[00:09] is important, but using them correctly is even more important. The real question is, is your cloud infrastructure secure, scalable, reliable or costefficient? Can your application handle more users? Can your [00:21] data stay protected? Can your system recover quickly if something goes wrong? Welcome to the session on a 305 designing Microsoft Azure infrastructure solutions. In this course, we will understand how businesses design cloud [00:35] infrastructure using Microsoft Azure. We will start with the basics of Azure infrastructure and understand why companies use cloud platforms to host applications, manage data and scale their services. Next, we will explore [00:48] important Azure concepts like subscriptions, resource groups, regions, availability, zones and governance. Then we will explore compute services like virtual machines, containers, app services and Kubernetes. These services [01:02] help businesses run applications based on their workload needs. Next, we will look at Azure storage and database solutions where businesses store files, backups, application data and structured information securely. We will also [01:16] understand networking concepts like virtual networks, subnets, load balancers, application gateways and private connectivity. These help cloud resources communicate safely and keep applications available. Finally, we will [01:30] explore monitoring, backup, disaster recovery, high availability and performance optimization because cloud architecture is not just about deployment. It is about designing systems that work reliably in the real [01:43] world. So before we begin our session, just a quick information guys. Simply learn offers a certification program in cloud computing and devops in collaboration with triple IT Bangalore. This program helps you master genai [01:57] devops and cloud tools across AWS, Azure and Google cloud through live online classes, integrated labs and real world projects. Here you will gain hands-on experience with tools like Docker, Kubernetes, Terraform, Genkins and [02:11] Cibible, AWS, Azure and Google Cloud and even build your portfolio with 30 plus hands-on project and three industry oriented capstone project. Here learners will also receive a program certificate and transcript from triple Bangalore [02:26] along with official Microsoft learn certificates in relevant Azure modules. The program also includes AI powered job assistance, rumé building, LinkedIn profile optimization, mock interviews and career support. All of this under [02:40] just one course. So now before we begin, let's have a short quiz question. And the question is, what is the main goal of Azure infrastructure design? And your options are option A to randomly deploy cloud services, option B to design [02:54] secure, scalable and reliable cloud solutions, option C to avoid cloud networking or the option D to remove security from applications. delivery of services. Now the first question that most of my student ask is [03:10] why do we need these services? Compute, storage. Do you guys know why do we need these services? Let's say there's no cloud. If there's no cloud and you want to host your website or an application, where do you host it? [03:25] application, where do you host it? So, if there's no cloud, we need to create a data center. Okay, we need to first have a data center before I or Windows Server, we need to have our data center. Now, what [03:40] do you think? How much charge or how much cost will I have to bear as a company or as an organization if I want to have my own data center? [snorts] First of all, I have to pay for the infra. I need to find a place and [03:56] infra. I need to find a place and imagine a uh imagine having a big big space in a city like Mumbai or Bangalore. How much you have to pay business? You'll have to pay for that infra. [04:11] You need to buy that that place first. You need to put your racks, your servers there. Then you need to think about the the power power supply. You need to [04:23] think about the redundant power supply since I don't want to rely on single since I don't want to rely on single power supply. Right? So this is the is power supply. Right? So this is the is the uh cost that you have to bear if you [04:36] do not go for cloud. But as Har is mentioned that we har is mention mentioning that we can go for colo. Yes you can go for collocation as well but for that as well someone has to have a data center. You can go for colo but [04:50] someone has to has a data center right? Someone should build a data center for you. Yeah. So that colo is like you're just renting spaces. So you're just renting the data uh you're just renting one or [05:03] two uh servers or you're just renting entire rack in that particular data center and you're putting your own servers there. So that's that is the meaning of co location right so that was also possible before cloud but after [05:16] that not everyone can afford of creating a or or developing or uh building a data center. So what happens the big companies like Amazon, [05:28] Google and Microsoft and there are a lot of others or all right so these big companies what they did they created data centers and they started providing the [05:42] and they started providing the computation services like compute storage database networking on rent. All right. So today when someone says that we need to move to cloud or we need to migrate to [05:56] cloud or we want to use cloud computing they're mostly mentioning that we want to use the AWS infra GCP infra Google infra or Microsoft Azure's infra or Oracle's infra depending on uh which part of world you are we need to use [06:09] their infra and deploy our computation resources all right so what is why do we need this computation resources compute resources like for example let's Say you have an idea and you need to use information [06:23] technology to bring that idea to life. That means you have a business. A simple example I can take is let's say Swiggy. So what is the idea behind this business? Deliver deliver food delivery service. [06:37] So when you use Swiggy, are you making the food? Obviously no. Someone else is making for you. So you're ordering it from their place, right? So what is this? This is like a food as a service. So it's again a uh cloud service right. [06:50] So you can say that it's it's a cloud kitchen from where you're ordering. So to build something like this whatever your idea is and you want to use uh your idea is and you want to use uh internet to deliver services. [07:04] So in order to use internet in order to develop or in order to bring my idea to life first of all what I need I need to hire a developer. Why do we need a developer? Developer [07:18] will write the application for me. So what is an application? Application is nothing but some files. So if you have ever developed a very simple HTML uh uh page or HTML website, static website, if you have developed that you know that an [07:34] application is nothing but list of files. There there will be a lot of files. If you're writing application inn net or Java or whatever you're just coding. If you're a developer, you might know better, but you're just coding. So [07:46] that code is saved in nothing but a file with some extension, with some extension, right? So in order to make sure that my right? So in order to make sure that my website is is is reachable to to my [08:00] customers or to my users who wants to deliver food or anything, whatever your idea is, I need need to keep this file somewhere and that somewhere is nothing somewhere and that somewhere is nothing but a server. [08:17] Now where will you place that server? You need to place that server in a data center. So as as Har mentioned, you can collo col you can get a collocation place in one of the data center. You'll be paying [08:30] one of the data center. You'll be paying some rent or you can simply launch the server on a cloud company. Now tell me what what what do you think what will be what what what do you think what will be the cost of buying a server from IBM or [08:42] from HP? What will be the cost of buying one server? Around $1,000, right? Around one lakh or two lakh or three lakh rupees depends on which company you go for and what configuration you want. [08:56] server, what server is? Server is nothing but a computer. So if you go today to buy a new laptop, what do you what do you see or uh which laptop you [09:10] buy? So what do you see in that laptop? You'll see the config, right? You'll see the storage, what is the SSD given, you'll see the processor, what processor is being used or being uh installed in [09:25] this laptop, right? You'll see memory, the RAM. So these are the three most important thing that we see. Similarly, server is like you can say a powerful computer which provides services. So you know the laptop is like for commercial [09:39] know the laptop is like for commercial use. That means for us just to uh do a use. That means for us just to uh do a meeting or do or or for entertainment purposes like I want to watch a movie, I can watch it on a on my laptop. I can do [09:51] some of my business business things. But you cannot host your website on laptop. Technically you can but your laptop is not as powerful as server to provide the services. Okay. So similarly similar to laptop you'll [10:07] server you'll be having some operating system in laptop you have an operating system right you have windows right so you you you go for Windows 11 nowadays [10:19] or if you're uh fond of Mac you'll go for Mac. So Mac has their own Macintosh. Apple has their own Macintosh operating system like or there's another uh [10:31] variant in market which is Linux right so on top of that server you'll be having an operating system what is an operating system operating system is the mediator between human beings and the uh hardware if I give you [10:46] a hard disk can you just see that hard disk and try to figure out what do we physically seeing that hard disk like Can you do that? [snorts] So right we need to connect that hard disk to the laptop. [11:01] How does the the laptop reads hard disk? Laptop has the operating system installed and that operating system can detect and read the hard disk and then we can identify what kind of files we have in that hard disk. Right? So [11:15] have in that hard disk. Right? So similarly here we deploy OS on top of similarly here we deploy OS on top of our server and then we keep our files. [11:28] like Swiggy and I also want to come up with a food delivery service, first of all I need to hire a developer or if you are a developer you can write your own code. But in order to host that application you need to have the server. [11:44] So using that server only you can host right now. In order to buy that server you have to spend a certain amount. let's say $1,000 and that amount is upfront cost. That is an upfront cost. When you say [11:58] upfront cost, that means I have to pay it now. Even before starting my business, I have to invest like $1,000 for one server. Now, tell me, you're buying one server and if that server goes down, what happens? [12:10] hosting your application on top of that you be able to reach your application or will your user will be able to reach the application? Obviously not right. If Swiggy is down, you won't be able to [12:24] anything from Swiggy. So I cannot rely on one server. Why do I need to buy another server? Just to make sure that if one server goes down, my application is reachable from the second server. [12:40] from the second server. So instead of $1,000, I need to spend $2,000 for two servers. So that's an upfront cost. And this upfront cost is nothing but capital expenditure for your business capex. Okay. [12:57] Now for for an individual user who or for an startup for a startup investing this amount could be huge. So what they can do they can simply launch portal.azio.com azio.com [13:13] portal.azio.com azio.com cloud create a server deploy their and that's all their their website is live. What is cloud computing? If you have a laptop and if you have an internet [13:26] laptop and if you have an internet connection you can get the server the storage the networking through that internet through the internet. That's all that's cloud computing. Cloud computing refers to the delivery of [13:39] inter delivery of compute services over the internet. services are nothing but you want in order to host a website you would need uh storage, you would need RAM, you would need CPU. So all these services [13:54] are given to you over the internet. You don't spend spend this much of amount up front. So you're saving already you're saving $2,000. Right? Now here you deploy two servers, five servers, doesn't matter. On cloud [14:09] you deploy two servers, five servers, 10 server. You're not paying $2,000 upfront. That means right now I'm not paying $2,000. So when I'll be paying, I'll be paying as per my use. Pay as you go. So this month, if I'm using five [14:24] servers, I'll have to pay for the five servers. Next month, if I don't require five servers, I'll remove two servers and I'll pay for three servers only. Pay as you go model. What is pay as you go? It's like your [14:36] electricity, right? So, every month do you get the right? So, every month do you get the similar bill for your electricity? Depends on your usage, right? In summer, we use air condition, uh coolers and all [14:50] those stuff. So, we pay more in summer, but in winter, do we pay more? Totally depends on your consumption, right? So, that's nothing but the pay as you go approach. Pay as you go. As much as you use, you pay for that. If you use [15:07] 10 servers, 20 servers, for that much, you'll pay more. If you use only one server, you'll pay for only one server. Okay. I hope you have understood what cloud computing is and why do why you will be [15:21] using cloud computing. Okay. All right. computing? Cost optimization. As I mentioned that uh if you want to use two servers, three servers, you use that. So [15:35] depends totally depends on your requirement. You'll be using two servers, three servers, right? So it helps you to achieve the cloud uh uh achieve the cost optimization, right? Optimize the cost. I'm not paying up [15:48] front everything. I'll be paying according to my use. performance according to my use. performance efficiency very quickly you can uh get the performance increase the performance of your app right I want two [16:02] servers I want more CPU I can I can do that I want more RAMs I can change my change u the amount of RAM assigned to my compute service right so all those thing you can do very quickly apart from that accessibility [16:18] want to come up with your with your IT business or business using it. Where you'll be creating or deploying your server, you will be creating or [16:30] deploying your server depends on wherever you you are. You let's say I stay in Mumbai and I want to I have an idea and I want to come up with a service. So I'll be searching a place in Mumbai itself [16:44] and if my user base in is is in US I need to go to US and there I have to deploy my server in one of the data center right so with cloud it has become very easy I can deploy wherever I want depending on uh let's say I want to [17:02] deploy a server so in cloud it's it's quite is known as virtual machine so I'll click on create create virtual machine and And here you see if you want to deploy it in US you can select US, [17:16] east, US, west. If you want to deploy it in Australia you can select Australia. you need? You just need an internet connection and you can deploy wherever you want. Wherever Azure has it presence, right? I want to deploy in [17:29] Europe. I can go for Europe. I want to deploy in uh UK. I can go for UK. Right? So these are the different these are the benefits of using cloud computing. These benefits you cannot get when you're deploying everything on prem. Okay. [17:45] deploying everything on prem. Okay. Reliability uh flexibility. So cloud is reliable. Why it's reliable? Because they by default monitor it. Okay. Uh by default monitoring as in it's not like that they [18:01] will take actions on your behalf. Only if you configure they can take actions on your behalf but if you don't configure uh they'll not they'll not take that action right. So cloud is reliable, flexible, you can deploy where [18:17] similar to accessibility, you can deploy wherever you want. Whatever size of uh RAM, depends totally on your requirement. And security whatever data [18:29] you you are keeping on cloud uh by default is it is secured. You don't need to worry about security. Why? because what I'm putting in my uh [18:41] storage account in my storage Microsoft is automatically encrypting that. What is like uh a security algorithm [18:53] uh a security algorithm which is making your data unreadable. which is making your data unreadable. Okay, sorry. >> So sec uh encrypt encrypting is a way is a security algorithm which is making [19:06] your data whatever data you're putting on cloud unreadable that means when I'm putting a data in in your own laptop where do you add your where do you store your data we have hard disk right [19:21] solid state drive or hard disk in that hard disk we keep our data so if you remove that hard disk from your laptop and attach it to another laptop. Can you and attach it to another laptop. Can you read the hard disk or no? [19:35] If I remove the hard disk that I have over here, remove it from laptop number one and connect it to laptop number two, will I be able to read my data? Yes. Right? I'll be able to read my data. So, similarly, when I'm putting data in [19:48] nothing new. Cloud is also using hardress drive or solid state drive to keep your data. So, what happens when you keep your data in cloud? It goes to center, they'll be having servers or [20:02] sand storage. And in that storage, your data is stored. So if someone goes there who has the physical access to the data center, if someone goes to that hard disk, take out the hard disk, connect it to our laptop, [20:15] where's the security then? He or she will be able to read the data. Right? Similar to this scenario, if someone goes to the cloud, take out the hard disk where your data is stored, connect that hard drive to its to his own [20:30] laptop, he'll also be be able to read that data, right? So to avoid this situation, what every cloud provider is doing is encrypting your data. What is the meaning of encryption? Whatever you're writing, you're writing ABC. So [20:44] you're writing, you're writing ABC. So that is stored in an encryption format. Okay? So if someone is removing that hard disk and connecting that hard disk to its own laptop, he or she won't be able to read the data unless and until [20:56] able to read the data unless and until that data is decrypt. decryption, we require the encryption and decryption keys. So Microsoft stores [21:09] keys. The uh you have the option to use your own keys as well. Right? So this is one of the benefit that we have in the cloud. Even if the data is even if the device where your data is stored is stolen, the data is secure. No one will [21:24] be able to read it unless and until they decrypt it. Okay. encrypted. Doesn't matter what cloud provider you're using. [snorts] [21:36] Okay. Now what is Microsoft Azio? Microsoft Azio as you know is the leading cloud provider from Microsoft. So Microsoft is the owner and Microsoft So Microsoft is the owner and Microsoft has created lot of data centers and [21:49] those services are given to you as uh as a service. Whenever we talk about cloud you will be hearing something a term known as as a service. So Microsoft Azure is a cloud provider. It's a leading cloud provider which [22:04] offers 200 products and cloud services to you to the users so that they can to you to the users so that they can bring their own idea to life. Okay. [22:27] well. So you you might uh see me going uh mute a lot of time. Okay. So just bear with me. Maybe tomorrow I I'll I'll feel better. Microsoft Azure is a leading cloud [22:42] provider available in the market which offers around 200 products. So this is the second I mean if you go 5 years back Microsoft Azure was the second leading cloud provider but now if you see we have like 55 45 uh ratio in the market. [22:59] have like 55 45 uh ratio in the market. The competitor to Microsoft Azure is AWS. Depends on which area or which part of world you are. you would see that AWS is used more or Microsoft Azure is used [23:13] more depend on which part of land I I stay in Malaysia so in Malaysia I see a lot of opportunities for Microsoft Azure whereas if you stay in Bangalore side in India in Bangalore side you would see AWS requirement more so totally depends [23:27] on which part of area you are if if you are staying in Middle East Saudi or Dubai you would see Oracle being used for okay so totally depends on which part of area you are but it doesn't matter that uh [23:42] which cloud you are learning if you learn one cloud you'll automatically understand the second cloud cuz services are are are same the only difference is Microsoft might be having few different services AWS might be having few [23:56] different services the names for those services are changed like in Microsoft Azure we say virtual machine whereas in AWS they say uh elastic cloud compute [24:08] In Google they say compute engine. So totally depends uh which cloud you're using. Services are same the names are different. Okay. [24:27] whatever benefits we have we have discussed for cloud computing same benefits applies here. As you can see, security, cost effective, scalability, data recovery, flexibility. So all the benefits you'll get on every cloud. [24:43] You're using Microsoft as your same benefits. You have security, cost effective, data recovery, scalability, flexibility. But then the question arise flexibility. But then the question arise if all clouds have the same benefits [24:58] uh why should I use Azure over AWS or why should I use AWS over Azure or why should I use GCP or why should I learn Azure or why should I learn uh AWS so that question only I have only one [25:12] so that question only I have only one answer to that question that if you are already familiar with Microsoft product or let's say as a company if I'm already using Microsoft products which most company are. If I'm [25:27] already using Microsoft product, I can crack a good deal with Microsoft. If I want to use Azure, if you're using Microsoft products, it's possible that your company is already Microsoft partner. So they can crack a [25:43] good deal and they can get get a good discount uh with Microsoft uh they if if they want to use Azure right right AWS benefits you like uh if you are [25:58] already I mean Microsoft Azure started late as compared to AWS AWS was the first cloud in the market so that's why AWS has had lot of shares if you go 5 years back so if you are already with Amazon and if [26:12] your sales team can crack a good deal with AWS, your company might be using AWS. If your Microsoft partner in your company can crack a good deal with Microsoft Azure, they will be using Microsoft Azure. Another way is if let's [26:27] say your company is getting a new project and in that project they will be hiring few people. So they will be hiring people and those people are familiar familiar with Azure. So for that particular project, your company [26:41] will go with Azure. If your company is launching another project and they're hiring people and they see that yeah, we have lot of professionals who who understand AWS. So for that project, they'll go for AWS. I've seen this in [26:55] lot of companies. For my own company, we have few services When I raised this question to my manager, why do we why do I why are we using two different services? So they said that whatever developer we have in [27:10] this project they are familiar with Azure they're familiar with net so they are familiar or more aligned to white m towards Microsoft project so that totally depends on your on company by company scenario which cloud you'll see [27:24] company scenario which cloud you'll see more okay but AWS and Azure are the top more okay but AWS and Azure are the top contender GCP is also coming up right so these are three these three are the top contenders in the market so if you're [27:36] choosing Azure uh you'll definitely ely land a job and you'll get a good good land a job and you'll get a good good pay as well. Okay. So the two things that we didn't discuss in the benefit is scalability and data [27:48] recovery. So what is scalability? Scalability is a way to add or remove the instances from your solution. So let's say I have from your solution. So let's say I have a website. [28:06] host this website. How do I decide how many servers I should be uh launching on many servers I should be uh launching on Azure and on how many servers I should be launching my website or installing my website? How do I decide that? I can't [28:24] decide when when the website is new. You cannot predict the amount of traffic your product is going to receive. Can you predict that? Obviously no. So what you'll do, you'll start with less number of servers. Let's say I'll start with [28:39] two two servers and suddenly my marketing team has done and suddenly my marketing team has done a quite fantastic job and promoted my a quite fantastic job and promoted my website on on some on some popular show. [28:53] So as soon as my as my website was promoted, I saw the spike in the traffic. So in that case if the traffic is more can you u can your two servers handle all all [29:08] all that all that traffic obviously no depends on what what configuration you have right so as soon as the traffic as the traffic increases I need to add extra servers so [29:23] increases I need to add extra servers so that adding or removing of extra servers is known as scalability either adding the services or removing the adding the services or removing the services is known as scalability. [29:37] All right. So there are two types of scalability horizontal and vertical. So scalability horizontal and vertical. So you can increase the configuration that you can increase the configuration that means you can scale up. [29:51] Right now let's say you have 2 GB of RAM and uh four virtual CPUs. So you want to increase the config that means I want now 16 GB of RAM and eight virtual CPUs. [30:04] So this kind of scaling is known as scale up or scale down from 16 to 4 GB and two virtual CPUs. Right? So you are either increasing or decreasing. So that is known as scale up. If you're [30:19] increasing that is known as scale up. If you're decreasing that is known as scale Similarly, if you're adding the number of instances, that means you're adding extra servers. So, you're scaling out. [30:32] You're decreasing the number of servers. You're scaling in. Okay? When someone says scale up, that means you're increasing the size, the means you're increasing the size, the configuration, amount of RAM. [30:46] configuration, amount of RAM. If someone says scale in sorry scale down then you're decreasing the amount you're decreasing the configuration. When someone says scale out you are adding number of instances. Someone says [31:01] scale in that means you're removing the extra instances. Okay? Doesn't matter if you remember scale up scale out nothing. You just need to remember scalability. Scalability means adding extra instances or increasing the configuration or [31:14] decreasing the configuration. That's all. Okay. Data recovery. all. Okay. Data recovery. Uh by default there's no data recovery. You need to configure it. But when it comes to cloud, it's very easy to [31:28] configure the data recovery. So as we progress in our Azure journey, we will have one chapter where you'll understand how you can recover your data in case uh there's a failure or in the in case there's a loss of data, how can you [31:42] recover it? Okay. So data recovery is very simple when it comes to cloud. [snorts] Cost effective and security we have already discussed right. Salman is asking difference between scalability and flexibility. You are flexible to [31:57] deploy in any region. So any cloud gives you option to deploy your ser services in different regions like I can deploy in India, I can deploy [32:09] in US, I can deploy in Australia. So depends on my requirement I can deploy it anywhere wherever Azure has its presence. So that is flexibility. You're flexible enough to deploy in any region plus you are flexible enough to deploy [32:24] plus you are flexible enough to deploy in any size of of the server any configuration which is provided right. Scalability is removing the extra instances. Now a very good example of scalability [32:40] Now a very good example of scalability is the Amazon e-commerce website for uh shopping? shopping? So every year [32:57] Amazon comes up with a sale, right? What what that sale is known as? Great Indian what that sale is known as? Great Indian something [33:12] No, we have the sale, right? Great Indian festival or something, right? So during that sale, what do you think? The traffic will be more towards Amazon or traffic will be more towards Amazon or the traffic will be less. [33:29] platform, do you think the internet traffic will be high or will be low during the sale period? It will be high. Right? So when the sale when when