Introducing Azure Resource Manager
Start off with the basics for a few reasons. Most notably, it makes sure we are all on the same page. But another reason why is you always end up finding one bit of information that you didn't know before. Repetition of the basics is just as important as learning something new and complicated.
Why Every "as a Service" Matters to Networkers
The only resources that really need a virtual network (or VNet) are IaaS offerings, right? Wrong! There are many architectures and design patterns in Azure where PaaS or even SaaS can leverage a VNet. In fact, Azure actually recommends using PaaS when designing your solutions, so if privacy is a concern at all to you, learning how to integrate PaaS offerings with VNets is crucial.
Knowledge Check
Which "as a Service" abstracts the operating system and compute management away from the tenant but still allows them to ship and run custom code?
Azure Regions and Availability Zones
Let's refresh our memory on how Azure Regions are laid out, and where the data centers really live. This will be important because our application's communication architecture will ultimately depend on where we deploy our resources - within the same region, but spread out across availability zones? Or cross-region?
Knowledge Check
True or False: An Azure region is a data center.
The Azure Resource Manager Model
Now that we know where resources can be stored and run, let's focus in on the logical layout and organization of Azure resources. This also has a huge impact on how we design user security and permissions.
Knowledge Check
If you want an administrator to have permissions to every resource in a subscription, where should you assign their role?
Explore Entra ID (formerly Azure AD)
Entra ID used to be called Azure Active Directory and I will probably always call it Azure AD for the rest of my life. But that aside, it never hurts to explore and familiarize yourself with the place that your user accounts live. It also is where applications live, and importantly, managed identities. Now, App Registrations and Managed Identities are more of an AZ-104 and 204 topic, but still, familiarize yourself with these concepts before you begin.
Knowledge Check
What can you assign to an Azure resource so that it can identify itself to other Azure resources (like a service account)?
Review Your Bill (and Set Up Alerts)
Yes, the true reason Microsoft launched Azure was to make money. And as such, you will be billed for the resources you consume in Azure. If you're not careful, your bill could get out of hand quick. So I want to make sure you know where you can go to monitor your bill and even configure billing alerts.
Knowledge Check
True or False: You can configure alerts based on either a breached threshold OR a forecasted breach.
CHALLENGE
Set up a Budget and Cost Alerts for your new subscription. Make sure you set a number that actually matters to you - you don't want to spend more than this number in a month! Review your results with the video below
Knowledge Check
Did you actually set up a Cost alert?
This interactive assessment is available in the full learning experience.
View Transcript
Introducing Azure Resource Manager
0:00<v ->Welcome to the content on understanding</v>
0:02the Azure Resource Manager model.
0:05Say that three times fast. Azure Resource Manager model.
0:07Okay, the idea here is that in order to get ready
0:11for the advanced virtual networking topics
0:14that we're going to cover, they are advanced,
0:17we really need to make sure that we're all on the same page.
0:20Put it another way,
0:21if it's been a while since you've ridden a bike,
0:24we all need to make sure
0:25that we need to ride the bike smoothly and safely
0:28before we take off down the hill.
0:30So there's a few topics
0:31that we really need to prime ourselves on
0:34before we jump into the advanced topics.
0:36Things like VPNs, ExpressRoute, DNS, load balancing,
0:40all of that really, really fun stuff
0:41that we will absolutely cover.
0:43So first, we're gonna make sure we understand
0:46how Azure resources are deployed and laid out.
0:50Also upcoming, we're gonna be talking about things
0:52like dependencies that you actually
0:54need to install in your environment.
0:56Maybe that's going to be the AZ CLI, PowerShell,
0:59or things like maybe VS Code if you're gonna be deploying
1:02from ARM templates or Bicep files.
1:05Another really big part to understand
1:07that Microsoft likes to sneak in on these exams.
1:10I haven't taken a Microsoft exam yet
1:13that doesn't include PowerShell.
1:15So we'll also prime ourselves on PowerShell
1:18just to make sure we understand the PowerShell language.
1:21But that comes in a later set of videos.
1:23First, we're gonna focus in on just understanding the layout
1:27of Azure resources with the Resource Manager,
1:31things like resource groups,
1:32understanding regions versus availability zones,
1:36and stuff like that.
1:37So without further ado, let's get ready
1:39to understand the Azure layout of resources.
1:41Let's go.
Why Every "as a Service" Matters to Networkers
0:00<v Presenter>So to begin our journey,</v>
0:01we're going all the way back to the basics.
0:03We're gonna be talking about something as a service,
0:08and this is actually really important
0:09for the virtual networking conversation,
0:12the advanced virtual networking conversation,
0:14because you will bleed between these
0:17as a service offerings.
0:19It's actually a really important understanding thing
0:22that you need to wrap your head around.
0:24We're gonna talk a little bit more
0:25and preview just a little bit about what it is
0:28that we're gonna cover when the time comes.
0:30But we're gonna start off with good old fashioned.
0:34The classic one, infrastructure as a service.
0:37This is what everybody begins their cloud journey with.
0:41And importantly
0:42because this is what we know,
0:44this is what we're familiar with,
0:45this is what we did for a decade
0:48or two there when we had virtualization
0:51brought into the scene.
0:52When we had a hypervisor, maybe it was ESXI,
0:57or maybe it was Hyper V, whatever the case is,
1:01is we could take this big physical server
1:03and we could dice it up into virtual machines, couldn't we?
1:06That would be VM, you know, one or VM2,
1:10and they would all serve their relevant purpose.
1:13But interestingly, one of the more powerful things
1:15that virtualization did, you know, at the high level,
1:18the systems engineer would see this
1:19and think like, oh, this is amazing.
1:21I can spin up virtual machines.
1:23But then by default, just where your head goes to
1:26is you're thinking, oh, well,
1:28virtualizing a network would be way too hard.
1:30So these virtual machines
1:32must be all on the same land segment.
1:34It's exactly what you would think.
1:35But if that's the case, you would actually be really wrong
1:39because virtualization did networking really well.
