BRK3201 Slidedeck
BRK3201 Slidedeck
Microsoft Azure
Administrator
Josue Vidal
Senior Cloud Solution Architect
GFT Group
Carlos Mattos
Director of Technology and Innovation
GFT Group
BRK3201
Hello ME! Josue Vidal
Senior Cloud Solution Architect and Co-founder IgniçãoTI
..help leverage and accelerate the career of IT professionals to achieve their goals,
being recognized and having an excellent career.
Based out of Sao Paulo, he is known as a subject matter expert, always able to
provide training in a fun and enthusiastic way.
Vidal is a MCT for +12 years, and an MVP for 10 years.
Senior Cloud Solution Architect at GFT Brazil.
Vidal is a technical writer for IgniçãoTI, courseware author for Microsoft and
several training partners.
[email protected] https://josuevidal.com.br/
/carlosmattos @cmattos
Tips and Tricks
What is your methodology of study?
Study
Pratice
• Clarify Plan • Content • Knowledge
• Path • Concept
Key takeaway 1
Session objective(s): help you prepare
for exam AZ-103
Key takeaway 2
Exam topics and breakdown of
questions
Key takeaway 3
Exam study material, links, resources
Certification overview
Azure Applications and Infrastructure certifications
Fundamentals Role-based Specialty
Associate Expert
Microsoft Certified:
Microsoft Certified: Azure for SAP Workloads
Azure Administrator Associate Specialty*
Microsoft Certified:
OR Azure DevOps Engineer Expert
Microsoft Certified:
Azure Fundamentals Microsoft Certified:
(Optional) Azure Developer Associate
Microsoft Certified:
Azure Security Engineer Associate
Key
Optional Path
Microsoft Certified:
Required Path Azure Solutions Architect Expert
* Exam in beta
Azure Administrator audience profile
Azure
Azure Administrator
Administrator
Audience
Audience profile:
profile:
Azure
Azure Administrators
Administrators manage
manage cloud
cloud services
services that
that span
span storage,
storage,
security,
security, networking,
networking, and
and compute
compute cloud
cloud capabilities.
capabilities. They
They have
have
aa deep understanding of each service across the full IT lifecycle,
deep understanding of each service across the full IT lifecycle,
and
and take
take requests
requests for
for infrastructure
infrastructure services,
services, applications,
applications, and
and
environments.
environments. They
They make
make recommendations
recommendations on on services
services toto use
use
for
for optimal
optimal performance
performance and and scale,
scale, as
as well
well as
as provision,
provision, size,
size,
monitor,
monitor, and
and adjust
adjust resources
resources as as appropriate.
appropriate.
In
In addition,
addition, Azure
Azure Administrators
Administrators should
should have
have proficiency
proficiency in
in
using
using PowerShell,
PowerShell, the
the Command
Command Line Line Interface,
Interface, Azure
Azure Portal,
Portal,
ARM
ARM templates,
templates, operating
operating systems,
systems, virtualization,
virtualization, cloud
cloud
infrastructure,
infrastructure, storage
storage structures,
structures, and
and networking.
networking.
Learning path for Azure Administrator Associate
Skills required for certification Exams Certification
Start here
40-60
40-60 questions
questions Plan
Plan for
for 180
180 minutes
minutes More
More than
than just
just Case
Case Studies
Studies
•• Some •• 150
150 minutes
minutes to multiple-choice
multiple-choice •• Detailed
Detailed information
information on
Some questions
questions worthworth to on
more
more than 11 point
than point answer
answer questions
questions questions!
questions! business
business and
and technical
technical
•• 30 requirements;
requirements; existing
existing
•• Answer
Answer all all the
the questions
questions 30 minutes
minutes for
for •• Build
Build list,
list, hot
hot area,
area, active
active environment
instructions, environment and other
and other
•• No penalty for guessing instructions, comments,
comments, screen,
screen, drag
drag and
and drop,
drop, etc.
etc. background
No penalty for guessing score background you need to
you need to
•• Some score reporting, etc.
reporting, etc. solve problems
Some questions
questions cannot
cannot •• Performance
Performance based
based solve problems
be skipped!
be skipped! coming soon!
