Skip to content
CBT Nuggets
DemoBook a Demo

Deploy SQL Resources Using Manual Methods

This skill, led by Knox Hutchinson, covers the deployment of various Azure SQL offerings using manual methods. It includes detailed instructions on deploying Azure SQL databases, SQL virtual machines, SQL managed instances, and elastic pools through the Azure portal. The content is designed for those preparing for the DP-300 certification and provides insights into both infrastructure as a service (IaaS) and platform as a service (PaaS) models, emphasizing practical steps and considerations for each deployment type.

Full skill from DP-300. Preview the IT training 23,000+ organizations trust.

1h 7m

Skill 1 of 24 in DP-300

Overview

Join Knox Hutchinson as he demonstrates how to deploy various Azure SQL Offerings.

Recommended Experience

  • An understanding of relational data, non-relational data, and different types of data workloads such as transactional and analytical is recommended

Related Certifications

  • Microsoft Certified: Azure Database Administrator Associate

Related Job Functions

  • Azure Database Administrators
  • Azure Data Engineers

Knox Hutchinson has been a CBT Nuggets trainer since 2018 and has received a variety of Microsoft and Cisco certifications. His areas of expertise include data analysis, data visualization, and business intelligence solutions.

Deploy Azure SQL Resources Manually

Let's get started by deploying the various types of Azure SQL resources using the portal.

Azure SQL IaaS Deployment

Let's take a look at how to deploy Azure SQL virtual machines.

Knowledge Check

Which image should you choose if you want to leverage an Azure Hybrid Enterprise SQL license to reduce costs?

Single Azure SQL Database Deployments

Now let's look at how to deploy an Azure SQL DB.

Knowledge Check

Which object should you whitelist IP addresses on for connectivity?

Elastic Pool Deployments

Now let's deploy our Azure SQL Databases within a single elastic pool.

Knowledge Check

Which pricing tier is omitted from the Elastic Pool deployment?

Azure SQL Managed Instance Deployments

Now let's look at the Azure SQL Managed Instance deployment steps.

Knowledge Check

You can deploy a Managed Instance on the same VNet AND subnet that has a virtual machine on it. True or false?

Want to answer questions like this yourself?
with no purchase required. Already have an account?

Summarizing Azure SQL Manual Deployments

Let's recap what we've learned about Azure SQL deployments using manual methods.

Conclusion

I hope this has been informative for you and I would like to thank you for consuming.

View Transcript

Deploy Azure SQL Resources Manually

0:06Welcome to the content on deploying Azure SQL database

0:10resources.

0:11The DP-300 certification exam actually

0:15explicitly calls out deploying resources

0:18via the manual methods.

0:20In a separate section of the certification exam,

0:23it calls out deploying resources for the automated methods.

0:27So in this set of content, we're going

0:29to tackle the manual methods first.

0:31This is going to be things like using the Azure

0:34portal to deploy these.

0:36Or I also want to point out that you can do a lot of these steps

0:40directly from an application called Azure Data Studio.

0:44This is going to replace SMS at some point.

0:47It's not there yet.

0:49But it's good to start using that application

0:51and at least get familiar with it.

0:53So in this video, we are going to deploy an Azure SQL

0:56database the old fashioned way, as well as

0:58with an elastic pool.

1:00We're also going to talk about how to deploy an Azure SQL

1:03Managed instance.

1:04Block out your calendar for that one

1:06because it takes a long time.

1:07All right, without any further ado,

1:09let's get started deploying some Azure SQL resources.

Azure SQL IaaS Deployment

0:06The easiest way to get started working with Azure SQL

0:10resources, and probably the one that's

0:12going to be most familiar for database administrators

0:16is to simply deploy an Azure SQL virtual machine.

0:20This looks and feels exactly like the things

0:23that you would be doing from vCenter or hyper-v manager,

0:26however, it's just done from the Azure portal.

0:29This, again, is going to be the infrastructure as a service

0:32offering.

0:33The one where you are going to be responsible for managing

0:36and maintaining, not only the SQL server instance itself,

0:40but also the operating system.

0:42This is great for lift and shift operations

0:45until you can start to refactor your applications

0:48and your databases to be more towards the platform

0:51as a service offering.

0:53So let's jump into this and just deploy an Azure SQL

0:56virtual machine, and you can see the factors that come

0:59into deploying this resource.

1:00Let's go.

1:01So our first step is to deploy an Azure virtual machine.

1:04And we're going to do this the manual way via the portal.

1:07And there are a few different ways that you could do this.

1:10You could, of course, deploy your virtual machine

1:13just by choosing virtual machines

1:15and then selecting the correct image with it.

1:19You can, in fact, deploy your own virtual machine,

1:21and then manually install SQL Server,

1:24provide your own license, and do it that way.

1:26And that makes a lot of sense.

1:27It's perfectly fine to do it that way,

1:29if that's what you want to do.

1:30But if you want to deploy a SQL virtual machine

1:34and have SQL already installed, we

1:36can go ahead and do that right here by choosing the actual SQL

1:40virtual machines that helps us skip a step.

1:43And it helps us actually identify

1:45the image a lot quicker.

1:46Now we are going to talk about licensing and how

1:48that works with SQL virtual machines in just a second.

1:51So let's click on SQL virtual machines.

1:53It takes us in here.

1:55It will go ahead and click Create SQL virtual machine.

1:59Now we've seen this page before, right?

2:00It's not actually the SQL virtual machine page.

2:03There's the platform as a service offerings,

2:05and then there's SQL virtual machines.

2:08From the image dropdown, we see these

2:10are all of the possible images that has the SQL server

2:14additions on top of Windows Server.

2:17Now you can scroll down and see there's

2:19a bunch of different mix or match options here.

2:21We have things like SQL Server 2019 Enterprise

2:26on Windows Server 2022.

2:28Scroll down some more though, and now we've

2:30got SQL Server 2019 on Windows Server 2019.

2:34We also have these (BYOL) for Bring

2:37Your Own License of SQL Server 2019 on Windows Server 2019.

2:44So if you had SQL Enterprise Edition,

2:48that does entitle you to hybrid environment benefits

2:52where you can provide your own license for SQL Server 2019.

2:58When you launch it it's going to ask you to license

3:01the actual application itself.

3:03And this actually gives you a lower cost per month.

3:07As opposed to above where it's not Bring Your Own License,

3:10the licensing for SQL Server is then

3:13built into your hourly rate.

3:17So that's how you actually can go

3:18about paying for this particular service in the cloud,

3:22is you're going to be able to bring your own license.

3:25Or if you don't have a license that enables you

3:28to Hyper benefits, then you can just

3:31build it into your hourly rate.

3:33The same thing goes for Windows Server for that matter.

3:36If you actually have the Windows Server Enterprise Edition,

3:39the data center editions, then you can actually

3:43use the Bring Your Own License for the Windows Server itself

3:46and get a reduced fee.

3:48So you could actually do the SQL Server 2019 Enterprise, which

3:51is not Bring Your Own License, build that

3:54into the hourly cost, but provide your own license

3:56for Windows Server 2019 and lower the cost there.

3:59There's a bunch of different options.

4:00Beyond that we also know that SQL Server, for a while now,

4:03has been able to be run on top of Linux environments.

4:06So if you want to use Red Hat or Ubuntu,

4:09then you can absolutely use all of those as well.

4:12So you get to choose the environment that

4:15works best for you, or really the licensing

4:17model that works best for you.

4:19And in my case, I was going to choose the free SQL server

4:22license for the developer edition on Windows Server 2022.

4:26So I'll click Create, and then this

4:28takes me into the actual wizard where we can create

4:32the virtual machine itself.

4:34Now just like everything in Azure,

4:35you're going to want to choose the correct resource

4:37or the correct subscription.

4:39And then I'm going to create a new resource group.

4:41I'm going to call this Knox SQL to create a new resource

4:44group on the fly.