1:42So that VM1 could be on, say, the yellow land
1:46and VM2 could be on say, the blue land,
1:50and we absolutely have the ability to dice up our network
1:54and our virtual machines into multiple subnets,
1:57even if they were all running
1:59on the same physical piece of software,
2:01or same physical piece of hardware, excuse me.
2:03So all of a sudden,
2:05network engineers were still absolutely a part
2:08of the picture when it came to working
2:10with systems engineers
2:11and designing network layouts for their various workloads
2:15to run on top of the physical servers.
2:18Now, beyond that, some physical servers actually had built
2:21into the nix themselves some really powerful networking
2:25components such that these could actually serve
2:27as VTEPs part of the land fabric
2:30and infrastructure that could run throughout
2:32the data center.
2:33With infrastructure as a service,
2:35this is where we start to draw the line,
2:37and I do mean quite literally draw the line,
2:39I'm gonna use pink right here,
2:41and anything below the pink line is no longer
2:44something that you touch.
2:46So any of the physical hardware that's running here,
2:49or the backbone configuration for the data center
2:52where you're configuring VX lamb, that's all gone.
2:55Now with infrastructure as a service,
2:57we are renting infrastructure to run our virtual machines,
3:03but the software component, the software side
3:05of it right here, if I were to actually redraw this pink
3:08line a little more correctly, would be kind of like this.
3:12You still absolutely have control over
3:16the networking portion that your virtual machines
3:19would be running on.
3:20So infrastructure as a service is the thing
3:23that we usually dabble with first.
3:25Whenever we're getting started working with the cloud.
3:27None other than, because this is most familiar to the things
3:31that we were doing on premises,
3:32we just have a few less responsibilities
3:35because managing the hypervisor,
3:38the physical hardware itself, things like, you know, disc
3:41and raid configuration,
3:43or managing the networking fabric
3:45throughout the data center, that's all gone,
3:47and we get to just focus on designing subnets
3:50for our virtual machine workloads
3:53and infrastructure as a service.
3:56Now, this has all been primarily focused in
3:59on the networking side of things
4:00because you know, this is a networking certification exam,
4:03but you also gotta keep in mind
4:05from the systems engineer standpoint,
4:07this is really important.
4:08I'm gonna explain why this is really important for you,
4:10the network engineer to understand this.
4:12Everything that goes on in the virtual machine
4:15is your responsibility too.
4:17You should think about this as a toolbox
4:19where you're renting a toolbox
4:21that has every tool imaginable on it,
4:23but it's still up to you to build something.
4:26So from the software developer standpoint,
4:30this is a big part of it.
4:31The software, the developer standpoint,
4:33they're responsible for managing dependencies.
4:36What version of Node does it need?
4:38What version of Python does it need?
4:40What version of go does it need?
4:43And whenever we design software, our software itself,
4:4799% of the time, is using what we call a package
4:51or a module or a library.
4:54Basically we're saying, Hey, out of the box,
4:56JavaScript can't do everything that I needed to do.
5:00So install this additional piece of software into JavaScript
5:04so that I have access to all of these things.
5:07A great example is PowerShell.
5:10You're gonna get a lot more familiar
5:11with PowerShell in some upcoming videos.
5:13PowerShell is extremely powerful
5:15and it is, well a shell, it's a scripting shell.
5:18But out of the gate, if you just installed PowerShell into
5:21your computer and then fired up PowerShell,
5:24you would not have the commands, they call them commandlets.
5:28To interact with Azure, you would have to install a module
5:33that comes with all the commands that you need
5:36to interact with Azure.
5:37Do you see what I'm saying?
5:38So if I had this virtual machine right here
5:41and I wanted this virtual machine to interact with Azure,
5:45I would have to make sure
5:47that PowerShell was installed,
5:48specifically PowerShell version seven,
5:50and then from there I'd have to install the module
5:53that gives it the ability to work with PowerShell.
5:56Only then have I met my dependencies to
5:59where I could actually start writing
6:01scripts to work with PowerShell.
6:03Do you see where I'm going with this?
6:04Virtual machines have overhead,
6:10and with that overhead most of the times comes cost.
6:14Virtual machines can be more expensive
6:16than you might be used to,
6:17but beyond that, more labor goes into running them.
6:20So much so that Azure, interestingly,
6:23actually recommends if you're doing a greenfield deployment
6:26or a new design, try to avoid infrastructure as a service.
6:30Check this out, you might not believe me.
6:32See, they have a whole document on it right here,
6:34updated just a few days ago, actually.
6:36Use platform as a service options.
6:39You scroll down a little bit
6:40and they actually tell you why you should choose
6:44platform as a service over infrastructure as a service,
6:47and then they offer you the alternative solutions
6:50that Azure offers.
6:51And this is a very, very small list of the things
6:55that Azure offers that are platform as a service.
6:57Now, ultimately, this comes from the document
6:59that's designed principles for Azure applications.
7:02You can kind of see where my mouse is right here,
7:04and if you go to the overview,
7:06it gives you the little bullet points right here.
7:08You scroll down just a hair about halfway,
7:10and you see this used managed services
7:11when possible use platform as a service
7:14rather than infrastructure as a service.
7:16So there you go.
7:16You are hearing it straight from their mouths
7:19and not from mine.
7:20This isn't just my opinion, even though that is my opinion,
7:24you're hearing it right now.
7:25That platform as a service, if you have the choice to use,
7:29it should be your choice.
7:31Well, why?
7:32And does that mean that you
7:34as the network engineer, no longer have a job?
7:37Absolutely not the case at all.
7:39Let's talk a little bit more about that.
7:41Bringing my doodling back onto the screen here a little bit.
7:44I'm gonna do a little bit of a racing to clear up some room.
7:47So gimme just one second while I clear this up
7:49and we can talk a little bit more about platform
7:51as a service and how it differs quite a bit
7:54from infrastructure as a service.
7:56Okay, so platform as a service.
8:00The idea with platform as a service,
8:02this is largely a developers playground.
8:06It's a developer's toolkit rather than a virtual machine.
8:10In fact, if we were comparing certification exams,
8:13you would see mostly infrastructure
8:15as a service on the AZ104 with a little bit
8:20of platform as a service on it.
8:22Whereas the AZ204 developing solutions for Azure
8:27is almost exclusively platform as a service.