coming soon! •• Requires
Requires you
you to
to understand
understand
•• Mark
Mark items
items forfor review
review and integrate information
and integrate information
ifif you’re
you’re not sure of
not sure of across
across multiple
multiple sources,
sources,
your
your answer
answer determine
determine what’s important,
what’s important,
and
and make the best decision
make the best decision
Performance-based testing - prove your skills with
hands-on labs
Applies to role-based certifications with at
least one exam per certification
Study
Pratice
• Clarify Plan • Content • Knowledge
• Path • Concept
Azure
Resource Naming
policy Resource groups Azure automation standards
& audit
Role-based access
Azure Security Center
controls
Subscriptions
Account/enterprise agreement
aka.ms/Azure/Scaffold
Manage Azure Subscriptions
RBAC Administrator Permissions
aka.ms/Azure/Subscriptions aka.ms/Azure/RBAC
Role-Based Access Control
Resource
Subscription Resources
Groups
Resource
Resource
Group
Resource
Resource
Subscription Resource
Group
Resource
Resource Resource
Group
Analyze Resource Utilization and Consumption
Configure diagnostic settings on resources;
create baseline for resources;
create and rest alerts;
analyze alerts across subscription;
analyze metrics across subscription;
create action groups;
monitor for unused resources; monitor spend; report on spend;
utilize Log Search query functions;
view alerts in Log Analytics
https://docs.microsoft.com/en-us/azure/monitoring-and-diagnostics/monitoring-overview
Analyze Resource Utilization and Consumption
Log Analytics
Configure diagnostics on resources
Custom visualizations
Analyze alerts
Across subscriptions
Analyze metrics
Across subscriptions
https://portal.loganalytics.io/
Analyze Resource Utilization and Consumption
Cost Management https://docs.microsoft.com/en-us/azure/cost-management/overview
Analyze usage
Monitor spend
Report on spend
Optimize
Reserved Instances
Sizing Recommendations
Analyze Resource Utilization and Consumption
Create Action Groups
Define an Action Type
Email / SMS / Push / Voice
Function or LogicApps
Webhook / Azure Automation
ITSM integration
Manage Resource Groups | Move Resources
Checklist:
• Common Azure AD Tenant
• If not the same
• Transfer Ownership
• Associate or add an Azure Subscription
Batch AI Public IP
aka.ms/Azure/Storage
MUST Read How To
Import and Export Data to Azure
Azure Storage integration
3. Wait
• Microsoft CDN profiles: 10 minutes.
• Akamai CDN profiles: 1 minute.
• Verizon profiles: 90 minutes.
• Policies
2. Full Systems
• Azure Backup Server (or DPM)
• Dependencies
3. Azure Virtual Machines
• Azure VM Backup • Monitoring & Reporting
• Limitations
aka.ms/Azure/Backup
Demo
Azure File Sync
Deploy and Manage Azure Virtual Machines (15-20%)
Manage Azure VM
May include but not limited to: Add data disks; add network interfaces; automate configuration management by
using PowerShell Desired State Configuration (DSC) and VM Agent by using custom script extensions; manage
VM sizes; move VMs from one resource group to another; redeploy VMs
Manage VM backups
May include but not limited to: Configure VM backup; define backup policies; implement backup policies;
perform VM restore
aka.ms/Azure/VMSS
Automate Deployment of VMs
Deployment options
• Marketplace
• PowerShell
• Azure CLI
• ARM Template
• Portal
• Code (C#/Java/Python)
}
}
• Benefits
• Connect 2 VNets in same region
• Routed through Azure Backbone
(= no custom encryption like S2S VPN)
• Requirements
• Same Region & Across Regions
• Non-overlapping IP Addresses
• No Transitivity
• Capabilities
• Open or Close NSGs
• Internal DNS only within VNet, no Azure DNS across
• Private IP
• Allocated from subnet range
• Internal resolution by Azure DNS
• Subnet, part of VNet range
• VM, ILBs, App GWs
• Dynamic or Static
(default)
aka.ms/Azure/Addresses
Configure Name Resolution
• Create DNS Zone
• Zone name must be unique within Resource Group
• Can add Azure Tags for Billing or Grouping
• Creating the zone makes SOA and NS records in Azure
aka.ms/Azure/DNS
Create and Configure a Network Security Group (NSG)
• Special Rules
• Microsoft Owned IP Address of 168.63.129.16
• Outbound Port 1688 reserved for KMS
• aka.ms/Azure/NSG
Demo
Configure Name Resolution
Implement Advanced Virtual Networking (30-35%) – part 2
Azure Load
VPN Network Watcher ExpressRoute
Balancers
Azure Load Balancer Characteristics
Basic Standard
Up to 1000 backend instances
Up to 100 backend instances
Zone-redundant frontend
Non-zonal frontend Zonal frontend
Availability Sets not required and Availability
Availability Set (single) Zones
Integrated Frontend and Backend health metrics
