0% found this document useful (0 votes)
219 views

BRK3201 Slidedeck

Uploaded by

adel edward
Copyright
© © All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PPTX, PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
219 views

BRK3201 Slidedeck

Uploaded by

adel edward
Copyright
© © All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PPTX, PDF, TXT or read online on Scribd
You are on page 1/ 69

Exam Prep | Exam AZ-103:

Microsoft Azure
Administrator
Josue Vidal
Senior Cloud Solution Architect
GFT Group

Carlos Mattos
Director of Technology and Innovation
GFT Group
BRK3201
Hello ME! Josue Vidal
Senior Cloud Solution Architect and Co-founder IgniçãoTI

Vidal has +16 years of professional expertise in the Microsoft Infrastructure


segment, with a main focus on Microsoft Azure nowadays, relying on a background
in Active Directory and System Center.

..help leverage and accelerate the career of IT professionals to achieve their goals,
being recognized and having an excellent career.

Based out of Sao Paulo, he is known as a subject matter expert, always able to
provide training in a fun and enthusiastic way.
Vidal is a MCT for +12 years, and an MVP for 10 years.
Senior Cloud Solution Architect at GFT Brazil.

Vidal is a technical writer for IgniçãoTI, courseware author for Microsoft and
several training partners.

[email protected] https://josuevidal.com.br/

/josuevidal @josuevidall /josuevidal @josuevidall


Hello ME! Carlos Mattos
Director of Technology and Innovation
Team leader with a track record of success and over 18 years of
experience in global enterprise software development, strategy, sales,
business development and operations for the software market.

Director of Technology and Innovation at GFT Brazil.

Recognized by Microsoft as Most Valuable Professional for 12 years


(2003-2016) for its contributions to the technical and academic
communities.

Received the Microsoft ACE Award in 2005 for contributions to Visual


Studio.

He was named Microsoft Regional Director in 2017-2019.

Professor, writer, speaker, and technology evangelist, and loves talking


about career and workplace behavior.

/carlosmattos @cmattos
Tips and Tricks
What is your methodology of study?

Study
Pratice
• Clarify Plan • Content • Knowledge
• Path • Concept

Mind Map Videos Simulate


Key takeaways

Key takeaway 1
Session objective(s): help you prepare
for exam AZ-103

Key takeaway 2
Exam topics and breakdown of
questions

Key takeaway 3
Exam study material, links, resources
Certification overview
Azure Applications and Infrastructure certifications
Fundamentals Role-based Specialty
Associate Expert

Microsoft Certified:
Microsoft Certified: Azure for SAP Workloads
Azure Administrator Associate Specialty*

Microsoft Certified:
OR Azure DevOps Engineer Expert

Microsoft Certified:
Azure Fundamentals Microsoft Certified:
(Optional) Azure Developer Associate

Microsoft Certified:
Azure Security Engineer Associate

Key
Optional Path
Microsoft Certified:
Required Path Azure Solutions Architect Expert

* Exam in beta
Azure Administrator audience profile

Azure
Azure Administrator
Administrator
Audience
Audience profile:
profile:
Azure
Azure Administrators
Administrators manage
manage cloud
cloud services
services that
that span
span storage,
storage,
security,
security, networking,
networking, and
and compute
compute cloud
cloud capabilities.
capabilities. They
They have
have
aa deep understanding of each service across the full IT lifecycle,
deep understanding of each service across the full IT lifecycle,
and
and take
take requests
requests for
for infrastructure
infrastructure services,
services, applications,
applications, and
and
environments.
environments. They
They make
make recommendations
recommendations on on services
services toto use
use
for
for optimal
optimal performance
performance and and scale,
scale, as
as well
well as
as provision,
provision, size,
size,
monitor,
monitor, and
and adjust
adjust resources
resources as as appropriate.
appropriate.
In
In addition,
addition, Azure
Azure Administrators
Administrators should
should have
have proficiency
proficiency in
in
using
using PowerShell,
PowerShell, the
the Command
Command Line Line Interface,
Interface, Azure
Azure Portal,
Portal,
ARM
ARM templates,
templates, operating
operating systems,
systems, virtualization,
virtualization, cloud
cloud
infrastructure,
infrastructure, storage
storage structures,
structures, and
and networking.
networking.
Learning path for Azure Administrator Associate
Skills required for certification Exams Certification