8:29If I recall, there's not virtualization
8:32or virtual machines on that exam at all, but,
8:35and this is where I'm, I'm dead serious about this in my,
8:37this is where I will give you my opinion.
8:39In my opinion, the true power of the cloud,
8:43the true point of the cloud is right here.
8:47Platform as a service,
8:48and you as a network engineer,
8:50someone who's going for the AZ700
8:52and are interested in advanced virtual networking,
8:55I would still say it's worth your time
8:58to at least watch the content on the AZ204,
9:02just so that you understand the workloads
9:04and the types of things that developers are gonna want
9:06to do and why.
9:08Because at the end of the day, there is little to no
9:12overhead with platform as a service.
9:15There is no operating system to patch.
9:18Most of the time there is no need
9:22to manage dependencies.
9:27You declare the dependencies upfront when you deploy
9:29the resource and Azure will handle the rests for you.
9:33It is also most of the time very cheap.
9:37In fact, I drew way too many dollar signs right there.
9:40It should probably only be like $1 sign.
9:42Resources like function apps
9:44and logic apps actually give you millions
9:47of runs upfront for free.
9:51Whereas a virtual machine,
9:52it's absolutely gonna cost you
9:53money the moment you deploy it.
9:56Also, lots of times the WAN infrastructure for the platform
10:00as a service is handled for you.
10:02So routing or public DNS to get to your platform
10:06as a service if it needs
10:07to be publicly accessible is handled for you.
10:09There are some exceptions to that, things like app services
10:12where you want to bring your own domain,
10:14but nonetheless, when it comes to things like function apps
10:16or logic apps, Azure's just like, Hey,
10:19we'll just tell you this is your domain,
10:20send traffic here.
10:22One of the most useful things
10:23that you'll get started with when learning about
10:25platform as a service is the storage account.
10:29This is the most widely deployed resource in all of Azure,
10:32and it does exactly what you think it does.
10:34It stores data.
10:35Maybe that's files, maybe that's JSON payloads
10:39or maybe that's kind of column nerd data.
10:41Kind of like what you would see when you open Excel
10:44where there's columns and rows.
10:46The point is, with platform as a service,
10:48you are not deploying virtual machines
10:50and sizing discs or anything like that.
10:53You just have a place to send data
10:55and they just bill you per gigabyte.
10:57But this is where the network engineer is gonna come in.
11:00What if our data is sensitive?
11:02What if our data is really, really important?
11:05We don't want to have a storage account deployed
11:07and we access it over the web maybe via www.
11:12or maybe via SFTP,
11:15or depending on what we're doing, maybe even using SMB,
11:19there are some portions
11:20of a storage account that support that.
11:22Now I put www.,
11:23you should consider that as both HTTP or HTTPS.
11:28The point is, we may not want to expose our data publicly,
11:32even though if we put it behind something like in like,
11:34you know, identity to secure it, no,
11:37there are absolutely ways to deploy
11:39platform as a service offerings
11:42and connect them privately to a virtual network
11:46in the actual, you know, the actual configuration.
11:49And the only way traffic can make its way to this platform
11:52as a service that you owned is through your virtual network.
11:56These are using things called end points.
11:59Now there's a couple different kinds of end points,
12:02and they meet two different kinds of objectives,
12:04but we'll talk about that later when the time comes.
12:06The point is, is I want to allay some
12:08of your fears right now
12:09that at least I had when I was getting started was, oh,
12:12if all of these developers wanna use platform as a service,
12:15then they'll never want to use infrastructure as a service
12:18and therefore they'll never want to use virtual networks.
12:21While it's true that they probably could get
12:23around using virtual networks,
12:25that would probably be exposing data at some point along
12:29the way in such a way that that is a really bad idea.
12:33So designing your own network infrastructure,
12:36subnet infrastructure and routing infrastructure
12:39and including platform as a service offerings through
12:44that particular infrastructure is absolutely something
12:47that you can and will want to do.
12:49But again, a bunch of these platform as a service offerings
12:53all do a lot of different things.
12:56You have loosely coupled asynchronous architectures.
12:59You have event-driven architectures,
13:01you have message driven architectures,
13:03you have web front ends, you have storage backends,
13:07and that's why I kind
13:08of recommend just peeking under the hood over at the AZ204
13:13because understanding what those resources do
13:16and how communication is expected to flow from one of those
13:19to the next will actually benefit you tremendously
13:22when designing a network to facilitate that flow.
13:25Now, there is one final as a service
13:27that I'm gonna mention right here,
13:29even though there are many more as a services
13:32that exist nowadays.
13:33The last one that we're gonna talk about is good old
13:35fashioned software as a service.
13:38Nine times out of 10, this is a public facing resource,
13:42kind of like having Excel online.
13:44Everybody needs to be able to get
13:45to this software somewhere in the world that they are
13:48and then authenticate, log in,
13:50and then get access to their data
13:52and the application itself that they use
13:54to manipulate the data.
13:55That being said, it is potential or possible
14:00that your company might design software via
14:03software as a service,
14:05but then offer access to it only privately.
14:09In this case,
14:10a lot of the times you're building something
14:12like VPN architectures between yourself
14:15and your customer so
14:16that they access the traffic securely within Azure
14:20over a VPN rather than going over the public internet.
14:23Even though A VPN is usually going over the public internet,
14:26at least it's through an encrypted tunnel.
14:28Now, like I say, we really are gonna cover a lot
14:31of ground in this set of videos talking about how all
14:33of these things work as we progress through this playlist.
14:37So now that we understand the as a services
14:40and where our objectives as network engineers might lie,
14:45we can progress on and talk about how Azure is laid out.
14:48I hope this has been informative for you,
14:50and I'd like to thank you for viewing.
Azure Regions and Availability Zones
0:00<v Instructor>Okay, I absolutely love recording</v>
0:01this particular video.
0:03I've recorded it a few times now throughout my career
0:05at CBT Nuggets, and this is still one of my favorite things
0:08to do because Microsoft has done such an incredible job
0:12of highlighting the work
0:14that they've done into building Azure.