4:46We're going to give our virtual machine a name.

4:48I'm going to call this knox-sql-iaas,

4:54just to get this deployed.

4:55And I'm going to deploy this in the South Central US.

5:00Now the availability zones, this is where we could actually

5:02define what kind of availability or infrastructure redundancy,

5:07I should say, that we want for our specific virtual machines.

5:11With an availability zone, we can physically

5:14separate our resources within an Azure region.

5:18That's the idea there.

5:19So there were actually multiple data centers

5:22within the South Central US region.

5:24And by choosing the availability zone,

5:26we are able to actually add redundancy

5:28that spreads our virtual machine out across multiple regions.

5:32This would be things like having redundant copies of our data,

5:35as well as redundant copies of our virtual machine

5:38configurations.

5:39Now beyond that, we have the security type.

5:42So what do we want here?

5:43Well, we've got the standard level

5:45of security for our virtual machines or the trusted launch

5:48virtual machines.

5:49It protects against persistent and advanced attacks on Gen 2

5:53virtual machines by enabling features

5:55like secure boot and Trusted Platform Module.

5:58This is a virtual TPM.

6:00For me I'm just going to keep this at standard for right now.

6:03Now, again, we've already selected the image.

6:05But if you need to go back and change this,

6:07you can choose See all images here,

6:09and it will bring you into this long list of images.

6:12Now, I am going to ignore this and go back

6:14to my Create virtual machine.

6:16Now, ultimately, the big thing right

6:18here is where does all of this costs come in?

6:20It all comes in with the size of the virtual machine.

6:25If you choose See all sizes at the bottom,

6:28you can see all of the different sizes of your virtual machines

6:31that you can deploy.

6:32Again, this is a SQL server.

6:34So chances are we're going to want at least two cores and 8

6:37gigs of RAM, depending on your workload, of course.

6:39But you can also choose different size

6:42virtual machines, depending on the different series

6:44that you have here.

6:45It also gives you kind of like what

6:48we were doing with the platform as a service offerings,

6:50where you could choose the different kinds of CPUs

6:53or resource optimizations if that's

6:56what you want to dig into.

6:57So you can see the different series

7:00for higher memory speeds or continuous full CPU

7:04performance.

7:05That's the idea with all of these different series

7:07of virtual machines.

7:09The standard general purpose virtual machines,

7:11though, are almost always the D series of virtual machines.

7:15And when you see things like the D2,

7:18D4, D8, what you're really looking at there

7:21is the number of CPUs that it has.

7:25So when I see the D4s version 3, this

7:28is going to be the third version of a general purpose

7:32server virtual machine here that has

7:33four cores and 16 gigs of RAM.

7:36It can have up to 8 data disks, and its Max IOPS is 6,400.

7:42So, again, this is probably going

7:43to be a very, very important thing

7:45for you to make sure you're looking

7:46into the IOPS and performance as well.

7:49So when I see things like the D2as version 4 here,

7:54I know we've got 2 cores, 8 gigs of RAM, and 3,200 IOPS.

7:58If that's not going to meet my performance needs,

8:01maybe I could sacrifice 1 gig of RAM for higher IOPS.

8:05Or maybe I need to jump down here into the larger size VMs,

8:08like the D4s_v3.

8:10Let's click Select there on that particular one.

8:13I see it's going to cost $308.06 a month.

8:17Now for a Windows Server Virtual machine,

8:19you do have to specify a local administrator account first

8:23before you can do things like domain join in.

8:26So I'll type in a local administrator account,

8:29here we go.

8:30And also point out right there that the name that you gave--

8:35I forgot to mention this-- the name of your virtual machine

8:38will also be the hostname of your VM2.

8:41I'm going to allow 3389 inbound, so we can already be up to it.

8:44And right here there's the checkbox

8:45where you can reduce the licensing by owning

8:48the Azure hybrid benefit.

8:49This is specifically for the Windows Server license.

8:53Just the Windows Server.

8:54If you were trying to do the SQL server license,

8:56you need to make sure you pick that from the image,

8:59the (BYOL) license.

9:02Now the number of disks that get attached

9:04to this virtual machine by default. If we take a look here

9:07and we go under Advanced, we're not seeing any virtual disks

9:11here, are we?

9:12Well, that actually has to do with the fact

9:14that we did a SQL virtual machine deployment.

9:17It's already getting a handle adding the additional disks

9:20for things like our database files, for our log files,

9:23for our temp files.

9:25Trust me, we'll see more of that in a second.

9:27Now let's jump into the Networking section here.

9:29Well, since we're deploying a new resource

9:31group and a new virtual machine in that resource group,

9:34it's going to attempt to scaffold

9:36a virtual network for us.

9:39And by default, it uses a subnet within a block of IP addresses.

9:43In this case, it's 10.0.0.0/24.

9:48What I'm going to do is I'm actually

9:49going to choose to create a new virtual network here,

9:52and I'm going to change this up a bit.

9:53I don't want to use this particular block of address

9:57space.

9:57I want to use something like 10.99.0.0.16.

10:03And, therefore, I'm going to have to create

10:05my own subnet for this.

10:07I'll call this default SQL, and give it the address range

10:11or address name of 10.99.00/24.

10:15It's going to be a little bit of subnetting there for you,

10:18so don't worry if you don't totally understand that.

10:21You may want to learn a little bit

10:22about subnetting at some point because it's

10:24very, very interesting stuff.

10:25And we've got some great IPv4 subnetting content here

10:28on CBT Nuggets that Keith Barker teaches.

10:30I'll click OK to this, and we see

10:32it updates this to have a new subnet that

10:35doesn't overlap on my particular on-premises subnets.

10:39Because ultimately what I'm going to want to do is I'm

10:42going to want to create a site-to-site tunnel,

10:46and I can't have the same subnets on-premises

10:49as I do in this virtual network.

10:52So with all that being said here,

10:53I've got the virtual network scaffolded.

10:55And here there are a bunch of different additional parameters

10:58that you can specify, like a network security

11:00group which kind of acts like a sudo firewall.

11:03I am going to allow 3389 in, so I can still

11:06reach this virtual machine and reachable

11:09on the actual network.

11:11So with that being said, we'll move on to the Management.

11:13Well, there's not a whole lot here that we want to do,

11:15except for we may want to enable Boot diagnostics which

11:19comes by default with the managed storage account.

11:22There's some content in the AZ-801 certification exam

11:26that covers the difference between the managed storage

11:29account and the custom storage account.

11:31The big difference here is with the custom storage account

11:33you can actually get direct access to the console

11:38of the virtual machine.

11:40Whereas with the managed storage account,

11:41you really are just looking at boot logs at that point.

11:45So that's it, that's what I want to do.

11:47There is for some virtual machine images,

11:50there is the capability to do log in with Azure AD,

11:52this is not one of them.

11:53And at this point I'm just going to leave the rest alone

11:56because we're going to cover the rest of that upcoming later.

11:59I'm going to jump to the SQL server settings

12:01because this is where the interesting stuff is.

12:03Here we have the ability to specify our SQL connectivity.

12:08By default, it only allows SQL connectivity

12:12via within the virtual network.

12:15If we've tried to fire up SSMS and connect to the SQL server

12:19over the public internet, it is not accessible.

12:22So you would have to switch this to the public internet

12:26if that's what you want to allow.

12:28Otherwise, this is only going to be

12:30accessible within the virtual network

12:33itself via the private IP address

12:35effectively, is what it's saying.

12:37You're specifying the port that it's listening on.

12:39Now, SQL authentication, do we want

12:41to enable SQL authentication or do we want to leave this

12:45to a particular user?

12:46If I put Enable here, it is going

12:48to specify a login name, as well as

12:51a password for what is going to be the administrator account.

12:55Let me go ahead and just specify an administrator account there.

12:58There's also the ability to do Azure Key Vault integration,

13:01which is where we can store secret keys

13:04and certificates where this particular SQL

13:07server can access that.