sale is announced, you know that for 4 days we need extra servers. [33:46] Since that 4 days we have sales. So we might have lot of traffic. So we know we can predict. So if we have lot of traffic we can add the extra instances instances and then when sale is done after 4 days [34:01] obviously the traffic will reduce to normal we'll have normal traffic so we can reduce the number of servers now I don't know uh how old are you but the first sale that flipkart announced big billion something [34:15] the first sale was a flop why because flipkart didn't scaled its servers and it was it it failed for the first day. So they had to increase or add one [34:27] more day there. So they will be adding the scaling uh they they have to add the servers when when they are receiving lot of traffic. Okay, of traffic. Okay, [snorts] [34:48] screen. Okay. So these are the Microsoft Azure benefits to the business when they are opting out for the Microsoft Azure. Sisha is asking horizontal vertical scaling bins. I just explained scale up [35:03] scale out right. [snorts] So when you're scaling like this what is this horizontal right or sorry this is vertical right? So you're adding or you're increasing the configuration of your your server. So earlier you were [35:19] using let's say 2GB now you're using 4 GB that means you you now you're using 4 GB that means you you have added 2GB RAM extra so that is known as vertical scaling whereas horizontal scaling is you're adding [35:32] extra instances you had one instance you added two instance so now you have total three instance so now you have total three instance this is known as uh horizontal scaling [35:45] this is known as uh horizontal scaling here. [36:12] So, what skills are we going to cover in A305? Now, AZ305 has a study guide. So, A305? Now, AZ305 has a study guide. So, let me just launch. [36:31] If I go to a 305 here, not GitHub. exam I would ask you or I would encourage you to please uh go to this [36:46] website. Okay, this is the official page from Microsoft. So whenever you are sitting before sitting for the exam just go to this. [37:01] sitting for the exam just go to this. Okay just go to this page. So what this page is having this page if you go to this page you will see [snorts] the learn path. [37:18] Okay. What is this learning path? The learning path is the modules learning path is the modules the flow or the topics that Microsoft expects you to know before sitting for the exam. So what skills are we going to [37:31] cover? Now I'm not covering the skills from from the PPT. What skills I'm going to cover? I will be following this Microsoft learn path since this is up to Microsoft learn path since this is up to date as per the current exam. Okay. So [37:45] what are we going to cover? We are going to cover all this uh topics. Whatever is mentioned like if I go for the first module which is design, identity, governance and monitor solution. If I click on it, uh [37:58] this is what we are going to cover. So everything is mentioned here topic by topic what you should be knowing before sitting for the exam. sitting for the exam. Okay. Now if I go one page back and if [38:12] you see here somewhere you should see the study guide. So what is the study the study guide. So what is the study guide? The study guide is uh is again a guide? The study guide is uh is again a web page where Microsoft has defined [38:25] web page where Microsoft has defined uh what skills will be measured. Compute, network, storage, monitoring, security. If I scroll down, every skills is given certain percentage like every module is given a certain percentage. So [38:41] from identity governance and monitoring solutions you can expect around 30% of questions from storage you can expect around 20 25 from business continuity you can expect expect around 15 to 20 right similarly [38:56] from infrastructure solution you can expect around 35%. So what you should be knowing you should be knowing some logging solution like routing logs where you can keep the logs where you what monitoring solutions Azure has to offer [39:10] what is an authentication solution right so all this topic by topic is is is provided in this study guide now same thing is for any certificate that every certificate is mentioned over [39:24] preparing for before sitting for an exam, make sure you uh glance here to see if you know this, if you know this, if you know this, right? If you do not know this, please try to see what this topic is where you can see you can see [39:41] topic is where you can see you can see it in the learn path. Right? it in the learn path. Right? All right. So that's what this these are the skills that we are going to cover. Okay. [39:53] Everything whatever mention is here we we are going to cover. Now why I I ask you to visit here because if you see Microsoft keeps on adding or removing Microsoft keeps on adding or removing something from their exam [40:07] every 6 month or 1 year right so if you read this this note if you read this note says the exam will be updated on April 17 2026. When was the April 17th? [40:21] April 17 2026. When was the April 17th? Yesterday. So something is changed. is changed, you should review this study guide. [40:34] Okay. So if let's say next time, next year or after 6 month, if they don't year or after 6 month, if they don't want this particular topic uh in a 305, so they will remove it from from the study guide. So you don't need to need [40:46] that uh need to know that. So whatever Microsoft is making changes they will put that in the study guide. Okay. So I went through the old study guide and the new study guide but I don't see lot of things have been [41:01] changed. The only thing that Microsoft changed was audience profile. Okay. So it's a minor change from the syllabus wise. Nothing changed. Only audience profile change. So if you [41:16] see the audience profile here, you should have all the audience profile should have all the audience profile somewhere. [41:29] here. So this part is only changed. Now what Microsoft added as as far as I know Microsoft only added this. This wasn't part of the old study guide. Okay. But that's that thing which is added course wise nothing changed. your topic wise I [41:44] have went through the old and new study guide nothing is changed everything is guide nothing is changed everything is same from the course point of view okay uh there the link is shared if you see the chat box okay I already shared the [41:59] the chat box okay I already shared the link [42:11] now if you see the simply learn syllabus we have like uh we have divided this into 15 different topics but I'm not going to cover it topic by topic as defined here 15 everything I'll be covering or [42:24] summarizing in 10 or 11 topics okay whatever is mentioned over here everything is summarized in 11 topics since we have 10 days so I' I've summarized everything whatever we have [42:37] summarized everything whatever we have here from identity until uh infra everything I have sum summarized into 11 topics. Okay. Since we have to do the the the uh projects as well. So we need to [42:52] uh projects as well. So we need to complete everything in 10 days. Whatever Microsoft is asking me to cover, we will be covering everything which is defined in the study guide. Clear? [43:11] brings to you? the course uh is bringing you the u some projects some co-signed projects some assisted practices. So what these assisted practices are assisted practices is is the word documents that I'll be adding to the [43:26] LMS. So you will be having access to that. You can download it. It's like a stepbystep guide on how to do the demonstration on how to do the hands-on. So those assisted practice I'll be adding. We will be having case studies. [43:41] We will be having course and projects, ebooks. Microsoft has stopped providing ebooks. Microsoft has stopped providing ebooks. So your ebook is the learn path. So this is your ebook. Okay. The first link that I shared, please follow that [43:55] link. Uh or simply search for easy 305 in your search engine and you'll be landed to that page. Okay. So here you can find your learn path. Now why I'm [44:07] exam you have access to the learn path. So when you sit for the exam uh you can access the learn path learn path from there. So if you are stuck or if you [44:19] you can go to the learn path and you can try to read it there within the exam itself can try to find out the answer. So access is there. That's why I want you to go through the learn path. So you know in which page what service can get [44:35] me the answer. All right. getting with this course. Now when it comes to the exam a305 [44:54] the name is design Microsoft as your infrastructure solution you will be having around 60 to 70 multiple choice question totally depends on your set of paper that you're getting. So when I set for the exam I had like [45:08] for 53 questions multiple choice question and rest of the questions were question and rest of the questions were under case studies. Okay. So total 60 to 70 questions you'll be having including case studies. [45:22] Then the um the time that you'll be getting is 2 hours. So you'll be getting 120 minutes to complete the exam. And then in order to pass the exam uh you'll have to get 700 that means 70% [45:37] of passing mark out of 100 you'll have to have you'll out of 100 you'll have to have you'll have to get 700 and uh have to get 700 and uh there and once you click on submit there [45:50] only you'll come to know the result you don't have to wait for the result okay everything is proctored everything is computer basis so once you submit uh it will calculate the software will calculate your percentage and you'll [46:06] pass you need to have 700 you need to get 700. Clear? different languages. English, Japanese, Chinese. So whichever language you [46:18] Chinese. So whichever language you prefer, you can uh book exam in that language. Now where to book the exam from? [snorts] So if you go to the 305 page from there itself you have the option to book the [46:32] exam. Okay. So if you are in India you select your region wherever you are. Then click on uh then click on schedule exam and from there it will take you to [46:44] exam and from there it will take you to the Pearson VE page and from there you can schedule you can select the date when you want to sit for the exam. All those stuff you can do in a Pearson VOE site. [46:59] All right. [snorts] From the Microsoft page itself, you can book the exam. So that's all about the introduction about cloud computing, about simply learn and about easy 305. Any questions on the basics yet? [47:19] platform as a service, and software as a service? Now this is uh important to understand uh it's a it's a basic cloud computing service model. Okay. Um [47:34] when you are dealing with different compute services you'll have to understand the different between is PA and SAS. All right. So what is before going on break let me answer this quickly uh [47:51] and then uh if I'm not able to complete this in in in the next 7 minutes we'll continue this since this is important to understand is pass and s [48:03] understand is pass and s is pass and s from for me is pass and s from for me or for you to understand is paz and s or for you to understand is paz and s from a305 point of view okay I'm not [48:16] going at the A900 level since this is something which we cover in a 900 uh and a 104 as well. I'm not going into that level. So I'm I'm explaining it to you level. So I'm I'm explaining it to you from a 305 point of view. Okay. [snorts] [48:31] The full form is quite simple. Infrastructure as a service, platform as Infrastructure as a service, platform as a service and software as a service. All right. Now what is infrastructure as a service? So in infrastructure as a [48:43] service your responsibility is more your as in you are the customer of Azure or any cloud provider. So your responsibility here is more in p your responsibility is less as compared to infrastructure as a service. [48:59] Uh we are not saying that there's no responsibility there is responsibility. Okay. So how does this is pas and sas are are defined is defined in a shared [49:11] responsibility model. People people think that since we are using cloud everything is cloud provider's responsibility. That's not correct. We are sharing responsibility with the [49:24] cloud provider. Okay. So what is our responsibility? What is cloud provider's responsibility? What is cloud provider's responsibility? that will be defined depending on the model depending on the service model you are selecting [49:37] infrastructure service pass platform service software service now just to explain this in a simple term [snorts] I just gave you an example of of suiki let's say you have an you have a similar idea and you want to use uh internet for [49:51] your business so what you need to do you need to come up with an application first what is an application in simple term application is nothing but collection of files where your developer or if you are a developer you will be [50:04] developing the application. So how do you write how do you code an app code an application? You simply open a file if whatever you are using you simply start writing your code and that code is [50:17] written in a in a file. So you'll be having multiple files or you having single file depending on how big your application is. Now in order to store this or save these files, I need a server. [50:30] Okay. So when I'm when I'm selecting cloud within the cloud, I have two options to select from. Infrastructure as a service or platform as a service. In infrastructure as a service, the hardware server [50:45] hardware server is cloud provider's responsibility. Okay. Uh if you remember the data center model where you have to spend $1,000 or [50:57] whatever the server cost is [snorts] you have to spend that up front. We are not using on-prem model right. So we are not going to spend this upfront. So what we are doing we are using cloud. See even in cloud there is a hardware server. [51:10] Someone has bought the hardware server. Who has bought? In our case it will be So if I'm using infrastructure as a service, this hardware server is cloud provider's responsibility. Now within that [51:25] hardware server, the cloud provider will be deploying their own operating system. So in case of Microsoft Azure, they are deploying [51:37] HyperV. HyperV is nothing but an operating system. It's a hypervisor which allows them to create multiple uh machines on or multiple virtual machines on top of this hardware server. Okay. So this HyperV is also their [51:51] responsibility. [snorts] All right. Now on top of this HyperV I will be creating my virtual server. This is a physical server which is cloud provider's responsibility. The operating system which is again cloud provider's [52:06] responsibility. on top of this hyperV I will be creating my server my virtual will be creating my server my virtual server let's call it virtual machine 01 [52:18] responsibility now within this virtual machine 01 I will be deciding whether to go for Windows operating system or Linux operating system that's I'll have to decide as as a customer I have to decide this okay so here what uh what Microsoft [52:36] what we will do we will select let's say we select Windows operating system and on top of that Windows operating system you have to use the runtime or [52:48] the framework. So when you are writing an application your developer will write an application your developer will write that application ill in certain code in some code right he might be using Java he might be using python might be using [53:02] net whatever he's using you need to ask your developer or if you're a developer you should know that that there is framework I need to I need to use that language so in order to host the application I need to have this runtime [53:16] host my application where I want to add my files. So on top of Windows operating system, you will be deploying the .NET framework. Okay. And on top of that Net Framework, you [53:31] will then host your application. That means you will add your files. So what is my responsibility as a user here? My responsibility is the operating system that I'm choosing, Windows operating system. My responsibility is [53:46] the framework that I'm choosing,Net. My responsibilities is to take care of my application. That means I have to either hire a developer or if I'm a developer hire a developer or if I'm a developer I'll have to develop the code. [53:58] Now tell me every month Microsoft launches the update right? you know the update update patching [54:11] receive the update for the applications that you have installed right every that you have installed right every month or every week whatever so since this is hosted on cloud the Windows operating system on my virtual [54:24] machine who will be responsible to patch that your responsibility. You as a user, Azure will not patch it [54:41] for you. Okay? Yes, there are way to ask Azure to patch. Uh but Azure by default operating system. So you have to patch it. Then if there is a new version available for net, who will be installing that new version? Again you. [54:58] So whatever above HyperV is our responsibility. So infrastructure as a service model requires more responsibility uh from from the user. Whereas PA model is same there will be [55:13] physical hardware server on top of it there will be any on top of it there will be any hypervisor like HyperV or ESXi whatever cloud providers is using. There will be virtual machine there will be a [55:27] virtual machine there will be a framework like net java whatever when I'm using p all this stuff becomes the cloud provider's responsibility what is my responsibility when when I'm using p the [55:40] the application code is my responsibility so if I'm a developer p is something that I'll be choosing why because I'll get more time to focus on the development the virtual machine whether it's Linux [55:55] or operate or Windows it's Microsoft responsibility to patch your responsibility uh reduces when you use the paz model the p service model clear [56:15] entire software is given to you as a service like M365 Microsoft 365 you're using Google Drive. So Google Drive is a software as a storage service given to you. What are your responsibility when you are using Google Drive? [56:31] What is your responsibility when you're using Google Drive? Just adding data and sharing that data with whoever you want. That's all. That's your responsibility. So you're using that software entirely. Do you know where Google is hosting? [56:45] Where Google is saving? Whether it's saving in India, Australia, US, wherever how Google is storing that is is that something we need to bother about as a user obviously not so software as a service what is your [56:59] so software as a service what is your responsibility reduced entirely zero. using free version you can store up to 15 GB. If you need more you just subscribe for a plan that's all software as a service. Netflix software as a [57:12] service. Are we paying for each movie separately? No, we are buying a plan. Do we need to keep a CD of all the movies? No. We just subscribe to a plan. We watch our our content, right? Software as a [57:28] service. What is the infrastructure as a and a platform part of Netflix? Do you know CDVD was CDVD? What what what was required? [57:40] We need the CD player or the DVD player, right? So, we need to buy it. So, I am responsible for the hardware. I am responsible for bringing the CD or DVD. I'm responsible for placing that CD DVD within the DVD driver uh DVD reader and [57:55] then I can enjoy my movie. If I don't have a CD of one particular movie, I don't have the CD. Right? The CD DVD player becomes the infrastructure as a service part in case of movies and all. What could be the [58:10] platform as a service part? Uh I cannot think of any here. Okay. you go for infrastructure service model. Who will do the service of CDVD? Obviously I have to do as a as a as as a owner of that. Right. In Netflix, [58:26] however they are hosting it, I don't care. I just pay them. I enjoy their service. That's all. Clear? Any questions on this? We will revisit this when we are on the compute section. Okay. [58:42] So let's move on to our first topic which is uh authentication and authorization. So from the study guide we will we are from the study guide we will we are covering uh this topic [58:54] this module design identity and governance and monitoring solutions and there we are covering authentication and authorization. This is the uh these are the topics that we are going to cover. Okay. [59:08] Okay. And from the learn path covering this one design identity governance and monitor solution. So [59:23] first three topic will be identity and governance. Monitoring we'll cover once we have done uh covering all the services. So at the end of the uh I mean monitor solutions. Right now we are [59:36] starting with identity and governance. Okay. [snorts] Now before I start I need an answer from you. How many of you have worked with uh adds active directory domain services or if you're from the Linux back background uh how many of you [59:52] Linux back background uh how many of you know what LDAP server is? What are these two services? And those who uh who are freshers please uh wait I'll explain what I'm uh what this topic is about. Okay. Okay. So what [01:00:09] is ADS? Those who have worked with active directory what is this? So what are these services? Adds an LDAP. [01:00:31] Okay, never mind. Those who don't know, please pay attention. Okay, those who haven't worked with any of these services, you might have uh these services, you might have uh account right in OTT platforms like [01:00:46] Netflix or Amazon Prime. Do you hold the account? Amazon Prime. Do you hold the account? How many of you have account in Netflix? [01:01:05] order to access or watch any any web series or a movie, what do you do first? You go to dubdubdubnetface.com, right? If you're using uh laptop, you go to this website. What happens? First thing what it ask does it allow directly [01:01:22] to watch the movie or there is something which we need to do? Login, right? So we need to provide our credentials. login we need to provide our username and password. So what happens when we provide username [01:01:37] and password? Netflix service checks your username and password. It checks whether you are providing correct username and password. If you're providing correct username and password, you are allowed. [01:01:51] If you provide wrong username and password, it may deny deny you the entry and you won't be able to access those services. Right? So this process of providing username and password and identifying that username and password [01:02:07] is known as authentication. That means That means I am not I am Netflix is authenticating me checking me whether the credential that [01:02:22] I have provided is correct or not. Okay. So what is authentication? Okay. So what is authentication? Authentication is a way to to check someone with a certain credential. Apart from credential, how you can check [01:02:36] someone? You can check them with with their card, smart card. If let's say you work, you go to your office. When you go to your office, there is a door. In that door, you have to there's a reader where you [01:02:50] you have to there's a reader where you have to place your your smart card. Those who are working might know Right? You have to place your smart card. Without smart card, there's no entry. You cannot go in. Right? Unless [01:03:03] your company has no security. Most of the company do have security and they do provide the smart card to their uh employees. And in order to enter the building, you need to place that smart card. So when you place that smart card, [01:03:17] the identity service that is deployed within that building checks whether your smart card is valid or not. If it's valid, you can go in. If it's not valid, valid, you can go in. If it's not valid, you cannot go in. Okay. So, what runs [01:03:32] you cannot go in. Okay. So, what runs behind uh behind that authentication is this kind of services adds or LDAP. They runs behind the services and they checks whether your username or password [01:03:45] is correct or not. You use your laptop, you [snorts] use your company laptop or provide your username and password correct or not. We need to provide [01:03:57] nowadays Microsoft has made it made it compulsory to enter your [snorts] address. So once you provide your email address and password then only you can enter your laptop and do whatever changes you [01:04:10] want. So this part of verifying the user the application or whatever you have whoever needs access [01:04:23] is known as authentication. Authentication is a is a is a process of verifying a person person is nothing but a user or application to see whether the [01:04:35] credentials provided are correct or not. Okay. So that authentication is done by the services. Then [01:04:47] once you are in once you're inside the building which flow you can access which flow you cannot access that path that part is cannot access that path that part is known as authorization. [01:05:05] [snorts] different plans, right? You subscribe for different different plans. We have mobile plans, we have standard plan, and then we have HD plan, right? I don't know the current plans, but this was the plans we we had, right? So you [01:05:21] have uh mobile plan where when you log into Netflix, you can only watch Netflix within I mean within your mobile app. Then you have standard plan where you can uh watch in two different screens [01:05:37] uh at at the same time and then you have some plan where you can watch in four some plan where you can watch in four different screen. So once you log in once Netflix authenticates you once you're inside the application that means [01:05:50] you have got the access now it totally depends on the plan that you have subscribed to depends on that you're authorized to watch either on mobile or on two screens at a time or on four screens at a time. So that part of [01:06:07] application and then checking what you are authorized to do, right? So like in cloud world, cloud world you are logging into Azure portal. So that login thing is nothing but [01:06:23] authentication and then once you are logged into that application, what you can do? Can you create another user? Are you authorized to create another user? Can you delete the existing users? Are you authorized to do that? So to check [01:06:37] what you can do, what can what you cannot do is known as the process of checking what you can do, what you cannot do is authorization. Okay? Clear? What is authentication? What is [01:06:50] authorization? Is that clear? Now this is basic of any identity uh any identity and access management system. [01:07:03] All right. [snorts] So, authentication and authorization. If you want to implement in your organization, you need some kind of identity and access management system. If I want to implement authentication [01:07:18] and authorization in my organization, I need some kind of AM service. AM stands for identity and access management. Okay. So if I want to uh [01:07:30] implement that [snorts] let's say I'm not using cloud I'm using on-prem network. So in my on-prem data center I can either use active directory center I can either use active directory domain services or if I'm good with [01:07:44] domain services or if I'm good with Linux I'll be using LDAP services. How do you use these services? You need to have a server first hardware server or or a virtual server whatever if you're using on-prem [01:07:58] server on top of that hardware server depends on whether you are using virtualization or directly physical server you'll have to have Windows OS if you want to use ADDS or Linux OS if you if you want to [01:08:13] use LDAP okay on top of that on top of Windows operating system you'll be deploying the active directory domain services role and there on top of it services role and there on top of it you will be promoting this server to [01:08:28] creating your domain and once it's promoted and your domain is ready then promoted and your domain is ready then you can go ahead and create your users users groups whatever you want you can add computers and all right [snorts] so [01:08:42] this is all all all the stuff you need to do when you're doing onrem that means to do when you're doing onrem that means your own data enter everything you need to do. You need to bring a server. You need to install the [01:08:55] or uh install the operating system. Then you need to install the adds role on top need to promote it to domain controller. Once everything is done, then only Once everything is done, then only you'll be able to create users and [01:09:09] uh groups and uh add computers. groups and uh add computers. Okay. Now if you want to use Azure for IM, Azure has Microsoft Entra ID which is [01:09:26] Azure has Microsoft Entra ID which is nothing but a cloud-based AM service. When we say cloud-based I uh AM service, we don't need to bother about all this stuff. We don't need our own server. We don't need to install Windows operating [01:09:40] system. We don't need to install ADS on top of it and then promote it to domain. top of it and then promote it to domain. Everything