Azure subscriptions Storage solutions


& resources AZ-103: Microsoft Azure
Administrator

Online courses and instructor-led Microsoft Certified:


training available to support learning Azure Administrator Associate

Start here

Virtual machines Virtual networks Identity management


Exam basics

40-60
40-60 questions
questions Plan
Plan for
for 180
180 minutes
minutes More
More than
than just
just Case
Case Studies
Studies
•• Some •• 150
150 minutes
minutes to multiple-choice
multiple-choice •• Detailed
Detailed information
information on
Some questions
questions worthworth to on
more
more than 11 point
than point answer
answer questions
questions questions!
questions! business
business and
and technical
technical
•• 30 requirements;
requirements; existing
existing
•• Answer
Answer all all the
the questions
questions 30 minutes
minutes for
for •• Build
Build list,
list, hot
hot area,
area, active
active environment
instructions, environment and other
and other
•• No penalty for guessing instructions, comments,
comments, screen,
screen, drag
drag and
and drop,
drop, etc.
etc. background
No penalty for guessing score background you need to
you need to
•• Some score reporting, etc.
reporting, etc. solve problems
Some questions
questions cannot
cannot •• Performance
Performance based
based solve problems
be skipped!
be skipped! coming soon!
coming soon! •• Requires
Requires you
you to
to understand
understand
•• Mark
Mark items
items forfor review
review and integrate information
and integrate information
ifif you’re
you’re not sure of
not sure of across
across multiple
multiple sources,
sources,
your
your answer
answer determine
determine what’s important,
what’s important,
and
and make the best decision
make the best decision
Performance-based testing - prove your skills with
hands-on labs
Applies to role-based certifications with at
least one exam per certification

Real-world scenarios where you configure,


manage resources and services

Demonstrate your hands-on skills

1 or 2 labs with up to 15 tasks that you need


to complete
Exam overview and
objective domain
Tips and Tricks
What is your methodology of study?

Study
Pratice
• Clarify Plan • Content • Knowledge
• Path • Concept

Mind Map Videos Simulate


Exam AZ-103 - Objective Domain

Manage Azure subscriptions and resources (15-20%)

Implement and manage storage (15-20%)

Deploy and manage virtual machines (VMs) (15-20%)

Configure and manage virtual networks (30%-35%)

Manage identities (15-20%)


Manage Azure subscriptions and resources (15–20%)
 Manage Azure subscriptions
 May include but not limited to: Assign administrator permissions; configure cost center quotas and tagging;
configure subscription policies

 Analyze resource utilization and consumption


 May include but not limited to: Configure diagnostic settings on resources; create baseline for resources; create
and test alerts; analyze alerts across subscription; analyze metrics across subscription; create action groups;
monitor for unused resources; monitor spend; report on spend; utilize Log Search query functions; view alerts
in Log Analytics

 Manage resource groups


 May include but not limited to: Allocate resource policies; configure resource locks; configure resource policies;
implement and set tagging on resource groups; move resources across resource groups; remove resource
groups

Tagging & Cost Monitor &


RBAC & Policies Log Analytics Move Resources
Management Diagnostics
Manage Azure Subscriptions: Understand the Scaffold

Resource tags Resource locks

Azure
Resource Naming
policy Resource groups Azure automation standards
& audit

Role-based access
Azure Security Center
controls

Subscriptions
Account/enterprise agreement
aka.ms/Azure/Scaffold
Manage Azure Subscriptions
RBAC Administrator Permissions

aka.ms/Azure/Subscriptions aka.ms/Azure/RBAC
Role-Based Access Control

ROLE NAME DESCRIPTION


Contributors can manage
Contributor
everything except access.
Owner can manage
Owner
everything, including access.
Readers can view everything,
Reader
but can't make changes.
Lets you manage user access
User Access Administrator
to Azure resources.
Lets you manage virtual
machines, but not access to
Virtual Machine
them, and not the virtual
Contributor
network or storage account
they're connected to.
Role-Based Access Control

