money goes.


7. Azure Advisor โ€“ Your cost-saving advisor

Definition: Azure Advisor is a free service that gives you personalized recommendations to save money, improve performance, and increase security.

Why important: It tells you exactly what to do to save money.

Simple: Like a friend who gives you tips on saving money.

Real-life: Azure Advisor recommends shutting down idle VMs.

School: The school gets recommendations to resize VMs.

Home: Not used at home.

Nigerian: A startup gets recommendations to use reserved instances.

    Azure Advisor
    โ”œโ”€โ”€ Cost recommendations (save money)
    โ”œโ”€โ”€ Performance recommendations (make things faster)
    โ””โ”€โ”€ Security recommendations (make things safer)
    

โœ… Summary: Azure Advisor gives you free recommendations to save money.


8. Reserved Instances โ€“ Prepay to save

Definition: Reserved Instances let you pay for a VM or other service for 1 or 3 years in advance, at a discount of up to 72%.

Why important: It saves a lot of money for long-term workloads.

Simple: Like buying a yearly movie pass instead of paying per movie.

Real-life: A company reserves a VM for 3 years and saves 50%.

School: The school reserves a database server for 1 year.

Home: Not used at home.

Nigerian: A bank reserves VMs for 3 years to save costs.

Payment optionDiscountBest for
Pay-as-you-go0%Short-term, variable workloads
1-year ReservedUp to 40%Predictable workloads
3-year ReservedUp to 72%Long-term, stable workloads

โœ… Summary: Reserved Instances save money for long-term use.


9. Savings Plans โ€“ Flexible savings

Definition: Savings Plans are similar to Reserved Instances but more flexible โ€“ you commit to a certain amount of spend per hour, and you get a discount on many services.

Why important: It offers flexibility โ€“ you can change services and still get a discount.

Simple: Like a monthly subscription that gives you a discount on everything you buy.

Real-life: A company commits to spending $50/hour and gets a discount on VMs and databases.

School: Not used in schools.

Home: Not used at home.

Nigerian: A startup uses Savings Plans to save on multiple services.

    Savings Plans = Commit to a hourly spend, get discounts
    โ”œโ”€โ”€ Compute Savings Plan (VMs, App Service, etc.)
    โ””โ”€โ”€ EC2 Instance Savings Plan (similar)
    

โœ… Summary: Savings Plans offer flexible discounts for committing to a spend.


10. Azure Hybrid Benefit โ€“ Use your existing licenses

Definition: Azure Hybrid Benefit lets you use your on-premises Windows Server and SQL Server licenses in Azure, saving up to 40%.

Why important: You already paid for the licenses, so you save money.

Simple: Like using a gift card you already have.

Real-life: A company with on-premises Windows licenses uses them in Azure.

School: Not used in schools.

Home: Not used at home.

Nigerian: A bank with existing SQL Server licenses saves 40% in Azure.

    Azure Hybrid Benefit = Use your existing licenses in Azure
    Saves up to 40% on Windows VMs and SQL Server
    

โœ… Summary: Azure Hybrid Benefit saves money by using your existing licenses.


11. Right-sizing โ€“ Don't overpay for resources

Definition: Right-sizing means choosing the right size for your VMs and other resources โ€“ not too big, not too small.

Why important: A VM that is too big wastes money. A VM that is too small is slow.

Simple: Like buying shoes โ€“ you need the right size!

Real-life: A company monitors VM usage and resizes VMs to save money.

School: The school resizes a VM from Standard D4s to D2s.

Home: Not used at home.

Nigerian: A startup uses Azure Advisor to right-size VMs.

    Monitor CPU usage โ†’ If usage is low (below 30%) โ†’ Downsize VM
    If usage is high (above 80%) โ†’ Upsize VM
    

โœ… Summary: Right-sizing helps you avoid paying for resources you don't need.


12. Managing idle resources โ€“ Stop what you don't use

Definition: Idle resources are resources that are running but not being used. For example, a VM that runs 24/7 but is only used during business hours.

Why important: You pay for idle resources, so you can save money by stopping them.

Simple: Like turning off the lights when you leave a room.

Real-life: A company automatically stops VMs at night and on weekends.

School: The school stops VMs during holidays.

Home: You turn off your computer when not in use.

Nigerian: A startup uses Azure Automation to stop VMs after business hours.

    Schedule: Stop VM at 6 PM, start at 8 AM
    Save 60% of VM cost!
    

โœ… Summary: Stop idle resources to save money.


13. Storage optimization โ€“ Choose the right tier

Definition: Storage tiers (Hot, Cool, Archive) let you pay less for data you don't access often.

Why important: It saves money on storage.

Simple: Like moving winter clothes to the attic โ€“ they are harder to reach but save space.

Real-life: A company moves old project files to Archive after 2 years.

School: Old student records are archived.

Home: Old photos are moved to Archive.

Nigerian: A bank archives old transaction records.

TierAccess frequencyCost
HotFrequentHigh
CoolInfrequentMedium
ArchiveRareLow

โœ… Summary: Use storage tiers to save money on old data.


14. Tags for cost allocation โ€“ Know who pays

Definition: Tags are labels you add to resources to track costs by project, department, or environment.

Why important: You can see which department or project is spending the most.

Simple: Like putting a name tag on your lunch box.

Real-life: A company tags resources by department (Marketing, IT, Finance).

School: The school tags resources by class.

Home: You tag photos with names and dates.

Nigerian: A startup tags resources by region (Lagos, Abuja).

    Tag: Department = Finance
    Tag: Project = PayrollApp
    Tag: Environment = Production
    

โœ… Summary: Tags help you track costs by project or department.


15. Azure Cost Management best practices

Definition: Best practices are the recommended ways to manage costs effectively.

Why important: They help you save money and avoid surprises.

Simple: Like a checklist for saving money.

Real-life: A company uses all these practices to keep costs low.

School: The school follows these practices.

Home: You follow similar practices for your personal budget.

Nigerian: A startup uses these practices to stay within budget.

    Best Practices:
    1. Use Pricing Calculator
    2. Set budgets and alerts
    3. Use Reserved Instances
    4. Right-size resources
    5. Stop idle VMs
    6. Use storage tiers
    7. Tag resources
    8. Use Azure Advisor
    

โœ… Summary: Following best practices helps you save money in Azure.