13:08So that's something we will talk about in a later set of videos,

13:11we won't dwell on that too much right now.

13:13Check this out, the storage configuration.

13:16OK, let's do change configuration

13:17and you'll see what's going on here.

13:19See, this is where it adds the disk types here.

13:22Now we've got a 1 terabyte drive with 5,000 max IOPS,

13:26throughput 200, and there is one disk here

13:29to be used for the data drive location.

13:32Again, if you need to specify these things

13:35or change these things, this is where

13:36you can go about doing it.

13:37Similar items for the actual log storage, it says,

13:41use a separate drive for log storage.

13:43Again, 1 terabyte drive, same settings,

13:45effectively using the premium SSD.

13:48And then the TempDb storage, this

13:50uses a local SSD drive stored right there on the spot.

13:55You can configure your TempDb files,

13:57that way you can see the number of files,

13:59initial size, and auto growth, and configure

14:02the TempDb log file as well, right here on the spot.

14:06So we'll click OK to that.

14:08Now we can actually configure the SQL instant settings

14:12itself.

14:14Give this a quick click here--

14:18try and say that three times fast.

14:19And then you can specify, first of all, your collation

14:22and then the max degree of parallelism to option,

14:26to the limit, and the number of processors

14:28to use in parallel plan execution.

14:31We can also specify our SQL server memory limits.

14:34And do notice right here that it does, in fact,

14:37set a max memory limit.

14:39Right here it looks like it's roughly 2 megabytes in size.

14:42Remember, though, are two-- yeah, excuse me,

14:45what am I saying here?

14:46This is specified in megabytes right here.

14:49So this gigantic number here effectively

14:51means that it's going to eat up as much memory

14:54as the host virtual machine will allow it to at this point.

14:58But you can specify a max server memory right here

15:02if you want to manually set it.

15:04We also have the ability to optimize for ad-hoc workload,

15:07lock pages in memory, instant file initialization which,

15:10of course, reclaims storage space that's been

15:14used by filling it with zeros.

15:17Interesting idea there that it can actually

15:19instantly initialize the file operations when it needs to.

15:22I'm going to discard all this, and then we'll scroll on down.

15:25Notice something else here, we can

15:27automate when Windows and SQL Server

15:31will be patched, right here.

15:33And notice, very, very important.

15:34This is enabled by default for Sunday at 2:00 AM.

15:38You may not want your SQL Server to automatically patch itself.

15:43And this is a configuration that you would want

15:45to change when you do that.

15:47Also notice that the Azure SQL platform

15:49has the ability to actually automate backups themselves.

15:53So if I click Enable here, we can set things,

15:56like our retention period.

15:57We specify what storage container, basically

16:00what blob storage do we want this to live on.

16:03Do we need to enable encryption?

16:05Do we want to back up the Sys Db?

16:07Do we need to configure the automated-- do

16:09we want to manually configure our backup schedule?

16:12Or do we want to leave this to the default backup schedule?

16:14Which is the one that we actually

16:16talked about when we were going through the evaluation

16:19of our SQL resources.

16:21Then, of course, we have the ability

16:22to enable our services with Advanced analytics, which

16:25is great for the machine learning operations.

16:28So having made all of these changes here,

16:30I am going to review and create my virtual machine,

16:33and let it go through the process of creating

16:36all of the resources.

16:38Starting with the resource group,

16:39the virtual network, then the actual virtual machine

16:42itself, which has the image of MySQL server on it.

16:46So all of these things here look good to me.

16:49I pass Validation, I click Create, and there it goes,

16:53it's off to the races.

16:54I'm going to circle back to it when this virtual machine has

16:57been deployed.

16:58Now while this is deploying, I want to point out

17:01this template over here.

17:02If you've been following along in your deploying

17:04your own virtual machine, and you

17:06plan on continuing with this content,

17:08you'll want to click out this template button right here.

17:11And then you'll want to download this template.

17:14This is going to be really, really important for us later

17:17down the road in a different set of videos.

17:19I'm going to click Save here.

17:20I'm also going to click Add to library.

17:23This is going to be a fun one to remember.

17:25So let's add this item to the library real quick.

17:29And we'll give this a name called knox-sql-iaas, something

17:34simple like that.

17:35I'll put this in-- may just put it in my app-- no, let's put it

17:38my sql-iaas-group, that's where I want to put this.

17:41And I'll just say Review and create.

17:42Or actually we've got to put a version number here,

17:45let's put version 1.

17:46And we'll just go ahead and say Review

17:48and create to save this template real quick.

17:51There, create, just like that.

17:52Now we've saved this template while the resource

17:55is deploying.

17:55And we'll be able to deploy from that template later.

17:58Trust me, that's going to help us a lot when the time comes.

18:02All right, so the total resource deployment time

18:05is about seven minutes to get this thing

18:07completely up and running.

18:09I'm going to go into the resource itself.

18:11And now I actually see that I have a virtual machine,

18:15I see its public IP address located here,

18:18and I see its private IP address located right here.

18:22I can connect to the virtual machine with RDP,

18:25and we will do just that.

18:27Let me get logged in.

18:29It takes just a moment to get into the virtual machine

18:32itself.

18:33If I click Start here-- let's just take

18:35a look to see if it's working.

18:36Under the SQL server section-- well, first of all,

18:38let's see if the SQL Service is installed, right?

18:40I can bring up the configuration items,

18:43and I see right there the SQL service is running.

18:46That's a great start.

18:48Let's bring up SQL tools, launch SSMS,

18:51and see if we can connect in to this local machine using

18:55the credential specified.

18:57Again, remember I was doing a SQL authentication.

19:01So we can use Windows authentication or SQL server

19:04authentication.

19:05Let's start with Windows authentication

19:07because it is in mixed mode.

19:08Click Connect, and boom, we are connected.

19:11We don't have any databases yet but guess what, we now

19:15have a functioning SQL server using

19:17infrastructure as a service in the Azure cloud.

19:20So that's how you go about deploying this particular type

19:23of resource.

19:24In the next video, we're going to focus in

19:26on how to deploy the platform as a service offerings.

19:29I hope this has been informative for you,

19:30and I'd like to thank you for viewing.

Single Azure SQL Database Deployments

0:00[MUSIC PLAYING]

0:06Now we're going to jump into the portal and, this time,

0:09deploy a platform as a service offering.

0:11We're going to be deploying an Azure SQL database.

0:15Now, I want to tell you right now, the thing that oftentimes

0:17throws people for a loop is deploying the Azure SQL

0:21server first because it's just a logical SQL server.

0:25And it feels a little fuzzy the first time you do it.

0:28But don't worry, because we're going to make some sense out

0:30of it in this video.

0:31Let's start deploying an Azure SQL database.

0:34Now we're going to have some fun and get a quick and dirty SQL

0:37database brought to life using the Azure SQL platform

0:41as a service offerings.

0:43Remember, this one, when we deploy

0:45just an individual database, is just that.

0:48It's an individual database that,

0:51by default, comes with a publicly accessible, fully

0:55qualified domain name.

0:56And this is perfect for deployments that are, really,

1:00based on platform as a service offerings

1:03that we're going to integrate into many different apps,

1:06particularly in the Azure fabric.

1:09We can either go to the SQL virtual machines,

1:11or just jump straight into SQL databases.

1:14I'm going to do SQL virtual machines, first of all.

1:17Because we do see my SQL virtual machine right here, don't we?

1:20Yeah, here it is.

1:21I'm going to click Create, and then it

1:23should jump me into this page right here,

1:25where we see the three different types of the Azure SQL

1:28platform.

1:30Now, for this video, I'm going to be

1:31deploying a single database.

1:33But trust me, there is going to be

1:34a moment that kind of throws you for loop

1:37the first time you see it.

1:39I'm going to click Create to jump into the wizard,

1:41and we're going to get started with this right now.