Resource
Subscription Resources
Groups

Resource
Resource
Group
Resource

Resource
Subscription Resource
Group
Resource

Resource Resource
Group
Analyze Resource Utilization and Consumption
 Configure diagnostic settings on resources;
 create baseline for resources;
 create and rest alerts;
 analyze alerts across subscription;
 analyze metrics across subscription;
 create action groups;
 monitor for unused resources; monitor spend; report on spend;
 utilize Log Search query functions;
 view alerts in Log Analytics

https://docs.microsoft.com/en-us/azure/monitoring-and-diagnostics/monitoring-overview
Analyze Resource Utilization and Consumption
Log Analytics
 Configure diagnostics on resources

 Custom visualizations

 Analyze alerts
 Across subscriptions

 Analyze metrics
 Across subscriptions

https://portal.loganalytics.io/
Analyze Resource Utilization and Consumption
Cost Management https://docs.microsoft.com/en-us/azure/cost-management/overview

 Analyze usage

 Monitor spend

 Report on spend

 Optimize
 Reserved Instances
 Sizing Recommendations
Analyze Resource Utilization and Consumption
Create Action Groups
 Define an Action Type
 Email / SMS / Push / Voice
 Function or LogicApps
 Webhook / Azure Automation
 ITSM integration
Manage Resource Groups | Move Resources
 Checklist:
• Common Azure AD Tenant
• If not the same
• Transfer Ownership
• Associate or add an Azure Subscription

• Common Resource Providers


• Quotas Exceeded?
• Minimum Permissions
• Microsoft.Resources/subscriptions/resourceGroups/moveResources/action on the source
resource group.
• Microsoft.Resources/subscriptions/resourceGroups/write on the destination resource group.
• Limit of 800 moves, possible timeouts
Manage Resource Groups | Not supporting move:
 AD Domain Services  Express Route

 AD Hybrid Health Service  Kubernetes Service

 Application Gateway  Lab Services – not across subscriptions

 Azure Database for MySQL  Load Balancers

 Azure Database for PostgreSQL  Managed Applications

 Azure Database Migration  Managed Disks

 Azure Databricks  Microsoft Genomics

 Azure Migrate  NetApp

 Batch AI  Public IP

 Certificates - App Service Certificates can be moved,  Recovery Services vault


but uploaded certificates have limitations.  SAP HANA on Azure
 Container Instances  Security
 Container Service  Site Recovery
 Data Box  StorSimple Device Manager
 Dev Spaces  Virtual Networks (classic)
 Dynamics LCS
Demo
Manage Resource Groups | Move
Resources
Implement and Manage Storage (15-20%)

 Create and configure storage accounts


 May include but not limited to: Configure network access to the storage account; create and configure storage
account; generate shared access signature; install and use Azure Storage Explorer; manage access keys; monitor
activity log by using Log Analytics; implement Azure storage replication

 Import and export data to Azure


 May include but not limited to: Create export from Azure job; create import into Azure job; configure and use
Azure blob storage; configure Azure content delivery network (CDN) endpoints

 Configure Azure files


 May include but not limited to: Create Azure file share; create Azure File Sync service; create Azure sync group;
troubleshoot Azure File Sync

 Implement Azure backup


 May include but not limited to: Configure and review backup reports; perform backup operation; create
Recovery Services Vault; create and configure backup policy; perform a restore operation

Blob Storage & Azure File Sync & Azure Backup


Storage Accounts SA security
CDN File Share (Hybrid !!)
Create and Configure Storage Accounts

Key topics to understand: 3 different scenarios:


• Services: • General-Purpose:
• Blobs, Files, Tables, Queues • Blobs, Files, Tables, Queues

• Security: • General-Purpose v2:


• Storage Access Keys • Blobs, Files, Tables, Queues
• Shared Access Signatures
• Blob Storage Account:
• Replication • Block & Append blob
• LRS, ZRS, GRS, GRS-RA • No Page blob

aka.ms/Azure/Storage
MUST Read How To
Import and Export Data to Azure
Azure Storage integration

1. Azure Storage Accounts and Managed Disks


• Regular data types go to Azure Storage Accounts (blobs)
• VHD disk upload to Azure Marketplace custom deployments

2. Storage Account Explorer


• GUI or Rest API

3. Portal, PowerShell, Azure CLI

4. Data is more than Azure Storage


• Databases (SQL, MySQL, CosmosDB,…)
Import and Export Data to Azure
Configure Azure content delivery network (CDN) endpoints