๐Ÿ“š Key Vocabulary

  • Pay-as-you-go: Pay only for what you use.
  • Pricing Calculator: Tool to estimate costs.
  • TCO Calculator: Compares on-premises vs. cloud costs.
  • Cost Management: Tool to track spending.
  • Budget: A spending limit.
  • Cost Analysis: Detailed view of spending.
  • Azure Advisor: Gives cost-saving recommendations.
  • Reserved Instance: Prepay for 1 or 3 years to save.
  • Savings Plan: Flexible discount commitment.
  • Azure Hybrid Benefit: Use existing licenses in Azure.
  • Right-sizing: Choosing the right resource size.
  • Idle resources: Resources not being used.
  • Storage tier: Pricing based on access frequency.
  • Tag: Label for organisation.

๐Ÿง  Important Concepts

  • Plan before you spend: Use calculators.
  • Track what you spend: Use Cost Management.
  • Set limits: Use budgets and alerts.
  • Save with commitment: Use Reserved Instances and Savings Plans.
  • Optimize constantly: Right-size, stop idle resources, use tiers.
  • Organise: Use tags for cost allocation.

๐Ÿ”ข Step-by-step: Set up a budget alert

  1. Go to Azure Portal.
  2. Navigate to "Cost Management + Billing".
  3. Select "Budgets".
  4. Click "Add budget".
  5. Set a name and an amount (e.g., โ‚ฆ100,000 per month).
  6. Set an alert threshold (e.g., 80% of budget).
  7. Add an email to receive alerts.
  8. Create the budget โ€“ now you'll get an email if spending goes too high.

๐ŸŒ Real-life Examples

  • Netflix: Uses Reserved Instances to save on VMs.
  • Spotify: Uses Savings Plans for flexibility.
  • Adobe: Uses Azure Advisor for cost recommendations.
  • E-Trade: Uses storage tiers for old transaction logs.
  • Nike: Uses tags to track costs by region.

๐Ÿ‡ณ๐Ÿ‡ฌ Nigerian Examples

  • Flutterwave: Uses Reserved Instances to save on VMs.
  • Paystack: Uses Cost Management to track spending.
  • Kuda Bank: Uses Azure Advisor for cost optimization.
  • Chipper Cash: Uses storage tiers for transaction logs.
  • Farmcrowdy: Uses tags to track costs by project.

๐ŸŽˆ Fun Examples for Kids

  • Pocket money: You have a budget โ€“ you can't spend more.
  • Movie pass: Buying a yearly pass is like Reserved Instances.
  • Turning off lights: Stopping idle VMs is like turning off lights.
  • Storage boxes: Using storage tiers is like putting old toys in the attic.
  • Name tags: Tags are like name tags on your lunch box.

๐Ÿ  Everyday Examples

  • Budgeting: Your family has a monthly budget for food.
  • Phone plan: You pay for data as you use it (pay-as-you-go).
  • Subscription: Netflix subscription is like a Savings Plan.
  • Storage: You move old photos to an external hard drive.
  • Tags: You have labels on your school folders.

๐Ÿ‘ฉโ€๐Ÿซ Teacher Notes

  • Emphasise that cost management is as important as building solutions.
  • Use the lemonade stand analogy to explain planning, tracking, and optimizing.
  • Relate to Nigerian context: use local examples like Flutterwave, Paystack.
  • Encourage students to use the Pricing Calculator and Cost Management.
  • Discuss real-world cost management stories.

๐Ÿง‘โ€๐Ÿคโ€๐Ÿง‘ Parent Tips

  • Discuss with your child how you manage money at home.
  • Explain that Azure has tools to help you stay on budget.
  • Talk about the importance of saving money.
  • Ask: "How would you save money on your cloud project?"
  • Encourage them to explore Azure's free tools with you.

๐Ÿ’ก Interesting Facts

  • Azure customers save up to 72% with Reserved Instances.
  • Azure Advisor has saved customers billions of dollars.
  • Some companies save 60% by stopping idle VMs.
  • Storage tiering can save up to 80% on old data.
  • Azure Cost Management is used by over 90% of Azure customers.

๐Ÿค” Did You Know?

  • You can set Azure to automatically shut down VMs at night.
  • Azure Policy can block the creation of expensive resources.
  • You can get cost recommendations on your phone.
  • Savings Plans cover many services, not just VMs.
  • Azure Hybrid Benefit can save you up to 40% on Windows VMs.

๐Ÿงพ Remember This

  • Plan with Pricing and TCO calculators.
  • Track spending with Cost Management.
  • Set budgets and alerts.
  • Use Reserved Instances and Savings Plans for long-term savings.
  • Right-size resources and stop idle VMs.
  • Use storage tiers for old data.
  • Use tags for cost allocation.
  • Follow Azure Advisor recommendations.

โš ๏ธ Common Mistakes

  • Mistake: Not setting a budget and getting a surprise bill.
    Fix: Always set a budget and alert.
  • Mistake: Using a VM that is too large.
    Fix: Monitor usage and right-size.
  • Mistake: Leaving VMs running 24/7.
    Fix: Stop VMs when not in use.
  • Mistake: Storing all data in Hot tier.
    Fix: Use Cool or Archive for old data.
  • Mistake: Not using tags.
    Fix: Tag resources for cost allocation.

๐ŸŒŸ Best Practices

  • Use the Pricing Calculator before deploying.
  • Set budgets and alerts for all subscriptions.
  • Use Reserved Instances for stable workloads.
  • Use Savings Plans for flexible savings.
  • Right-size resources regularly.
  • Stop idle VMs.
  • Use storage tiers for data lifecycle.
  • Tag resources for cost allocation.
  • Follow Azure Advisor recommendations.