will be handled by Microsoft. What we can do if you're using Microsoft Enra ID, as I mentioned, Microsoft Enra [01:09:52] Enra ID, as I mentioned, Microsoft Enra ID is a cloudbased AM tool. You sign up and start using it. You just sign up for Azure service for Azure portal and start creating your users. Don't need to bother about all this stuff. [01:10:07] scratch, then you you are responsible for everything from scratch. If you want to go for cloud, we have we [snorts] can sign up and we have access to Microsoft enter ID. We can start creating users [01:10:21] uh directly. Okay, [snorts] is IM clear? It was just basically just giving you an It was just basically just giving you an overview of IM. So what is ZTM? ZTM [01:10:35] stands for zero trust model. Yeah. Now zero trust model is not a service. It's zero trust model is not a service. It's not a policy. It's just a framework uh based on the principle of never trust always verified. [snorts] [01:10:50] Now if you go back few years like before cloud if you go back 10 years cloud if you go back 10 years how do we used to consider the security? If you go back 10 years, if you go 10 years back, uh at that point in time, we [01:11:06] had the parimeter network where you used to keep the firewall, uh IDS, IPS, all these devices we used to keep in a parimeter network before anyone can get into our network, uh the traffic was verified by these devices. And once the [01:11:22] traffic considered as safe, then it can go inside our network. then it can access our servers whatever servers we had right so this is how we used to keep not using firewall now we still using firewall but back in the days the [01:11:40] were kept in the demilitarized zone in the parimeter zone here but now we need to protect [01:11:54] we need to protect our identities Since if everything is cloud now uh 90% of the workload is in cloud only the banking the airport the airline those mostly are still using onrem but 85 to 90% traffic is already [01:12:12] uh in the cloud. Now if someone logs in and if he is authorized to do something and if let's say the login credentials are compromised then we are gone right. [01:12:25] So with the changing pattern a new model came in which is known as zero trust model. So what zero trust model does it's just a framework which based on this [01:12:38] principle never trust always verify. You have to always verify whatever request is coming in. Okay. So what are the key principles? We And in order to implement this zero trust model, you need to have certain IM [01:12:55] trust model, you need to have certain IM service in place in your organization. So zero trust model based on this principles like verify the request first. So every access request whatever request is coming in. So if someone is [01:13:10] entering your building, you need to verify that you need to verify uh him or her. How do we verify? We use smart card, we use biometrics, whatever. Right? We need to verify that. Then second principle we have is least [01:13:26] privilege. What what is least privilege? Now in in an organization or in an office building, we have different different areas like we have common areas like cafeterias, like gaming zone, right? And [01:13:41] then we have some sensitive areas. So in IT we have data center, right? >> In airport, if you go to airport, we have immigration. Then before immigration, we have the check-in area. So check-in area is not [01:13:56] sensitive area. Anyone can go there and and and do the check-in. So it's like a and and do the check-in. So it's like a common area. So we need to provide the least privilege to the users. Like common areas everyone can go but [01:14:09] common areas everyone can go but sensitive areas only authorized person should go. So when we are using smart card based authentication we will divide the smart card into different types like everyone will have in uh whoever has the [01:14:23] smart card they will have access to the common areas whereas only authorized people will have access to the sensitive areas like data center building itself right like [snorts] knock room what is knock room is network [01:14:38] operation center where from where you can monitor your your client's network, your own network. So those areas are sensitive. Why? Why? Because no rooms have access to the servers, remote access to the servers. [01:14:53] So I cannot allow everyone to go to the knock room. So we need to uh give the lease privilege that means only people belonging to the knock team they can enter the knock rooms. Lease privilege, [01:15:07] right? Micro segmentation. Micro segmentation is like dividing the [snorts] uh area or the network into smaller uh area or the network into smaller smaller uh VLANs or smaller smaller [01:15:22] segments so that we can keep our monitoring uh continuous. We need to divide our area into smaller segment. Like [snorts] here we can have [01:15:35] certain CCTVs. Here we can have certain CCTVs. Here we can have certain CCTV. So this is my one area. This is another area. This is another area sensitive area where I can have multiple CCTVs. Uh this is knock room. So within that room [01:15:49] we can have uh three or four different uh CCTVs from different different uh CCTVs from different different angles. Right? So I need to divide my angles. Right? So I need to divide my uh let's say network or areas into micro [01:16:03] segments. All right. So that I can have a continuous monitoring. So these are few principles that we have uh in zero trust model. Now again I'm saying zero trust model is not a [01:16:18] saying zero trust model is not a security uh policy or is not a a tool it's just a framework which defines some principles and you need to make sure when you're implementing IM or you're designing IM you need to keep these [01:16:32] things in mind all right verific [01:16:44] have a team who can continuously monitor and always assume breach. What do you mean by assume breach? We have to do continuous monitoring and we have to assume assume breach and continuous monitoring works hand in [01:17:00] hand. Assume breach as in let's say we have applied all the zero trust models that doesn't means you are secure. Why it doesn't means we are secure. It's possible that someone who has the access has lost the credential. [01:17:14] has uh the credentials he was he or she was having uh was compromised and some person who should not be having his or her credential has got the credential and now roaming freely everywhere. Right? So every time we need to assume [01:17:30] breach now how do we assume breach? What what is the meaning of this assume assume breach? [snorts] How many of you uses uh Gmail? [01:17:44] you users? I'm sure 90% of people are using Gmail, right? So, have you ever tried logging into Gmail from a different device, from a from a totally new device? Back in the days, we used to have cyber cafe, but I don't know if we [01:17:58] we still have the cyber cafes. But let's say you change your mobile and you log in from from a new mobile. So, what happens when you log into your Gmail account from a new mobile? You get a message right? you tried uh [01:18:14] from a different mobile please uh please uh approve your notification in already existing mobile or your YouTube application or or wherever right so we get that kind of message so what is that Gmail is assuming [01:18:29] that it's not you who's trying to login so it's not you who's trying to login so that's why Gmail is uh sending you that popup please notify uh please uh approve please approve so that's That is the [01:18:42] please approve so that's That is the meaning of assume breach. Okay. So even though you have applied all the principles of zero trust model, you need to make sure or you need to assume breach so that [01:18:59] breach so that wrong person or a hacker cannot get into your account. It's possible that my username is compromised since Gmail we have used or we have given our email id to lot of people. So email id is already [01:19:13] compromised. Now what hackers can do they can launch different kind of different kind of attack against the username since username is already uh public right everyone knows my email id obviously not everyone knows but who I [01:19:27] have shared my email ID with banks with e-commerce applications with Netflix with with different different service providers who knows who's selling my data right so if someone is has sold my data my uh uh email ID is already in [01:19:43] public so hackers can get that get my email id and try to launch different different kind of attack so that's why we have to assume reach if you log into your Gmail from a new location from a new device you would see that popup [01:19:58] new device you would see that popup all right so in order to make sure that [snorts] your data is secured your access is secured you need to follow the zero trust model framework so what does zero trust model says in [01:20:12] so what does zero trust model says in short Never trust always verify right even though when you're logging into logging in from new mobile you're providing correct username you're providing correct password still [01:20:26] providing correct password still Gmail is popping uh popping up to you to Gmail is popping uh popping up to you to approve that that login right even though you have provided correct username password Gmail is thinking that [01:20:39] it's it might be a breach clear so So that's what zero trust model is. Now how to implement zero trust model? You need to have some kind of IM service. So in Azure we have Microsoft Entra ID. [snorts] So what is identity [01:20:54] and access management? Identity and access management is just a service which helps you to implement authentication and authorization. It al it also gives you a way to manage accounts. Uh some IM also gives you the [01:21:10] way to do the reporting right. I want to fetch a report of my users who log in when from where. So all those stuff identity and access management gives you. In simple what is identity and access management? You have an identity [01:21:25] access management? You have an identity that identity is is some object which that identity is is some object which requires the access to your resources. Okay. Simple ter Identity is a is an object which requires access to the [01:21:41] resources. In basics [snorts] of cloud computing, we understand we understood what cloud computing is. What is cloud computing? I'm again going back to the basics. Cloud computing is a way to deliver [01:21:57] cloud uh to deliver the compute services over internet. Why you will be using over internet. Why you will be using cloud? to deploy the resources. What those resources are? You need to deploy server. You need to deploy database. You [01:22:12] need to deploy storage. So these are your resources. Now how are you going to deploy these resources? You are deploying these resources. So you are the object who is deploying these resources. So you are [01:22:24] the identity. Whether or whether you can deploy or cannot deploy, we need to first identify this guy who wants to deploy. So he needs to go to portal.azio.com com and our AM service will identify [01:22:40] that user will identify that identity will identify that object who's trying to coming into our uh system right after [01:22:53] identifying we will authenticate I mean not we the identity and access management service will authenticate that user whether the username and password provides provided are correct or not okay Then the authorization kicks [01:23:06] or not okay Then the authorization kicks in. Once you are inside the cloud, deploy server? Can you deploy database? Can you deploy storage? Can you do that? Authorization [01:23:22] account management. You want to create few new users. You can do that using any IM service. Whatever IMC services you have developed, access control. what a user can do, cannot do, you can define that using access control. Okay. And [01:23:37] then auditing and reporting. Any IM service uh most of the IM service gives service uh most of the IM service gives you the auditing and reporting them. So what is IM? Is that clear? Now in Azure, [01:23:51] we have Microsoft Enra ID. So Microsoft Enra ID is the service uh which is a cloud-based identity service. So as I mentioned earlier, you don't need to deploy a server or anything. You just sign up for uh Azure [01:24:06] anything. You just sign up for uh Azure and you have your Microsoft Entra ID. We to sign up for Azure. That means you need to create your account on Azure and once you have created your account, you already have Microsoft Entra. So it's a [01:24:20] cloud sorry it's a cloud-based identity and access management solution. All right. So it gives you centralized centralized single Microsoft Entra tenant, you can simply use that tenant and start [01:24:35] creating your users. Right? If someone is already using Active Directory domain synchronize their users with Microsoft Enter ID. So, Microsoft enter ID [01:24:47] previously known as Azure Active Directory it was launched in Directory it was launched in 2013 or 15 I'm not sure on the exact year but during that time it was launched before that Microsoft had this [01:25:03] service active directory domain services which uh the short form for that is adds which people were using on prem cloud started people were using on prem cloud started gaining prop popularity after 2010 or [01:25:18] 2011. I think 2006 or 7 AWS got launched and I think 2006 or 7 AWS got launched and 101 Microsoft came in and by 15 it was 101 Microsoft came in and by 15 it was all popular 1516. Okay. So before that [01:25:31] when cloud was not there people were already using ADDS for their on-prem identity and access management services. So those those organization who are already having ADDS and they want to use Microsoft Enra ID [01:25:46] then which identity and access management service will do the authentication will do the authorization will do the verification. So you have adds you have Microsoft enter ID both are IM service which will [01:26:02] enter ID both are IM service which will do the authentication which will uh if you are resetting password which will be considered as as the uh having the highest control. So all those question were arises arised if you use two [01:26:17] services. So what Microsoft did Microsoft created Microsoft entra connect. So it's a tool which you can install on your on-prem server and using [01:26:29] that you can synchronize your on-prem users to Microsoft Entra ID. Okay. So if I have hundreds of users on prem and if I use Microsoft Entra [01:26:43] connect all hundreds of user will be synchronized to Microsoft Enra ID. Okay. So whatever user you have over here, all users will be synchronized. [01:26:55] Instead of recreating user in Microsoft Enra ID, you use this tool and synchronize your users. That's all. All right. [clears throat] So that option [01:27:07] Microsoft uh gave to the people who are already using Microsoft uh active directory domain services. Microsoft created a tool. You deploy that tool on a server and you start synchronizing your user. If you create a [01:27:21] new user, that new user will also get synchronized. All right. [snorts] So, Microsoft Enra ID in short is a cloud-based identity and access management solution that you can use [01:27:34] once you sign up to the Azure. It's free of cost. Obviously, there are different plans and pricing, but uh when you start, it's free of cost. Okay. So how to see Microsoft enter ID in action. [snorts] [01:27:49] [snorts] If I go to uh Azure portal. All right. [snorts] Now in Azure portal before I show you the Microsoft Endra ID let me show you the Microsoft Endra ID let me just explain or give you the tour of [01:28:03] Azure portal. Okay. So I'll do it from scratch. Let me Okay. So I'll do it from scratch. Let me sign out. [01:28:21] thing that you need to do whenever you want to interact with Azure platform, want to interact with Azure platform, you need to go to portal.azure.com. [01:28:33] be going when you want to log into Azure or when you want to interact with Azure or when you want to interact with Azure portal. when I click on uh when I press enter first thing that Microsoft Azure portal or Microsoft is doing is what [01:28:49] it's asking what is this process I went to portal.asure.com your.com and it directed me to this what it is doing right now authentication. right now authentication. Okay, it is asking me to prove my [01:29:04] Okay, it is asking me to prove my identity. So this step that we are going that we are doing right now is authentication. All right. So authentication is the process of [01:29:18] verifying and identifying the identities. This is my username. How do we usually authenticate? We ask for the username. So my username is already selected here. Already mentioned here. If it's not [01:29:31] mentioned, I can simply provide my email ID. Whatever my email ID is, right? So this is my email ID. For example, I'm providing that. I click on next. It will ask me for the password. I provide the password. I click on sign in. Okay. Once [01:29:45] If my username and password are correct, I'll be inside. So I'll I'm in my application. All right. Now this is Azure portal. Now [01:29:57] those who do not have access to Azure portal, what you can do is [snorts] either if you want to use your own account uh unrestricted account, you can sign up for free tier. [01:30:16] You search for Azure feed free tier and you will see uh the Microsoft Azure page in Google or Bing. You just search for Azure free tier. [01:30:33] providing and there you'll be having a button which says get started with Azure. Click on it. Once you go once you click on it, you can click on try Azure for free. Once you click on try Azure for free, it will [01:30:48] you click on try Azure for free, it will ask your email ID and your password. Right? So, you need to provide your uh Microsoft email ID. If you do not have one, you can create one from here. So, whatever email ID you have, you provide [01:31:00] that. Now, in my case, I have already utilized. So, if I enter my email address, uh it will trigger it will say that I'm not eligible. Why? because I've already used it. Okay. [01:31:19] it will say I'm not eligible. So, uh in order to utilize Microsoft Entra ID, sorry, in order to use Azure free tier, you [01:31:32] need to have a unique email address that you have not used before, right? [01:31:54] email address that you have not used before. Right. [snorts] So here it says I'm not eligible. Why? Because I've already utilized it. So I can sign up for a pay as you go go pricing. I cannot sign up for a free tier. What I'll do? [01:32:11] I'll see if I have any other email address. But I'm not signing up since apart from email address, you also need a unique credit card, right? So I don't have a credit card. I've already utilized all my credit card. So if I [01:32:27] have any other email address, I can use that. So let me see. [snorts] [01:33:39] able to demonstrate how you can come up with the but it it's very basic you just provide your email address once you provide the email address you can then uh provide your details like your mobile number that should also be unique, your [01:33:52] email address that should also be the one that you have never used before and the credit card which you have never used before. So, Microsoft Azure has this restriction where you cannot [snorts] use the same email twice to [01:34:06] avail the free services. So, you need to use new email every time. But with new email, you need to have a new credit card as well as you need to have a u a different mobile number that you have never used before. [01:34:20] All right. AWS I think doesn't have that issue. With AWS, you just need a new email address. You can use the same credit card again. Okay. So that's how you can sign up for a free tier from here. Once you have the [01:34:34] free tier um you can then sign into portal.azio.com. So once you get your free tier you can then sign in by going to portal.azio.com [01:34:46] providing your email address that you use to sign up and your password. That's all. All right. Now let me introduce you or give you a tour to Azure portal. So [snorts] the first thing that you see on left hand side here [01:35:00] uh where where you see nine dots. So this nine dots is a cloud menu. Okay. What what do what what is the cloud menu? This is a newly uh uh new feature or or a new option that Microsoft has added where you can launch different [01:35:15] Microsoft portal directly from here. So let's say I want to work with GitHub. So the GitHub. I want to work with Intune, I click on Inune, it will take me to the Intune. Right? So different different portals. shortcut to that portal [01:35:30] portals. shortcut to that portal Microsoft has just added here doesn't u it is helpful when you want to switch between different u different portals if you want to uh go to GitHub from here [01:35:46] click on this shortcut and go to that right after the cloud menu the second thing that you that you see with the three lines uh is known as [snorts] [01:35:59] uh portal menu. So if I click on it, you'll see the menu over here from where you'll see the menu over here from where you can go to you create any resource. Uh some shortcuts are given, right? Go to homepage, go to dashboard page, uh go [01:36:12] to Microsoft Enra ID, go to monitor services, right? So shortcuts are given. So you can launch whichever service you want. I want to work with virtual machine. I click on this portal menu. I launch the virtual machine and I go to [01:36:25] Similarly, any service that that we want to use, we we go there and we can use it. Okay. [snorts] Next, after that, you have this it's the brand name. So, if you click on it, you'll be landed to the homepage. [01:36:40] Whatever page you have selected, you'll be landed to there. All right? It's just uh a shortcut to go to the to the homepage or to the dashboard whichever you have selected. Then, if you go right hand side, you have the search bar. [01:36:55] If I want to, we will be using this search bar every time we want to work with any service. So this search bar will help me to search for different resources. Like if I just type virtual, it will list out all the services which [01:37:09] has uh virtual in it. Like I want to work with virtual machine. I search for click on virtual machine. It will be landed to the virtual machine page. From here I can create virtual machine. I can stop existing virtual machine if I want. [01:37:23] start, restart, whatever. Right? Similarly, if I search for database, so anything related with with this particular keyword will be uh placed over here, right? Database watcher, SAP solution, whatever I search [01:37:38] for SQL, all the SQL related services will be provided. Right? So, this is just the search bar, a shortcut you can say to search and go to any service that you want. Then if you go on again on right hand side you [01:37:52] you go on again on right hand side you have copilot. What is copilot guys? So copilot is a gen AI tool from Microsoft right. So if I click on co c co c co-pilot within the browser itself I will get a way to chat with the [01:38:09] co-pilot. So if I have any issue like I want uh copilot to answer any of this any of the question like I just uh added hi it it gave me the response right I want copilot to create an ARM template [01:38:27] want copilot to create an ARM template for me me a give me a response depending on my prompt. So the better the prompt is the [01:38:41] better the response will be right. So it is now generating the template. I can use that template then right [snorts] apart from that it also has few bots kind of question already created. So if you click on it that will be the [01:38:55] prompt for for your copilot. So copilot option is is given there. If you want to utilize it for anything you can want to utilize it for anything you can utilize. So uh nowadays Gen AI is quite [01:39:09] utilize. So uh nowadays Gen AI is quite smart. Okay. So if you see this, it have created a template for me. I can now use this template. If I don't know how to deploy the template, I can again ask the copilot how do I deploy this template? [01:39:22] copilot how do I deploy this template? It can help me. Right? So anything I I It can help me. Right? So anything I I need [01:39:34] on your prompt. how good your prompt is, it will give you the answer. Now, obviously, I'm not saying that it's it's perfect. It can make uh mistakes, right? perfect. It can make uh mistakes, right? So, whatever you're using, uh use it [01:39:51] uh try it and then if it's wrong, ask it. Ask the copilot or the chat GPT again. Right? So, you see how how to deploy this. It has given you the the the steps, right? So nowadays it has become very easy to do the hands-on by [01:40:08] use by using chat GPT or copilot or whichever geni tool you prefer. Right? whichever geni tool you prefer. Right? So it's just a simple way instead of launching copilot in a different tab Microsoft has given you that uh option [01:40:22] within the portal itself. Then after copilot the next option or the next icon that we have is the cloud shell. So what is cloud shell? So if I [01:40:34] click on the cloud shell, it will launch the command line interface within the portal itself. So within the graphical portal.azio.com, [01:40:46] I have the option to launch the cloud shell directly. So what is this cloud shell? It will allow me to interact with the Azure platform using the commands. virtual machine, I need to use certain command. Now what that command is uh you [01:41:03] command. Now what that command is uh you need to uh rely on Microsoft documentation to get the command or you can take help as well. Right? So type help to learn more. Type a to use Azure CLI. Right? A VM stop and then the VM [01:41:18] name and all. If I give it will simply stop that VM. So these are the required stop that VM. So these are the required field. If I want to stop any a VM, it's just a way to interact with the Azure portal or Azure platform we can [01:41:32] say using command line. So you can use either the bash shell, the Linux shell or if you're more comfortable with power p PowerShell, you can switch to [01:41:45] PowerShell as well. Okay. So now if you see I have clicked on switch to PowerShell. this button right now it's showing as switch to bash but when you are in bash it will show switch to powershell so I clicked on that and now [01:41:58] I am in powershell so I can run the powershell commands now to interact with us your portal all right now if you want to restart the terminal I mean the cloud terminal you can click on restart and it will give [01:42:11] can click on restart and it will give you a new uh terminal right as as soon as I clicked on restart it is now requesting a new cloud shell requesting a new cloud shell All right. Then the next option that you [01:42:24] have is manage file. So you can upload or download files uh to cloud shell. So if I want to work with file, I can simply click on manage file upload. And if I want to upload any local file, I can upload it like for [01:42:40] example template.json. I want to upload it. It's uploaded right where it is it. It's uploaded right where it is uploaded to this path. So if I do ls now uploaded to this path. So if I do ls now here which is list you see template zone [01:42:54] here which is list you see template zone right. So this option gives you the way to upload or download. Now new session will simply give you a new powershell a new portal and then within that portal you'll get new cloud shell session. [01:43:07] Okay. So that's the option as well. Now after that we have a very basic visual studio editor. So if I click on editor, a visual studio will open. It's a very [01:43:19] basic visual studio editor. Okay, it's a file editor. So if I want to edit my files from here, I can do that. I don't need to switch between the desktop and the and the portal. I can simply if I if I have obviously it's [01:43:35] not featurerich. It's a very basic cloud shell that uh sorry file editor that you have. If you want to make any changes you can do from here, right? So if you want to close you go over here and you can close it. [01:43:50] You have the web preview as well. So for web preview uh if you let's say have deployed any basic application here and you want to see how it will look like when someone launch it from from from browser how it will look like you can [01:44:06] simply use the web preview from here. Okay. Then the settings like you just Okay. Then the settings like you just want to change text size, font or uh theme you you want dark theme, light theme. So all those things you can [01:44:20] change from setting. Then there's help like I want to see all the PowerShell command, all the all the CLI command. So I click on that. It will take me to the Microsoft documentation and here I see all the CLI related command. Okay, I [01:44:36] want to work with uh virtual machine. So I search for VM and it should give me I search for VM and it should give me the the VM related command. So this is you scroll down you'll see all the command that that are that you can use [01:44:53] for for VM. Okay. cloud shell we have a very simple notification uh tab. So what this [01:45:05] notification uh tab. So what this notification tab does um