1. Create a CDN Profile

2. Create a New CDN Endpoint

3. Wait
• Microsoft CDN profiles: 10 minutes.
• Akamai CDN profiles: 1 minute.
• Verizon profiles: 90 minutes.

4. Know the difference between


Standard and Premium
Pricing Tiers
aka.ms/Azure/CDN
Configure Azure Files | Azure File Sync
Azure File Sync Service
• Supported on
• Windows Server 2012R2/16
• NTFS Volumes/Compression
• DFS with 1.2 Agent
• BitLocker, AIP, AAD RMS,
• NOT supported
• Other file systems period
• Sysprep
• NTFS EFS
• No Other HSM
Azure Sync Group
• Defines Sync Topology for set of files
aka.ms/azure/files Deploy Azure File Sync
Implement Azure Backup
Azure Backup Scenarios: What to know:

1. Files & Folders • How to deploy


• Azure Backup Agent

• Policies
2. Full Systems
• Azure Backup Server (or DPM)
• Dependencies
3. Azure Virtual Machines
• Azure VM Backup • Monitoring & Reporting

• Limitations
aka.ms/Azure/Backup
Demo
Azure File Sync
Deploy and Manage Azure Virtual Machines (15-20%)

 Create and configure a VM for Windows and Linux


 May include but not limited to: Configure high availability; configure monitoring, networking, storage, and
virtual machine size; deploy and configure scale sets

 Automate deployment of VMs


 May include but not limited to: Modify Azure Resource Manager (ARM) template; configure location of new
VMs; configure VHD template; deploy from template; save a deployment as an ARM template; deploy Windows
and Linux VMs

 Manage Azure VM
 May include but not limited to: Add data disks; add network interfaces; automate configuration management by
using PowerShell Desired State Configuration (DSC) and VM Agent by using custom script extensions; manage
VM sizes; move VMs from one resource group to another; redeploy VMs

 Manage VM backups
 May include but not limited to: Configure VM backup; define backup policies; implement backup policies;
perform VM restore

ARM-template PowerShell DSC,


VM end-to-end Azure VM Backups Windows & Linux
Deployment VM extensions
Create and Configure a VM for Windows and Linux

aka.ms/Azure/VMSS
Automate Deployment of VMs

Deployment options
• Marketplace
• PowerShell
• Azure CLI
• ARM Template
• Portal
• Code (C#/Java/Python)

MICROSOFT CONFIDENTIAL – INTERNAL ONLY Different ways to create a VM


Automate Deployment of VMs
ARM Templates

 JSON files with a predefined syntax and schema


 Azure and Azure Stack compatible
 Deployment from:
 Azure Portal / Add Resource / Template Deployment
 PowerShell
 Azure CLI

 GitHub -> Azure QuickStart Templates


 Visual Studio Code
 Visual Studio 2015 and up (all editions)

ARM Template Walkthrough


Manage Azure VM
Desired State Configuration (DSC) Configuration Contosoweb app
{
param ($MachineName)
Node $MachineName

DSC configurations separate intent, {


#Install the WebServer
or "what I want to do", from WindowsFeature IIS
{
execution, or "how I want to do it.“ Ensure = "Present"
Name = "Web-Server"
}

DSC is also repeatedly checking if #Install ASP.NET 4.5


the VM is still according the WindowsFeature ASP
{
desired state, where script Ensure = "Present"

extension only runs once. }


Name = "Web-Asp-Net45"

}
}

DSC Template Overview


Demo
Desired State Configuration (DSC)
Configure and Manage Virtual Networks (30-35%) – part 1

 Create connectivity between virtual networks


 May include but not limited to: Create and configure VNET peering; create and configure VNET to VNET; verify
virtual network connectivity; create virtual network gateway

 Implement and manage virtual networking


 May include but not limited to: Configure private and public IP addresses, network routes, network interface,
subnets, and virtual network

 Configure name resolution


 May include but not limited to: Configure Azure DNS; configure custom DNS settings; configure DNS zones

 Create and configure a Network Security Group (NSG)


 May include but not limited to: Create security rules; associate NSG to a subnet or network interface; identify
required ports; evaluate effective security rules