๐Ÿ“Š ASCII Illustrations

Cost Management Process

    Plan โ†’ Use โ†’ Track โ†’ Adjust
    

Storage Tiers

    Hot   (frequent access)   โ†’  $$$
    Cool  (infrequent)        โ†’  $$
    Archive (rarely)          โ†’  $
    

Reserved Instances Savings

    Pay-as-you-go  โ†’  100% cost
    1-year RI      โ†’  60% cost (40% savings)
    3-year RI      โ†’  28% cost (72% savings)
    

๐Ÿ“‹ Comparison tables

Cost-saving options comparison

OptionCommitmentDiscountFlexibility
Pay-as-you-goNone0%High
Reserved Instance (1-year)1 yearUp to 40%Low
Reserved Instance (3-year)3 yearsUp to 72%Low
Savings Plan1 or 3 yearsUp to 65%Medium

Storage tiers comparison

TierAccess frequencyCostRetrieval time
HotFrequentHighMilliseconds
CoolInfrequentMediumMilliseconds
ArchiveRareLowHours

๐Ÿ“Œ End-of-module Summary

In this module, we learned how to manage and optimize costs in Azure. We covered:

  • Planning: Pricing Calculator and TCO Calculator.
  • Tracking: Cost Management + Billing, budgets, and cost analysis.
  • Saving: Reserved Instances, Savings Plans, and Azure Hybrid Benefit.
  • Optimizing: Right-sizing, stopping idle resources, storage tiers, and tags.
  • Recommendations: Azure Advisor.
  • Nigerian examples: How local companies save money.

You now have the tools to keep your Azure costs under control. In the next module, we will learn about Management, Monitoring, and Automation.

โ“ Frequently Asked Questions

  1. What is the Pricing Calculator? โ€“ A tool to estimate costs.
  2. What is the TCO Calculator? โ€“ Compares on-premises vs. cloud costs.
  3. How do I track spending? โ€“ Use Cost Management + Billing.
  4. What is a budget? โ€“ A spending limit with alerts.
  5. What is a Reserved Instance? โ€“ Prepay for 1 or 3 years to save.
  6. What is a Savings Plan? โ€“ Flexible discount commitment.
  7. What is Azure Hybrid Benefit? โ€“ Use existing licenses in Azure.
  8. What is right-sizing? โ€“ Choosing the right resource size.
  9. What are storage tiers? โ€“ Pricing based on access frequency.
  10. What is Azure Advisor? โ€“ Gives cost-saving recommendations.

๐Ÿ“ Review Questions

  1. What is the pay-as-you-go model?
  2. What does the Pricing Calculator do?
  3. What does the TCO Calculator compare?
  4. How do you track spending in Azure?
  5. What is a budget?
  6. What is Cost Analysis?
  7. What does Azure Advisor do?
  8. What is a Reserved Instance?
  9. What is a Savings Plan?
  10. What is Azure Hybrid Benefit?
  11. What is right-sizing?
  12. Why should you stop idle resources?
  13. What are storage tiers?
  14. How do tags help with cost allocation?
  15. Give a Nigerian example of cost optimization.

โœ๏ธ Fill-in-the-Blank

  1. ___________ is the tool to estimate costs. (Pricing Calculator)
  2. The ___________ calculator compares on-premises and cloud costs. (TCO)
  3. ___________ is a spending limit with alerts. (Budget)
  4. ___________ gives cost-saving recommendations. (Azure Advisor)
  5. ___________ let you prepay for 1 or 3 years to save. (Reserved Instances)
  6. ___________ offer flexible discount commitments. (Savings Plans)
  7. ___________ lets you use existing licenses in Azure. (Azure Hybrid Benefit)
  8. ___________ is choosing the right resource size. (Right-sizing)
  9. ___________ tiers help save money on old data. (Storage)
  10. ___________ are labels for cost allocation. (Tags)

โœ… True or False

  1. The Pricing Calculator is used to track spending. (False)
  2. Budgets help you avoid surprise bills. (True)
  3. Reserved Instances are only available for 1 year. (False โ€“ 1 or 3 years)
  4. Savings Plans are more flexible than Reserved Instances. (True)
  5. Azure Hybrid Benefit saves money on VMs. (True)
  6. Right-sizing means always choosing the largest VM. (False)
  7. Stopping idle VMs saves money. (True)
  8. Archive tier is more expensive than Hot tier. (False)
  9. Tags help with cost allocation. (True)
  10. Azure Advisor gives only security recommendations. (False)

๐Ÿงช Multiple Choice Questions

  1. Which tool estimates costs?
    a) Cost Management b) Pricing Calculator c) TCO Calculator d) Azure Advisor
    Answer: b
  2. What does TCO stand for?
    a) Total Cost Overview b) Total Cost of Ownership c) Total Cloud Optimisation d) True Cost Operations
    Answer: b
  3. Which tool tracks spending?
    a) Pricing Calculator b) TCO Calculator c) Cost Management d) Azure Advisor
    Answer: c
  4. What is a budget?
    a) A spending limit b) A VM c) A storage account d) A network
    Answer: a
  5. Which gives cost-saving recommendations?
    a) Cost Management b) Azure Advisor c) Pricing Calculator d) TCO Calculator
    Answer: b
  6. How long can you reserve an instance?
    a) 6 months b) 1 or 3 years c) 5 years d) 10 years
    Answer: b
  7. Which is more flexible than Reserved Instances?
    a) Pay-as-you-go b) Savings Plans c) TCO d) Tags
    Answer: b
  8. What does Azure Hybrid Benefit do?
    a) Saves money with existing licenses b) Reduces storage costs c) Monitors security d) Manages tags
    Answer: a
  9. What is right-sizing?
    a) Choosing the right resource size b) Stopping VMs c) Using storage tiers d) Setting budgets
    Answer: a
  10. Which tier is cheapest for old data?
    a) Hot b) Cool c) Archive d) Premium
    Answer: c
  11. What are tags used for?
    a) Cost allocation b) Security c) Performance d) Backup
    Answer: a
  12. What is an idle resource?
    a) A resource that is running but not used b) A stopped VM c) A resource in archive d) A tagged resource
    Answer: a
  13. Which Nigerian company uses Reserved Instances?
    a) Dangote b) Flutterwave c) NNPC d) Airtel
    Answer: b
  14. What is the discount for 3-year Reserved Instances?
    a) Up to 40% b) Up to 72% c) Up to 90% d) Up to 100%
    Answer: b
  15. What should you do to save money on storage?
    a) Use Hot tier for all data b) Use Archive for old data c) Delete all data d) Use Premium tier
    Answer: b

๐Ÿ”— Matching Exercises

Match the tool/service with its purpose.