Free
Azure External Load Balancer
• Internet-facing IP-address
• Load Balances ALL traffic
(TCP, UDP – all ports)
• Required when deploying Virtual Machine AzLB
194.2.5.78
Availability Sets
• Can communicate with Azure Internal
Load Balancer and/or Application Gateway
Availability Set
WebVM2 WebVM1 WebVM3
10.1.0.5 10.1.0.6 10.1.0.7
Azure Internal Load Balancer
• Private-facing IP-address
• Load Balances ALL traffic
(TCP, UDP – all ports) AzextLB
• Sits behind an External Load Balancer 194.2.5.78
Availability Set
WebVM2 WebVM1 WebVM3
10.1.0.5 10.1.0.6 10.1.0.7
Keep in mind:
An Azure Load Balancer cannot combine AzintLB
external and internal traffic at the same 10.4.0.25
time
Availability Set
SQLVM2 SQLVM1 SQLVM3
10.4.0.5 10.4.0.6 10.4.0.7
Azure Network Watcher
• Recently added Networking feature, providing
– Topology
– Variable Packet Capture
– IP Flow Verify
– Next Hop
– Diagnostics Logging
– Security Group View
– NSG Flow Logging
– VPN Gateway Troubleshooting
– Network Subscription Limits
– Role Based Access Control
– Connectivity
Azure Network Monitor
Centralized hub for different Azure Resources Monitoring aspects:
Alerts
Metrics
Log Analytics
Service Health
Application Insights
Network Watcher
Azure Security Center - Networking
Centralized Dashboard, focusing on Security posture of Azure and hybrid systems and applications
Networking Features:
Networking Recommendations
Internet Facing Endpoints security view
Networking Topology security view
Manage Identities (15-20%)
Manage Azure Active Directory (AD)
May include but not limited to: Add custom domains; configure Azure AD Identity Protection, Azure AD Join,
and Enterprise State Roaming; configure self-service password reset; implement conditional access policies;
manage multiple directories; perform an access review
• Requires
• Azure AD + Subscription
• Windows 10 (Pro/Ent)
• Admin Tasks
• See picture ->
• User Tasks
• Register Windows 10 Device – BYOD
• Join Corp Device
• Settings, Account, Access Work or School
• Verify
Manage Azure Active Directory (AD)
Enterprise State Roaming
• Requires
• Azure AD Premium
• Windows 10
• Azure AD Domain Join
• Other Notables
• 3 regions: NA, EMEA, APAC
• Not replicated across
• Country/Region set on attribute
• Cannot be changed after!
• Retention
• Retained until deleted or becomes “Stale”
aka.ms/Azure/Roaming
Manage Azure Active Directory (AD)
Providing conditional access control to Conditional
Access
Identity
Protection
Multi-Factor
Authentication
APIs+ applications
• With "What if" capabilities
APPLICATI ONS & APIS
USER ATTRIBUTES
in some clouds or elsewhere
User identity
Roles and group memberships
Authentication strength/context CONTROLS
Azure AD MFA
DEVICE
ALLOW ACCESS
Registration state
Health state and policy
compliancy
Platform type ENFORCE MULTIFACTOR
Lost or stolen AUTHENTICATION
LOCATION
CONDITIONS FORCE PASSWORD RESET
IP range
*****
APPLICATION
Application policy BLOCK ACCESS
Client type (native, web)
10 To Risk profile
par jour Terms of Use
Time
IDENTITY PROTECTION
• Integrating behavior-based threat analytics via risk-based policies against
suspicious logins and compromised credentials
Manage Azure AD Objects (Users, Groups, and Devices)
perform bulk user updates
• PowerShell
• Import a CSV
• Export from HR or SQL
• Process
• Connect-AzureAD (MSonline still works, mainly used for Office 365 integration)
• Define Variables
Implement and Manage Hybrid Identities: 4 Scenarios
1. Cloud-only
• Users and Groups are managed in Azure Active Directory only
• Azure AD stores the password (encrypted)
aka.ms/Azure/AD/Connect
Much more in here!!!!
How to prepare
How to prepare
Aligned learning experiences
Exam
Exam page
page
Find
Find out
out exam
exam details
details –– skills
skills measured,
measured, training
training options,
options, and
and schedule
schedule your
your exam
exam
Microsoft
Microsoft Learn
Learn
Build
Build practical
practical job
job skills
skills with
with easily
easily accessible,
accessible, free,
free, self-paced
self-paced courses
courses
Classroom
Classroom training
training
Attend
Attend in-depth
in-depth training
training taught
taught by
by Microsoft
Microsoft Certified
Certified Trainers
Trainers
Practice
Practice tests
tests
Practice
Practice the
the certification
certification exam
exam in
in either
either aa study
study mode
mode or
or timed
timed testing
testing mode
mode
Tips and Tricks
What is your methodology of study?
Study
Pratice
• Clarify Plan • Content • Knowledge
• Path • Concept
Community
Access session recordings in 48 hours
Ask questions & continue the conversation
© Copyright Microsoft Corporation. All rights reserved.