Azure DNS Network Security VPN and ER


VNET Peering VNET end-to-end
(Hybrid!!) Groups (NSGs) (Basics)
Create Connectivity Between Virtual Networks
Create and configure VNET peering

• Benefits
• Connect 2 VNets in same region
• Routed through Azure Backbone
(= no custom encryption like S2S VPN)

• Requirements
• Same Region & Across Regions
• Non-overlapping IP Addresses
• No Transitivity

• Capabilities
• Open or Close NSGs
• Internal DNS only within VNet, no Azure DNS across

Peering uses the MS Backbone; if you want


(custom) additional encryption, use S2S VPN
aka.ms/Azure/Peering
Implement and Manage Virtual Networking
• Public IP
• Separate Azure Object
• Public Azure Service
• VMs, ILBs, VPN, App GWs
• Dynamic (default) or Static
• DNS hostname resolution

• Private IP
• Allocated from subnet range
• Internal resolution by Azure DNS
• Subnet, part of VNet range
• VM, ILBs, App GWs
• Dynamic or Static
(default)

aka.ms/Azure/Addresses
Configure Name Resolution
• Create DNS Zone
• Zone name must be unique within Resource Group
• Can add Azure Tags for Billing or Grouping
• Creating the zone makes SOA and NS records in Azure

• Create DNS Record


• Azure DNS supports all common records
• Use Record Sets for more than one record of same name and type + wildcard!
• SOA and CNAME are exceptions to Rule above

• Delegate Domain to Azure DNS


• Must know zone server names
• Get-AzureRmDnsZone –Name contoso.net –ResourceGroupName MyResourceGroup

aka.ms/Azure/DNS
Create and Configure a Network Security Group (NSG)

• Apply at Subnet or NIC


• Only 1 NSG per Azure Resource
• Only TCP or UDP

• Special Rules
• Microsoft Owned IP Address of 168.63.129.16
• Outbound Port 1688 reserved for KMS

• aka.ms/Azure/NSG
Demo
Configure Name Resolution
Implement Advanced Virtual Networking (30-35%) – part 2

 Implement Azure load balancer


 May include but not limited to: Configure internal load balancer, load balancing rules, and public load balancer;
manage Azure load balancing

 Monitor and manage networking


 May include but not limited to: Monitor on-premises connectivity; use network resource monitoring and
Network Watcher; manage external networking and virtual network connectivity

 Integrate on premises network with Azure virtual network


 May include but not limited to: Create and configure Azure VPN Gateway; create and configure site to site VPN;
configure Express Route; verify on premises connectivity; manage on-premise connectivity with Azure

Azure Load
VPN Network Watcher ExpressRoute
Balancers
Azure Load Balancer Characteristics

Basic Standard
Up to 1000 backend instances
Up to 100 backend instances
Zone-redundant frontend
Non-zonal frontend Zonal frontend
Availability Sets not required and Availability
Availability Set (single) Zones
Integrated Frontend and Backend health metrics

Basic NAT and Probe health status Supports HA Ports


NSG required
no HA Ports
Charged based on number of rules, data
processed inbound and outbound associated with
NSG optional resource.

Free
Azure External Load Balancer

• Internet-facing IP-address
• Load Balances ALL traffic
(TCP, UDP – all ports)
• Required when deploying Virtual Machine AzLB
194.2.5.78
Availability Sets
• Can communicate with Azure Internal
Load Balancer and/or Application Gateway

Availability Set
WebVM2 WebVM1 WebVM3
10.1.0.5 10.1.0.6 10.1.0.7
Azure Internal Load Balancer

• Private-facing IP-address
• Load Balances ALL traffic
(TCP, UDP – all ports) AzextLB
• Sits behind an External Load Balancer 194.2.5.78

Availability Set
WebVM2 WebVM1 WebVM3
10.1.0.5 10.1.0.6 10.1.0.7

Keep in mind:
An Azure Load Balancer cannot combine AzintLB
external and internal traffic at the same 10.4.0.25
time