Tool/ServicePurpose
Pricing CalculatorEstimate costs
TCO CalculatorCompare on-premises vs. cloud
Cost ManagementTrack spending
BudgetSet spending limit
Azure AdvisorGive recommendations
Reserved InstancePrepay to save
Savings PlanFlexible savings
Storage TierSave on old data
TagCost allocation

โœ๏ธ Short Answer Questions

  1. Explain the difference between Reserved Instances and Savings Plans.
  2. How does right-sizing save money?
  3. What are storage tiers and when should you use each?
  4. How do tags help with cost management?
  5. Why is it important to stop idle VMs?

๐Ÿงฉ Scenario-based Exercises

Scenario 1: A Nigerian company runs a VM 24/7 but only uses it for 8 hours a day. How can they save money?

Scenario 2: A school has 5 years of student records that they rarely access. Which storage tier should they use?

Scenario 3: A fintech startup has a steady workload on VMs and wants to save money. What should they do?

๐Ÿ‘ฅ Group Activity

In groups, design a cost management plan for a Nigerian company using Azure. Include:

  • How they will plan costs.
  • How they will track spending.
  • How they will save money.
  • How they will optimize resources.

๐Ÿง‘ Individual Activity

Use the Azure Pricing Calculator to estimate the cost of running a VM for 1 year in the South Africa region. Write down your estimate and the assumptions you made.

๐Ÿ’ฌ Classroom Discussion Questions

  1. Why is cost management important in the cloud?
  2. How can Nigerian businesses benefit from Reserved Instances?
  3. What are the risks of not managing costs?
  4. How can tags help a large organisation?
  5. What would you do if you got a surprise Azure bill?

๐Ÿ› ๏ธ Mini Project

Cost Optimization Plan: Create a cost optimization plan for a fictional Nigerian e-commerce company. Include cost estimation, tracking, savings strategies, and optimization practices. Present your plan.

๐Ÿ’ป Practical Assignment

If you have an Azure account, try the following:

  1. Set up a budget alert.
  2. Use Cost Analysis to see your spending.
  3. Check Azure Advisor for cost recommendations.
  4. Add tags to a resource group.

๐Ÿ† Challenge Exercise

Research how to create an Azure Automation runbook to stop VMs automatically after business hours. Write a simple guide.

๐Ÿ”‘ Quiz Answers (Multiple Choice)

  1. b
  2. b
  3. c
  4. a
  5. b
  6. b
  7. b
  8. a
  9. a
  10. c
  11. a
  12. a
  13. b
  14. b
  15. b

๐ŸŽ Key Takeaways

  • Plan with calculators before you spend.
  • Track spending with Cost Management.
  • Set budgets and alerts.
  • Use Reserved Instances and Savings Plans for long-term savings.
  • Right-size resources and stop idle VMs.
  • Use storage tiers for old data.
  • Use tags for cost allocation.
  • Follow Azure Advisor recommendations.
  • Nigerian companies use these strategies to save money.

๐Ÿš€ Preparation for Module 4

In the next module, we will learn about Management, Monitoring, and Automation. We'll cover:

  • Azure Portal, CLI, PowerShell, and Cloud Shell.
  • ARM templates and Bicep for Infrastructure as Code.
  • Azure Monitor, Log Analytics, and Application Insights.
  • Alerts and Action Groups.
  • Azure Automation and Logic Apps.

Review your knowledge of resources and subscriptions โ€“ they will be important in Module 4.


๐ŸŽ‰ Congratulations! You have completed Module 3 (Intermediate). Keep going! ๐Ÿš€

5

Module Four

Module 4 ยท Management, Monitoring & Automation (Intermediate) ยท AZ-900

๐Ÿ“Š Module 4: Management, Monitoring & Automation (Intermediate)

Welcome to the control room! ๐ŸŽฎ In this module, we will learn how to manage Azure, monitor our resources, and automate tasks. Think of it like being the pilot of a big airplane โ€“ you need to know all the controls, watch the instruments, and sometimes let the autopilot take over.

๐ŸŽฏ Learning Objectives

  • Use Azure Portal, CLI, PowerShell, and Cloud Shell for management.
  • Create and deploy ARM templates and Bicep for Infrastructure as Code.
  • Monitor resources with Azure Monitor and Log Analytics.
  • Set up alerts and action groups for notifications.
  • Automate tasks with Azure Automation and Logic Apps.

๐Ÿ“– Warm-up Story: The Spaceship Control Room

Imagine you are the captain of a spaceship ๐Ÿš€. You need to:

  • Manage โ€“ use controls to fly the ship.
  • Monitor โ€“ watch the screens to see if everything is working.
  • Automate โ€“ let the computer do routine tasks.

Azure is like that spaceship! You use tools to manage it, monitors to watch it, and automation to make your life easier.

๐Ÿ“˜ Main Lessons

1. Azure Portal โ€“ The main control panel

Definition: The Azure Portal is a website where you can manage all your Azure resources visually.

Why important: It's the easiest way for beginners to interact with Azure.

Simple: Like a car dashboard โ€“ you can see everything and control everything.

Real-life: A company's IT team uses the portal to create VMs and storage.

School: The IT teacher uses the portal to manage the school's resources.

Home: You can use the portal to create your free account.

Nigerian: A startup uses the portal to deploy its app.

    Azure Portal = Web-based management
    โ”œโ”€โ”€ Create resources
    โ”œโ”€โ”€ Monitor resources
    โ””โ”€โ”€ Manage access
    

โœ… Summary: The Azure Portal is the main graphical interface for Azure.


2. Azure CLI โ€“ Command line magic

Definition: Azure CLI (Command Line Interface) is a tool that lets you manage Azure using commands in a terminal or script.

Why important: It's faster for repetitive tasks and can be used in scripts.

Simple: Like typing instructions instead of clicking buttons.

Real-life: A developer uses CLI to create 100 VMs in one command.

School: The IT teacher uses CLI to automate tasks.

Home: Not used at home.

Nigerian: A sysadmin in Lagos uses CLI to manage multiple subscriptions.

    az vm create --name MyVM --resource-group MyRG --image UbuntuLTS
    

โœ… Summary: Azure CLI lets you manage Azure via commands.