1:44I'm going to change my subscription

1:45to be the right subscription.

1:47I'm going to put this into my SQL group,

1:49even though it does say sql-iaas.

1:51I know, I know.

1:51Now, for the database name, you see some constraints

1:54immediately, like it can't end with special characters

1:57or contain these particular special characters.

2:00The database names shouldn't be empty.

2:03Now, we are going to attach this database to a SQL server.

2:07And that SQL server-- this can't have the same database

2:11name of any other databases that are attached to that SQL

2:14server.

2:15So let's go ahead and type this in.

2:17We're going to say knox-sql--

2:19I'm going to call this P-A-A-S for Platform As A Service.

2:22And I check--

2:24I get the little check mark here that says everything

2:26is passing the checks here.

2:29Now, the SQL server itself, is something

2:31that will have to create for the first time.

2:33This is a pretty interesting concept

2:35to wrap your head around because this SQL server isn't

2:39like a typical SQL server.

2:42This is just a logical instance that you will connect to.

2:48This SQL server will have a fully qualified domain name

2:53that you will connect to over the public internet,

2:57for the first time that you connect to it, using SSMS.

3:01Now, how you connect to it and how you authenticate to

3:04it is something that we're going to cover.

3:05But I just wanted to wrap your head around this right now.

3:08You're not paying for this logical instance.

3:11You're paying for the amount of compute

3:14that is dedicated to this particular database.

3:17And you can have multiple databases connected

3:20to this one logical instance.

3:23And you'll pay for each of those databases individually.

3:27So really, all this SQL server is,

3:30is just a connection point into the associated databases

3:34and how you authenticate to it, and that's really about it.

3:38Let's go ahead and create the SQL server for the first time.

3:41Notice, it is going to end with .database.windows.net.

3:45So if I call this knoxsql, check it out.

3:48This is uniquely identifiable around the world.

3:51I'm going to also put this in South Central US where

3:54the rest of my SQL items are.

3:57Now, look here's where we can specify the authentication

4:00method.

4:01We can use SQL authentication.

4:03We can use only Azure Active Directory authentication,

4:07and you have to specify an admin upfront.

4:10Or we can use a mixed mode of both.

4:13So I'm going to choose mixed mode, just for good measure.

4:15I'm going to set my Azure AD admin to be myself.

4:19I'll search for myself, click on my name, and click Select.

4:23Now I have an Azure admin located here.

4:26I can also specify a manual Azure admin for a login here--

4:31a local login--

4:33for the SQL server instance itself.

4:36Again, this is for the SQL instance,

4:38not the given database.

4:40You will be able to attach many different databases

4:43to that instance, and this is where

4:45we're specifying the admin of all of those databases.

4:48So I'll click OK here.

4:50And now it's going to create a new SQL server

4:53instance that we can specify.

4:56Notice here, we've got the elastic pool option here.

4:58We also have compute and storage that we specify here.

5:02Now, we covered this in great detail.

5:04For very simple reasons, I'm just going to drop this

5:07in basic and just leave everything else the same

5:10because this is very, very cheap to deploy at $4.90 a month.

5:14And this is just a lab environment

5:15at the end of the day, anyways.

5:17So now that I've got the basic tier set for the DTU model,

5:20we can also look at the backup storage redundancy.

5:23Remember, again, that backups are automatic with the given

5:31Azure SQL database.

5:33And when we choose geo-redundant backup storage,

5:36this is going to replicate to a different data

5:40center, a different region in Azure,

5:42and give us read access to those database backups.

5:46Now, in the networking tier, this

5:48is going to be an interesting thing.

5:51You would think that this is what

5:53specifying the connectivity to the actual SQL server.

5:57But this is actually creating unique objects when

6:01we look at the connectivity method

6:02so that other applications in Azure see this endpoint

6:07and can connect to this endpoint,

6:09rather than an IP address or a fully qualified domain name.

6:13We can skip this because it does allow

6:15you to create these services after the fact,

6:18after deployment.

6:20The connection policy also here is how clients communicate

6:23with your SQL database server.

6:26When it's within Azure, by default--

6:29we've got Default selected.

6:30When it's within Azure, it tells you right here,

6:32"Clients establish connections directly

6:35to the node" using the redirect method.

6:38When it's outside of Azure, coming in,

6:41all connections are proxied via SQL database gateways.

6:45Remember that database.windows.net?

6:48That's really a proxy.

6:49There's only two IP addresses that that resolves to.

6:52And from there, it knows based on the host name

6:57that's being connected to, the record that's

6:59being connected to.

7:00From there, it knows to redirect you

7:02to the correct Azure SQL instance in database

7:06using the proxy.

7:07So leave this as default. And for encrypted connections,

7:10you'll want to leave this as a minimum of TLS 1.2--

7:13that is the latest version--

7:14unless you have a really old application

7:18that needs to connect over older standards of TLS.

7:22Now with that being said, I'm just

7:23going to jump ahead a little bit, past Security

7:25and Additional Settings, because we just want

7:27to get this resource deployed and then connect

7:29to it via SSMS.

7:31So I am going to create this configuration real quick

7:34and deploy the Azure SQL database.

7:37It should deploy pretty quickly.

7:39So we'll come back to it when it's done.

7:41So it doesn't take terribly long for the resource

7:44to get deployed.

7:44We see that the SQL server has successfully deployed

7:47with a database instance to it.

7:49When we click on it, it says get started

7:51working with your database.

7:52But first, we have to configure access to your SQL server.

7:56It doesn't allow anybody in over the public internet by default.

8:00I know, that was probably something

8:02you were worried about, is that when you deploy these

8:04and it's got a fully qualified domain name, that it just

8:07allows anyone in.

8:08It doesn't.

8:08Let's go to Configure so that we can allow access

8:11for a specific network or a specific IP address

8:16to be allowed in.

8:18Check this out.

8:18With public network access, it does allow public network

8:22access to selected networks.

8:24Otherwise, we can just disable it outright.

8:27We can choose what virtual networks are allowed

8:30to connect to our public access endpoints

8:34if we created those endpoints.

8:35Otherwise, we could allow specific IP addresses or IP

8:40address ranges to be allowed in.

8:42It detects my IP address by default.

8:45So I can white-list my IP address

8:48by clicking this "Add your client IPv4 address" and click

8:51Save.

8:52So now only my IP address can connect in to the actual SQL

8:59server instance itself.

9:01And then, of course, it has to pass authentication from there

9:04in order to actually be connected.

9:06So now that I've gotten my IP address white-listed right

9:10here--

9:12no, you can also specify a firewall rule.

9:14So you can specify a starting IP and an ending IP

9:18if you want to white-list a range or a subnet

9:20that you may have public access to.

9:23So let's jump back to my SQL database now.

9:26And now that I've got the configured access,

9:28we could choose to connect--

9:30we could get our connection strings

9:32in order to actually connect our applications into it.

9:35Or we could actually start editing

9:37or developing directly right here within the platform

9:40itself.

9:41Now that is in preview, the query editor.

9:43It's still in preview right here.

9:45I want to point that out.

9:46But you can-- look.

9:48Because we chose to log in with Azure authentication,

9:51it does allow me to continue.

9:53Right here, look, boom.

9:54Now I'm connected into this database

9:55where I can create tables and everything like that.

9:58I also see hooks into the Power Platform,

10:00like Power BI, Power Automate, and Power Apps.

10:03Again, I want to stress this.

10:05Power Automate is something that individual users

10:08can use on their account.

10:09Logic Apps is the equivalent for developing a central workflow

10:15application.

10:16And that's probably better suited

10:18for most systems administrators.

10:20Now let's actually go ahead and get

10:21connected into this SQL server.

10:23Let's see how we go about doing that.

10:26From the Overview pane right here, I

10:28see my server name knoxSQL.database.windows.net.

10:32What I can do is I can actually launch SQL Server Management

10:35Studio on my local computer.