0:16So what we're gonna talk about now,
0:18something really important, that's the difference
0:20between regions and availability zones,
0:22and this is again, something that you'll have
0:24to consider when designing any of the networking portions
0:28of your solutions.
0:29This is a really big fundamental thing to understand.
0:33So what I want you to do is I want you
0:34to Google Azure Region Maps.
0:36Go ahead, bring up a browser, I'll wait.
0:38Or actually you could just pause it
0:39and come back to it when you got it.
0:41Okay, now that you got it, find one
0:43that looks like choose the right Azure region for you.
0:46If you see right here
0:47is azure.microsoft.com/explore/geographies.
0:51So we'll give that a click
0:53and it's basically just giving a little splash page
0:54about it.
0:55But what I really want you to do is come down here
0:57and click Explore the Globe.
0:59So it brings up this data centers page.
1:01And then right here
1:02where you see Azure Global Infrastructure, click learn more.
1:07Now this part may take a little bit of time to load up,
1:10but when it loads up, you now have an interactive map
1:14that you can click and drag upon and spin around.
1:17This is showing you all of the infrastructure
1:20that Azure has deployed around the world
1:23and these are effectively your options for the places
1:28that you can deploy and begin designing.
1:30So here we go, I'm gonna kind
1:31of focus in on North America right now.
1:34That's where I am and that's where I'll be doing a lot
1:36of my deployments for these videos here.
1:39Now you see the green dots, these are your actual regions.
1:43Now, important talking point immediately out of the gray,
1:47when you think about regions,
1:48you might think regions equals a data center,
1:52wrong, regions do not equal a data center.
1:56Regions equal data centers plural,
1:59specifically those data centers are known
2:03as availability zones.
2:06And availability zones are a big talking point.
2:10Fundamentally, when you think about deploying stuff
2:13in the cloud, the big reason why you deploy stuff
2:16in the cloud is you expect the cloud
2:18to keep your stuff alive.
2:20And a big part of that is we expect them
2:22to keep it alive in such a way
2:25that even when there's failures in a single data center,
2:28we expect some sort of failover
2:30or changing of traffic to take place.
2:32That's not always automatic, sometimes it's on us to design
2:36for that to happen, but they give us options by doing that,
2:40by deploying availability zones.
2:43In other words, whenever we look at something like East US,
2:46let's actually click on East US here for a second.
2:49When we scroll down just a hair,
2:51you see all sorts of cool information.
2:53When we see the availability zones,
2:56it says it's available with three zones.
2:59You should really think about this as here's East US,
3:03which is located in Virginia,
3:06and with the three availability zones,
3:07you should think about that as three availability zones
3:10like AZ1, AZ2 and AZ3.
3:16These are geographically close data centers,
3:19as in they're all within Virginia,
3:22but they're just far enough apart to where if some type
3:25of like natural disaster
3:27or some sort of event happens in availability zone one,
3:31it's unlikely to impact availability zone two
3:34or availability zone three.
3:36So with a lot of our workloads like virtual machines,
3:40we get the option
3:42to deploy them within different availability zones.
3:46For instance, a good compute layout would
3:48of course have multiple virtual machines operating
3:51in some form of a cluster.
3:53So I might have VM one in availability zone one
3:57and communicating and maybe replicating data
4:00or something like that to VM two in availability zone two
4:04or VM three in availability zone three.
4:08Now as a network engineer, your head might immediately go
4:10to, ah, they're in separate buildings,
4:13therefore there must be a huge amount of latency.
4:16How is replication going to be reliable
4:18and importantly synchronous?
4:21Or are we going to have
4:22to rely on something like asynchronous communications
4:25and replications?
4:26That is not the case, the connections between each
4:30of these availability zones are extremely high throughput,
4:35private fiber connections.
4:38It's not a stretch to expect to see these hovering
4:41around the 10 millisecond latency times
4:43between any of these availability zones.
4:47Now, when we start to stretch and think about replicating
4:50or communicating to regions outside of say,
4:54the East US perhaps maybe we're looking at something
4:57like the West US over here, see there's West US too,
4:59which is in Washington.
5:01This was open in 2007 and it has three availability zones.
5:05When we're talking about having something like a West US,
5:09let's just make up something like availability zone two,
5:12communicating over here
5:13to the East US availability zone three,
5:17this is where we could start to incur latency,
5:20but it's still extremely fast traffic
5:24and communication between Azure regions
5:27because it's all using Microsoft's backbone
5:29to communicate between resources.
5:32So it is possible that you may have to switch
5:34to something like an asynchronous architecture
5:36between regions, but within a region
5:39and between availability zones,
5:41you can absolutely rely on synchronous communications
5:44and architectures that way.
5:45So take a moment right now to start poking around
5:48and getting used to some of these regions.
5:51In particular, I'm gonna spend the most
5:53of my time right here in the South Central US, why?
5:56Because that's where I am.
5:58Well, not specifically, this is Texas
6:00and I'm right next door in Louisiana.
6:02I was born in Texas, there's that.
6:04But also take a look at the things that go
6:06around these Azure regions and support them
6:09like the wind farms or maybe like solar farms.
6:13Also, notice another pretty important thing is
6:15these little blue dots.
6:16What are these all about?
6:18These are actually points of presence.
6:20This is gonna be a big factor for you
6:22to consider if you're looking at doing something
6:24like express route or importantly content caching.
6:28Using content delivery networks.
6:30Specifically, that's the Azure front door resource.
6:33Also, one last thing I wanna point out is
6:35check out the white dots.
6:36These are regions that are coming soon.
6:38So here's East US three,
6:40which looks like it's gonna be right around Atlanta.
6:42Down here we have Mexico,
6:45which looks like it'll be near Mexico City.
6:47Even down here we have Chile.
6:50Also, not too surprisingly, you see a huge amount
6:52of expansion that's gonna be taking place
6:54throughout Asia and India.
6:57So we needed to take a moment to pause
6:59and make sure that you understood the differences
7:01between a region and a data center,
7:03which is more specifically availability zones.
7:06One final thing that you can do for fun is do take a tour.
7:09That's kind of fun too.