3. Azure PowerShell โ€“ Command line for Windows

Definition: Azure PowerShell is a tool that uses PowerShell commands (like CLI) to manage Azure, especially on Windows.

Why important: It's powerful for Windows automation.

Simple: Like CLI but for PowerShell fans.

Real-life: A Windows admin uses PowerShell to manage Azure VMs.

School: The IT teacher uses PowerShell for Windows tasks.

Home: Not used at home.

Nigerian: A bank uses PowerShell for Windows-based automation.

    New-AzVM -Name MyVM -ResourceGroupName MyRG -Image UbuntuLTS
    

โœ… Summary: Azure PowerShell lets you manage Azure from Windows.


4. Azure Cloud Shell โ€“ Browser-based terminal

Definition: Cloud Shell is a browser-based terminal where you can run CLI or PowerShell commands without installing anything.

Why important: You don't need to install any software โ€“ just use your browser.

Simple: Like having a terminal in your browser.

Real-life: A developer uses Cloud Shell from any computer.

School: Students use Cloud Shell for labs.

Home: You can use Cloud Shell from your browser.

Nigerian: A startup uses Cloud Shell for quick management.

    Cloud Shell = Terminal in the browser
    โ”œโ”€โ”€ Azure CLI
    โ””โ”€โ”€ Azure PowerShell
    

โœ… Summary: Cloud Shell lets you use CLI/PowerShell from your browser.


5. ARM Templates โ€“ Infrastructure as Code (IaC)

Definition: ARM (Azure Resource Manager) templates are JSON files that define your infrastructure in code.

Why important: You can deploy the same environment over and over consistently.

Simple: Like a recipe โ€“ follow it to bake the same cake every time.

Real-life: A company uses ARM templates to deploy its production and test environments.

School: The school uses a template to set up a lab for students.

Home: Not used at home.

Nigerian: A startup uses ARM templates to deploy their app in multiple regions.

    ARM Template = JSON code
    โ”œโ”€โ”€ VM
    โ”œโ”€โ”€ Storage
    โ”œโ”€โ”€ VNet
    โ””โ”€โ”€ Deploy โ†’ Creates all resources together
    

โœ… Summary: ARM templates let you define your infrastructure as code.


6. Bicep โ€“ Simpler Infrastructure as Code

Definition: Bicep is a new language for Infrastructure as Code that is simpler and more readable than ARM templates.

Why important: It's easier to write and understand.

Simple: Like writing a recipe in plain English instead of a complicated list.

Real-life: A company uses Bicep for faster deployments.

School: The school uses Bicep for lab environments.

Home: Not used at home.

Nigerian: A startup uses Bicep for faster infrastructure deployment.

    resource vm 'Microsoft.Compute/virtualMachines@2023-03-01' = {
      name: 'MyVM'
      location: 'southafricanorth'
      ...
    }
    

โœ… Summary: Bicep is a simpler language for Infrastructure as Code.


7. Azure Monitor โ€“ Watch your resources

Definition: Azure Monitor collects data from your resources (like performance, logs, and metrics) and helps you understand what's happening.

Why important: You need to know if your app is running well.

Simple: Like a doctor's check-up for your cloud resources.

Real-life: A developer uses Azure Monitor to see if a VM is running out of memory.

School: The IT team monitors the school's website to see if it's fast.

Home: Not used at home.

Nigerian: A fintech uses Monitor to track transaction processing times.

    Azure Monitor
    โ”œโ”€โ”€ Metrics (CPU, memory, etc.)
    โ”œโ”€โ”€ Logs (detailed records)
    โ””โ”€โ”€ Alerts (notify when something is wrong)
    

โœ… Summary: Azure Monitor helps you see how your resources are performing.


8. Log Analytics โ€“ Dive into logs

Definition: Log Analytics is a tool within Azure Monitor that lets you query and analyze logs using KQL (Kusto Query Language).

Why important: You can find specific events or patterns in your logs.

Simple: Like searching through a giant diary to find a specific event.

Real-life: A developer uses Log Analytics to find errors in their app.

School: The IT team uses Log Analytics to see who accessed the system.

Home: Not used at home.

Nigerian: A bank uses Log Analytics to detect fraud.

    Log Analytics
    โ”œโ”€โ”€ Query logs
    โ”œโ”€โ”€ Create dashboards
    โ””โ”€โ”€ Set up alerts
    

โœ… Summary: Log Analytics lets you search and analyze logs.


9. Application Insights โ€“ Monitor your app

Definition: Application Insights is a tool that monitors your application's performance and user behaviour.

Why important: It tells you how your app is performing for users.

Simple: Like a fitness tracker for your app.

Real-life: A company uses Application Insights to see which pages are slow.

School: The school uses it to monitor the online learning portal.

Home: Not used at home.

Nigerian: A startup uses Application Insights to improve their app.

    Application Insights
    โ”œโ”€โ”€ Performance metrics
    โ”œโ”€โ”€ User analytics
    โ””โ”€โ”€ Exception tracking
    

โœ… Summary: Application Insights monitors your application's performance.


10. Alerts and Action Groups โ€“ Get notified

Definition: Alerts are notifications that something is wrong (e.g., CPU too high). Action Groups are groups of actions to take (e.g., send an email).

Why important: You need to know when something goes wrong.

Simple: Like a smoke alarm โ€“ it tells you when there's a fire.

Real-life: A company sets an alert when VM CPU is over 80%.

School: The school gets an alert when the website goes down.

Home: Not used at home.

Nigerian: A fintech gets alerts for high transaction volumes.

    Alert: CPU > 80% โ†’ Action Group โ†’ Send email to IT team
    

โœ… Summary: Alerts notify you when something needs attention.


11. Azure Automation โ€“ Automate repetitive tasks

Definition: Azure Automation is a service that lets you automate tasks using runbooks (scripts) and DSC (Desired State Configuration).

Why important: You can save time and reduce errors.

Simple: Like a robot that does your chores.

Real-life: A company uses Automation to stop VMs at night.

School: The school uses Automation to back up data daily.

Home: Not used at home.

Nigerian: A startup uses Automation to deploy updates.