10:38And because I've white-listed my IP address,

10:41I can go ahead and get connected in.

10:43Once SSMS gets launched up on my computer-- it's still

10:46launching right now-- then we'll go ahead and get connected.

10:51So here we go, SQL Server has launched on my screen.

10:54I'm going to change my server name

10:56to be the knoxSQL.database.windows.net.

10:59Now, remember I set this to be SQL authentication as well

11:03as Azure Active Directory authentication.

11:06So we have three different options

11:08for how to do Azure SQL--

11:10or Azure Active Directory authentication.

11:12There's the universal with modern factor authentication--

11:16or multi-factor authentication, excuse me.

11:18So if you have modern authentication set up

11:21and MFA enabled on a particular account,

11:25this is the method that you want to specify.

11:27All you have to do is type in a username right here,

11:30and it'll actually pop up a window in an embedded browser,

11:35where it walks you through the login process

11:37and validates your credentials.

11:39Otherwise, you can specify your username and password right

11:42here.

11:42I'm just going to use SQL authentication right

11:44now because it's very easy.

11:45I know my username and password.

11:47I actually don't know my Azure password.

11:50All right, we're going to click connect here, and boom,

11:53I am connected in just like that, because there's

11:56my database, because I white-listed my IP address

11:59and I used the credentials that we're allowed to use.

12:03So now I have successfully deployed a platform

12:05as a service offering using the Azure SQL Database options.

12:10In the next video, we'll take a look

12:11at how to do it with an elastic pool.

12:13I hope this has been informative for you,

12:15and I'd like to thank you for viewing.

Elastic Pool Deployments

0:06Now, we're going to deploy an Azure SQL database again,

0:09but this time, we're going to focus on deploying it

0:12within an elastic pool.

0:14Remember, the idea here is that you can buy a bundle of compute

0:18and then deploy your Azure SQL databases attached to that.

0:22That way when some have an unexpected spike in workload,

0:26we've already paid for a pool of compute resources

0:30that our databases can actually pull from and scale using that.

0:34So let's deploy an Azure SQL database

0:36within an elastic pool.

0:38So in the previous video, we got a public

0:40facing Azure SQL database up and running.

0:43Woo-hoo!

0:44Congrats to us.

0:45But now, we want to take it a step further

0:47and start deploying our databases at scale.

0:51But it could be tricky, because our databases could

0:53have unpredictable workloads.

0:56And it would be ideal to just reserve a pool of compute

1:00and then deploy our databases into that pool.

1:04And that's what Elastic pools do for us at the end of the day,

1:07right?

1:07Here we see SQL elastic pools as a resource

1:11that we can create and deploy.

1:13Let's start by clicking on that and actually creating

1:16a SQL Elastic pool.

1:18So we'll click the Create button,

1:19and it takes us in to the basics of deploying

1:22this configuration.

1:23I'll change my subscription.

1:24It automatically dumps me into my resource group

1:28that has the SQL resource groups in it.

1:30But you can choose the ones or create a new resource

1:33if that's what you want to do.

1:34Now, what we can do is we can choose an elastic pool that we

1:39want to create and deploy to.

1:41Notice though, pretty interestingly,

1:44how this all came together is trying

1:46to pick my server as the elastic pool,

1:50or that's going to be the authentication and connection

1:53point into the elastic pool.

1:55So think about this.

1:57If I'm here smiling on my computer in my office

2:01and I connect in over the public internet,

2:05I was going to write internet right here, into Azure,

2:08what am I connecting into?

2:10I am connecting into this Knox SQL server,

2:15and that Knox SQL Server is logically

2:18connected into the database that we

2:20deployed in the previous video that I reserved for $5 a month.

2:25But now I can also deploy an elastic pool of resources

2:31and have this still be my connection

2:34point to connect into in order to reach these databases that I

2:39want to deploy.

2:41So that's the idea that we're having here, keeping in mind

2:44that the SQL server really isn't so much a SQL

2:47Server in the traditional sense that you're

2:49used to administering, but rather it's just the connection

2:52point to get to this group of databases.

2:55Sure, you can spin up multiple SQL servers,

2:58doesn't cost you a penny to create the server itself.

3:02What you're reserving is the workloads

3:05for the individual databases.

3:07Now, here is where you specify what your pool is going to be.

3:12And guess what, it looks exactly like the previous options

3:15that we have, doesn't it?

3:16If we click on the Configure elastic pool,

3:18well, guess what, we still have general purpose

3:20and business critical, but we no longer have hyperscale.

3:24Thus, the only thing that's missing from this dropdown

3:28now is it removes hyperscale out of the mix,

3:31because the idea with hyperscale is

3:33you are trying to hyperscale a single database rather

3:38than a pool of databases.

3:40So I'm going to leave this at the general purpose

3:42as it is now, and that's really all you

3:45need to do to create your pool.

3:47So let's review and create this.

3:49Oh, I got validation field.

3:50Something messed up somewhere.

3:51Let's figure out where it's going.

3:52Oh, I forgot to get my pool name, duh.

3:54Let's call this azsql--

3:56just got to spell SQL correctly though-- sqlpool.

3:59And now, we're OK to go.

4:00Now, let's go to review and create validation succeeds.

4:03And I'll create my Azure SQL pool of resources.

4:07So that'll take a moment to deploy this.

4:09And then we can deploy databases directly into this pool.

4:13Let's let that sit for a second and come back

4:15to it when it's done.

4:17So the Elastic pool gets deployed pretty quickly.

4:19I can go to the resource.

4:20And now, I actually have a menu where

4:22I can look at the elastic pool overview.

4:25Very, very cool to see this because I can see the resource

4:28utilization for the entire pool or, very cool,

4:32under the monitoring section if you scroll down

4:34just a little bit, you can see these storage.

4:37There's also database resource utilization

4:39which is pretty neat.

4:40You can see for individual databases what

4:43the CPU percentage, data space, Log IO, Workers, blah, blah,

4:46blah, blah, are.

4:47So that's actually a really, really interesting thing.

4:50And this is a great way to manage and maintain

4:52your overall pool.

4:54We can also set up maintenance windows

4:56and set up SQL health alerts too which is also pretty nice.

5:00There's even some quick starts to help you get started with

5:02connecting to your database, as well as using the SDK a four C#

5:07and other programming languages as well.

5:09All right, now that the pool has been deployed,

5:11let's start deploying resources to those pools.

5:14This is not going to look too unfamiliar

5:16from what we just did.

5:18I'll create a new SQL database here,

5:20choose the correct subscription, got in the right resource

5:23group.

5:24It automatically defaults to the correct server.

5:27I'm going to give this a new name like knox-sql-paas2.

5:32Because this is a unique database name,

5:34it can be linked up to the server.

5:36And I'm going to say, yeah, I want to use the Elastic pool

5:39the one I just created right there.

5:41So now I've got this SQL database

5:43as part of the elastic pool.

5:45And with everything else looking good,

5:48I can review and create this database.

5:50So now, I'm not paying for this necessarily

5:53at the individual database level but rather at the entire--

5:57rather it's just coming from the prepaid pool,

6:00effectively, is what it's doing.

6:02So the deployment is in progress.

6:04And when I open up SSMS and connect to that SQL server,

6:08it should dump me right there into the pool.

6:12Now, with that being deployed, I'm

6:13also going to deploy one more database

6:15into the exact same pool at the exact same time.

6:18Look at this.

6:18I'm a madman like this.

6:20I'm going to call this knox-sql-paas3, got

6:25to give it a unique name.

6:26Leave everything the exact same.

6:28Yeah, I'm going to put it in the elastic pool

6:30that I created before, reviewing create and create.

6:34Boom, there we go.

6:35So now I've got two Azure SQL databases

6:38coming from that same pool as soon

6:40as this resource gets deployed.

6:42So once this resource is deployed,

6:44we will pull up SSMS, get connected to the SQL server,

6:48and validate that I see all of those three databases.