Availability Set
SQLVM2 SQLVM1 SQLVM3
10.4.0.5 10.4.0.6 10.4.0.7
Azure Network Watcher
• Recently added Networking feature, providing
– Topology
– Variable Packet Capture
– IP Flow Verify
– Next Hop
– Diagnostics Logging
– Security Group View
– NSG Flow Logging
– VPN Gateway Troubleshooting
– Network Subscription Limits
– Role Based Access Control
– Connectivity
Azure Network Monitor
 Centralized hub for different Azure Resources Monitoring aspects:
 Alerts
 Metrics
 Log Analytics
 Service Health
 Application Insights
 Network Watcher
Azure Security Center - Networking
 Centralized Dashboard, focusing on Security posture of Azure and hybrid systems and applications

 Active in 3 different areas:


 General Security View
 Prevention
 Detection

 Networking Features:
 Networking Recommendations
 Internet Facing Endpoints security view
 Networking Topology security view
Manage Identities (15-20%)
 Manage Azure Active Directory (AD)
 May include but not limited to: Add custom domains; configure Azure AD Identity Protection, Azure AD Join,
and Enterprise State Roaming; configure self-service password reset; implement conditional access policies;
manage multiple directories; perform an access review

 Manage Azure AD objects (users, groups, and devices)


 May include but not limited to: Create users and groups; manage user and group properties; manage device
settings; perform bulk user updates

 Implement and manage hybrid identities


 May include but not limited to: Install and configure Azure AD Connect; configure federation and single sign-on;
manage Azure AD Connect; manage password sync and writeback

 Implement Multi-Factor Authentication (MFA)


 May include but not limited to: Enable MFA for an Azure tenant; configure user accounts for MFA; configure
fraud alerts; configure bypass options; configure trusted IPs; configure verification methods; manage role-
based access control (RBAC); implement RBAC policies; assign RBAC Roles; create a custom role; configure
access to Azure resources by assigning roles; configure management access to Azure

Azure AD MFA, Conditional Bulk user


Azure AD Connect Federation - SSO
end-to-end Access, PW Reset management
Manage Azure Active Directory (AD) aka.ms/Azure/Roaming
Azure AD Join

• Requires
• Azure AD + Subscription
• Windows 10 (Pro/Ent)

• Admin Tasks
• See picture ->

• User Tasks
• Register Windows 10 Device – BYOD
• Join Corp Device
• Settings, Account, Access Work or School

• Verify
Manage Azure Active Directory (AD)
Enterprise State Roaming

• Requires
• Azure AD Premium
• Windows 10
• Azure AD Domain Join

• Other Notables
• 3 regions: NA, EMEA, APAC
• Not replicated across
• Country/Region set on attribute
• Cannot be changed after!

• Retention
• Retained until deleted or becomes “Stale”

aka.ms/Azure/Roaming
Manage Azure Active Directory (AD)
Providing conditional access control to Conditional
Access
Identity
Protection
Multi-Factor
Authentication

APIs+ applications
• With "What if" capabilities
APPLICATI ONS & APIS
USER ATTRIBUTES
in some clouds or elsewhere
User identity
Roles and group memberships
Authentication strength/context CONTROLS
Azure AD MFA
DEVICE
ALLOW ACCESS
Registration state
Health state and policy
compliancy
Platform type ENFORCE MULTIFACTOR
Lost or stolen AUTHENTICATION

LOCATION
CONDITIONS FORCE PASSWORD RESET
IP range
*****
APPLICATION
Application policy BLOCK ACCESS
Client type (native, web)

OTHER LIMIT ACCESS

10 To Risk profile
par jour Terms of Use
Time
IDENTITY PROTECTION
• Integrating behavior-based threat analytics via risk-based policies against
suspicious logins and compromised credentials
Manage Azure AD Objects (Users, Groups, and Devices)
perform bulk user updates

• PowerShell
• Import a CSV
• Export from HR or SQL

• Process
• Connect-AzureAD (MSonline still works, mainly used for Office 365 integration)
• Define Variables
Implement and Manage Hybrid Identities: 4 Scenarios
1. Cloud-only
• Users and Groups are managed in Azure Active Directory only
• Azure AD stores the password (encrypted)

2. Hybrid Active Directory with password Sync


• On-premises Active Directory is the « master »
• Users and Groups are synchronized to Azure Active Directory using ADConnect (or MIM or 3rd party)
• Password is synced encrypted out of ADConnect (or MIM or 3rd party)

3. Hybrid Active Directory with Federation


• Relies on ADConnect to synchronize objects
• ADFS or 3rd party Federation engine, running on-premises or in Azure VMs (with S2S or ER)