let's say I'm I'm working with or I'm deploying anything. So I'm deploying uh I'm I'm creating a resource group. Don't ask me what [01:45:17] resource group is. I'll I'll cover that in detail when we are on that topic. But I'm just explaining the notification tab right now. Okay. So if I search for resource group [snorts] and I create a new resource group or I delete an [01:45:31] existing one. So a notification will trigger like for example RG02 central India click on review create and click on create. So once the creation is [01:45:43] completed you see resource group create a notification will be triggered. So if I delete the same resource group another notification should trigger another notification should trigger which says resource group deleted. [01:46:11] come in like right now it's deleting resource group. Once the deletion is completed it will trigger delete. So whatever you are doing uh and if you want to monitor that you can come over here and you can see that all the events [01:46:24] that whatever you have you have the option to dismiss as well also no notification you cannot see the history there's no way to see the history okay then you have uh settings uh for the [01:46:39] then you have uh settings uh for the portal itself if you want to if you if you're part of multiple Microsoft entra ID You will see all the Microsoft Enra ID over here. If you want to switch between [01:46:51] switch from here. Right now I'm only part of one. If you're part of multiple, I have seen people who are part of multiple directories. I can show you that in my another account. So if I go to another account and click on [01:47:04] settings, you see I'm part of two different uh tenants, two different Microsoft Enter IDs. So if I want to switch between any of the Microsoft Enra ID, I can do that. How I can do that? I click on settings. [01:47:19] Settings will land me to this page and I can click on switch. It will be switched can click on switch. It will be switched to a new um the other directory. Right? So that you can do from settings. Apart from that you can you can uh change the [01:47:33] appearance like I want a dark theme. So a dark theme will be applied over here. I want a light theme. Light theme will be applied. This is just a normal language and region like you want English or any other language. Uh your [01:47:46] information like your email id and all if you want to uh get a notification right uh sign out and notification uh if you're not doing anything and if it's idle do you want to sign out when when inactive after 15 minutes if you're not [01:48:00] doing anything for 15 minutes it will automatically sign out. All right. So all those stuff you can do from the settings tab from the settings option. Then you have support and troubleshooting. So if you have any [01:48:14] issue with Microsoft Azure portal, you can search for it if they have the documentation. You'll see the documentation over here or from here also you can raise the ticket as well. So let's say my subscription is not [01:48:29] allowing me to deploy any resource. I can raise a ticket and I can ask Microsoft Azure team why it's not allowing me to deploy the resource. So they will come up with an answer like maybe your subscription is not eligible [01:48:42] or you don't have the kota kota whatever right. So you just uh can raise a ticket from here. Now remember this thing where to raise a ticket from you can either raise from support and troubleshooting option or you can raise it from uh your [01:48:58] subscription itself. All right. Now why I'm asking you to remember this because in interview if you are fresher uh the interviewer might ask how to raise a support ticket to Microsoft Azure team. Okay [snorts] then [01:49:13] if you want to provide any feedback to Azure team you can provide like I'm you're liking you're not liking it what you're not liking. So this feedback will you're not liking. So this feedback will will go to Microsoft team. Okay. Then [01:49:26] the last option that you have within the portal itself is your username. So this is your username. Uh you can switch directory or switch Microsoft enter ID from here as well. You can view your Microsoft account from here as well. All [01:49:41] right. So just to summarize, you have the shortcut to go to uh uh uh go to any other portal outside Azure. You have the option within Azure. If you want to [01:49:53] launch any service, there's a shortcut. If you want to go to homepage from any other uh page like for example, I'm here in the network page. I want to go back Azure here. It will take me to the homepage. Then you have the search bar [01:50:07] shortcut to reach any service. For example, I want to go to health page. I want to see the health. If I have access, I will be able to see it. Right? So, whatever shortcut uh to the services, you search for it and you go [01:50:19] to that service. Then you have copilot. You have cloud shell which is like a You have cloud shell which is like a like a uh an option to interact with azure platform using command line. You have [01:50:31] notifications. You have settings your appearance your language and all you can select in the settings or you can change in the setting. You have uh support and troubleshooting from where you can raise tickets related to Azure [01:50:46] portal itself. Then you have feedback and then you have your user detailing. right the user that you have logged in from right it's just a short tour to from right it's just a short tour to Azure portal how which will help you to [01:50:59] Azure portal how which will help you to navigate from u uh within the Azure portal itself right all right so now where do I see the Microsoft enter ID question for you guys I want to go to Microsoft enterra ID [01:51:13] I want to go to Microsoft enterra ID page how to go [snorts] how do I go to Microsoft enterra ID page page, right? We have the search option. We can search for Microsoft Enra ID from here [01:51:26] and go to Microsoft Enter ID or you have the portal menu here. From here, you can the portal menu here. From here, you can simply uh click on Microsoft Enra ID and you can go once you sign up for Azure, you have to [01:51:40] do nothing. You'll get Microsoft Entra ID for free. You don't have to pay ID for free. You don't have to pay anything. Okay. [01:51:53] identity and access management system which is free of cost. If you see here license, I have got the free license. So you have I have got the free license. So you have the Microsoft Entra ID free of cost. Uh [01:52:09] obviously with free of cost you'll have less features. There are different licenses available for Microsoft Enra ID. If you're going for free, there is certain limitation like I think you can create uh half a million records only [01:52:22] that that means half a million objects only. If you want more if you want to go above that you need to go for Microsoft Entra ID premium. Entra ID premium. So if I search for Microsoft Enra ID [01:52:47] this is the page where Microsoft has mentioned uh different features available in different plans. So there are like three or four plans. If you see we have premium P1, we have P2 and then Microsoft Entra suite. So these are the [01:53:01] three different plan. By default it's free. You don't have to pay anything. But if you want to use certain premium plans then you need to go for P1 or P2 or suite depending on what features you want. Now if I scroll down here you see [01:53:17] if you want Microsoft enter ID protection it's available here in P2 or Microsoft Enra ID suite. It's not available in free tier. All right. So [01:53:29] whatever is checked over here is available on the on on that particular available on the on on that particular plan not on free. Okay. So here are the plan not on free. Okay. So here are the limitation that you see with free tier. [01:53:43] [snorts] Uh it supports multiffactor authentication. It supports the single sign on. It supports the basic reporting. You can manage users and groups. Uh it also [01:53:57] supports the self-service password reset. It can also allow you to sync your on-prem directory users with Microsoft enter ID. So this can be done. But if I want let's say verified ID, it's not mentioned here. I won't be able [01:54:13] to use that. If I want to use identity protection, it's not mentioned there. I cannot use it with the free TM. Okay. So all these are premium uh plans. All these are premium features. So if you want to use those [01:54:28] features, you need to sign up for a features, you need to sign up for a premium t. All right. So in order to interact with Microsoft enter ID, I can search for Microsoft [01:54:40] Enra ID and I landed to that page. Okay. what what license I have whether Okay. what what license I have whether it's a it's a free license or a uh premium license will be mentioned under under your overview page uh within the [01:54:54] license section. Okay. So that's what Microsoft Entra ID Okay. So that's what Microsoft Entra ID is. Now Microsoft Enra ID comes with two is. Now Microsoft Enra ID comes with two different flavors B2B and B2C. Now since [01:55:08] it's 10:40 already I have only 20 minutes. So I'll cover B2B. I'll explain B2B and then we will stop for the question and answers. question and answers. Okay. So what is Microsoft Enra ID B2B? [01:55:23] Okay. So what is Microsoft Enra ID B2B? B2B stands for business to business. what does it mean business to business? Uh you have your Microsoft Entra ID. So [01:55:36] once you sign up for Azure, you'll get Microsoft Enter ID and you have a partner company who will be developing certain products or certain softwares for you. So you have your own enter ID. So this is your entry ID [snorts] [01:55:53] and you have your partner company who will be developing certain products for you. Now when you're developing certain when they are developing certain products you want them to host those products. [01:56:07] When I'm saying products I mean websites. So when they are developing that website for you you want to host you want them to host that website on your resources. So they will have their their developer [01:56:21] here. Now tell me this developer who belongs to the partner company the user account for their developer [01:56:33] will reside where in our entra ID or their entra id when you join a company let's say you join xyz company so that xyz company has its own IM service and [01:56:46] there's another company ABC company they have their own IM service so when you are joining XYZ company your account will be created in XYZ or ABC [01:57:02] so my account should be created in XYZ when I'm signing up for Netflix my account will be created in Netflix it's not going to be created in prime video right so similarly these three developers who are [01:57:16] developers who are uh employees of partner company their created in the partner company's entra and this is my entra our entra ID now if [01:57:33] and this is my entra our entra ID now if these guys wants access to my resources I have a virtual machine here I have storage here I have a database here they want to develop an application for me a product for me a website for me and they [01:57:48] need access to my resources So with zero trust model how are you going to provide the access? How can you access or let's say you want [01:58:01] to log into your enter ID and you want to access what happens first? What is trigger? First thing if I want to provide them the access what I need let me explain it from the portal. Okay. So if I go to the [01:58:17] portal, this is my entra ID with the name as your trading. So this is my entra ID. Okay. If I go to the manage section here, in the manage section, you see users. So if I click on users here, I'll see all the users which are part of [01:58:32] I'll see all the users which are part of my tenant which are part of my entra ID. These are all the users who are part of my entra ID. Okay. So this is Azure training which is my entra ID and these are the users who are part of it. [01:58:49] are the users who are part of it. I have another entra ID of my friend let's say my partner and they're good in development. So I want them to develop a re or develop a software for me but I want them to host that software in my [01:59:04] resources in my virtual machines. the virtual machine that we have now in order to provide them the access they have their account in partner entra ID they don't have account here so what I need to do first [01:59:21] what I need to ask what I can do one way is to create their account so what I'll do let's say this is user one this is user two this is user three so I'll come over here you see new user I click on new user I [01:59:34] create account user 01, user 02, user 03. So I can create an account for them. That's the one way. But now think from user point of view. Think from the user [01:59:46] point of view. If I create additional account for them, account for them, what is going to happen? The user needs to remember two different set of credentials. [02:00:00] they need to remember these credentials which they they are going to use to access my resources plus the they need to uh [02:00:12] remember the credentials for their own enter ID as well. enter ID as well. Now tell me as a security team member or Now tell me as a security team member or as an IM solution or IM team member is [02:00:24] it good to ask your employees or your users to remember more than one set of credential. Is it a good idea? [02:00:40] forget password. They can forget password. They can forget user ID. Since I might be using a different kind of user ID like if you see here I have different kind of user ID. Some company uses first name, last [02:00:54] name at the rate their company domain. Some uses first name and then surname different different companies have different different ways of coming up with the user ID. Right? So I don't want them to to remember two set of [02:01:09] credentials. What I can do? I can use B2B. This is my business. This is their business. So I'll use B2B here. What is B2B? Business to business. Microsoft Entra ID business to business. I can invite their user [02:01:26] to join my tenant. I can invite their user. If you click on I can invite their user. If you click on new user here, we have two options. new user here, we have two options. Create new user and invite external [02:01:39] Create new user and invite external user. So this invitation or inviting an external user will create an account here in my tenant. They don't need to remember two set of credentials. They can use the same email ID that they are [02:01:52] using, same user ID that they are using in their own tenant. They can use that and once they use that they can log into my tenant. How I uh well when I'm I'm I [02:02:05] was giving you the the tour I demonstrated this directories. Directories are nothing but the entra ID. You have your one [02:02:17] directory here. Apart from that you can have another directory as well. So once I invite them they will have the option to switch between the directories. [02:02:32] Okay. So what is B2B? B2B is a way or sorry external identities external object external users to your own tenant [02:02:49] to your own directory. Okay. So why we have B2B here to make things easier for the external employees. I don't want them to remember different set of password. They can use the same [02:03:04] password and they can log in uh to multiple tenants. Now it's possible that the partner company is developing software for different different clients software for different different clients like TCS. TCS develop what is TCS? TCS [02:03:18] is a consultancy consultancy firm, right? So they develop software for multiple partners. Now imagine you are asking your developer to remember password for all the tenants is going to first of all forget all [02:03:33] is going to first of all forget all forget most of the passwords right so to make it easier Microsoft came up with this B2B business to business now what is business to business how does it work we don't have to bother about it [02:03:48] why because we are using this as a service what what Microsoft is doing behind the scenes is not something we need to bother. Okay. But yeah, if you want to come up with your own B2B, you don't want to use Microsoft Enra ID, you [02:04:03] don't want to use Microsoft Enra ID, you you're using onrem services, you have active directory domain services, you need to create something known as federation server. So it works in the same way but uh lot of work is involved. [02:04:19] Microsoft has made it quite simple. Uh when it come to Microsoft Enra ID B2B, we just need to click on new user, invite external user, uh provide proper [02:04:32] email address, whatever the email address is and once the user accepts, he address is and once the user accepts, he or she will become part of my 10. All right. All right guys, so that's all about B2B. [02:04:46] need to cover. Obviously we cannot cover today so we will cover it tomorrow. Now what these topics are just to give you an overview. Uh apart from B2B we have another type of uh tenant in Microsoft entry ID which is B2C. I'll explain what [02:05:02] B2C is tomorrow. Then we have few premium features like conditional access, identity protection, access reviews. So these are the these are the premium features. If I go to the Microsoft Entra plans and and pricing uh [02:05:17] premium feature. It's not available with free tier. So in order to use conditional access you need to have premium at least premium P1. premium at least premium P1. Okay. Then there is identity protection. [02:05:32] So identity protection is also part of uh premium tier. Then access whatever we are discussing tomorrow uh is is uh falls under the premium features. In order to use that you need to have premium in place. [02:05:46] Then then we will discuss identities for uh applications. So manage identities discuss as your keyboard. So for the first half tomorrow we will able to complete our Microsoft uh entra ID and then we will discuss the [02:06:02] case study. Okay. So make sure you're re-watching second half of today uh before you're coming for the tomorrow's class so that you know the basics of [02:06:14] identity and access management uh what is entra ID what is B2B right all right is entra ID what is B2B right all right so what we have covered so far uh basics of cloud computing we have covered yesterday where we understood what cloud [02:06:29] computing is why do we need it in simple cloud computing is just the delivery of comput services. What are those compute services? Those compute services are servers like you can get CPU, RAM, storage, all those stuff. Apart from [02:06:43] that, you can get network, you can get databases, you can get uh different managed services. So all of the services you get as a service from cloud from cloud provider. So we see we saw that in the first half. In second half we jump [02:06:57] to Microsoft Entra ID where we understood understood what AM is. Why do we need AM? IM stands what AM is. Why do we need AM? IM stands for identity and access management where [02:07:09] if you want to manage your objects, your your ids, your identities. Identities are nothing but the users or the groups who requires access to your resources. So if you want to manage them, you have AM which stands for identity and access [02:07:24] management. Before seeing identity and access management, we covered the uh uh module the framework which defines how your identity and access management should be. ZTM stands for zero trust model. So it's just a framework which [02:07:39] defines how you can secure your AM solutions. Then we saw if we want to do uh if we want to implement identity and access management on cloud on Azure specifically what service we have? We have Microsoft Entra ID. So what is [02:07:55] cloud-based identity and access management service. You can call it as identity as a service. You don't need to deploy your server. You don't need to deploy the uh EDDDS on top of your [02:08:08] it to the domain controller. Everything is done for you. Everything is managed for you. Okay? So everything is managed and you're getting that as a service. Then Microsoft Enra ID comes with two different uh flavors B2B and B2C. We [02:08:24] have covered what B2B is. B2B stands for businessto business. So if if I have a company, this is my Microsoft Endra ID tenant and I want to invite or or provide access to a partner company or let's say I have company A, B, C and [02:08:40] XYZ. So these are the two companies I have. XYZ is my company. Whereas I uh have. XYZ is my company. Whereas I uh bought or uh I I bought ABC's business. So ABC is also my company. Now I want to provide all the users access to my [02:08:57] tenant. So I can use B2B here as well. This is another scenario where I can use B2B. All right. The next thing that we are going to discuss today is B2C. So let's go to the next topic which is Azure ADB2C. B2C [02:09:12] stands for business to consumer. All right. Before doing B2C, let's just uh right. Before doing B2C, let's just uh see the invitation one that we covered yesterday. Like if I want to invite any uh user who's not from my tenant and I [02:09:26] want to invite a user who belongs to another company. Doesn't matter if that another company. Doesn't matter if that company is using uh Microsoft Tendra ID or any other identity platform. The required thing is they should have their [02:09:38] users should have a valid email address. That's all. If they have the valid email address, we can invite them. All right. So how to invite? If I go to Microsoft Enra ID from the start menu from the portal menu if I click on Microsoft [02:09:53] Endra ID I'll be landed to this page. This is the homepage of Microsoft Enra ID. From here under manage section I can see users group. So if I want to manage users, create users, delete users, modify users, I have to go under the [02:10:08] manage section. So within that manage manage section we have users and groups. All right. So if I click on users here, I'll see I'll I'll get a list of all the talent. Okay. Now this is the user [02:10:25] Okay. Now this is the user who is an external user. This one if you see this user root cloud easy, this is an external user. Now you consider the same scenario which I dis which we discussed yesterday that [02:10:39] we can invite any user who belongs to any company doesn't matter whether they are using entra ID or they are using Google workspace or they are using AWS uh AM services we can invite anyone as long as they have a valid email. Okay. [02:10:56] So to see that in action, what I'll do? I'll simply delete this user. whenever you delete a user from Microsoft Endra ID, the user is there [02:11:10] for for 30 days. It's not getting deleted uh permanently. So you have to delete that permanently if uh if you know that you don't need that user account. Okay. In our case right now, this is just uh a a tenant, a test [02:11:26] tenant. It's not a production tenant. So, I deleted that user. Right? Now, I go back to all users. And in order to invite any user, I click on new user. Here under the users section, we have all users. There we have new user. So, I [02:11:41] click on new user. I click on create new user. If I want to create a user uh within my tenant within my Microsoft Enra ID, if I want to any external user from any other organization, I select this [02:11:55] option. All right. So I click on invite external users. I just provide the email external users. I just provide the email address. [02:12:08] providing that email address. Doesn't matter whether it's your company uh whether they are using Microsoft Enter ID, Google Workspace or it's a normal ID, Google Workspace or it's a normal email id. We can invite them. All right. [02:12:20] create. That's all. Your user will be invited. So you see here notification user invitation in progress. So a mail will be sent to user from your Microsoft Enra ID. Now if you see here uh in some time if you refresh you should see that [02:12:37] time if you refresh you should see that user here now how to verify whether this user is part of your tenant or uh external [02:12:53] tenant how to verify that so if you see this user type here you have different types of users this is important to understand member Member user that means your own your tenants user. This fabric admin is a member [02:13:06] user. This fabric admin is a member user. This is my tenants user. You see this one this is a guest user that means uh this is an outside user whom you have invited to your tenant. All right. Similarly root cloud easy. This is a [02:13:22] guest user outside user who you have invited to your tenant. All right. So remember there are three types of users. These questions often lands in the uh [02:13:34] exam. You have member user, you have guest user and you have uh ad sync user. All right. So there are three types of users you can see when you are dealing [02:13:48] with Microsoft enter. Member user, your own user, your company's user, your own user, your company's user, your tenants user, guest user, outside user, uh ad sync user, if you have an active directory domain services and you are [02:14:00] synchronizing that with Microsoft Enra ID, the users who have been synchronized ID, the users who have been synchronized will be the type of that user will be ad All right, clear. [02:14:14] clear. Then uh inviting a user is one step. The user who have you have whom you have invited should accept the invitation. If invitation, he or she won't be able to use the temp. Right? So what I do right [02:14:30] now, I go to Gmail, I log into my account. [02:14:44] Microsoft invitation. So similarly that user will also receive the invitation and he or she needs to accept that. So if I click on it I need to accept it. So in order to accept what I'll do I'll go to the in private window. I'll copy the [02:14:59] to the in private window. I'll copy the uh link Now why I'm doing this in in private so that uh in in the in this session I've [02:15:11] already logged in with the simply learn user. Okay. Okay. So I don't want to use the same session. So that's why I have triggered or open the in private window. All right. So it it's saying it will send me a a code to my email in order to [02:15:27] can click on send code and I'll receive the code in my Gmail account. [02:15:39] multiffactor authentication. like a confirmation that the person who's trying to log in is the same person. So 583 439. So I just go there and enter 583 439. So I just go there and enter it. 583 [02:16:02] Okay, that's all. Now I will be logged in to uh [02:16:22] from here and just to confirm I have logged into the same tenant uh from from where I was invited to confirm that how how you can confirm you can go to Microsoft Enra ID. Now one more thing you need to remember [02:16:37] whenever um a new user account that's been created or new user who has been invited to your tenant has to complete the multiffactor authentication. So before I I give some information let's understand [02:16:53] many of you already know what multiffactor authentication is? [02:17:05] What is multiffactor authentication? Multiffactor authentication is like an additional form of authentication. Okay, I hope you know u what authentication is, right? You know what authentication is. Authentication is a process of [02:17:19] verifying the identities, right? So, how do you uh verify the identities? You that's what we provided here. Username and password already provided. But it's possible that username and password are compromised. So in order to avoid [02:17:35] uh allowing access to an unauthorized user, what do we do? We add an additional form of authentication, two form authentication or multiffactor authentication, one extra form of authentication. [02:17:49] Username and password you have to provide. Apart from that, prove your provide. Apart from that, prove your identity by entering the OTP or approving the authentication in the authenticator app [02:18:04] or if you have a gate or something where you have the fingerprint reader, you can ask them to provide the biometric authentication as well. authentication, MFA stands for multiffactor authentication. From [02:18:19] October 2024, Microsoft has made this mandatory. So you don't have to do nothing. I mean, you don't have to enable multiffactor authentication. It's by default enabled for all the users within your tenant. [02:18:32] Before October 2024, we had to enable multiffactor authentication from each and for each and every user. After October 2024, it has been made After October 2024, it has been made mandatory for all the users. Okay. So [02:18:45] whenever user logs in, Microsoft's collects some extra information from that user. Most probably it would be uh adding an account in Microsoft authenticator or any other authenticator app that you that you want to use. All [02:19:00] right. So whenever I create a new user, I need to do this setup every time whenever I'm uh logging in from a new user. So I click on next. [02:19:14] file. Let me log in again. [02:19:35] information that I need to install Microsoft authenticator. It's not mandatory that you need to use Microsoft authenticator. You can use another authenticator app as well. There are lot of authenticator apps available in the [02:19:48] market like Google authenticator, um, octa, last pass. There are