6:51Let's give it just a second to get done deploying.

6:55Deployment succeeds relatively quickly.

6:57It takes just a few seconds to get it up and running.

7:00But the ultimate test is, did it work?

7:02We're going to launch SQL Server Management Studio one more

7:05time from my platform item right here,

7:08and we'll get connected in to the actual database

7:11once SSMS gets done loading up.

7:14OK, so in this case, now, notice here 10.99.1.4.

7:17That was actually the infrastructure

7:19as a service virtual machine that we deployed

7:21a couple of videos ago.

7:22I got to site-to-site VPN set up between my office

7:25and that virtual network.

7:26It was just validating that I had connectivity.

7:28Let's jump back though to knocksql.database.windows.net.

7:33Type in the local admin credentials, get connected in

7:38and let's see what's under my databases.

7:40Now, if I expand it, ah, there they are.

7:43Now, I have three databases deployed.

7:45One was deployed with a basic deployment model, using DTUs.

7:50The other two was using vCore models

7:53in an elastic pool, all linked to the same logical SQL server.

7:58Isn't it beautiful?

7:59That's how you deploy Azure SQL databases

8:02in the platform as a service offerings using Elastic pools.

8:05I hope this has been informative for you,

8:07and I'd like to thank you for viewing.

Azure SQL Managed Instance Deployments

0:05Now this is going to be the big one, where we're actually

0:08deploying kind of the mixture of both.

0:10This is the platform as a service offering

0:13that happens to attach itself to an Azure VNet, which is really

0:17the infrastructure as a service section of Azure itself.

0:21Remember the big thing here is that we are still abstracting

0:25away the need to manage the operating system,

0:28as well as the SQL server instance itself.

0:31But we get almost identical functionality

0:35to all of the things that SQL server can do.

0:38We get things like the temp dB, we

0:39get things like the SQL agent, and many other things

0:43along with that.

0:44So we're going to deploy this instance in this video.

0:47But I want to tell you right now, if you're

0:49starting from scratch, if you're building this up

0:52for the first time, this can take a very long time

0:55to deploy, especially if you have

0:58to do something like deploy a site-to-site VPN first.

1:01For instance, if you're deploying

1:03the VNet for the first time and all the resources

1:05to it for the first time, you're connecting the hybrid network

1:08connection using the site-to-site VPN

1:10for the first time, then deploying the Managed Instance

1:13on top of that, you might as well clear out your day.

1:15And it's not because it's a lot of work,

1:17it's because these resources take a very long time

1:21to deploy, sometimes hours, from the moment you click Start.

1:25So I'm just warning you right now.

1:27If you're going to be following along and doing

1:28this, first of all, you can rack up a big bill doing this.

1:31Second of all, it takes a long time.

1:33So just brace for impact on that one.

1:35All right, let's get going deploying an Azure SQL Managed

1:37Instance.

1:39Now, our final resource that we're

1:41going to deploy in the Azure SQL platform-- of course,

1:44I'm saving the best for last-- and that's

1:46going to be the Azure SQL Managed Instance.

1:49This is a big one to deploy.

1:51And I'm telling you, it takes a long time to deploy.

1:54Now I'll tell you right now one thing that I've already done.

1:58I've already got my HQ network, right here I am in my HQ.

2:03I have already connected it in to an Azure Virtual Network.

2:09The same virtual network that we deployed when I deployed

2:13the SQL virtual machines.

2:15Recall that the subnet for that virtual network was

2:1710.99.1.0/24 bit mask.

2:22Let me write a two a little bit better than that.

2:24So this is what is the virtual network that I am targeting.

2:27And I want MySQL Managed Instance to get an IP address

2:30out of 10.99.1.0/24.

2:34And I want to be sitting here on my local SSMS launcher,

2:39connecting in to that Managed Instance

2:42using the private IP address.

2:44Now, I did kind of hint at that in the previous video.

2:46I've already validated that network connectivity works,

2:49because I can get to the Azure SQL VM

2:53that we deployed previously.

2:55I can connect in using SSMS, so network connectivity

2:58is already there.

3:01If you haven't gone through the process of deploying

3:03a site-to-site VPN yet using the virtual network

3:07and the virtual network gateways,

3:08the local network gateways, I'd encourage

3:10you to watch the content on CBT Nuggets on how to deploy that.

3:14That can be an expensive process,

3:16and it is very time consuming too.

3:20The virtual network gateway can take up to an hour to deploy.

3:25In my experience it's been about 30 minutes for just

3:29the resource to deploy.

3:31Then you have to go through the process of configuring

3:33both firewalls, or in this case, the virtual network gateway

3:37connection on both ends.

3:39And then validate the connection comes up and takes place.

3:42The connection itself can take several minutes

3:44to come to life, and you'll spend something

3:46like five minutes troubleshooting

3:47why isn't it up.

3:48It will come up, you just got to give it

3:50some time to actually breathe and get there.

3:53So with all that being said, I have network connectivity

3:55between my on-premises and the virtual network

3:59in place already.

4:00And now I can deploy the SQL Managed Instance.

4:04So we have an option here, single instance

4:06or single instance with Azure Arc.

4:09You may be wondering what is Azure Arc.

4:12There are some types of specific servers that you in your HQ

4:18can deploy that server in your HQ,

4:22and manage that server from Azure, right here.

4:28So when you want to deploy a new virtual machine,

4:31you go to the Azure portal and you

4:33click on a new virtual machine.

4:35But you can tell it to deploy down here

4:38on your on-premises server.

4:41That is all enabled using the Azure Arc service.

4:46So when you see here that you can deploy a SQL Managed

4:49Instance with Azure Arc, you should really be thinking,

4:53I can deploy a SQL Managed Instance from the Azure portal

4:58into my on-premises resources because those on-premises

5:03are connected via Azure Arc.

5:05It's just a hybrid management option

5:08that's helping people get more into Azure for their management

5:12even if they're managing on-premises resources.

5:15In my case, I'm choosing single instance

5:17because I'm trying to deploy this in the cloud.

5:19So I'll click Create and it takes me

5:21into the management section.

5:23And this is where it gets kind of fun.

5:24I'm going to choose Pay as you go.

5:26And I'm going to choose My resource group, the one that

5:29has MySQL IaaS resource group.

5:31Now, this is the interesting part,

5:33you cannot deploy this in all regions.

5:37There are only specific regions that you can deploy this in.

5:41In fact, sometimes you'll choose a region like East US

5:45or East US 2, and it'll tell you the Managed Instance

5:48is not available for the chosen subscription and the region.

5:53You have to request that region access.

5:56Kind of interesting, right?

5:58Well, in my case, I'm going to choose South Central US,

6:01and that warning goes away.

6:02So now I have the ability to put that

6:04on the virtual network in the South Central US

6:07that's in that resource group.

6:10I'm going to call this sql-mi for the Managed Instance name.

6:14Oh, but that specified server name is already in use.

6:18How about sql-mi-knox?

6:19Yeah, there we go.

6:20Now we've passed the test.

6:21So SQL Managed Instance Knox, that is not a Managed

6:25Instance that is in use.

6:27The Managed Instance size, no, this is big, 8 vCores,

6:31256 gigs of storage-- that's kind of small--

6:34Geo-redundant storage.

6:36Let's click on Configure Managed Instance here, and you

6:38and see your estimated cost for this general purpose

6:42virtual machine.

6:43Using just the standard series of everything,

6:46we're looking at $1,681 a month for the eight virtual cores

6:50and 256 gigs of storage.

6:52If I ratchet this down to four virtual cores,

6:55it does cut the cost in half.

6:57You can apply your own license, bring your own license

7:01for a Azure hybrid benefit, and you can choose

7:04your backup storage redundancy.

7:06Again, we are talking platform as a service here,

7:10and Azure will automatically take backups of the storage.

7:15Now this is kind of another interesting thing

7:17that we haven't really hinted at because it

7:19is a very specific nuance.