7:11You can do virtual Microsoft data center
7:13and it'll actually take you to a virtual data center
7:16where you could actually like click around
7:18and explore what goes on inside the data center.
7:21Do something like enter the lobby here and it'll zoom in
7:24and you'll actually feel like you're in the lobby
7:26of an Azure data center, which is pretty cool.
7:28You can learn a lot about the Azure data centers
7:30and what it is that they do by just poking around
7:34and clicking at like what the security teams look like.
7:37It's worth pointing out things that like the staff
7:39that works here is obviously, you know,
7:41under a tremendous amount of pressure to keep things secure,
7:44but they even have Azure regions
7:46that are specifically for government entities,
7:48and all the staff that works there
7:50have government secret clearance,
7:53which I think is a pretty interesting thing.
7:55So this has been understanding Azure regions,
7:57data centers and availability zones.
7:59I hope this has been informative for you,
8:01and I'd like to thank you for viewing.
The Azure Resource Manager Model
0:00<v Instructor>So if you don't already</v>
0:01have a free Azure account,
0:03please take a moment to go to azure.com
0:06and click try Azure for free
0:08to get started trying Azure for free.
0:10Click start free from here
0:12and walk through the process of signing up for Azure.
0:15It will take a credit card on file,
0:17but you will get a certain amount of resources for free
0:21to use or to try out, depends on, you know,
0:23your region or stuff like that.
0:25But usually you get $200, a $200 statement credit
0:28for your first month in Azure.
0:30That should be enough to walk through this, you know,
0:33all the, the demos that we're gonna do in the AZ 700,
0:37should, but we're also gonna talk about
0:39ways that you can monitor that
0:40and protect yourself at the end
0:42of this particular set of videos.
0:44Once you've got your account stood up,
0:46your home away from home is now going to be portal.azure.com
0:50and I'm starting out by zooming in right now
0:52for an important reason.
0:54If I go back to 100% right here, first of all,
0:56you can't really see that probably on the screen
0:58that you're watching on, but second of all, when I zoom in,
1:01certain aspects of the screen are going to get cut off.
1:06I want you to be aware that I'm gonna be zoomed in
1:09and that your screen might not always look like my screen
1:12because of my zoom level.
1:14Okay, so the way Azure works is not entirely unlike every
1:18other public cloud that's out there like AWS
1:21or Google Cloud or anything else.
1:23You have a list of resources that you could pick from
1:26that you want to deploy and then you answer a few questions
1:29and they provision the resources for you.
1:32Now, where do you go to find these resources though?
1:35Well, when you land in Azure,
1:36you see this little hamburger menu in the top left,
1:38give that a click and you kind
1:39of see it broken apart into two spaces.
1:42You have the stuff that's above favorites,
1:44you see the little favorite star right there,
1:46and that's your home.
1:47This could be a monitoring dashboard
1:49and then this is all services.
1:51Give all services a click
1:53and you can see literally every single service
1:57that Azure offers that you can deploy right here.
2:01Hundreds of options, it's a lot
2:04and you can get lost pretty quickly.
2:07The other thing that I wanna point out right now,
2:09and this is a big talking point most,
2:12and by most I mean the overwhelming majority
2:14of these services are platform as a service services.
2:19There is no avoiding it.
2:21Accept this now, that you will encounter platform
2:23as a service in your journey and nay embrace it
2:27because that means you're probably doing something right.
2:31So there's a lot,
2:32but then there's some that are gonna be your staples,
2:34your go-tos, and that's why we go back
2:36to the hamburger menu here
2:38and everything that's under favorites is probably something
2:42that you're gonna want to encounter at some point.
2:44Now how can we actually work with this?
2:47Well, the first thing is is under favorites.
2:49You see this list? This list is editable first of all.
2:52If you hover over these like app services
2:55right here, it pops out this little window
2:57and if you no longer want app services here,
2:59you can just click the little star right here
3:02to remove it from your favorites.
3:03Beyond that, these are all movable,
3:05so I can move app services to the top.
3:08Actually, it's kind of acting weird.
3:09It's on my other screen right now.
3:11Honestly, it's kind of a wonky monitor that I'm using,
3:14this monitor's for like it's specific,
3:15it's like a gigantic tablet basically,
3:19and it has some resolution conflicts
3:19with upgrading to the latest Mac list.
3:22So just trust me on your screen,
3:23you see the little dot dot dots here.
3:25Click and drag these around
3:26and see if you can move these higher like I just did there.
3:29Hey there, it worked that time. That's cool.
3:31These are gonna be your heavy hitters.
3:32You see virtual machines, you see virtual networks,
3:36you see SQL servers
3:37and you see Entra ID, that was actually what was known
3:40as Azure AD just a couple weeks ago.
3:44They're rebranding it to Entra ID.
3:47Of course they're storage accounts
3:48and yeah, we're gonna spend a lot
3:49of time on load balancers in this set of videos too,
3:52so get ready for that.
3:53The thing is, with all of these resources,
3:56there are some fundamental, crucial clutch things
4:00that you have to have upfront.
4:03The first one is the thing that you created
4:05whenever you actually signed up, and that is a subscription.
4:12You see right here, this is my account, knox@knoxdata,
4:15and within that I can have multiple subscriptions.
4:19I can have a pay as you go subscription
4:26and I can have something like a Visa on file for
4:29that subscription, but then I might create subscription two.
4:32This might have prepayment for this particular use case
4:38and that may have a MasterCard on file,
4:41or it could be even as simple
4:42as I just separate my cost centers
4:45into different subscriptions.
4:47I can have an HR subscription which has the HR
4:51credit card on file.
4:52I could have an IT subscription,
4:54which has the IT credit card on file.
4:57Whenever you deploy a resource, no matter
4:59what resource it is in Azure, the very first question
5:03that they ask is, who's paying for it?
5:06What subscription does it belong to?
5:08Which card should we charge?
5:10Understand that right now, upfront,
5:13this is gonna be automatic, hence forth, moving forward,
5:16subscription mandatory for every resource you deploy.
5:20Now, there's another thing that's usually going
5:23to be required for every resource that you deploy.
5:26Not always, but usually, and that's the region.
5:29Where's it going? What data centers are going to host this?