a lot of lot of there but this is the simplest one since we are using Microsoft product. Let's go with Microsoft authenticator. Then I [02:20:01] click on next. Here after clicking on next, I need to go on my phone. Now I am not I cannot share the phone screen here but within in my phone I should have the authenticator app and I should be adding the work or [02:20:16] you read it's quite simple it's saying if prompted allow notification then add an account work or school and then scan the QR. When I click on next it should give me a QR. So I'm scanning that QR in [02:20:29] give me a QR. So I'm scanning that QR in my authenticator app and once that is done I can click on next. It should send me a approval notification or a number that I have to enter within my phone. I don't know if you can see. Okay. So, I [02:20:42] need to enter that name here. Uh sorry, number here. [02:21:01] entered, it should uh refresh and it should allow me to login. Okay, now I'm inside portal. So this MFA setup is something that uh [02:21:15] every new user needs to do once when when they are logging in. All right. Now if you see I'm logged into Azure portal. If I go to Microsoft Enra ID as root cloud easy to just confirm that this is the same tenant where uh now obviously I [02:21:33] don't have access because I I am authenticated but I don't have the access to do anything with Microsoft enter ID as a root cloud easy user. If you remember we only just we only invited this user. We did not provide [02:21:46] any permissions to this user. All right. So now this user can login but in order to confirm obviously we cannot confirm over here. It doesn't uh give any detail which tenant this user belongs to. Okay. But if I go back to the browser where [02:22:01] I've logged in with a user who has the access like simply learn user who has the access and if I see rootcloud a from here he uh is part of this email id is part of my tenant. All right. What is the type of user? It's a guest user. [02:22:16] Clear? So that's MFA and that's how you you work with the external users who are you work with the external users who are not part of your tenant. Okay, not part of your tenant. Okay, clear guys? B2B [02:22:34] mentioned yesterday do not do the de uh the lend hands on uh alongside me. Okay, you you you can do it in your free time. All right. So B2B clear or no? Uh quick [02:22:46] answers guys we have to cover a lot of topics. [02:22:58] Har is asking in organization I assume you use org MFA software it's not org software what is IM whatever IM service you are using that IM service now MFA is very basic topic which is included in all IM services. So if if you're using [02:23:13] active directory domain services or you're using AWS IM service, they already have MFA. Okay, that totally depends on you which uh AM service you're using, your organization is using. [02:23:29] All right, next topic that we have is B2C business to consumer. Active Microsoft Enterra ID business to consumer. Now B2B [02:23:41] works when you want to invite users to your tenant like you have two different tenants and you want to invite your invite external users to your tenant. B2C works in a totally different uh manner. Okay. Uh what is that totally [02:23:56] diretory tenant also a Microsoft entra ID tenant where you have an application [02:24:09] you have that application and you want users to log that application so when you are authenticating a user within that application you need to have an [02:24:21] identity module you need to create or you need to develop it yourself you need to ask your developer to come up with an identity module and before providing an login they need to prove their authentication they need to prove their [02:24:33] identity so in that case what you can do let me just give you the real world example here if I go to lms simplylearn.com [02:24:49] asking users to do we asking users to authenticate here I need to provide my email address and password right I have to enter my email address and password then only I can login now this simply learn this is an application [02:25:02] lms.simplearn.com simply.com. This is an application where we are asking the end users to login. Now tell me that end user are I mean the end users are they user are I mean the end users are they our employee [02:25:17] the end users like you guys who are accessing our LMS learning platform you are not not simply learns employee right so does it make sense for the nonmp employees to create an account within our tenant [02:25:33] does it make sense let's say we have like in one batch we have uh hundreds of uh students, hundreds of candidate. It doesn't make sense for me or my my AM administrator to go here and create users for each and every uh account. Uh [02:25:50] we cannot do that, right? I mean we can do that but it it doesn't make sense to do that since in one batch we have hundreds of user. Imagine we deliver like parallelly we deliver like 10 batch a weekend. So 100 into 10 is,000 users. [02:26:04] I cannot create thousand users every month. Right? So it doesn't make sense. So we should not be creating their user should not be creating their user account or end users user account [02:26:16] within our B2B tenant within our Microsoft enter ID tenant or what what's Microsoft is doing? Microsoft is providing another set of another tenant providing another set of another tenant which is B2C business to consumer. So if [02:26:29] you have an application and you want to handle identity that means authentication for that application then you can rely on Microsoft Android IDB2C where you can come up with signup flows what information you want to collect [02:26:42] from users like if you see here we have given the option to sign up right we have the option to sign up so when you click on sign up you need to provide things we are collecting we are collecting first name last name email [02:26:57] address so this is known as Signup flow. So you can create signup flows and all what information you want to collect. This information will be kept in Azure This information will be kept in Azure Active Directory B2C tenant. All right. [02:27:09] So for your end users, for your customers, you can use B2C. For your own employees, you can use B2B. Clear where you'll be doing B2C and where you'll be doing B2B. Now how to create a B2C tenant? I'm not [02:27:25] going to create B2C tenant. B2C talent are not free. Uh you'll have to pay, right? But if you want to create in any point in time, you can click you can see within your Microsoft Entra ID page, you have this manage tenant. So I click on [02:27:40] manage tenant and I can click on create a new tenant and from here I can select Azure AD B2C. Okay. So this is something that we can Okay. So this is something that we can use to create a B2C tenant. [02:27:55] All right. >> [snorts] >> Now you have to remember one thing uh as uh as mentioned here from May 1, 2025 it's already one year a uh B2C tenants are no longer available for sales that [02:28:10] means if I go ahead and create a new B2C tenant it won't let me uh create the B2C tenant. Why? Because it's it's not there. Okay. So what is the uh [02:28:22] what is another method? If I want to use something similar to B2C, you can uh click uh you can rely on this uh app registration thing where it is this one. So this also works in the similar way as B2C. [02:28:37] Okay. There you have the option to create uh signup flows and all. Okay. Kalashnat is asking who typically uses B2C. I just give an example. If you have [02:28:49] an application, you will be using B2C. Okay. So if I have this application like we have this application, we are not using B2C but we can use B2C since we have the application and we want authentication module for that [02:29:02] application. Now who uses obviously Microsoft didn't disclose their customer who are using B2C. uh if you have an application and you want to you don't want to bother about creating another authentication module [02:29:15] just for your end user to login. How does it work in real world? You have an application you want your user to authenticate. Obviously you want your user to authenticate, right? We do not have a a [02:29:30] very simple website here. We have the LMS portal where we have our content. This recording goes to the LMS portal. So we don't want to provide access to anyone who can login. We want users who have enrolled for our courses. Only they [02:29:44] should be able to uh watch the recordings. So what do we want? We want authenticate what I need to do, I can ask my developer to create an identity module and then add the username and password of all users in one of the [02:30:00] databases. So I can come up with a database. I can uh ask user to sign up from here. Whenever user is signing up all the information is uh collected in a database. Now when user is trying to login in uh login this application will [02:30:16] checks the username and password in the database. If username and passwords are correct we are allowing them to login. If username and password is not correct we are not allowing them to log. But why should I be using B2C? Let's say [02:30:29] my company don't want to manage this database. Managing database, you need database administrator, right? You need an extra personnel who knows how to uh create a database and how to integrate that [02:30:43] database with the application. You need a backend uh developer as well. All this stuff, I can go with simply with B2C. So if you if your organization don't want to manage, you can go for the B2C. Who uses is Netflix can use it. [02:30:59] Netflix also has the identity and access management. Right? If I try to go to netflix.com, I need to log in first. So Netflix is nothing but an application. Netflix is nothing but an application. So in order to watch any movie or any [02:31:13] show, you need to sign in. So when I'm clicking on sign, it's possible then clicking on sign, it's possible then Netflix might be using uh B2C. There are lot of applications who uses IM and if they don't want to manage [02:31:25] their own database separate database only for identity and access management only for identity and access management they can simply use B2C. Okay. [snorts] All right. [02:31:43] Yeah. Next topic we have any questions before I move to the next topic. [02:31:57] need database for maintain paid subs. Obviously you need database. Okay. Uh modules as well. Different application have different kind of authorization modules. Authorization authorization is not something that you can uh use [02:32:12] Microsoft Enra ID for for your application. Okay. For Azure portal obviously you can use Microsoft enter ID for authorization use Microsoft enter ID. For that you need to come up with your own uh within [02:32:26] your uh application module you need to come up with the authorization. Okay. All right. Next thing is conditional access. So conditional access is [02:32:38] a premium feature. You cannot use it with the free tier. Uh yesterday uh we discussed the different plans and pricing of Microsoft Android ID. So this conditional access is a premium feature. So if I want to use conditional access, [02:32:52] I need to have the premium P2 premium P2 license. If I have premium P2 license, conditional access. So what is conditional access? As the name conditional access? As the name specifies depends on certain conditions [02:33:07] the access will be defined depends on certain conditions uh the policy will define whether to grant the access or to block the access [02:33:19] or to enable the multiffactor authent or to ask for the multiffactor All right. So on depends on certain conditions whatever you define in your policy you either grant the access ask the user to [02:33:35] prove the authentication using multiffactor or you block the access. Now what that condition can be that conditions can be anything like you just conditions can be anything like you just want to block a a particular user or a [02:33:47] want to block a a particular user or a part a group of users or you want to uh block users from non-compliant device. Okay. Uh what is non-compliant device? Non-compliant device is a device which is let's say not joined to your domain [02:34:01] or the device which is which does not belong to your company. then on on on depends on certain locations as well like uh my company let's say is based in [02:34:13] India and if someone is trying to connect uh my application or Microsoft Azure portal from any other location let's let's say Singapore I don't want them to [02:34:27] uh login right so all all these are conditions so depends on you what you're defining what is your compliance requirement you can take certain actions requirement you can take certain actions like allow the access or ask user to [02:34:41] prove the authentication using multiffactor or simply block the access. All right. Now um if you're a working professional you might have noticed if you're using uh iPhone you might have noticed even in Android uh and if you [02:34:57] use if you have downloaded outlook your your company's outlook your company's outlook uh email within your phone uh teams within your phone you are not allowed to access it unless and until you are on [02:35:11] the secured iOS platform I think this is the latest one so you might see that if up with this they use conditional access for that okay so conditional access is a [02:35:23] way depending on certain conditions you will be defining whether to provide them the access or not now you're not going to monitor this uh manually every now to use conditional access you'll be coming up with policies [02:35:38] you will create conditional access policies and that conditional access policies in that conditional access policies you will define If so and so user, so and so group logging in from so and so device uh from [02:35:52] certain locations, allow them or deny them. So that's what you'll be defining. conditional access comes with the premium feature uh is a premium feature and if in order to use that you need to have Microsoft Enra ID premium uh [02:36:07] have Microsoft Enra ID premium uh license. [02:36:27] pricing then if I want to see uh with which tier or which premium license Microsoft conditional access comes with. You can come over here and you can see that conditional access comes with P1. So in [02:36:44] order to use conditional access you need to have at least uh Microsoft enter ID P1. If I go back to the portal where I have logged in what license do I have? I have a free license so I won't be able to use the conditional access. Now I [02:36:58] to use the conditional access. Now I have another tenant which is uh P2. So I can go to that tenant and in that tenant [02:37:25] Okay. So now I've logged into this tenant where we have the P2 license. So for conditional access I can make use of this. [02:37:57] have the P2 license. Now Har is asking why different tenants to be used. You don't have to use different tenant as I mentioned. If uh one company should only have one tenant in any case uh if you have multiple tenants then you need to [02:38:10] switch between the tenants. Okay. Here you need to switch between the tenants if you are part of multiple tenants. All right. You don't need to have All right. You don't need to have multiple tenant but most of the uh [02:38:23] companies who did not follow the best practices initially when Azio was new they might be having more than one tenant. more than one tenant unless and until you are uh [02:38:38] you're taking over another another company. So in that case obviously you'll be having more than one tenant. So I can switch from here. [02:38:56] I can make use of uh this tenant and premium P2 is not a free license. You have to pay. So that totally depends on your company whether they approve or [02:39:08] not. But obviously since this is these are the security features uh your company should approve the budget and you should be able to use [snorts] you should be able to use [snorts] uh the premium uh gear. Okay. All right. [02:39:20] So in order to use conditional access I need to go to Microsoft Enra ID and there if I go under manage section somewhere I should have the uh security [02:39:32] option. Uh within security if I go to protect you should see the conditional access. How does it work? Conditional access is just a policy. You need to define your own policy. What are what are the conditions that you want to [02:39:45] evaluate and what actions you want to take. The conditions are take. The conditions are users, groups, devices and locations. The actions are allow throw multiffactor authentication challenge or block the [02:40:00] access. Okay. If I go back to the browser where I have logged in with uh P2 uh tenant. You see here conditional access. [02:40:14] from from last patches. So if you see here I have a policy which says block access to Azure portal from Malaysia. In order to create a new policy you can click on new policy here and you can [02:40:28] create a policy. All right. Now I I use this but let me just walk you through the uh creation uh steps. So conditional access policy I click on new policy. Here are few few things that I [02:40:44] need to provide like what is the name of policy. So you want to block access allow access whatever the name should be descriptive enough so that uh anyone visiting the conditional access policy should be able to understand what this [02:40:56] should be able to understand what this policy is doing. Then users whom which user you want to target. Do you want to target a specific user, all users or selected users. All right, you want you you can target [02:41:09] all users. But remember if you are targeting your all users, this policy will impact you as well. Even if you are the administrator and you are targeting all users, this policy will lock you. If you're locking, if you're defining a [02:41:23] policy which is locking the access to a particular resource or a particular application, you are locking yourself out as well. If you target all users, right? So, how to avoid that thing? If you click on all all user, make sure you [02:41:38] excluding one or two users like who who are admin. So, in case if you want to change the policy, at least you can login. Okay. So you can add your username. Whatever your username is, you can provide your username. I don't know [02:41:52] if I have my same account here, right? So I can select my account. I can select. So this user won't be impacted with the policy. All other users will be impacted. All right. So I click on include uh and [snorts] [02:42:07] I'll just select a particular user. I might have user 01 here. Okay. So this user will be impacted whatever I'll be defining next. So what [02:42:19] we are defining here block access this is the user user 01. So this policy will only impact user 01. Then target resource. Target resource is something which is the application that you want to uh [02:42:34] select. Okay. So what we are defining this is my policy. There is a user this is the target user. So whenever this user is trying to log in or whenever this user is trying to do anything as of now we have only created policy and we [02:42:48] have selected that user we have not defined what what condition what this doing that's that's something that we are defining here in target resource. So in target resource you are defining the condition this user is trying to login [02:43:03] let's say a simple example for this user is trying to log into portal.azio.com This user is trying to log into portal.azio.com. That's my condition. So this is portal.azio.com is my target resource. So that's what we are defining [02:43:16] over here. Target resource. Okay. So what we can select in the target resource we can select [snorts] the specific resources like I want to uh [02:43:28] select all the admin portals in Microsoft all the Microsoft admin portals. So these are the these are all the Microsoft admin portals. So if you want to evaluate for this portal that means user 01 is trying to loging into [02:43:40] this portal. So these are the target portals right [snorts] uh you just want portals right [snorts] uh you just want to target uh Microsoft 365 you want to target Azure active directory reporting you want to target uh Azure perview or [02:43:56] whatever you want to target. So you can select uh that from here. All right. Now in order to target the Azure portal we have something known as Windows API uh Windows Azure service management. So [02:44:13] this is the application which is equivalent to portal.azio.com. So if I equivalent to portal.azio.com. So if I select that it says this policy impacts Azure portal. So they have changed the name into Windows Azure service [02:44:25] portal.azure.com. So what we have defined so far we have So what we have defined so far we have defined user 01 target resource is then you can define network as well. If this if this user is coming from so and [02:44:40] so network so you can define that as well. Okay. So how to define the network? In order to define the network u you need to select any network or any u you need to select any network or any location all trusted networks. So if you [02:44:55] have added certain IP address as trusted IP address that will fall under all trusted network. Okay. You can also select uh networks and locations like I just want to uh block from a certain location only from one country or uh two [02:45:12] countries or three countries. So I can select that as well. But in order to define the networks and all we need to do that beforehand before defining the do that beforehand before defining the policy. So where we can do that within [02:45:26] the conditional access policy you have one [snorts] uh option where you can define the trusted or untrusted location. So if I go over here uh go to the security go to the conditional access and here [02:45:41] under manage you have named location. So here you can define the named locations like I define country's location depending on on exact country like I don't want to allow people or I want to allow people uh to log in from uh so and [02:45:57] so location. So I can create country's location over here. I need to switch since I logged into uh different tenant. So I need to switch [02:46:23] you see named location. So here you see the option is available in in last tenant uh in my default tenant is not this option was not available because I had the free tier. Right. So here you can define your uh name location. Here I [02:46:37] can create on the basis of countries or on the basis of IP IP ranges. So if I let's say I have a VPN I can define click on IP ranges and provide certain IPs like if I click on IP ranges I can provide IP addresses here like only uh [02:46:52] this IP address should be allowed only one IP address should be allowed. So I I can mark that as a trusted location. So if traffic is coming from this and this IP that's what we are defining in the conditional access policy. [snorts] [02:47:05] Okay. I already have the name location over here. So I'm not creating a new but in in case you want to create you can create on the basis of IP ranges or in the basis of countries. So let's say you want to block traffic or allow traffic [02:47:19] only from Afghanistan, uh Alan Island, Albania, Algeria. So you select all of your location which you feel trusted or untrusted. Okay. So I can select Barbados, Bellarus. So I can select all this which [02:47:32] Bellarus. So I can select all this which I want to define as as a white list a blacklist countries from where I want to block the traffic. I can select that. So with this name location you're you're only selecting location that's all. [02:47:47] create. Obviously I need to provide a name. So once I provide the name I I'll get that option uh to create that particular location. So that location will be created here. Similarly, I created uh a new a location in my last [02:48:01] created uh a new a location in my last patch uh with the name Malaysia. Okay. So, this is named location Malaysia and here I have only selected Malaysia. So, if you see all other countries are not selected only Malaysia is selected, [02:48:15] right? So, that [snorts] is selected. So, I can use that. So, if I go back to the to the page where we were defining the policy here, I can select Malaysia. Okay. Click on save. So what we have defined we have only defined the [02:48:27] conditions as of now. We have defined the user who is our target user. The resource the target resource where user is uh user [snorts] will be trying to login. Then we have defined the network. All right. Then you [02:48:41] can define the conditions. So here I can go to the conditions and here I can go to the conditions and here I can define whether I want to uh allow or or deny or whatever. Right? Right. So I've selected the network here and then if [02:48:54] you scroll down here you have the access control whether you want to grant the access. So you click on grant. So here you can define block access. That means you can define block access. That means if user one which we selected here is [02:49:08] trying to log into Azure portal from Malaysia then you defining block access or grant access but ask for the multiffactor authentication multiffactor authentication right or grant access and ask user to [02:49:23] change the password or grant access and ask the user to or grant access and ask the user to login from from so and so network. You compliant device. That means a device which is connected to your or a device [02:49:38] which is provided which your company has provided to the user. So that device will be marked as a compliant device. Right? So whatever you want to select, you can select. Just to keep it simple, I'll do a block access. Okay. Before [02:49:50] applying the policy, I want to show you that if we do not apply the policy, the user 01 should be able to login. So before doing anything with the policy, let's go back to the users section [02:50:05] [snorts] and let's confirm that we have user 01. If you see here, we have user user 01. If you see here, we have user 01. Uh hopefully I know the password. So I copy the user 01's credential. I mean I copy the user 01's user ID. I open in [02:50:20] I copy the user 01's user ID. I open in private window. Go to portal.azio.com. just want to show you uh what is the location from where this traffic is [02:50:32] going. So if I type what is my IP address, I should know what is my address, I should know what is my location, right? So I if I click on what is my IP address? Oh, it's this. [02:50:55] address, you should see the location from where this traffic is generating. If you see this Kola Lampur, where is Kalur? Kalur. Colola Lampur is in Malaysia, right? You know, you guys know or know. If you see this is the [02:51:09] Malaysia. If I if I just minimize uh or maximize, you see the name right? So when I'm trying to go into portal.io.com, my traffic is going from [02:51:21] Malaysia. All right. So I copied the username. I paste it here. Uh I need to provide the password. Hopefully I remember it. [02:51:36] okay, this doesn't have the MFA seems. it has. So [snorts] I need to provide the code as well. [02:51:53] policy, if you see I am able to login. You see I was able to login and this is the same tenant where uh if you see the tenant name is the same tenant as your tenant name is the same tenant as your training premium P2. If I switch to the [02:52:08] uh if I switch you see the same tenant Azure premium P2 so without applying the policy user can login right now let's go back to the page where we are defining the policy so we have defined user 01 target resource is Microsoft as your [02:52:24] portal network [snorts] is Malaysia condition is uh same uh same network selected right and the uh grant the access control is block. I [02:52:36] select block and then I enforce the policy and I click on create. So new policy is being created and I'm enabling that policy. Report only will only report when there is such traffic. It won't uh directly block of your [02:52:52] turning of the policy that means policy is not in effect. All right. There are three uh there are three options when you go to enable policy. Report only will only report when such traps such uh requests [02:53:09] are coming in. On you are turning on the policy. Off is your policy is completely off. It's not doing anything. All right. So if I go here I should see my policy. If you remember we only provided the name as block access. So this is the [02:53:24] policy that we just created. All right. that policy is on. The the other policy which I created in last batch is is is off. All right. [snorts] So this policy is on. Now when that user is trying to log in that user should be blocked [02:53:40] condition access policy on the basis of certain conditions user will be allowed or blocked depending on whatever you have selected. Now obviously one thing you need to keep in mind the existing session will not be impacted only the [02:53:54] next session when user is trying to log in that will be impacted. All right so in order to see that in action I'll sign out after signing out I'll try to sign in again and conditional access should take [02:54:08] again and conditional access should take effect and block this traffic. MFA. It's saying your sign-in was successful but does not meet the [02:54:23] criteria to access this resource. What we applied in our conditional access