    Automation
    โ”œโ”€โ”€ Runbooks (scripts)
    โ”œโ”€โ”€ Desired State Configuration (DSC)
    โ””โ”€โ”€ Schedules (when to run)
    

โœ… Summary: Azure Automation automates repetitive tasks.


12. Azure Logic Apps โ€“ Build workflows without code

Definition: Azure Logic Apps is a service that lets you create workflows using a visual designer โ€“ no coding required!

Why important: You can connect different systems and automate processes.

Simple: Like building a LEGO castle โ€“ you just connect the pieces.

Real-life: A company uses Logic Apps to send emails when a file is uploaded.

School: The school uses Logic Apps to send notifications.

Home: Not used at home.

Nigerian: A startup uses Logic Apps to integrate with payment systems.

    Trigger (e.g., file upload) โ†’ Action (e.g., send email)
    

โœ… Summary: Logic Apps let you create workflows visually.


13. Azure Service Health โ€“ Is Azure okay?

Definition: Service Health shows the status of Azure services across regions and alerts you about outages or planned maintenance.

Why important: If Azure has a problem, you need to know.

Simple: Like a weather report for the cloud.

Real-life: A company checks Service Health before blaming their app for slowness.

School: The school checks if Azure is down before calling IT.

Home: You might check if Xbox Live is down.

Nigerian: A startup checks Service Health to know if Azure is having issues.

โœ… Summary: Service Health tells you the status of Azure services.


14. Resource Groups and Management Groups โ€“ Organising

Definition: Resource groups are containers for related resources. Management groups are containers for multiple subscriptions.

Why important: They help you organise and manage access and policies.

Simple: Like folders and filing cabinets.

Real-life: A company has resource groups for each project and management groups for each department.

School: The school has a resource group for each subject.

Home: Not used at home.

Nigerian: A bank has management groups for branches.

    Management Group
    โ”œโ”€โ”€ Subscription 1
    โ”‚   โ”œโ”€โ”€ Resource Group A
    โ”‚   โ””โ”€โ”€ Resource Group B
    โ””โ”€โ”€ Subscription 2
        โ”œโ”€โ”€ Resource Group C
        โ””โ”€โ”€ Resource Group D
    

โœ… Summary: Resource groups and management groups help you organise Azure.


15. Best Practices for Management, Monitoring, and Automation

Definition: Best practices are the recommended ways to manage, monitor, and automate Azure effectively.

Why important: They help you stay organised, save time, and avoid issues.

Simple: Like a checklist for a clean and efficient Azure environment.

Real-life: A company follows all these practices to keep their Azure environment healthy.

School: The school follows these practices.

Home: Not used at home.

Nigerian: A startup follows these practices to scale.

    Best Practices:
    1. Use resource groups and tags.
    2. Use ARM or Bicep for IaC.
    3. Set up alerts for critical resources.
    4. Use Azure Automation for repetitive tasks.
    5. Monitor performance regularly.
    

โœ… Summary: Following best practices helps you manage Azure effectively.


๐Ÿ“š Key Vocabulary

  • Azure Portal: Web-based management interface.
  • Azure CLI: Command-line management.
  • Azure PowerShell: PowerShell-based management.
  • Cloud Shell: Browser-based terminal.
  • ARM Template: Infrastructure as Code (JSON).
  • Bicep: Simpler Infrastructure as Code.
  • Azure Monitor: Collects performance data.
  • Log Analytics: Query and analyze logs.
  • Application Insights: Application performance monitoring.
  • Alert: Notification of a problem.
  • Action Group: Set of actions for alerts.
  • Azure Automation: Automates tasks.
  • Logic Apps: Visual workflows.
  • Service Health: Status of Azure services.
  • Management Group: Container for subscriptions.

๐Ÿง  Important Concepts

  • Management: Use Portal, CLI, PowerShell, or Cloud Shell.
  • Infrastructure as Code: Use ARM or Bicep for repeatable deployments.
  • Monitoring: Use Azure Monitor, Log Analytics, and Application Insights.
  • Alerting: Set alerts and action groups to stay informed.
  • Automation: Use Azure Automation and Logic Apps to save time.

๐Ÿ”ข Step-by-step: Create an Alert for VM CPU

  1. Go to Azure Portal.
  2. Navigate to "Azure Monitor".
  3. Select "Alerts".
  4. Click "Create" โ†’ "Alert rule".
  5. Choose a VM as the resource.
  6. Set condition: CPU > 80% for 5 minutes.
  7. Create an Action Group (email or SMS).
  8. Review and create the alert.

๐ŸŒ Real-life Examples

  • Netflix: Uses Azure Monitor for streaming performance.
  • Adobe: Uses ARM templates for deployments.
  • E-Trade: Uses Alerts for critical systems.
  • BP: Uses Automation for infrastructure management.
  • Nike: Uses Logic Apps for integrations.

๐Ÿ‡ณ๐Ÿ‡ฌ Nigerian Examples

  • Flutterwave: Uses ARM templates for deployments.
  • Paystack: Uses Azure Monitor for performance.
  • Kuda Bank: Uses Alerts for security.
  • Chipper Cash: Uses Automation for backups.
  • Farmcrowdy: Uses Logic Apps for farmer notifications.

๐ŸŽˆ Fun Examples for Kids

  • Roblox: Uses monitoring to keep games running.
  • Minecraft: Uses automation to back up worlds.
  • Zoom: Uses alerts for server issues.
  • Google Classroom: Uses Logic Apps for notifications.
  • Fortnite: Uses Infrastructure as Code for game updates.

๐Ÿ  Everyday Examples

  • Email alerts: You get a notification when you receive an email.
  • Smart home: You use a mobile app to control lights.
  • Backups: Your phone automatically backs up photos.
  • School portal: The school uses monitoring for the website.
  • Online shopping: Logic Apps send order confirmations.

๐Ÿ‘ฉโ€๐Ÿซ Teacher Notes

  • Emphasise that management and monitoring are as important as building.
  • Use the spaceship analogy to explain controls and monitoring.
  • Relate to Nigerian context: use local examples.
  • Encourage students to try CLI and PowerShell in Cloud Shell.
  • Discuss real-world automation examples.