4. Hybrid Active Directory with PassThrough Authentication


• Relies on ADConnect to synchronize objects
• Instead of ADFS federation, deploy the PTA agents on on-premises servers (ADDS DCs)
Implement and Manage Hybrid Identities
Install and configure Azure AD Connect

aka.ms/Azure/AD/Connect
Much more in here!!!!
How to prepare
How to prepare
Aligned learning experiences

Digital skilling Events Classroom Certifications


Build practical job skills Choose from Attend in-depth training Validate skills with
with easily accessible, free, workshops, conferences, taught by Microsoft fundamentals, role-based, and
self-paced courses and other events  Certified Trainers  specialty certifications

Microsoft Learn Training Events Microsoft Official Courses


Microsoft Certification
(instructor-led training)
Ways to prepare for certification
docs.microsoft.com/learn/certifications/exams/az-103

Exam
Exam page
page
Find
Find out
out exam
exam details
details –– skills
skills measured,
measured, training
training options,
options, and
and schedule
schedule your
your exam
exam

Microsoft
Microsoft Learn
Learn
Build
Build practical
practical job
job skills
skills with
with easily
easily accessible,
accessible, free,
free, self-paced
self-paced courses
courses

Classroom
Classroom training
training
Attend
Attend in-depth
in-depth training
training taught
taught by
by Microsoft
Microsoft Certified
Certified Trainers
Trainers

Practice
Practice tests
tests
Practice
Practice the
the certification
certification exam
exam in
in either
either aa study
study mode
mode or
or timed
timed testing
testing mode
mode
Tips and Tricks
What is your methodology of study?

Study
Pratice
• Clarify Plan • Content • Knowledge
• Path • Concept

Mind Map Videos Simulate


Attend Exam Prep sessions available this week

Session Title Presenter Code


Microsoft Certification 101 Sudarshan Krishnamurthi BRK1053
Exam Prep | AI-100: Designing and Implementing an Azure AI Solution Glenn Morris BRK3197
Exam Prep | AZ-103: Microsoft Azure Administrator Josue Vidal BRK3201
Exam Prep | AZ-203: Developing Solutions for Microsoft Azure Mike Pfeiffer BRK1046
Exam Prep | AZ-300: Microsoft Azure Architect Technologies Tiago Costa BRK3200
Exam Prep | AZ-301 Microsoft Azure Architect Design Tim Warner BRK3276
Exam Prep | AZ-400: Microsoft Azure DevOps Solutions Dwight Goins BRK4012
Exam Prep | AZ-500: Microsoft Azure Security Technologies Gareth Jones BRK3277
Exam Prep | AZ-900: Microsoft Azure Fundamentals Tim Warner BRK1047
Exam Prep | DP-100: Designing and Implementing a Data Science Solution on Azure Glenn Morris BRK1050
Exam Prep | DP-200: Implementing an Azure Data Solution Dwight Goins BRK1051
Exam Prep | DP-201: Designing an Azure Data Solution Armando Lacerda BRK2155
Exam Prep | MB-200: Microsoft Power Platform + Dynamics 365 Core Julian Sharp BRK2156
Exam Prep | MB-900: Microsoft Dynamics 365 Fundamentals Sarah Jelenik BRK1102
Exam Prep | MD-100: Windows 10 Andrew Bettany BRK2154
Exam Prep | MS-100: Microsoft 365 Identity and Services Ed Baker BRK2157
Exam Prep | MS-101: Microsoft 365 Mobility and Security Ed Baker BRK1052
Exam Prep | MS-700: Managing Microsoft Teams Jenny Chen BRK1106
Exam Prep | MS-900: Microsoft 365 Fundamentals Mark O'Shea BRK1048
Please evaluate this session
Your feedback is important to us!

Please evaluate this session through


MyEvaluations on the mobile app
or website.
Download the app:
https://aka.ms/ignite.mobileapp
Go to the website:
https://myignite.techcommunity.microsoft.com/evaluations
Find this session Visit aka.ms/MicrosoftIgnite2019/BRK3201

in Microsoft Tech  Download slides and resources

Community
 Access session recordings in 48 hours
 Ask questions & continue the conversation
© Copyright Microsoft Corporation. All rights reserved.

You might also like