we applied in our conditional access policy, we applied if user 01 is trying to logging into portal.io.com block the access from Malaysia. If [02:54:37] trying to logging in from portal.asure.com from Malaysia block the access that's what is defined in my policy. All right. But if this user tries to loging in from any other location, it [02:54:49] should be allowed. Now I don't have uh any other location over here. Uh if I have that location, uh it should allow. All right. So now it's blocked. Now where you can implement this in real world. U tell me how many of you uses [02:55:05] hot star and Indian hotar. Okay. In India we have Jio hot star right? It was Disney hot star but then Jio took over. So now it's Jio hot star. Have you ever traveled and tried to access the hot star from [02:55:19] outside India? Have you ever tried that? Yeah. So I I stay in Malaysia and uh if you know IPL is going on right and IPL is broadcasted in hot star. I cannot watch it. Why? Because Indian content on Jiohostra can only be accessible from [02:55:35] within India. So if you are in India then only you can consume the Indian content. If you're outside India, you cannot uh consume that content. So this [02:55:47] is like a conditional access. Now I'm not saying that hotar is using Microsoft enter conditional access but they might be using similar kind of policies. All right. So that's one. Same goes with any any OTT content. Even prime video I [02:56:01] cannot watch Indian content from here. Even uh Netflix Obviously Netflix is available here. Hot star is available here but the only thing is I cannot consume the Indian content. All right. Now people are [02:56:17] asking work with VPN and all. Obviously it will work with VPN. What VPN does? VPN changes your location. Right. So if I use NVPN or ExpressVPN and connect to any Indian server [snorts] technically I'm in India [02:56:31] right from Malaysia. If I use NodeVPN or ExpressVPN and if I change my location connect to Indian server, what will be the traffic the source traffic from where it will be generated? [02:56:44] Computer only understand the source IP address, destination IP address, all those stuff right. So if I launch NodeVPN or ExpressVPN and connect to NodeVPN or ExpressVPN and connect to India and then try to access Hot Star or [02:56:57] Prime Video, what will Hostar uh what will the application uh sees the source as the traffic the traffic source? Obviously the Hotstar will see my source is India. So India if your source is India you are allowed to watch right? So [02:57:13] that should be allowed. So VPN is a technology or a network which changes your location which hides your original location. So if you're your original location. So if you're connecting any uh using NVPN to any part [02:57:27] of the world, your source traffic will change to that part. So if I use NodeVPN and connect to Australia, my source will be Australia. So my whatever I'm trying be Australia. So my whatever I'm trying to access, the target will will will [02:57:40] identify my source as Australia, not as Malaysia. Okay. So obviously you can bypass this kind of thing using VPN and all but [snorts] this is something that you can apply in your corporate corporate [02:57:53] network. Now I just gave an example of hot star but that's not uh like a confidential resource and all right but for your corporate network let's say you [02:58:05] work for a finance company so for corporate network corporate network keeping uh uh keeping in compliance keeping uh uh keeping in compliance makes matter it it matters right like I [02:58:17] don't want my people to access my data from so and so location. For this kind of scenario, I can use access from Australia. Why? Because my business doesn't I I don't have any [02:58:33] business in Australia and I don't want my people to travel to Australia and and my people to travel to Australia and and uh during the work time and access my uh my my my resources. I don't want them to do. So what I can do? I can simply block [02:58:46] from Australia. What I can do? I can create another policy and only allow Malaysia you are allowed. Outside Malaysia you're not allowed. So those kind of thing you can you can uh you can do using uh conditional access. All [02:59:02] right. Hopefully conditional access is is is cleared. [snorts] Let's move on to the next topic. Now identity protection. Uh there's no demo for identity protection but it's another premium feature that we have with [02:59:14] Microsoft. Next topic that we have is identity protection. So what is identity protection? It's another premium feature. If I go to the plans and pricing, uh identity protection again falls under [02:59:29] premium feature. Okay. So, if you want to use identity protection, you need premium P2. If you do not have premium P2, you won't what [snorts] is identity protection? [02:59:42] Let's try to understand. As the name specifies, it has something to do with with your uh identity. It's something to do protecting your your something to do protecting your your identities. Okay. Identity protection is [02:59:56] again a cloud-based uh premium service in Microsoft Entra ID uh which helps in Microsoft Entra ID uh which helps your identities to log in uh within your your identities to log in uh within your system uh securely. So what it does it [03:00:10] system uh securely. So what it does it detects the risk risk detection it detects whether or it analyzes when when your user is trying to sign in uh that your user is trying to sign in uh that sign in is risky or not. Right? [snorts] [03:00:25] You can do the risk based conditional access. If the user or the sign in is we can apply the conditional access policy over there. Right? You can see policy over there. Right? You can see the risk reports and insight. You can do [03:00:39] the automated remediations. You can integrate identity protection with different security solutions. Now what it does in real world, it only analyzes it does in real world, it only analyzes your users for their risk. [03:00:54] What do I mean by risk? If you have used the banking application, you might know banking application from any other location apart from your usual location, location apart from your usual location, u either they will send or or block your [03:01:09] uh access, right? Either they will uh allow you the access by only approving or approving uh MFA. That means they will send a notification to your mobile app and they'll ask you to approve, right? [03:01:23] uh if they detects that your traffic is coming from anonymous IP that means a IP which is already blacklisted and if your traffic is coming from that IP uh that is considered as a user at risk or the [03:01:40] sign in that user is trying to do is risky. So identity protection is a tool is a security feature in Microsoft Endra ID which detects this uh risky behaviors [03:01:52] involving with your identity and depending depending upon the risk uh criteria whether that risk is a low, medium or high depending on that whatever you have defined block or a law it will take that action. All right. [03:02:08] Now, unfortunately, we do not have any demonstration for this since this this works automatically. Okay. So, what you can do, [snorts] you can simply uh set up the identity protection policies. Like if I go back to security over here, [03:02:23] you have another tab or another blade here which says identity protection, right? So, when I click on it, you'll see you have three different policies. If I go under protect, you have [03:02:38] three two different policies user risk policy sign in risk policy. All right. You have you can integrate identity protection with with conditional access. You can also register MFA from here. Now obviously MFA Microsoft has made [03:02:53] mandatory. So this MFA registration policy [snorts] uh is by default require for every user. Okay. We we don't have to do anything for this. The user risk [03:03:06] policy if your user is at risk let's say the the the password that user is using is compromised so user become a risky user if user is trying to logging in from anonymous IP that means the sign in that user is trying is risky sign in [03:03:21] right so all those stuff you can define over here now you don't have to do anything you just have to come over here and define what users are the targeted user if you want to select few users you can select if you want to apply to all [03:03:33] users you can select all users And then the risk. And then the risk. What risk? High risk uh medium and above risk or low risk. Even if there is a low risk like [snorts] [03:03:47] [snorts] uh user logs in the the the regular login of user is from 9 to 5. user never logs in after 5:00 p.m. But sometimes logs in after 5:00 p.m. But sometimes let's say um so what this identity [03:04:00] protection does it learns the pattern that user whatever the usual pattern of that user whatever the usual pattern of user is is recorded by Microsoft enter user is is recorded by Microsoft enter ID so every time user only logs in 9 to5 [03:04:13] from this particular browser now let's say user changes the device when user is changing the device again logging into the same time 9:00 a.m. But device is C, the browser is C. So that is detected detected as risky. Okay. [03:04:31] Why it is risky? Because Microsoft enter ID never saw this user coming in from this browser from a new browser. So that can be an unusual browser. So that can be an unusual location that can be an unusual uh login [03:04:46] location that can be an unusual uh login that can be detected as as a low risk or medium risk or high risk. Sorry. So you just have to come over here and define [03:05:00] if you want to block or allow access even for low risk sorry for high risk or for medium and above risk. That's all you want to define. Okay, [snorts] [03:05:14] that's all. Now, we cannot see the demo here since this totally works uh alongside with Microsoft threat intelligence. All right. So what they do they regularly see the threat um coming in from thread detection and [03:05:31] depending on that they they consider whether the signin is risky or whether the user is at risk and depends on that whatever access you have defined block access allow access. So that that thing will be considered and uh if you have [03:05:45] blocked the access user will be blocked from logging in. If you have allowed the access, user will be allowed. All right. So that's will be allowed. All right. So that's what identity protection is. Clear. Now [03:05:58] remember one thing uh as as the information is mentioned over here. Uh in order to work with identity protections from October 1, 2026, you need to align that with conditional access policies. So if I go back to the [03:06:12] conditional access policy here [snorts] you have the conditions within that conditions you have the identity protection as well user risk signin risk right so all this stuff are already here [03:06:28] all right Clear. [03:06:43] Clear guys. [snorts] the real world we use identity protection. Every application is using identity protection. I log into Gmail from a new browser. Their identity [03:06:56] protection is working and they're asking me to uh confirm. That means they are using multiffactor authentication right. So when when they are they when they are uh when they're doing or they are [03:07:09] configuring their identity protection they're not completely blocking you. So if I go to the security and identity protection here they're not completely blocking me. So here you have the control. You have the option to allow [03:07:22] the access or the block the access. But when you are allowing the access you're asking user to change the password or you are asking user to uh to rec to to prove their identity using multiffactor authentication. So when we work when we [03:07:37] log into Gmail from a new location they are doing this thing. when I'm logging from a new location Gmail obviously tracking my login activity if I'm using my regular mobile application they [03:07:52] I'm sorry they will not trigger for MFA but when I'm using a browser within the same mobile but browser is a new session they will detect that as a unusual login [03:08:04] unusual IP address or unusual login and then they will trigger they will ask me to confirm my identity using the multiffactor authentication that's what they're using. Okay. All right. Similar your banking applications [03:08:18] even your uh if you're working professional you might know that you need to use the company provided laptop for all of your uh outlook your teams. If you're using [03:08:32] SharePoint you need to use that right. If you're using your own laptop try try using your own laptop. you'll get an get a call from your cyber security team, a call from your cyber security team, [snorts] right? Cuz they're tracking in [03:08:47] everything automated. So you can use user risk policy or sign in risk policy want to entirely block access, just access and ask user to provide multiffactor authentication, you use [03:09:01] that. All right. Now, just for simplicity, I I'll disable it. I don't want any of my user to get impacted with this. So, I'm I'm disabling it, [snorts] but if you enable it, it should uh work behind the scenes. All right. [03:09:25] access review. What is access reviews? [snorts] So, next topic that we have is managed identities. So, what is managed identities? So far [03:09:37] whatever we have discussed what were were mostly related to the user or group were mostly related to the user or group based identities. So you have user and he wants he or she wants access to the resources. So you create their user [03:09:52] account and provide them the access. Okay. Now in case an application Okay. Now in case an application requires an access tell me how an application is going to access the resources. [03:10:11] user how how do you authenticate yourself? You provide your username and password. Right? [snorts] So your identities is created within any IM solution. Your identities get created and that IM solution [03:10:27] username and password or whatever identity uh mechanism you're using MFA and all. But in case any application requires an access how you going how that application is going to be authenticated [03:10:40] using that IM service should be authenticating the application and then providing the access. We are not going to provide access to our back-end to provide access to our back-end services like SQL or storage direct [03:10:53] access to any of the application right we need to authenticate that application. So what could be the way SSO is not the So what could be the way SSO is not the way MFA is not the way uh the way is one [03:11:05] of the way that we have in Azure is managed identities. managed identities. So what does manage identities do? It creates an object ID for your application and then you can use that [03:11:18] object ID to provide access to the backend services like storage or or SQL or whatever. [snorts] All right. Now if I go to the portal whatever user we have I go to the portal whatever user we have created if I go to Microsoft enter ID [03:11:33] and if I go to the users if you see here let's say I I I I pick up any random user fabric admin. If you see this, this user is having an object see this, this user is having an object ID. What is this object ID? This object [03:11:48] ID is the reference or the identification for this particular user identification for this particular user within my tenant within my entra ID. Okay. So this object ID is the identification [03:12:03] identifier for this particular user. So when this user is trying to logging in as a user what it will be providing? this user will be providing the username this user will be providing the username but the IM service will identify this [03:12:15] user with this object ID. [snorts] Okay. So similarly when an application requires an access we need to register an object ID for that application. So [03:12:27] remember from yesterday's class yesterday's discussion uh application is nothing but some files right people will develop the code will write the code that code is written in one of the file or or uh multiple files and that that [03:12:42] files is stored somewhere in one of the server. So this is my server in in on top of this server I am hosting my application. Now this application requires access to the backend services like database like storage. But before [03:12:59] providing the access I need to authenticate this application. So how to authenticate this application? So if this application is hosted on Azure this application is hosted on Azure virtual machine or Azure app service or [03:13:12] Azure or any uh service any compute service Azure any compute service of service Azure any compute service of Azure then you can create manage identity for that service and that manage identity registers an object ID [03:13:27] for your application. That means in simple term a user gets a user ID gets created for your application and when you create the user ID then it becomes quite easy to provide access to [03:13:42] becomes quite easy to provide access to the resources to the required resources. Okay guys is the screen visible? I see that Baba is saying screen is most visible. What do you mean by most visible [03:14:05] connection. Please rejoin. [snorts] It's visible for everyone. Not visible to you only. [03:14:19] an access for real world scenario you have this application. This lms.simplearn.com simply.com is an application right when I go to continue application right when I go to continue learning [03:14:37] should see your live classes here but when I go to the past classes sorry it's not this one let me show you with a 104 if I go to a 104 when I go to the live [03:14:56] Now this is my application. ls.simplearn.com is my application. Now tell me [snorts] do we keep the assets like videos and images within the same server where our application is [03:15:12] the same server where our application is hosted. separate our front end with our back end. Front end is something that user see you lms.implearn.com you can login and you can see you can interact with [03:15:27] our application but if you want to access any backend service like the storage like we have files whenever I upload file that file will be visible here right if I click here I should I should be able to see [03:15:41] the files that have been uploaded right so this application lms.simplearn.com simply.com is hosted on a compute service like virtual machine. So lms.simplearn.com will be hosted here. But the actual [03:15:54] video, the recording of the live class is not stored on the same virtual machine. We don't store it here. Imagine we have running 10 classes parallelly every weekend. If we keep on saving all the videos in the same virtual machine, [03:16:10] require. So we can't keep it in the same virtual this with our back end. So we might be using storage service, storage account. recording that you see over here that will be stored in the storage service. [03:16:32] needs to access that video. When someone clicks on this video obviously the application will run that video, will play that video. So when any user is clicking on this video the application will play that [03:16:46] video but in order to play application itself needs an access to the storage account. Storage is a separate service. The compute is a separate service. So when application is trying to access the storage. Now tell me whether storage [03:17:00] will do the authentication and authorization or not. Storage is the service in Azure. So Microsoft enter ID will first authenticate this will first authenticate this lms.simplearn.com simply.com whether the [03:17:13] lms.simplearn.com simply.com whether the object ID is present or not the username password provided by this application is correct or not so all those thing will be checked and if it's correct then it will see whether this [03:17:26] application is authorized to see or run or play this video or not. So for user it's quite easy we create the user user gets username and password but what about application? So application you can create credentials [03:17:42] for your application in Azure by using manage identities. All right. So manage identity is the way to create an identity for your application. Okay. I just gave you an example of uh [03:18:00] lms.simplearn.com. You can take any example. Every application works in the same way. most popular video streaming service YouTube. So YouTube what you see is the front end youtube.com you see all the videos and [03:18:15] all everything when you click on any video the YouTube application is communicating with their backend service wherever they are storing the video and that backend service is responsible for storing the video. It could be a [03:18:28] storage service any storage service that Google is using YouTube is using. All right. So in order to provide the identity to your application within Now there [snorts] are two types of manage identity. System assigned and [03:18:42] user assigned. In order to understand system assign manage identity and user assign manage identity, you need to answer me a question where group. What is the difference between user and group? [03:19:06] connection please. You need to uh turn off and and rejoin. You should be able off and and rejoin. You should be able to see the screen. Okay. [03:19:26] users. So if you have multiple users, you create a group and you put all the users within the group. So system assign and user assign is is the is is based on the similar concept. System assign is an individual identity for one application. [03:19:41] So when you use system assign, one object ID will be created and that object ID will be assigned to only one uh application. Whereas when you create user assigned [03:19:54] manage identity that user assigned manage identity is shared across multiple applications. So if you have let's say 10 applications and all these 10 applications require similar kind of access. So instead of creating 10 [03:20:10] different system assign identity, you create one user assigned manage identity and then you assign that user assign manage identity to all other VMs or app service or whatever. Okay. So it's similar to group and [03:20:25] individual user. System assign consider it as an individual user. So you create when you create system assign manage identity a single object ID is created application. Whereas user assigned manage identity is [03:20:40] like a shared manage identity which can be shared with multiple applications. So if I have five applications which require similar kind of access, I'll create one user assigned manage identity. I'll associate that one user [03:20:55] assigned manage identity with five different applications and then all that similar access. Okay, that's the difference. Now where don't have any VMs or all but I have existing VMs. So if I search for the VMs [03:21:11] it's not only for VMs it's can be for any compute service. So if I have app service we will have a separate topic uh module on compute service where you'll get an introduction to all compute services. So whichever compute service [03:21:26] you are using every compute service has a manage identity feature. Okay. So let's say uh this is my uh Linux VM OpenVPN 2 and this Linux VM needs access to the backend service. So what I can do I can create a manage identity for this. [03:21:42] If I go to the security there I should see identity and within that identity we have system assigned or user assigned. So if I select system assign then that would be an individual identity for this [03:21:56] VM only. Okay. So I click on on and then I click on save. So it will create a manage identity for this particular virtual machine that manage identity is [03:22:08] not shared across multiple virtual machines. Okay. So as soon as I click on on it should once it is done it should create the manage identity. So you see an object ID is created. Right. Now you can use this object ID to assign [03:22:23] whatever role you want. Like this virtual machine needs an access to storage. So you can use this object ID and assigned access to the storage. Okay, I don't need it. I click I I turn it [03:22:36] off. Okay, let's wait. [03:22:57] identity. Once this is done, I'll go to that tab. it on, it creates an object ID for that particular uh instance for this virtual [03:23:12] machine. when you turn it off, it dregistered the same object ID from dregistered the same object ID from enterra ID. Okay, that's what's happening behind the scenes. Now, if you want to use user assign, uh I need to [03:23:25] want to use user assign, uh I need to wait until uh it won't it won't disable. [snorts] [cough] [03:24:01] Hurry is asking where do we use that object ID? Okay, where do you use this object ID? Okay, where do you use this object ID? If I go to uh portal.asio.com object ID? If I go to uh portal.asio.com azio.com [03:24:17] user every group all of them are having the user ID [03:24:43] if I go to Microsoft Entra ID. If I if I select any user, we use this object ID as I mentioned when before starting the manage identity [03:24:56] that every identity within your Microsoft Entra IM solution has this object ID when this object ID is used when this user is trying to log into any azure.com [03:25:10] azure.com the IM service is identifying this user as this object ID we are not directly using this object we as a user we are not directly using this object ID if I ask you to remember this [03:25:24] object ID will you be able to remember the object ID let's say you are this user fabric admin obviously you won't be able to remember this right for you for us as a human being it's easy to remember the the names fabric admin at [03:25:38] whatever my domain name is. So I can remember that. So for for me I will be providing fabric admin at whatever my domain name is. I'll be providing that and then I'll be logging in. But for IM service, how that im service will [03:25:54] identify this user IM service will see this object ID. So behind the scenes when we are when the data is being sent or or received by the IM service, they will be using this object object ids. Okay. So when I registered when I [03:26:08] created an system assign object system assign manage identity an object ID got created it got registered in the Microsoft entra ID as mentioned here. [03:26:20] Okay. So Microsoft entra ID will identify the openVPN2 virtual machine as identify the openVPN2 virtual machine as that whatever object ID was created. identity it's an individual identity for [03:26:32] that particular virtual machine. When you use user assign you will have uh you you use user assign you will have uh you can use that user assign manage identity to share across multiple resources across multiple uh virtual machines. [03:26:48] across multiple uh virtual machines. Okay. assigned manage identity. So I need to first create it. So if I search for manage identity on top I should see manage identities and there I can create [03:27:03] manage identities and there I can create the user assigned manage identity. Okay. [03:27:34] Once this identity is created, multiple VMs can share it. [03:27:54] to the resources. So I go back to the virtual machine. I go back to the identity. Hopefully I can use it since I created it in central India and my VM is in different region. [03:28:20] somewhere in US, South Central US and identity was created in central India. I am not able to see that identity. Okay. So in order to use the user assign [03:28:32] that user assigned manage identity is created in the same region. All right. I cannot see it because it's in different region. If I go back to user uh if I go back to manage identities, I see this shared user [03:28:48] manage identity created in central India. That's why I cannot use it. Okay. If I create it in another manage identity somewhere in [03:29:14] So both the identities and the resource who wants to use the identity should be who wants to use the identity should be in the same region. [snorts] [03:29:33] back to identity. Click on user assign. Give it some time. I should be able to see. Just wait for some time. You should be able to see. [snorts] Okay. If you're not able to see, just give it some time. [03:29:59] see that we should be able to see it. Okay, that's it's not showing it takes some time. If we did not receive any error while creating the manage identity and and we are not seeing it, just give it some time. [snorts] [03:30:11] it some time. [snorts] Okay. Or better we go to the uh identity Okay. Or better we go to the uh identity and check the type of identity this is. [03:30:32] see. We should be able to see that user assign manage identity and we will be assign manage identity and we will be able to assign it to the uh OVM South central US identity is also in South Central US. [03:31:08] the identities now, right? So I can select this shared user 02 which we created in the same region. I click on add. And once I click on add, this add. And once I click on add, this openVPN will have that identity with [03:31:21] that object ID. Similarly, I can go to another VM in the same region and I can add that as a user identity for that VM. Okay. [snorts] [03:31:44] this, let's me go back to very basic. Tell me what is authentication? Have you understood what authentication is? There are users who wants to log in. Why? Why