5:33Sometimes within that you have the ability
5:36to choose the availability zone, but not always.
5:39For virtual machines, for sure, you get
5:41to choose the availability zone.
5:43When you start getting into things like platform
5:45as a service like function apps, you don't get
5:48to choose the availability zone
5:49because they're automatically going
5:51to deploy it across availability zones
5:53for redundancy purposes.
5:55Again, platform as a service.
5:57The point is not to worry about the infrastructure,
5:59they're just gonna handle that for you.
6:01So out of our mandatory things, we have subscription
6:05every resource, no matter what.
6:07Region, almost like 99% of things
6:11that you deploy in Azure will need a region.
6:14Now, the final thing that you have to have is known
6:18as a resource group.
6:22The resource group is not particularly complicated,
6:26but it is mandatory
6:27for pretty much every resource that you deploy.
6:30Quite simply, it's just a logical way
6:33to group resources together.
6:35For instance, I may be deploying application one,
6:40but application one is actually comprised of a bunch
6:43of different resources.
6:45It may have a virtual machine that serves
6:48as a backend worker, which requires a virtual network,
6:52which requires a network security group,
6:55which also requires a virtual nick.
6:58Those are all resources,
6:59but then this virtual machine might also communicate
7:02to a storage account
7:04and maybe an Azure SQL database is part of it too
7:09that it communicates to.
7:10And collectively, all of these resources together
7:13make application one.
7:16Now over here, I might create application two
7:20and it might live in a different region
7:22or it might live in a same region.
7:23Heck, it might even have the same virtual network
7:26that it deploys a virtual machine on top of,
7:29but it may need a separate Azure SQL database
7:33and a separate storage account.
7:36It makes sense to group these separately
7:39because application two requires a separate set
7:43of resources than application one,
7:46and we don't wanna muddy this up
7:47and get confused by looking at, oh,
7:49I'm in the application one resource group,
7:51but that VM was actually for application two,
7:53no, that's not good.
7:54We wanna keep things nice and clean like this.
7:57Importantly, we can also assign permissions to our users
8:01or other resources at the resource group level.
8:06Oh, hang on, let's bring that back.
8:07Here we go.
8:08At the resource group level.
8:09So if I grant Knox the admin role on application two,
8:17that means that by inheritance they get
8:20the admin role on all
8:22of the resources within the resource group.
8:25So you should think about the resource group also
8:28as a security boundary.
8:30Now, I can absolutely assign permissions on each individual
8:34resource in the entire resource group,
8:37but lots of times we know who our admin is or who our owners
8:41or stakeholders are for a specific resource group,
8:44and we can grant them the permissions at
8:46the resource group level.
8:47In fact, it's worth pointing out,
8:49permissions can be prescribed all the way
8:52at the subscription level.
8:54We assign someone a subscription admin, guess what?
8:58They get permissions to every single resource group
9:03that gets deployed within the, within the subscription,
9:06and that therefore gives them permissions
9:09to every single resource within the resource group.
9:12You get to pick effectively at which tier you want
9:16to apply these resources for specific people
9:18and these permissions.
9:21We do this by assigning roles.
9:23Roles are effectively a group of permissions.
9:26So if you're kind of thinking about it,
9:28we have a resource group, which groups well resources,
9:32I mean it's pretty straightforward.
9:34And then we have users, which of course can be grouped
9:39with classic security groups in Entra ID
9:41or on-premises if you're syncing from there.
9:44In the middle,
9:45we have roles which are groups of permissions.
9:50So if you see what we're doing here, we can give a group
9:55the owner role for a resource group.
10:00Do you see how we can kind of like blanket apply permissions
10:03or we could give them owner roles
10:05or permissions at, you know, a resource level
10:08or we could apply those permissions to an individual user,
10:11but it's, you see, you can kind of mix
10:12and match all of those together.
10:14Again, it's really important to understand what you have
10:17to have upfront in order to get started.
10:20Every resource you deploy, let's just go
10:22into virtual machines right now,
10:24click Create, Azure Virtual Machine.
10:26You'll see, what are the first several
10:28questions that you have right here?
10:30Subscription, resource group, region.
10:34Just gonna be a question that you have to answer
10:37for every single resource.
10:39And yeah, you'll probably have
10:40to give your resource a name too.
10:42I should probably throw that out there as well.
10:43That you're gonna have to come up with a clever name
10:45for some of your resources.
10:47Sometimes there's restrictions
10:48around those names, sometimes there's not.
10:50We'll cover that when the time comes.
10:52So for now, we understand the importance
10:54of the resource group
10:55and where it fits in to the entire resource model.
10:59The idea here is understanding the hierarchy
11:01of permissions from the subscription to the resource group
11:04and then to the resources themselves,
11:06and also why you might logically group them.
11:09The last thing I'll say is kind of just a different thing,
11:12is that you don't have
11:13to group resources based on their workload,
11:16meaning you don't have to group resources
11:18'cause they all be belong to app one.
11:21You could group resources based on the intended
11:24permission that you want to assign.
11:27For instance, maybe I want to put all
11:29of my networking resources,
11:32regardless of which app they support into a
11:34resource group for networking.
11:36That way I could assign permissions to all
11:39of my network engineers.
11:40Separately, I could assign all of my compute layers
11:44like function apps, logic apps, virtual machines,
11:46container apps in a separate resource group,
11:49and then delegate those permissions
11:50to the systems engineers or DevOps engineers.
11:53You can get creative with this, again,
11:56with all the mixing and matching,
11:57you also don't have to do it based on a logical application
12:01or workload that's being supported.
12:03You can do it based on the type
12:05of resource like virtual networks.
12:07So with that being said,
12:09this has been understanding resource groups.
12:11I hope this has been informative for you,
12:12and I'd like to thank you for viewing.
Explore Entra ID (formerly Azure AD)
0:00<v Instructor>Now it's important to take a peek</v>
0:01under the hood at Azure AD,
0:04or what is now known as Entra ID,
0:06and for a really important reason.
0:08And that's because permissions, you know,
0:10it's not just about allowing people to log into Azure
0:13and then poke around.