7:22When you set your storage for the database itself,

7:25like 256 gigs, you get that amount of storage

7:31provided free.

7:33So if you have 256 gigs of storage for the server,

7:38then you will get that much storage

7:41for the backups provided in addition completely free.

7:45Anything over this amount is where you

7:48start to rack up the charge.

7:50So that is the one thing that I wanted

7:51to point out just so it is a nuance to the platform

7:54as a service offerings.

7:55Now that being said, I'm going to click Apply here,

7:58so we have the sizing specified.

8:00The authentication, I am going to do, yet again,

8:03select both SQL and Azure AD authentication.

8:07I'll choose my admin here as Knox, let's go ahead

8:10and choose Knox.

8:11And I'll specify an instance log in for a local credential,

8:16just so that we've got it, type in the password here.

8:20But I got to type it correctly, that's an important factor

8:23for deploying databases.

8:25All right, well, no this is interesting,

8:27the password must be 16 characters in length.

8:31So my password isn't long enough.

8:33So let's do this, let's do an extra one.

8:37Is that good enough?

8:37One-- no.

8:38Yeah, OK, no, no, I just needed to add

8:40an additional character there of my password's 15 characters now

8:43and 16 characters.

8:45OK, now let's go to the Networking section.

8:47I want to make sure that this gets

8:49put on my other virtual network that is ready for a Managed

8:54Instance.

8:54But notice here my virtual networks are not

8:57ready for a Managed Instance.

8:58Well, what's this all about?

9:00One of the interesting requirements that's actually

9:03pointed out in the connectivity architecture of the Managed

9:07Instance is right here, it has to be a dedicated subnet.

9:12No other resources are allowed to be on the same subnet.

9:17Right here, the subnet can't contain any resource

9:20but Managed Instances.

9:22And you can't later add other types of resources.

9:25Well, hang on a second, let's look at this.

9:28In my subnets, what did we do?

9:31In the first subnet, my default subnet,

9:33we deployed a virtual machine and the gateway subnets

9:36used for my VPN.

9:38So I have to go back and create a new subnet

9:40right now that this Managed Instance can use.

9:44So let's do that.

9:45I'm going to go back to the basics here for one second.

9:47And you know what?

9:48This isn't-- It's going to--

9:49I'm going to have to blow this thing up.

9:50I'm just going to come back to this.

9:52Give me one second while I create a new virtual network.

9:54Here I'm going to jump into the VNet real quick,

9:57go down into my subnets.

9:58We'll create a new subnet real quick,

10:00I'll call this Managed Instance.

10:03The subnet range 10992 is perfect.

10:06I'll click Save.

10:07I am going to have to go back and edit my VPN,

10:11because this is going to break my VPN since they do not

10:14agree on the subnets that are in use right here.

10:17So I'll fix my VPN real quick, and then we'll

10:20be able to proceed.

10:23So I've just reconfigured the VPN just

10:24to make sure if I ping 10.99.1.4,

10:27I get return traffic.

10:28So my VPN on my local computer is looking good to go.

10:32So now I can go back to the actual determination

10:36of where we actually deploy the SQL virtual machine Managed

10:40Instance.

10:41So let me jump back to where we were on the network

10:43configurations, and we'll go from there.

10:46OK, so now I am back on the actual virtual networking pane.

10:51Notice it's trying to create a new virtual network

10:54called knox-sql-mi.

10:56But now when I click the dropdown,

10:58I do have a new subnet called in MySQL

11:02iaas-group-vnet for the Managed Instance itself.

11:05So this is good.

11:06Now we actually have a subnet that

11:09will be reconfigured to work for the Managed Instance

11:13once the connection has actually been applied

11:15and the resource has been deployed.

11:17The connection type for the private endpoint

11:19is still going to be set to be a proxy, that way we

11:23try to hit the resource itself.

11:25But it's actually going to go to a central Microsoft location

11:28and then be proxy to it.

11:30We don't have a public endpoint deployed for this in this case,

11:34we're just going to leave that one alone.

11:36And of course, the minimum TLS version is going to be 1.2.

11:41Checking out the Security section here,

11:42this is where you could actually add Microsoft Defender for SQL,

11:45as well as Identity Services if you

11:48need to add the actual system assigned identities

11:52to create a service principal for Windows authentication

11:56and Microsoft Active Directory.

11:57We don't need to do any of those things right now.

11:59We're going to cover all of that in a later video.

12:01We're going to jump straight to Review

12:03and create at this point.

12:05And we see, again, this is going to be a cost per month,

12:07and how it's going to be deployed.

12:09If I click Create, we'll let it get off to the resources.

12:12Now, again, this takes a long time, so just let it sit.

12:18Go to lunch, go do something else

12:20because it's going to be a while before this resource comes

12:23to life.

12:23Come back and check on it in an hour or so.

12:26And then once this is done deploying,

12:29we'll pick back up from there and make sure

12:31that we can actually connect to this over the site-to-site

12:35using the private IP.

12:36All right, see, I'm closing in on the hour mark.

12:41I started this at 11:25 AM, it's now 12.19.

12:44So it's probably close to getting done,

12:47but it's not done yet.

12:49So it's going to keep letting and spin until it finally

12:51gets deployed.

12:52See, I thought it would actually be worthwhile to show you

12:55what's going on here.

12:56You see what's actually happening in this deployment

12:59under the hood is it's actually creating a virtual cluster.

13:04And its creation is a synchronous step in incident

13:08management operations.

13:09Ultimately the estimated duration

13:11of this, 90% of operations finish in four hours.

13:16So this is just going to run for a really long time, that's what

13:20they're basically saying here.

13:21Now, once you've created a virtual cluster

13:24on the subnet for the first time, the next time you want

13:27to deploy a new Managed Instance to that same subnet,

13:31it should go quite a bit quicker.

13:33But that being said, the very first virtual cluster

13:37creation on the subnet, it's going to take up to four hours.

13:39So still just playing the waiting game.

13:42So just checking in, we're at a little over three hours now.

13:45Hopefully it'll be done within the hour.

13:47And we'll come back to it when it's finally deployed.

13:51Well, I'll be maybe just a few minutes after I just recorded

13:55that last clip, looks like about four minutes

13:57after I recorded that last clip, I

13:58get the fateful your Managed Instance

14:01deployment is complete.

14:03Let's go to the Resource to check it out.

14:05So here it is, we have now deployed, in our resource

14:09group, a Managed Instance.

14:11It has the series that we specified

14:13here, it is running on a virtual cluster,

14:17it's in the subscription.

14:18Let's scroll-- first of all check this out,

14:20the host is resolvable to database.windows.net.

14:24So this is why it's using the proxy, is it still accessible

14:28via a public or fully qualified domain name.

14:32So the big win for us here is that we've

14:34deployed a platform as a service SQL instance, rather than just

14:39an individual database.

14:40Now we can manage the entire SQL server instance.

14:44And check this out, we also have the ability

14:46to deploy multiple databases to this given instance.

14:51That's kind of one of the tricks here.

14:53This is almost like it's working like an Elastic pool,

14:57except for we have a full blown cluster of resources and access

15:02to nearly like 99% of all the features

15:06that you would get from deploying just

15:07a standard virtual machine.

15:10So we can deploy a new database right here directly

15:12to the Managed Instance, like so.

15:14We can walk through the process, we can say your subscription

15:17to the resource, we're going to enter the database name,

15:19like imdb for instance database.

15:23Something very simple like that.

15:25If you want, you can look at the data source itself,

15:27we can restore the data to a new database from a backup,

15:31if that's what we wanted to do.

15:32If we had an existing one.

15:33Otherwise, we can just do review and create,

15:35and create a new database on this Manage Instance

15:39directly from this portal.

15:42So let's deploy a database real quick.

15:45So that database resource gets deployed very, very quickly.

15:47We can go to the resource itself.