do you want users to login? I want user to login to make sure that the [03:32:00] user who he is claiming to be is the same user. So I need to verify. So in order to verify I have an IM solution. I need some kind of IM solution in place. Right? Have you understood that basic? [03:32:16] So in order to assign access to the users I need IM solution in place. Before assigning access I need to create an user ID for access I need to create an user ID for that user. Is that clear? [03:32:35] explaining manage identity I went to the lms.simplearn.com. I showed you the uh where it is. Okay, I showed you this. Okay, so what is lms.simplearn.com? Hopefully you you you know this is an [03:32:51] application. Okay, it's a web application since you're accessing it via web. It's a web application, not a desktop application, not a mobile application. It's an application. [03:33:03] Now when it comes to application, you design application in different tiers. You have front end. Front end is something that your user, your end user sees. You have back end. Back end is something which is separated from the [03:33:16] front end because we don't want our users to get the direct access to the download the video and you'll be able to spread the video right imagine Netflix what we can do we can download that movie and then we can share it on [03:33:32] torrent and all that is known as piracy similarly we want to protect our assets right so what do we do we separate front end everyone every application has this concept back end and front end. So front end is something uh which is accessible [03:33:47] to the user and user end user and user sees application in that form. Now when you are separating these layers front end and back end can your front end your directly access the back end without authentication or authorization. Is that [03:34:04] safe? Obviously not safe. Why it's not safe? Front end is also ours. Back end is also ours. So when front end wants to access access without doing the authentication or authorization. [03:34:19] Why we are not doing this? Because when as a end user you click on this this as a end user you click on this this video link a new uh a new uh browser will be open and your video will be played there. So if someone some hacker [03:34:35] is listening to your traffic and if you do not have any authentication or or or anything that hacker can uh track or can can hack the session and can get into our back end can download all the videos that we have. So for that reason we want [03:34:52] authentication and authorization between front end and back end as well. But this this application? Application is not a user. So when it's not a user, it doesn't have the username and password. So how do I authenticate this guy? This [03:35:06] application, this application is hosted somewhere, right? Might be hosted on virtual machine, might be hosted on app service or container wherever it is hosted somewhere. So if it is hosted somewhere [03:35:20] that virtual machine I can provide access uh I can provide identity to that virtual machine. So in Azure we have this managed identity concept. You can create a manage identity for your virtual machine [03:35:35] where your application is hosted. Once I create the manage identity that object ID gets registered to the entra ID. Why it's registered to the entra ID? How entra ID is going to identify a particular object? So in [03:35:51] Microsoft enter ID we uh they create the they create something known as object ID they create something known as object ID like in Windows you have uh SID in Linux you have some different identifier. So in every platform you have an identifier [03:36:06] object ID is nothing but an identifier how entry ID is going to recognize or verify or identify that particular identity. Identity is nothing but a an identity. Identity is nothing but a an object which requires an an access. [03:36:19] So in Azure we have something known as managed identity. So when I create the manage identity an object gets registered. So as soon as I created the manage identity shared user 02 an object gets registered within my uh entra ID. [03:36:35] Obviously I won't be able to see it here but when you are trying to assign the access since it's not an since it's not a user I won't be able to see it under users. You won't be able to see it here since [03:36:47] we are under user section. Okay, there's no separate section for application where you can see the object ID. But object ID is a way how entra ID is recognizing or verifying or identifying that particular ID. [03:37:03] When you create manage identity, there are two ways. So let's consider this open VP VPN 2 is a virtual machine where my lms.implearn.com simplylearn.com is my lms.implearn.com simplylearn.com is hosted [03:37:17] my back end because application is hosted on this virtual machine and that application requires access to the back end. So how do I provide the access in order to provide the access one way that we have [03:37:29] within Azure is manage identity. So when I create the manage identity an object ID gets created for that particular man for for that particular virtual machine. when it's created. Let's say now I want to assign an access to the storage. This [03:37:43] is my storage account. Now that application requires an access to the application requires an access to the storage account. So I go here, assignment and I provide whatever role is required like reading. So if if it [03:37:58] requires a reader role, I select reader role and then I select manage identity. I select that object ID that that got created. So this is the user assigned manage identity that we have. This is the one that we assigned to OpenVPN 2. [03:38:11] Click on select. Now OpenVPN 2. Once I click on review and assign, OpenVPN 2 will have access to the storage. And when application request the access, this object ID, this manage identity will be used for authentication and [03:38:24] authorization. Hopefully, it's cleared now. Clear for you. You just need to remember if you want the manage if you want the access for if your application wants the access to the back end and if your application [03:38:39] is hosted on Azure you can use manage identity. Okay. Is it clear har? Yeah. It's similar to service account but it's not service account. Service account is a windows based uh solution. Okay. To the similar [03:38:53] thing, right? That's a similar similar concept. [03:39:08] manage identity the limitation is you can only use when it's if if when your application is hosted on Azure. If your application is hosted outside Azure then you cannot use manage identity. If my application is hosted on AWS or onprem [03:39:27] application is hosted on AWS or onprem or uh GCP not in Azure any anywhere not the solution for you. Why? Because managed identity as the name specifies managed identity as the name specifies it's managed within Azure for you. Okay. [03:39:41] In that case if your application is hosted outside Azure you cannot use manage identity. Then what we can use? So we can use something known as service principle. Service principle similar concept the only difference is your [03:39:56] application is hosted outside Azure. So if your application is hosted outside Azure you cannot use manage identity. You need to use service principle. Okay concept is similar application requires an access to backend services [03:40:11] like storage account and SQL. Your back end is still within Azure. You are using Azure storage service. you're using DB SQL DB in Azure but your application [03:40:23] itself the front end is hosted somewhere else for any reason. So if that's the case then I'll be using service principle. Okay, in this case I'll be using service principle. Service principle will also create an object ID [03:40:37] principle will also create an object ID within that entra uh ID and then you can use that object ID to assign whatever access is required. The only difference between manage identity and service principle is [03:40:50] outside Azure you will be using service principle. Where do you see service principle. Where do you see service principle? Same if you go to enterra ID there you have app registration. Okay. So you register your application [03:41:04] Okay. So you register your application here. Uh this name can be anything. random name. All right. And then once I click on register, an object will be [03:41:17] created. So you see object ID see an object got created for this as well. Now I can use the same object to assign whatever access I want. Okay. So I can go again go back to the storage. I can click on uh access control IM. I can [03:41:33] click on add add role assignment. Now instead of manage identity I'll select here service principle. Okay. You see the first option it says user group or service principle. So I I use the first option and then I search for the name [03:41:49] that I use dubdubdub.simplylearn.com. So now this object ID will have access the reader access to whatever service I'm providing to. Okay. All right. I don't need it. So I'll I'll delete it or maybe later I'll delete it. [03:42:05] Let's let's proceed. Okay. All right. The next thing then last topic that we have for today not for today I mean this topic is this for today I mean this topic is this module is Azure key vault. So Azure key [03:42:18] module is Azure key vault. So Azure key wault is a is a service is a storage wault is a is a service is a storage service for storing your secrets keys and certificates. Okay what are the secrets keys and certificate? [03:42:33] Secrets are like password. So if you want to store password or configure uh want to store password or configure uh connection strings or keys uh within as your key somewhere then you can make use of Azure key wault. So it helps you to [03:42:49] store password secretly. It helps you to store keys secretly. It helps you to store certificates secretly. Now why [snorts] do we need to keep secret keys and certificate within Azure keyword? Why why can't we keep it [snorts] within [03:43:04] the application itself? What could be the reason? Now, in order to explain the reason? Now, in order to explain that, I need to go to my uh GitHub. that, I need to go to my uh GitHub. Okay. [03:43:25] If I go over here, first of all, answer me. Do you guys know what GitHub is? Since since we have like 40 50% of people who are freshers, do you know what GitHub is? [snorts] [03:43:44] GitHub as a central place where your developers will be pushing code. Code is nothing but your application code. Okay, it's a repository or a place where your developers will be pushing the [03:44:00] code. So [snorts] when you push the code, that code is your application code, that code is your application code. All right. So if you see here, code. All right. So if you see here, this is my uh GitHub and if I go to uh [03:44:13] the application and if I go to the application app. py you see here in my code itself I have placed the connection string storage connection string now we are going to [03:44:26] use this application uh letter when we are on on this particular topic okay but for for simplicity just to help you understand what keywalt is and where you understand what keywalt is and where you use keywalt storage uh uh uh GitHub is a [03:44:40] so this is one of my application written in Python now this application needs needs to interact with Azure storage needs to interact with Azure storage account. How do I [03:44:52] account? So, one way is to keep the storage connection string here. storage connection string here. Connection string is a way uh is an is a is like a password for your application to access whatever you have within the [03:45:06] storage. So, if I provide the connection string over here, then my application app. py can access storage account directly. Okay, you don't need manage identity. You don't need service principle. If you [03:45:20] keep connection string directly here, you can access directly. Doesn't matter where your application is hosted. So, connection string is like a password for the storage account. Okay. Similarly, there are lot of [03:45:33] services like service bus, event hub. Now, tell me is it safe to keep the connection string within the code and push it to the GitHub? Is it is it safe if I just give you this link? Try accessing this link. Can you [03:45:49] link? Try accessing this link. Can you see can you uh see the link? Let me just provide you the link. You don't need to login nothing. Just just don't need to login nothing. Just just launch that link. [snorts] [03:46:05] this link, I'm not logging with any any credential or anything. But I can see whatever whatever we have here. So if I put connection string over here and if this link uh since this is public anyone can access like you guys are accessing. [03:46:20] So if I keep my connection string over here you know my connection string then so if you know my connection string what you can do you can add anything to my storage account remove anything from my storage account [03:46:34] delete my storage account. So is this safe? Keeping storage connection string safe? Keeping storage connection string here. Is this safe? Are you going to ask your developer to push the secrets directly within the [03:46:47] GitHub? Obviously, it's not safe. Right? So what we do, we store or save this connection string in Azure keyword as a secret. So Azure key is a way to to [03:47:01] keep your connection string your password as a secret within Azure key. password as a secret within Azure key. So now instead of accessing the storage account directly I have another application over here. [03:47:23] Who is the application? I didn't push the application I think. [snorts] another application here. Program.json. Here if you see this application is not [03:47:38] C car C car C car C car C car C car C sharp. Okay. Now here if you see we are not adding the connection string. If you know how uh how C# works or hown net [03:47:52] works it's very simple. Okay. What it is doing? It is connecting to the key vault. It is connecting to the storage account. Within storage account, you might be having some container. So, it's connecting to that container. And then [03:48:05] connecting to that container. And then it is getting the secret from the Azure key vault. Okay. We are not adding the the key directly here in the code itself. Do you see connection string here or or [03:48:21] uh a secret here or or or a key here? What we are doing? We are declaring a variable. That variable is reading the secret value from the Azure keyword. [03:48:34] Okay. So instead of keeping everything within the uh code itself, we separate it. We secure it by putting all of our keys, [03:48:46] secrets and certificates within Azure keyword. keyword. All right. Any questions on keyword? [03:49:01] not not today uh tomorrow during your free time just go to this uh repository go to day one authentication and authorization [03:49:14] and within day one I have readme file inside the day one folder I have readme file just follow whatever is mentioned here everything is given to you step by step even application is created [03:49:28] step even application is created Okay, just follow this step by step and you'll understand where your your key how how key volt key works. Okay, so it's [snorts] very simple demonstration that you can do on your own. You don't [03:49:42] that you can do on your own. You don't need me. Okay, but I I have created this uh I have developed this application. It's a very simple application which is demonstrating you how uh you can interact how your application [03:49:57] can interact with Azure keyword. Okay. Uh if you see we have the templates here parameter.json template.json. So how to deploy that is mentioned in the readme [03:50:09] should know you should already know that. If you don't know the command is given over here deploy infrastructure. Okay. Then assign permission. So you you you can assign permission by going to this. All right. And then uh you can [03:50:26] this. All right. And then uh you can also see the keys by by this command a storage account keys list. Now where to run this command? That's why it was important to give the tour of Microsoft Azure portal. You can run all this [03:50:38] command here. You don't need to install anything on your machine. Okay? You choose bash or powershell whatever you want. Select that bash or powershell and run your command. Now this here I don't have the subscript. Uh here I don't have [03:50:53] that error. Okay. [snorts] Select whatever you want powershell or bash and run that command. Do not run it on your local machine since it's possible you local machine since it's possible you might not have uh things installed in [03:51:06] your local machine. So it's better to run directly within the cloud shell. All run directly within the cloud shell. All right. And you might uh get some issues. You might uh get some issues like something is not installed. Right? If [03:51:19] you if you go to the readme file, you should see none of this one. A lot of tabs are open. Let me close [03:51:31] GitHub. If you go to this readme file, uh I have mentioned net run. So net run is something which helps to run the application locally. But you don't need to do this since net run might not run [03:51:45] to do this since net run might not run directly on your cloud shell. So you can skip step number six. You can follow step number seven. Okay, this is for local. So if you have net installed locally in your machine, then only this [03:51:57] this particular command will run. All right. So that's all about authentication and authorization. Keys are changed frequently. That's correct. You have to change keys every now and then. That's why you need to [03:52:10] keys are changing, you need to go to the key wault and change the key manually. Okay? Or you can use PowerShell or Python scripts to change the key as soon as you're changing it in your storage [03:52:23] account or database or wherever. Okay. All right. So there are no questions. Let's see the case study. [03:52:42] authentication and authorization solution. So just go to this link read solution. So just go to this link read the case study. Kyash is asking how do we manage certificate expiry? What what do you [03:52:57] mean by manage? If certificate is expired, you replace the certificate in the keyword. That's all. What what what's there to manage? I need to buy the certificate first. Right? If uh if my HTTPS SSL certificate is [03:53:11] expiring, I need to get a new one from the provider and I need to add it to the keyword. That's all the new one. [snorts] [03:53:26] going to do? They're going to buy a new one and then they install on their web server the new one. That's all. Similarly, if you're keeping your certificates in key volt if certificates are expiring, you need to remove the old [03:53:40] are expiring, you need to remove the old certificate, add new certificates. where you can keep your certificates. Key volt is not giving you some kind of [03:53:54] rotate the keys or automatically change need to rely on your your scripts or your PowerShell scripts or Python scripts or whatever scripting language you're using or scripting method you're [03:54:07] It's just a place. It's just the storage service to keep your things secretly. service to keep your things secretly. So instead of keeping everything on on the code itself, you're keeping it in in in keyword. That's all. Okay. [snorts] [03:54:23] in keyword. That's all. Okay. [snorts] All right guys. So uh again key volt is just a place to store the data. It does not have any [03:54:36] additional way to remind you or send you an email about the expiry. No, it won't do that. For that you still need to rely on monitoring system or your scripts. Okay. So if you have a PowerShell knowledge you can create a PowerShell [03:54:51] script which will which will check the expiry date of all the assets of all the secrets or all all the keys that you have here. You can run that PowerShell send an email or however you want to [03:55:06] notify uh will notify the stakeholders that this certificate is going to expire or or or things like that. For that you still need to rely on something. Okay, it's just the storage service that's [03:55:19] it's just the storage service that's all. All right guys, case study. Let's come back to the case study. So I have shared the link of case study. So let's uh get through it. Design authentication and [03:55:35] authorization solution. So this is the requirement. So we have a fictitious uh company Tailwind traders who wants to expand their workforce. They have successfully acquired an online retailer [03:55:48] in sports apparel space. The company has also located a partner to outsource marketing literature. Tailwind traders is using Entra ID for user and groups accounts. Here are two specific initiatives the IT department would like [03:56:02] initiatives the IT department would like to would like your help uh with. So you >> [snorts] >> The online retailer acquisition will add 75 employees to the Tailwind traders. All the new users have on-prem account [03:56:17] in the retailer's existing domain. Okay. So, what do you understand by this? What service are you going to use? The online retailer acquisition. That means Tailwind Traders uh is acquiring online retailer and they [03:56:32] already have active directory domain services. The online retailer already have active directory domain services and 75 user accounts there. So how are you going to bring that 75 users to Microsoft entry ID? What [03:56:45] service you can use? Entra ID connect. That's correct. So here I'll be using entry ID connect and I'll be bringing those or synchronizing those 75 users those or synchronizing those 75 users with my entra ID. All right. [03:57:00] The new marketing partners. So they're all or they're also uh acquiring the marketing partner. So the new marketing partner will initially have 15 employees who will need corporate access. So these employees [03:57:15] already have Microsoft Entra identities in the partner Microsoft Entra tenant. So what service or feature we can use? So it's like you have two tenants [03:57:27] marketing partner and your own tenant Tailwind traders. So here we can use B2B since these are our partner and we want to uh collaborate with them right so we [03:57:39] just use B2B here then the new employees are located at need account privileges for their new job roles some changes to the existing employees roles are expected geographic [03:57:54] locations what what do you think over here what services you can use conditional access and identity protection. Right? These two services we can use here to make sure that whatever [03:58:10] identities are are logging in [snorts] uh are protected. Right? So conditional access we can define only those geographic locations from where the access is required. Okay. The IT department wants to take this [03:58:24] opportunity to include new identity security features. So whatever features we have learned conditional access, identity protection, access reviews, you can implement all those stuff. They haven't mentioned which one to use or [03:58:38] haven't defined which one to use. They have mentioned all the new features. So have mentioned all the new features. So you can implement all. Okay. Then the next thing is new application access. So application also requires some kind of [03:58:51] access. So the business development team has an application running on Azure virtual machine and data stored in Azure SQL database. They need to securely allow the VM to query the Azure SQL database. How how you can achieve that? [03:59:07] database. How how you can achieve that? [snorts] hosted on Azure VM database is stored in Azure SQL database. Now this VM should be securely able to query the SQL database. So what we can use we can [03:59:23] assign manage identity to this Azure VM and provide access to the Azure SQL database. Then whenever query is running the Azure SQL database will identify the using the manage identity and if access is granted or not. Okay. So here we can [03:59:38] is granted or not. Okay. So here we can use manage identity. They also need an on-prem server to be able to securely access SQL database without storing credentials in the application code or configuration file. It's an on-prem [03:59:53] server. Here you can use service principle and you can use Azure keyword principle and you can use Azure keyword to store the SQL database uh connection string within Azure keyword and then on-prem server can access SQL database [04:00:08] by reading the credentials from Azure keyword. So here we need to use service keyword. So here we need to use service principle plus Azure keyword. All right. Why service principle? Because the server where application is hosted is on [04:00:20] prem. It's not on Azure. If the server would have been on would have been on in it would have been easy. Just simply use manage identity, right? But it's not on All right. Then these are the tasks. So [04:00:34] need to discuss. But these are the task for you guys. So you need to diagram the process. Okay. Like what you need to diagram use the same tool that I'm using [04:00:46] draw io. If you just search for draw io, it If you just search for draw io, it should uh take you to the draw io website. So this is the tool that I'm using. All right. Now here uh we have [04:01:00] using. All right. Now here uh we have the shapes. So if you add more shapes, we have azure here somewhere. We should see azure. All right. Now you need to diagram the diagram whatever you want to diagram the [04:01:15] process of bringing in the acquired user accounts. 