0:14It's about making sure that you understand
0:16where permissions and roles and how all of that comes from.
0:20At the beginning, it all begins with users.
0:23Now, a lot of users this day and age,
0:25are coming from hybrid environments,
0:27meaning that businesses
0:28are synchronizing their On Premises Active Directory
0:32up into Entra ID.
0:34I'm going to tell you right now,
0:35I'm going to struggle with this, calling it Entra ID.
0:38It's been Azure Active Directory for me,
0:40for like six or seven years,
0:43and they just changed it like last week.
0:45So bear with me, as I say, Azure Active Directory's
0:49becoming Entra ID.
0:50It's right here on the screen.
0:51If I slip up, I mean Entra ID instead of Azure AD.
0:55Anyways, here's users.
0:57You can create users very simply
0:59with new user and create new users right here on the spot,
1:02and those users will have the ability to log into Azure.
1:05Now, of course,
1:05just like you have anywhere else in any other directory,
1:08you have the ability to group users together.
1:11If you go into the group section,
1:12you're really trying to create new security groups.
1:15Now, you might see Microsoft 365 groups.
1:19This is really for delegating permissions
1:21within the Microsoft 365 ecosystem,
1:24which is kind of separate from Azure.
1:27They both have the same identity store,
1:29they both have the same users, the same passwords.
1:32But when you're trying to delegate some permissions
1:35to say SharePoint or OneDrive for Business
1:38or something like that, you'd be looking at Microsoft 365.
1:42When you're back into Azure,
1:43you're looking at security groups.
1:46So that really just kind of highlights those.
1:48And, you know, this is more of an AZ-104 topic,
1:50but this is a bit of a crash course
1:52to make sure we all get brought up to speed.
1:55Now, when I navigate back to this,
1:56we have a couple other things
1:58that we can delegate permissions to.
2:00Applications are a big, like app registrations here.
2:04The idea with this is maybe I build a website,
2:09maybe it's like an intranet site,
2:11and before users are able to access data
2:15that might be stored in a database behind the scenes,
2:17or maybe a storage account,
2:20they have to get authenticated
2:21and we want them to get authenticated through Entra ID.
2:26We'll just allow Azure to handle
2:28letting people log in and log out
2:30or successfully authenticating.
2:32This is what app registrations do.
2:35Basically the idea here is the authentication is happening,
2:39basically it starts from outside of Azure,
2:42and the application communicates back to Entra ID
2:46and back and forth until the user gets authenticated.
2:48So when we're trying to build an application
2:51where we want a user to get authenticated
2:53with Azure Active Directory,
2:55but Entra ID, I already did it,
2:57then in this case we're registering our custom built app
3:01with Entra ID so that it can communicate back and forth
3:04and send, you know, grants or claims back and forth.
3:07Now this also deviates a little bit from something.
3:10It feels similar but not quite the same,
3:13and that's something called managed identities.
3:18Managed identities are really more like
3:21the good old fashioned service accounts
3:24that you used to run or maybe still do run
3:27on On Premises resources.
3:29A classic one is we may spin up a SQL Server on-premises
3:34and that SQL Server on a schedule
3:36has to take backups of the database.
3:39And what do we want to do?
3:40We want to put those data, those backups,
3:43on a file share like FS-NUG.
3:47Specifically, maybe we'll have
3:48a shared folder called Backup,
3:51something really clever like that.
3:53The thing is the SQL Server application
3:55will take the backup and generate the .bak file
3:59before it needs to log in to FS-NUG
4:02and place the file on the backups folder.
4:04It'll need NTFS permissions to do that.
4:07So back in the good old days,
4:08we created an account in Active Directory,
4:11specifically Active Directory Domain Services
4:13or Active Directory Users and Computers,
4:15and then told the SQL Server,
4:17use this account with this username and this password
4:20whenever you want to access the file share.
4:23Let that concept digest in your mind for just a second
4:28where you have a resource or an application
4:31trying to use Active Directory permissions
4:34to log into another resource.
4:37Now think about how this could work in Azure.
4:39I could potentially have a virtual machine
4:42that needs to access data in a storage account,
4:46or maybe I have an app service,
4:49which is basically just web hosting
4:51and it has a SQL Server backend.
4:54We can easily see where there's going to be
4:56some authentication in play here, right?
4:58The storage account wants to make sure
5:00that users are authenticated
5:02before we allow them access to storage.
5:04Or the database wants to make sure that the user
5:07or the front end application has credentials needed
5:10to access the database and change data there.
5:13In this case,
5:14this is a little bit different from an app registration
5:18because the app registration
5:20was all about my custom application
5:22that I built from scratch
5:23and I'm potentially running outside of Azure.
5:26I could even be running it on-premises.
5:28Whereas the virtual machine itself is an Azure resource
5:34and we want to give it permissions to an Azure resource.
5:38Rather than custom building some really wonky solution,
5:42I can just create what's known as a managed identity,
5:45which should be a synonym to you for a service account
5:50and assign it to this virtual machine.
5:54For all intents and purposes,
5:55this managed identity looks just like a user account.
5:59So I can go over to the storage account
6:02and assign a role
6:04that gives permissions to the storage account
6:06to the managed identity.
6:08See, come up here and search for managed identities
6:12and give it a click.
6:14See how easy it is to create a managed identity.
6:16If I choose Create right now,
6:18of course, I have to choose a subscription
6:20and a resource group.
6:21I'll just put this in AZ-104-demo.
6:23And I'll even choose a region
6:24and I can say,
6:25"Maybe I'll just use this for virtual machines."
6:27So I'll call this vmsid.
6:30I'll just hit Review and create, and Create.
6:34Now I have an identity named vmsid
6:37that I can assign to my VMs,
6:39and then I can go to things like my storage account
6:42and give permissions to vmsid.
6:44Boom, done.
6:46So I know that's a little bit, it's a really tough one.
6:49The first time you see it is understanding the difference
6:51between a managed identity and an app registration.
6:55I think the biggest and simplest way to put it
6:57is a managed identity is specifically for an Azure resource
7:02to access an Azure resource,
7:04whereas the app registration is really
7:07for an external application to use Azure AD
7:12to authenticate a user who's using that application.