๐Ÿง‘โ€๐Ÿคโ€๐Ÿง‘ Parent Tips

  • Discuss with your child how automation saves time.
  • Explain that monitoring is like checking the health of a system.
  • Talk about how companies use these tools.
  • Ask: "What would you automate in your daily life?"
  • Encourage them to explore Azure's free tools.

๐Ÿ’ก Interesting Facts

  • Azure CLI is used by over 70% of Azure developers.
  • ARM templates can deploy hundreds of resources in minutes.
  • Azure Monitor processes billions of data points per day.
  • Logic Apps can connect to over 200 services.
  • Azure Automation can save thousands of hours per year.

๐Ÿค” Did You Know?

  • You can use Cloud Shell from any device with a browser.
  • Bicep files are simpler and shorter than ARM templates.
  • Azure Monitor can monitor on-premises resources too.
  • You can get alerts on your phone via SMS.
  • Logic Apps can be triggered by events like file uploads.

๐Ÿงพ Remember This

  • Azure Portal is the main graphical interface.
  • CLI, PowerShell, and Cloud Shell are command-line tools.
  • ARM and Bicep are Infrastructure as Code.
  • Azure Monitor and Log Analytics help you watch resources.
  • Alerts and Action Groups notify you of issues.
  • Azure Automation and Logic Apps automate tasks.

โš ๏ธ Common Mistakes

  • Mistake: Using the Portal for everything (it's slow for repetitive tasks).
    Fix: Use CLI or scripts for repetitive tasks.
  • Mistake: Not setting up alerts and missing issues.
    Fix: Set up alerts for critical resources.
  • Mistake: Hard-coding values in ARM templates.
    Fix: Use parameters for reusable templates.
  • Mistake: Not using tags, making resources messy.
    Fix: Always use tags for organisation.
  • Mistake: Not monitoring performance and missing slowdowns.
    Fix: Set up Azure Monitor for all resources.

๐ŸŒŸ Best Practices

  • Use Azure Portal for exploration and CLI/scripts for automation.
  • Use ARM or Bicep for all deployments (Infrastructure as Code).
  • Set up Azure Monitor for all resources.
  • Create alerts for critical metrics.
  • Use Azure Automation for recurring tasks.
  • Use Logic Apps for integrations.
  • Use tags and resource groups for organisation.

๐Ÿ“Š ASCII Illustrations

Management Tools

    Azure Portal   โ†’  Graphical (click)
    Azure CLI      โ†’  Command line (type)
    Azure PowerShell โ†’  PowerShell (type)
    Cloud Shell    โ†’  Browser terminal
    

Infrastructure as Code

    Code (ARM/Bicep) โ†’ Deploy โ†’ Azure Resources
    

Monitoring Flow

    Resources โ†’ Metrics/Logs โ†’ Azure Monitor โ†’ Alerts โ†’ Action Group
    

๐Ÿ“‹ Comparison tables

Management tools comparison

ToolUser interfaceBest for
PortalGraphicalVisual, beginners
Azure CLICommand lineScripts, automation
PowerShellCommand lineWindows automation
Cloud ShellBrowser terminalQuick tasks, any device

IaC tools comparison

ToolLanguageComplexity
ARM TemplatesJSONHigher
BicepBicepLower

๐Ÿ“Œ End-of-module Summary

In this module, we learned about management, monitoring, and automation in Azure. We covered:

  • Management: Azure Portal, CLI, PowerShell, Cloud Shell.
  • Infrastructure as Code: ARM templates and Bicep.
  • Monitoring: Azure Monitor, Log Analytics, Application Insights.
  • Alerting: Alerts and Action Groups.
  • Automation: Azure Automation and Logic Apps.
  • Organisation: Resource groups and management groups.
  • Nigerian examples: How local companies manage, monitor, and automate.

You now have the skills to manage, monitor, and automate your Azure environment. This is the final module of the intermediate course โ€“ you are ready to take your Azure skills to the next level!

โ“ Frequently Asked Questions

  1. What is the Azure Portal? โ€“ The main graphical interface.
  2. What is Azure CLI? โ€“ Command-line management.
  3. What is Cloud Shell? โ€“ Browser-based terminal.
  4. What are ARM templates? โ€“ Infrastructure as Code in JSON.
  5. What is Bicep? โ€“ Simpler Infrastructure as Code.
  6. What does Azure Monitor do? โ€“ Collects performance data.
  7. What is Log Analytics? โ€“ Query and analyze logs.
  8. What are Alerts? โ€“ Notifications of issues.
  9. What is Azure Automation? โ€“ Automates tasks.
  10. What are Logic Apps? โ€“ Visual workflows.

๐Ÿ“ Review Questions

  1. What is the Azure Portal?
  2. What is Azure CLI used for?
  3. What is Cloud Shell?
  4. What are ARM templates?
  5. What is Bicep?
  6. What does Azure Monitor do?
  7. What is Log Analytics?
  8. What are Alerts?
  9. What is an Action Group?
  10. What is Azure Automation?
  11. What are Logic Apps?
  12. What is Service Health?
  13. What is a Management Group?
  14. Give a Nigerian example of using Azure Automation.
  15. Why is monitoring important?

โœ๏ธ Fill-in-the-Blank

  1. ___________ is the main graphical interface for Azure. (Azure Portal)
  2. ___________ is a command-line tool for Azure. (Azure CLI)
  3. ___________ is a browser-based terminal. (Cloud Shell)
  4. ___________ are Infrastructure as Code in JSON. (ARM templates)
  5. ___________ is a simpler Infrastructure as Code language. (Bicep)
  6. ___________ collects performance data from resources. (Azure Monitor)
  7. ___________ lets you query and analyze logs. (Log Analytics)
  8. ___________ notify you of issues. (Alerts)
  9. ___________ automate repetitive tasks. (Azure Automation)
  10. ___________ let you create visual workflows. (Logic Apps)

โœ… True or False

  1. The Azure Portal is a command-line tool. (False)
  2. Azure CLI is used for scripting. (True)
  3. Cloud Shell requires installation. (False)
  4. ARM templates are written in JSON. (True)
  5. Bicep is more complex than ARM templates. (False)
  6. Azure Monitor collects performance data. (True)
  7. Log Analytics is used for data storage. (False)
  8. Alerts can send email notifications. (True)
  9. Azure Automation only works on VMs. (False)
  10. Logic Apps require coding. (False)