15:49And we can actually explore some of the information

15:51about the database.

15:53Including we can also apply some security features

15:55like data discovery and classification,

15:57as well as Microsoft Defender for Cloud.

15:59These are things that we will be talking

16:01about later on in our journey.

16:03You can also configure backup retention

16:05right here if we need to change our retention settings

16:08for this specific database.

16:09All right, let's jump back into the SQL instance for a second,

16:12though, the managed SQL instance.

16:13And what we can do-- now I see my database,

16:16and it's online when it was created,

16:18and the restoration for it.

16:21We can also see some of the statistics like the CPU

16:23for the Managed Instance.

16:24We also see there's a built-in firewall.

16:27So let's see if we can actually go ahead

16:29and get connected into this.

16:30This firewall feature-- by the way, I just said that.

16:33This firewall feature is just part of the virtual network.

16:36When this was deployed into the subnet that it was deployed on,

16:39it also scaffolded some extra resources.

16:41Like a built-in firewall that will detect intrusions

16:45and protect you.

16:45So here's what I'm going to do, I'm

16:47going to choose to connect to the actual SQL instance

16:50by choosing this proxy host in order to connect into it.

16:54I'll bring up SQL Server Management Studio,

16:56and I'll click Connect.

16:58Here I'll paste in the actual endpoint here,

17:01and I'll specify the password, type that again,

17:04with 16 characters long to get connected in.

17:07Just like that I see that I'm connected,

17:09and there's the imdb that I created before.

17:13Now you may be thinking to yourself, wait,

17:15didn't you say we wanted to connect

17:16to this through the private IP address that's

17:19on the virtual network?

17:20That is correct.

17:21And you can do that if you scroll down

17:24to deploy a private endpoint connection right here.

17:27It tells you a private endpoint connections allow connections

17:30from within a virtual network to a private IP using

17:35the private IP endpoint feature.

17:37Connections to these private endpoints specified below

17:40provide access to all databases on the server.

17:44So if I create a private endpoint real quick,

17:46I can choose the resource group, I

17:47can give it the name like sqlmipriv,

17:50or something like that.

17:51It's going to create a new network interface.

17:54And I'm going to choose to put this in the South Central US

17:57where my particular resources are.

17:59I'll choose these specific resource

18:01that I want to specify, and there we go,

18:04there's the sub resource.

18:05It is a Managed Instance, so it automatically

18:07detected I'm trying to use a Microsoft SQL Managed Instance.

18:10The virtual network that I want to put this in,

18:12well, we can see it's going to put me

18:14on this particular subnet.

18:16I could choose a different subnet,

18:17like the default subnet, if that's what I wanted to do.

18:21So if I want my virtual machines on 1099.1

18:25to be able to connect directly to this item,

18:27this is the private endpoint that it's

18:29going to get an IP address on.

18:31Let's go on to DNS next, OK.

18:33Do we want to integrate with a private DNS zone?

18:39If you either are using the Microsoft private DNS zones,

18:42you can go ahead and specify that here.

18:45Now, this particular object already

18:47has a DNS record associated with it, because that's

18:51what we just use to connect in.

18:52But you can utilize your own DNS servers

18:54or create your own DNS records using

18:56the host files if you don't want to integrate

18:59with the private DNS zones.

19:00I don't need to do anything about tags right now,

19:02so I'll go to Review and create, and create my private endpoint

19:06on that virtual network.

19:09So the private endpoint is completed.

19:11We can wrap up this configuration

19:13by jumping back to the SQL Managed Instance,

19:16scrolling on down to the private endpoint connections.

19:19And we see now I have a private endpoint connection.

19:23It's got a connection name, it's kind of long.

19:25It's state is in approved, which is what we need.

19:28And I see the private endpoint name here.

19:30If we click on the Private endpoint name,

19:33we see that this is where all of the details of the connection

19:36are.

19:37Interestingly, you can't find the IP address,

19:40though, you have to jump down here to like the DNS

19:43configuration.

19:44And now you see there's the Nick,

19:46there's the IP address that it got from connecting in,

19:49and the fully qualified domain name

19:52which, again, is the same domain name that we use to connect in

19:55in the original place.

19:56Woo-hoo, so we've now created the actual private DNS

20:00configuration, or we've created a private endpoint for our SQL

20:04Managed Instance.

20:05And now the virtual machines or other objects

20:08that connect into that VNet can connect directly in.

20:12So check this out.

20:13I've actually promoted into the virtual machine

20:16that I have running in Azure right now.

20:20I want you to see how this routing is going to work.

20:22You see, previously when I was just

20:24getting connected in right now, I

20:26was getting connected in through my public internet.

20:28Right here over the public internet,

20:30it was routed by public resolution,

20:34and it came to a public IP that got proxyed inbound.

20:37But what about what happens when I

20:39try to connect in via my local devices

20:43now that are on the same virtual network?

20:45If I bring up my database engine that's on my RDP session here,

20:49I've already pasted in the Managed Instance endpoint name

20:53right here.

20:54Let me go ahead and get connected to see

20:56how this DNS resolution works.

20:59If I press Enter here, well, to you, to the naked eye,

21:02it looks like nothing happened.

21:03It looks like I just got connected

21:04the same way I always do.

21:06But check this out, I'll bring up a command prompt real quick,

21:09and I'm going to zoom in quite a bit.

21:11I'm going to run the command nslookup

21:13to see what DNS resolves to whenever I actually

21:17try to get connected to that particular address.

21:19Let me just do disconnect real quick,

21:21reconnect so I can copy this DNS name real quick by fully

21:24qualified domain name.

21:25When I paste it and I press Enter, look at this, right

21:29there, the end response that I got

21:32was a different DNS name, an alias name,

21:36the proxy that was getting deployed.

21:39And it resolved to the private IP

21:42address that's on the same virtual network, 10.99.254.

21:47This is a different subnet, but it's the same virtual network.

21:50And all of my devices on that virtual network

21:52have direct connectivity to each other,

21:54thanks to the routing table.

21:56So this is what we're pointing out here, is

21:58that when we actually deploy the private endpoint and resources

22:01within the same virtual network, it

22:03does, in fact, allow for local resolution of the private IP

22:08address, and therefore local secure connectivity.

22:11All right, so this has been deploying the Managed Instance.

22:14I hope this has been informative for you,

22:15and I'd like to thank you for viewing.

Summarizing Azure SQL Manual Deployments

0:06So there you go.

0:07Now we've actually deployed all of the various offerings

0:10when it comes to the Azure SQL platform.

0:12We took a look at them in the previous video

0:15when were evaluating the three different options.

0:17There was the platform-as-a-service Azure SQL

0:20Database, there was the platform-as-a-service manager

0:22instance, and then there was the infrastructure-as-a-service

0:25Azure SQL Virtual Machine.

0:27Now you've seen, at a very high level, how to deploy all three

0:31of those in the manual methods, and this is perfectly fine

0:35to deploy these in this particular manner

0:37if you're not deploying resources all the time.

0:40If you are deploying resources all the time at scale,

0:44chances are, you want to look into some automation

0:47capabilities.

0:48And that's why, in the next set of videos,

0:49we're going to look at how to deploy these resources using

0:52the automated methods--

0:53things like templates, things like PowerShell,

0:56things like AZ CLI.

0:58So get ready as we start to explore

0:59that in the next set of videos.

1:00For now, I hope this has been informative for you,

1:03and I'd like to thank you for viewing.

Team training path

Turn this skill into assignable team training

This free skill is a preview of the courses your team can assign, track, and report on with CBT Nuggets.

What's next?

Ready to keep going?

For your team

Bring this training to your team

See how CBT Nuggets helps IT teams close skills gaps, hit compliance targets, and prove training ROI.

Book a Demo
Just need DP-300?

Learning on your own? Browse individual plans ($49/month, billed annually)

Not ready to buy?
with no purchase required. Already have an account?
Book a Demo