7:15Again, this is an absolutely colossal, massive, major topic
7:20in the AZ-204, and it's touched on a good bit
7:24in the AZ-104 as well,
7:26but in the AZ-204, you are quite literally writing code
7:30throughout pretty much the entire course
7:32for managed identities.
7:33And then a separate huge chunk of it
7:35is for app registrations too.
7:37So I wanted you to be aware of Entra ID.
7:40The big reason that I wanted you to be aware of Entra ID
7:43is that at some point in your journey
7:45you will encounter needing to have,
7:48understand where your users or groups are,
7:50or understanding what applications,
7:53like app registrations or managed identities do.
7:56I hope this has been informative for you,
7:58and I'd like to thank you for viewing.
Review Your Bill (and Set Up Alerts)
0:00<v Instructor>There's one last thing</v>
0:01that I want you to be absolutely 100% aware of,
0:05and that is where do you go
0:07to keep track of your bill?
0:08As you're deploying new stuff
0:10and experimenting,
0:11how do you make sure you're not running
0:13up a huge, huge bill?
0:15Now, there's two separate places
0:16in Azure where you can go
0:17to look at this.
0:18Really one, but there, you know,
0:20there are two.
0:21Cost Management and Billing is gonna be the
0:23first place that you go.
0:25I really like Cost Management and Billing
0:27because right here, the spending forecast.
0:31Immediately I'm looking at this
0:33and seeing a forecast of 263
0:34and that actually seems pretty high compared to
0:36what I did last month, which was under 50
0:39and I'm like," Whoa!
0:40Where is this bill coming from?
0:41Where is this forecast coming from?"
0:43If I scroll on down a little bit more,
0:45I can see this month's top products by charges,
0:49and immediately I'm thinking," Oh yeah,
0:51I did deploy API management
0:54and I did have a big Azure app service
0:57that was running too."
0:58I need to go clean those resources up
1:00before I move on any further.
1:02All I have to do is delete those resources.
1:04That means they're gone permanently,
1:06but I won't be incurring a bill
1:07for them anymore on the per hour billing
1:09that I do.
1:10Now, under the Cost Management section,
1:12you can even see there is a cost analysis section
1:15where you can dig into these details
1:17a little bit more.
1:19Again, it's a lot of the same information
1:21that you just saw,
1:22but maybe broken down by service name,
1:25location, or subscription.
1:27Of course, you get the forecast up above,
1:29which is nice to have as well.
1:31Another thing that you may wanna take the time
1:33to do is go ahead and just set up cost alerts,
1:36but the real types of alerts
1:38that you would want to subscribe to,
1:40believe it or not,
1:41doesn't come under cost alerts.
1:43It comes under Budgets.
1:45And in this case, you would wanna create a
1:46budget for yourself.
1:48So I could give my budget a name,
1:50like "monthly budget"
1:51and if I scroll on down,
1:53I'm gonna take a look
1:54at my monthly budget forecast.
1:55It says, let's go ahead and put 551
1:59as our monthly budget based
2:00on our forecasted amount
2:02and growth expectations over time,
2:04and once we start to approach this threshold,
2:08we'll start alerting you
2:09whenever you're exceeding
2:10that particular budget.
2:11Right here, we get to set up
2:13the alert conditions.
2:14We can actually say,
2:15if there's an actual percent
2:18of budget over a certain amount
2:19or a forecasted percent of budget
2:22over amount, let's say 90%
2:24of this budget happens, then email me.
2:28We'll say knox@knoxsdata.com.
2:30We'll click create and boom!
2:32I've now set up a budget
2:33and an alert for if I start to approach
2:36that budget when it's forecasting me
2:39going beyond 90% of that budget.
2:42So I know, a quick and short video
2:44for you to understand where you can go
2:46to understand your bill
2:47and where you're currently heading,
2:49based on your cost analysis and your forecast.
2:52I think this is a really important tool
2:54for you to see before you begin your journey
2:56because some of these resources,
2:58particularly like Express Route
3:00or these VPN gateways,
3:03they can rack up a pretty big bill pretty quick.
3:05So do keep that in mind before you proceed
3:07that you'll want to check this
3:09at least every other day if you're serious
3:12about going through this playlist
3:15and spinning up and trying new resources.
3:17I hope this has been informative for you,
3:19and I'd like to thank you for viewing.
CHALLENGE
0:00<v Instructor>My challenge to you</v>
0:01was the quick and easy one,
0:02but one that's probably gonna save you at some point in your
0:06journey or in your career,
0:07and that is to set up an alert based on a budget
0:10that you're gonna set for yourself.
0:12Now you can go into budgets,
0:14click under cost management and billing.
0:16Under the cost management section, go into budgets
0:19and add a new budget.
0:21Now the scope here, you see this green circle
0:24that says Knoxs Data,
0:25and that means every subscription within my tenant
0:29or within my account, it is worth pointing out
0:32that you can do some really cool things like setting budgets
0:35based on a subscription or even based on a resource group.
0:39So if you wanna set a budget for just a subscription
0:42or just a resource group,
0:44like the resource group name right there,
0:46you have the ability to set filters for that.
0:49Now, I'll come on down here
0:51and I'll set my other monthly budget just to give it a name
0:55and we'll set a threshold here of like $900.
0:59In this case, we're gonna go a little bit
1:00beyond the forecast, just so I can warn myself
1:03before I get to a really big bill.
1:05We'll go into the alerts and this time I'll set the actual
1:08and set it to 50% of budget.
1:09I wanna know when I'm starting to go close
1:11or like I'm, you know, I'm encroaching on
1:14above 50% of that budget.
1:16We'll go ahead and set my recipient email
1:20address right there.
1:21Hit create and validates
1:24to make sure everything looks good for a second.
1:26And boom, there we go, budget and alerts were created.
1:29Go ahead and set that up.
1:31It's gonna be a big deal for you,
1:33at least at some point in your journey.
1:35I hope this has been informative for you,
1:36and I'd like to thank you for viewing.
Team training path
Turn this skill into assignable team training
This free skill is a preview of the courses your team can assign, track, and report on with CBT Nuggets.
$708
seat / year