๐Ÿงช Multiple Choice Questions

  1. Which is the main graphical interface for Azure?
    a) CLI b) Portal c) PowerShell d) Cloud Shell
    Answer: b
  2. Which is a command-line tool for Azure?
    a) Portal b) CLI c) Cloud Shell d) Logic Apps
    Answer: b
  3. What is Cloud Shell?
    a) A graphical interface b) A browser terminal c) A VM d) A storage account
    Answer: b
  4. What are ARM templates?
    a) A storage service b) Infrastructure as Code c) A VM d) A network
    Answer: b
  5. Which is a simpler Infrastructure as Code language?
    a) ARM b) Bicep c) JSON d) YAML
    Answer: b
  6. What does Azure Monitor do?
    a) Creates VMs b) Collects performance data c) Stores secrets d) Manages identities
    Answer: b
  7. What is Log Analytics?
    a) A storage service b) A log query tool c) A VM d) A network
    Answer: b
  8. What are Alerts?
    a) Notifications of issues b) VMs c) Storage accounts d) Networks
    Answer: a
  9. What is an Action Group?
    a) A set of actions for alerts b) A VM c) A storage account d) A network
    Answer: a
  10. What is Azure Automation?
    a) A storage service b) A task automation service c) A VM d) A network
    Answer: b
  11. What are Logic Apps?
    a) Visual workflows b) VMs c) Storage accounts d) Networks
    Answer: a
  12. What is Service Health?
    a) Status of Azure services b) A VM c) A storage account d) A network
    Answer: a
  13. What is a Management Group?
    a) A container for subscriptions b) A VM c) A storage account d) A network
    Answer: a
  14. Which Nigerian company uses Azure Automation?
    a) Dangote b) Flutterwave c) NNPC d) Airtel
    Answer: b
  15. Why is monitoring important?
    a) To save money b) To know if resources are healthy c) To create VMs d) To store data
    Answer: b

๐Ÿ”— Matching Exercises

Match the tool/service with its purpose.

Tool/ServicePurpose
Azure PortalGraphical management
Azure CLICommand-line management
Cloud ShellBrowser terminal
ARM TemplateInfrastructure as Code
BicepSimpler IaC
Azure MonitorCollect performance data
Log AnalyticsQuery logs
AlertNotify of issues
Azure AutomationAutomate tasks
Logic AppsVisual workflows

โœ๏ธ Short Answer Questions

  1. Explain the difference between Azure Portal and Azure CLI.
  2. What is Infrastructure as Code and why is it important?
  3. How does Azure Monitor help you?
  4. What is the purpose of Alerts and Action Groups?
  5. Give an example of how you could use Azure Automation.

๐Ÿงฉ Scenario-based Exercises

Scenario 1: A Nigerian company wants to deploy the same environment in three regions. Which tool should they use?

Scenario 2: A school wants to get an email when the website is down. Which service should they use?

Scenario 3: A fintech wants to automatically stop VMs at 6 PM every day. Which service should they use?

๐Ÿ‘ฅ Group Activity

In groups, design a management and monitoring plan for a Nigerian company. Include:

  • How they will manage resources.
  • How they will monitor performance.
  • How they will set up alerts.
  • What they will automate.

๐Ÿง‘ Individual Activity

Write a simple ARM template or Bicep script to deploy a VM. Share it with the class.

๐Ÿ’ฌ Classroom Discussion Questions

  1. Why is Infrastructure as Code better than manual configuration?
  2. How can monitoring help a business save money?
  3. What would you automate in your cloud environment?
  4. How can Nigerian companies benefit from automation?
  5. What is the role of alerts in cloud management?

๐Ÿ› ๏ธ Mini Project

Automation Plan: Create a plan for automating the deployment and management of a web application in Azure. Include Infrastructure as Code, monitoring, alerts, and automation.

๐Ÿ’ป Practical Assignment

If you have an Azure account, try the following:

  1. Use Cloud Shell to run a CLI command.
  2. Create an ARM template or Bicep file for a VM.
  3. Set up an alert for a VM.
  4. Create a Logic App that sends an email when a file is uploaded.

๐Ÿ† Challenge Exercise

Research how to create an Azure Automation runbook that stops a VM at a specific time. Write a simple guide.

๐Ÿ”‘ Quiz Answers (Multiple Choice)

  1. b
  2. b
  3. b
  4. b
  5. b
  6. b
  7. b
  8. a
  9. a
  10. b
  11. a
  12. a
  13. a
  14. b
  15. b

๐ŸŽ Key Takeaways

  • Use Portal, CLI, PowerShell, and Cloud Shell for management.
  • Use ARM or Bicep for Infrastructure as Code.
  • Monitor with Azure Monitor, Log Analytics, and Application Insights.
  • Set up Alerts and Action Groups for notifications.
  • Automate with Azure Automation and Logic Apps.
  • Use resource groups and management groups for organisation.
  • Nigerian companies use these tools to manage, monitor, and automate.

๐Ÿš€ What's Next?

Congratulations! ๐ŸŽ‰ You have completed all four modules of the Azure Fundamentals โ€“ Intermediate course.

You are now ready to take the next step in your Azure journey. Here are some suggestions:

  • Take the AZ-104: Azure Administrator exam to become a certified administrator.
  • Practice with hands-on labs and real-world projects.
  • Explore advanced topics like Azure DevOps, AI, and Machine Learning.
  • Join the Azure community and learn from others.

Good luck, future Azure expert! โ˜๏ธ๐Ÿš€


๐Ÿ† You have completed the intermediate course! Keep learning and exploring the cloud. ๐ŸŒŸ

๐Ÿ† Get Certified

๐Ÿ”’

Earn this certificate

Every lesson is already free to read. Sign up, pass the exam, and unlock Practice Tools plus a verified certificate with your name on it โ€” โ‚ฆ4,000/month.

๐ŸŽ“ Sign Up & Unlock for โ‚ฆ4,000/month
๐Ÿ› ๏ธ Practice Tools
Hands-on simulators & labs - subscription required.
โ†’
๐ŸŽฏ Internship Tasks
Real-world tasks to build your portfolio - try them free for 7 days, no card required.
โ†’