75 user accounts were acquired. Okay. So what I do here then I go to Azure identity. So this is Azure identity. Here you should see active directory. Now uh Microsoft enter ID [04:01:31] directory. Now uh Microsoft enter ID icon is still not there. So you can use active directory. This one this is like a Microsoft enter. The previous name was Azure Active Directory, right? We can add a text here. If I want to add a [04:01:45] add a text here. If I want to add a text, I can add text like this is the text, I can add text like this is the Tailwind traders font and all from here. So just so that uh you can read it [04:02:08] Telin traders tenant. They're acquiring 75 uh users. So they are running on ads. So you can search for ads here or domain you can search for ads here or domain services. So it would give you uh [04:02:23] services. So it would give you uh some server image this is the on-prem active directory domain services for the online retailer. [04:02:37] domain services for the online retailer. Right? So you can just label it. [04:02:53] what you what you can do here? You can simply use arrows and all. So I just use simply use arrows and all. So I just use uh arrows here. I uh pull the arrow and then I search for [04:03:06] entra connect. So somewhere you should see the entra id connect. Again within the identity you should see the entra id connect. Okay. So this is entra ID connect. So I keep it over here. And then again I label it [04:03:20] it over here. And then again I label it 75 users by keeping text a little low. [04:03:32] that. Okay. So you need to come up with this this kind of uh uh designs and this is what Microsoft expects you guys to to do to design things. Okay. We can't do do to design things. Okay. We can't do that uh within class. Okay. Since I need [04:03:47] to cover the theory and then uh certain demos. So case study is something I leave. We will discuss the case study but this design thing is on you. All right. So you can use this app.dagramgram.net [04:04:02] add Azure as a shape and you'll get all the Azure shapes. Okay. Then you have marketing retailer. So you can uh what is mentioned about that marketing retail marketing partner. So they're [04:04:16] also using Azure Active Directory or Microsoft Enter ID. So you can copy the same and you can label is that marketing partner and between the partner and partner and between the partner and Tailwind traders. What you can do is [04:04:34] Tailwind traders you can create like an arrow and you can use as your active directory B2B. If you search for B2B if we have any B2B uh icon you can directly use that but I don't think so we have B2B icon. [04:04:50] here B2C is there B2B is not there so you cannot use any uh icon but you can simply add a label there B2B 15 members okay so I want something like this once [04:05:02] okay so I want something like this once you are done you can share it with me over my email so I'm sharing my email id here okay and then I'll review and give you the reply over the email [04:05:17] the reply over the email clear guys is are you clear how to do the case study? We have only covered authentication and authorization. I was planning to complete the governance as well but uh doesn't matter [04:05:31] since this is the first weekend. uh we need to buckle up and and speed up the the things here. So this is the link [04:05:46] the the things here. So this is the link sur. [04:05:58] >> Yeah. Then it in related to manage identity identity >> and you go to the VM option. Okay. where >> and you go to the VM option. Okay. where you uh created the object ID first first [04:06:11] option and after that you go to the manage identity where you created the another object ID. >> Okay. >> Yeah. I'm unable to correlate that because in the when you open VM uh open [04:06:26] VM uh BPN02 you created object ID and after that you go to the MAR identity and also you created the an object ID and go to you [04:06:40] go to the storage and you manage the uh attach the object ID >> from the manage identity. I'm unable to understand that. Have you understood the concept of manage identity? >> Yeah, I have understood the manage [04:06:54] >> Okay. Can can you answer what manage identity is? >> Manage identity is the ID which is generated to authenticate between the data. >> Okay. Right. How many types of manage [04:07:09] >> We have two types of manage entities. System assigned and user assigned. >> Correct. Okay. What is the difference? System assign is based on the single single type user and user assign is [04:07:25] based on the multiple type user. Correct. Suppose that we have some >> Okay. Uh system assign is like for single resource. Okay. >> Yes. Yes. >> It's an individual identity. So if I [04:07:38] create system assign uh this VM will get an object ID and that object ID will belong to this VM only. single individual. Okay. When I create user [04:07:50] assignide manage identity, I can share that manage identity across multiple VMs. So I have 10 VMs. All those 10 VMs requires the same access. So what I can do instead of creating individual identity, I create one user assigned [04:08:06] [snorts] >> Okay. for individual system assigned manage identity you can create it from the v uh from the resource itself that mean I can go to virtual machine I can go to identity [04:08:21] and then I can create the system assign manage identity if I click on on here and save system assign manage identity will be created which is which will be will be created which is which will be associated with openvpn02 only. [04:08:35] >> Okay. If I want to create the user assigned manage identity, I cannot create it from within the resource itself. I cannot create user assigned from here. So what I need to do? I need to search for manage identities. [04:08:51] I need to go there. I need to create a new one. Here I'm creating user assigned manage identity. And then I can use that user assigned manage identity to user assigned manage identity to associate to as many VMs as I want. [04:09:05] So when I when I switched when I >> yeah that's the difference. So you in order to create user assign manage identity you need to create it like manage identity you can create from resource itself. [04:09:19] >> Okay. Now it's clear sir. >> Okay. All right. >> Okay. All right. >> Thank you. [04:09:33] are no uh questions, let's proceed with the next uh topic. We'll just cover the basics since it's already 10:34. All right. Those who are leaving, I see people are leaving. Uh I see participants only 50. Before leaving, [04:09:47] please make sure you're providing the feedback. All right. Now we are moving feedback. All right. Now we are moving on to the second part of uh authentication and authorization. Moving to the second part of AM. All right. [04:10:00] Identity and access management. So far whatever we have discussed was related to identity. That means we were creating users, we were managing users, we were modifying users, we were creating identity for applications like manage [04:10:15] identity or service principle. So we were just creating identity. We were not assigning any role or we don't know which role to assign, right? We don't know how to manage or how to assign access to the users or resources. So [04:10:30] that's something which we will cover in the governance topic. What res what role we can assign, which role is powerful, which role is not powerful, what is reader role, what is owner role. So all those stuff we will [04:10:44] be covering in this topic. Okay. So far whatever we have discussed is related to related with the identities creation or management only. [snorts] We haven't assigned any access to any user yet. We created one user, right? We invited one [04:11:00] user in our identity in our Microsoft Enra ID. We ass we we invited this root cloud a user. Remember at the start of the uh session today, we invited this [04:11:12] user. But we haven't assigned any role to this user. So when I log in with this user, this user cannot do anything. So in order for this user to do something, we need to assign a role. So which role we can assign that's what we will be [04:11:26] we can assign that's what we will be discussing in this topic of governance. Okay. [snorts] So what is governance? Governance is a way to come up with with certain control over [04:11:40] come up with with certain control over your your system or over over your uh uh uh infra you can say or platform you can say in general term what is governance you we live in India let's say and in India we have certain policies certain [04:11:54] rules right certain laws that we have to abide so every country uh will have their own governance policies, their own own laws, right? [04:12:06] Similarly, every companies or organization will have their own governance mechanism or own own policies. So, governance is just a way which provides a mechanism and process to maintain the access control over your [04:12:23] resources, over your applications, over your users in Azure. [snorts] So how to maintain the control that's what this topic is about. Okay. [04:12:36] All right. So you have a user that user requires an access. So for authentication we are using IM. Now after authentication what this user can do can this user access the virtual machines? Can this user access the SQL [04:12:51] machines? Can this user access the SQL database? Can this user delete the uh delete the SQL database? So what he or she can do that's what we are defining using governance. All right. [04:13:04] So what is governance in general? Is that clear? [04:13:24] just to secure authentication of resources or to provide connectivity. Manage identity does not provide the connectivity. That is something network you uh network should be doing. Okay. Manage identity does not provide the [04:13:39] connectivity. It does not connect your virtual machine to the storage account. The connectivity is a network part. So you need to define the connectivity. We have fourth chapter where we'll be discussing network. [04:13:52] authentication. Whatever we have discussed so far is related to All right. So what is governance? Governance is just uh a mechanism where [04:14:04] you can define certain policies. You can define access control which user or which application can access what right now how to achieve that in Azure that's what we are we are going to discuss in this chapter. Now this thing hierarchy [04:14:19] is important to understand when it comes to Azure. Okay. So Azure has this hierarchy. Now what is this hierarchy? This hierarchy is nothing but a scope where you can [04:14:35] define the access control. All right. Hierarchy is nothing but the scope the level where you can define the access control or you can define the access control or you can define the policy or you can define the uh tagging. [04:14:50] hierarchy. What is this hierarchy? At the top of the hierarchy you have a management group tenant root management group. Then within that tenant root management group you have you can keep different [04:15:04] management group within the tenant root management group. Then management group is like a container logical container where you can keep your subscriptions. Subscription again is a is a billing boundary. Okay. So using the [04:15:20] boundary. Okay. So using the subscription Azure will will charge you subscription within subscription after the subscription the scope that we have the level that we have is resource groups. So resource group is again a [04:15:32] logical container where you can keep your actual resources. Okay. So this is the hierarchy. Now I'm not explaining each in detail because if you see we have a separate slide for that. All right. For now for this slide [04:15:46] you need to remember the hierarchy. What is the hierarchy? At top of the hierarchy we have the first group which is the default group. So even if you're not creating the management group, Azure will create [04:15:59] one for you by default and that group is known as tenant root group. Now what is a management group? Management group is a way to manage your subscriptions. So within your management group, you can keep your as many subscriptions as you [04:16:13] want. What is a subscription? It's a billing boundary. For now, you just remember it's a billing boundary. Then within the subscription, you will be creating resource groups. So resource group is a way to keep uh in Azure it's [04:16:27] mandatory to create resource group. Without creating resource group, you cannot keep your resources. So resource group is a way to organize your resources. Now tell me when you buy a laptop [snorts] within the laptop we [04:16:41] have certain components right we have uh LAN card you know what LAN card is the network interface card where you connect your interface card where you connect your LAN cable right then we have hard disk [04:16:54] nowadays we have solid state drive we have processor right so a lot of things you when you buy a laptop lot of components you get obviously you you don't see it but uh those components are there within the [04:17:09] laptop [snorts] similarly when I create a virtual machine so it's not a physical machine it's a virtual machine you can't touch it so in Azure when you want to create a server you create a virtual machine with the virtual machine you get [04:17:22] the virtual disk a disk get created a virtual nick gets created network interface card the LAN card okay if you have assigned IP address or public IP IP gets created. So all this stuff get [04:17:38] created with the virtual machine itself. So where if if you scattered this in different different groups, it will be very hard for you to come up with an inventory and all those stuff. So what do we do? Whenever Azure is creating [04:17:51] machine, Azure keeps all these resources in one resource group. So that within that resource group, you can see all of your resources. If I show you the resource group in action, if I go to the resource group, any resource [04:18:05] group where I have my VM, this is one of the resource group that I this is one of the resource group that I have. And if you see my Windows 11 VM has the disk, has the public IP, has the virtual link. So whenever I create a VM, [04:18:20] virtual link. So whenever I create a VM, all this gets created with the VM So if you see the resource type over here on on on second row if you see the resource type it's a virtual machine it's a disk it's a public IP it's a [04:18:34] network interface. So when we create a virtual machine everything gets created. So you can keep them in same resource group. So we'll keep them in the same them in the same resource group? Because these resource are related resources. So [04:18:50] what I can do I can create multiple resource groups like prod resource group, dev resource group, UAT resource group and keep all the resources belonging to that particular environment in each resource group. So it will be [04:19:07] easier for me to manage. Okay. So resource group is one of the uh Okay. So resource group is one of the uh uh level in the hierarchy in Azure. The act the main way is it's it's it's a logical container where you contain [04:19:20] which contains your resources. That's all. Subscription is a billing boundary. Without subscription, you cannot create or or deploy resources in Azure. [04:19:32] Okay. And then the root the management group is a way to organize your subscriptions. So it's [snorts] it's bound to happen that you will be having more than one subscription within your tenant. Why? because every subscription [04:19:47] comes up with certain limits. So within a subscription there there might be limit that I can deploy only 25,000 VMs. So if I need more than 25,000 VMs. So if I need more than 25,000 VMs, what do I do? So I I buy [04:20:00] another subscription then. Okay. So what is a subscription? It's a billing boundary in Netflix. When you sign up for Netflix, you need to subscribe to their plan, right? without subscribing to their plan will you be able to watch [04:20:14] any movie or any any web series? No. Right? We need to subscribe. So similarly in Azure we have subscriptions. We need to buy subscription, you cannot deploy the resource. [04:20:27] Okay. Let me give you the demonstration very quickly here. So if I go here and I have logged in with this user. If you see the uh name simply learn at whatever the domain name is. If I search for virtual machine [04:20:42] I am landed to this page and I have the option to create and I can click on create virtual machine and I'm landed to the create virtual machine page. Once I provide all these detail virtual machine will be created. [04:20:56] will be created. Okay. But if I log in with another user the user that we invited, if I log in with that user, [04:21:28] I login with this user which we invited at the start of the uh [04:21:56] Okay. So, I've logged in with root cloud a guest user that we invited. [04:22:19] in if I search for virtual machine [04:22:36] a virtual machine when I when I search virtual machine from another user from this user I'm landed to this page where I have the option to create. I can virtual machine and then I'm I'm I'm going to the create virtual machine [04:22:52] page. But when I log in with rootcloud a I don't even have that create option here. Why I don't have because this user root cloud a doesn't have any subscription. So in Azure when you want to deploy [04:23:06] resources you need subscription. Without subscription you cannot deploy resources. So this user doesn't have any subscription that's why he cannot deploy the resources. The other user has the subscriptions. If [04:23:20] I switch back to the browser to a different browser and search for subscription here I have the subscription. have the access to the subscription I can deploy resources. If I don't have [04:23:35] the subscription I cannot deploy the resources. Okay. So in Azure subscription is a way for Azure to bill you. It's like a billing boundary. Clear? Any question guys? [04:23:51] Resources are the actual resources where your where your workload will be running. Resource group is like a container where your resources will be. So if you do not have subscription, you cannot create or deploy resources in [04:24:06] Azure. Management group is a way to manage your subscription. That means you can keep the subscriptions within the management group. All right. So let me show you the management group here from another account since that account [04:24:19] doesn't have access. Let me switch to the management group I should be seeing all the management group that I have within [04:24:35] the management group that I have within my tenant. management group that I have. So if you see the first management group that we have is tenant root group. This is by default. This is created by [04:24:51] Azure. Microsoft Microsoft Azure. As soon as you sign up for Microsoft Azure, you'll see tenant root group. Okay. [04:25:06] You can create as many management group as you want like I have created MG01 and within this management group you can keep your subscription. Right now both of my subscriptions are within tenant root group. If you see the hierarchy, [04:25:21] hierarchy is like this. You have top management group. Then you can create management group. Then you can create MG00003, MG00002, MG00001, whatever. Right? And between the management group, you can uh uh move your subscription. [04:25:38] Like if I want to move pay as you go to another management group, I can move it. I can select which management group I want to move. MG00001, MG00002, MG00003. [04:25:50] Okay, I can select that and click on save. Once I click on save, pay as you go dev test will go to whichever management group I selected. Okay, [snorts] so if you see now, if you refresh, everything is okay. You don't [04:26:03] receive any error. You should see your subscription within MG00003. All right. [snorts] So if I expand MG00003 now pay as you go [04:26:15] is within MG00003. Okay. So you have tenant root group then you will be having as many management group as you want and then you'll be having your subscriptions. Okay. Now question may arise like I see [04:26:29] one question by prain that why do we need so many management group? What is a management group? Management group is as the name specified is used to manage the name specified is used to manage something. Right? as when I started the [04:26:42] governance topic why do we need governance to put certain policies to governance to put certain policies to put certain control right now in Azure top of the hierarchy you have tenant root group so if I assign any access [04:26:56] here to any user let's say this is the user I assign a full access to this user at tenant root group this user will have full access over the entire hierarchy [04:27:14] subscription number one, then this user will have full access only at the resources which is within subscription one. He won't be able to [04:27:26] access the resources at subscription two. But if I assign full access at the tenant root group, he will have full access over whatever subscription you have within the tenant root group. Let me explain it from here from the portal [04:27:39] itself. If anyone is having whatever access at tenant root group that access will be inherited downwards. So if I have let's [04:27:51] say this user Imran kitani@hotmail.com has complete access over tenant root group then that user will have complete access over azure training subscription complete access over mg003 complete access over pay as you go complete [04:28:06] access over mg01 but if I change my access from tenant root group to only mg01 so whatever I have inside mg01 I can I [04:28:18] will only be able to manage manage those resources which I have within MG01. So in this particular scenario, there's no subscription within MG01. So if to deploy resources. Why? Because I don't have access here on on the top [04:28:34] hierarchy. I only have access here at MG01. So why do we need so many management group is to control the access. You have group is to control the access. You have dev, you have test, you have UAT [04:28:46] environment, you have QA, you have staging environment. You'll be having multiple environments. So to divide the access, you can create as many management group as you want and you keep your resources there. [04:29:00] management group, that is also fine. Totally up to you. How do you want to come up with your own hierarchy? It's not mandatory to have multiple not mandatory to have multiple management group. only if you have uh [04:29:13] number of subscription then management group makes sense. If you have only one subscription then having multiple management group does not make sense. All right. So and if you are working from enterprise a large scale [04:29:27] organization you are going to have lots of subscription. In my previous company we used to have one subscription per client. So imagine we had thousand subscriptions. So how to divide how to manage the access control within the [04:29:41] thousand subscriptions? Are you going to provide access to all of your users at each subscription? If I create a new subscription uh and my team is is having access over this subscription. And if I create a new [04:29:56] subscription, assign the access. Then if I create another subscription, I need to subscription, I need to assign an access. Imagine how much time you'll be wasting just for assigning the access. So what is the better way? Create a [04:30:11] management group, put your subscriptions there and assign access at the management group level. So whatever access you have at the management group subscriptions within that management group level, that access will be [04:30:24] inherited. Okay, clear. Let's proceed with our topic governance. Before that I'll just do a 5 minutes or 10 minutes of quick [04:30:36] recap what we have covered so far. Okay. Uh so what we have covered so far we started with basics of cloud computing where we understood what cloud computing is. Why do we need cloud computing in [04:30:49] today's world and then we moved on to our first topic of a305 which was AM. IM stands for identity and access management where we discussed about if we need a service if we want to implement AM in our organization or our [04:31:05] projects then if do we have any service in Azure. So we have Microsoft Entra ID as the service in Azure which helps you to manage or implement in your own organization. Now Microsoft Enra ID comes with two [04:31:19] different flavors B2B and B2C. B2B stands for businessto business. So if you have a partner company or any other collaborators who want to collaborate with your company and they want to build something for [04:31:34] your company or you have hired someone to build but it's it's a it's generally a contractor let's say not a permanent employee of your company and you don't want to create account for them. So B2B is something that you can make use of as [04:31:47] long as the collaborator has a valid email address. You can invite them directly to your tenant to your directory to your Microsoft tender ID and then you can give them whatever access is required to accomplish their [04:32:01] role or their job. Then another flavor of Microsoft enter ID is B2C. B2C stands for business to consumer. So when you have an application let's say this is [04:32:13] your company's application and this application is open for your let's say application is open for your let's say end users or maybe your employees and you want to manage a separate authentication module for this [04:32:25] application. So in this scenario you can make use of B2C business to customers business to client. Okay. Then we saw a few premium features in Microsoft Entra ID like uh uh conditional access on the basis of certain conditions you'll [04:32:41] provide access or you'll throw a multiffactor authentication challenge. Uh conditions can be anything like uh uh traffic is coming from a certain IP whether should allow that traffic should deny that traffic you'll define [04:32:54] everything in that conditional access policy. If you allow the access will be granted if you deny the access will be denied. If you ask for multiffactor authentication, a pop-up will be sent to their authenticator. [04:33:07] After conditional access policies, we went to identity protection. So in identity protection, you have like three different policies that you can set up. Uh you have user risk policy, you have signin risk policy and you have [04:33:19] multiffactor authentication registration policy. User risk policy if user is at risk signin risk policy. If the if the sign in method that that have been opted is detected as anonymous or risky. So all [04:33:34] those things Microsoft threat intelligence works behind the scenes and uh learns the pattern of user behavior like when what that what what time user logs in which device user uses. If any of this pattern changes then uh it could [04:33:50] be uh assumed by my by identity protection that it's a risk and whenever that risk is detected depending on your policy whether you have blocked it whether you have th whether you have asked for user [04:34:04] have th whether you have asked for user to uh to prove the identity prove the authentication using multiffactor. So that will be triggered. So depend on how you have what you have configured in your policy that action will be taken by [04:34:18] identity protection. When it comes to identity protection you don't do much as a user as a administrator I don't do much I just define whether I want to allow I want to throw a multiffactor authentication or I want to deny the [04:34:32] access that's all. So those are the three uh radio buttons that one of the radio buttons I have to select. After IDP we went on to access reviews before starting of this uh demo. U pankage asked for that and and I have explained [04:34:47] it right. So what is access review? In simple access review is just a way to review as the name specifies to review the accesses that you have given to your the accesses that you have given to your your users. Right? So whenever user [04:35:01] and then that group will be having access to certain resources and then after every 3 months 6 month depending on whatever policy you have with your uh security team you will be running that access reviews and then the manager of [04:35:16] that group or whoever is the reviewer of that group will decide whether the user will have a continued access or uh the access will be revoked for that user for those particular resources. Then after access review review we moved [04:35:31] on to two types of identities that is required for that we can use for application like manage identity and service principle. When an application requires an access to the backend resources like storage, SQL whatever. So [04:35:47] you create a manage identity for that application. Manage identity is something that you can use and assign it. It creates an object ID. Object ID is nothing but the way how Microsoft Endra ID recognizes or verifies a [04:36:00] particular object or particular identity. So that object ID is it uh gets assigned to that resource where your application is hosted and then you can use that object ID to assign access to whatever resources you want. But [04:36:15] manage identity the limitation of manage identity is if your application is hosted on Azure then only you'll be able to use manage identity. If application is hosted outside Azure then obviously manage identity is not the option for [04:36:28] you. So what you can do then you can make use of service principle concept is principle the application is hosted outside Azure. It might be hosted on prem might be hosted in some other cloud provider but they need access to Azure [04:36:43] resources. So in that case we can make use of service principle. Then we saw one uh resource in Azure which is Azure keyword. So Azure keyword is a storage [04:36:58] service uh which we use to store our secrets. Secrets can be passwords or can be connection strings. We can generate or or import the keys the cryptographic keys in Azure keyword and we can also make use of certificates. So we can keep [04:37:14] key certificates and secret in Azure keyword so that our application can securely access the secrets or the passwords or the connection strings directly from Azure keyword. It's not a good idea to store the password secrets [04:37:28] good idea to store the password secrets uh connection strings or uh access keys directly on the application code. It's not a good idea. That's why you can move that to a separate uh vault and from there your application can read it. All [04:37:42] right. So that's what we have seen so far. After that we moved on to the next topic which is governance. So what is the governance? Governance is nothing but a set of processes, policies, access control that you can [04:37:54] policies, access control that you can apply on within your organization, right? And within that governance topic we saw the hierarchy. So this is important to understand from Azure point of view. We have a hierarchy. Azure [04:38:07] hierarchy. Why this hierarchy is created? So that you can manage access policies, access control policies at any of the scope that is visible for your company, for your organization depending [04:38:22] on the requirement of your organization. Now what is this hierarchy? In this hierarchy, you have five different scopes, five different levels. Okay? Now, if you see, I've only mentioned four. 1 2 3 four. But in actual, you [04:38:36] have five, right? So what is that fifth level? The first uh the first scope in the hierarchy is the tenant root group which is present by default. When you tenant root group even when you don't create it. So tenant root group is the [04:38:52] top is the stop in the hierarchy. Within that tenant root group, you can create as many management group as you want. management group. Then within that tenant root group, you can create as [04:39:06] what is this management group? Let's see that. So management group is is is a scope is a level in hierarchy where where you can organize your [04:39:18] subscriptions. So here I can organize if I have multi it's bound to happen. You'll be working with multiple subscriptions within your organization. Why? So if you have done easy 104 you might know that every subscription has [04:39:30] its own limit. I cannot use Azure subscription limitless. That means I cannot go and use one subscription and deploy like the like millions of virtual machines. There will be limit. Okay. So, Azure has limit to two uh subscriptions. [04:39:46] subscription you are using. Every subscription will have limit. So, it's bound to happen if subscription is having limit and if I'm uh if I have utilized all of that limit obviously I need to buy another subscription. So [04:40:01] when I'm buying another subscription, the access control and the organization is very important when I'm when I'm having multiple subscription. Why? Let's say I have this subscription where few of my users are having access and they [04:40:15] can deploy resources. So this user is having access and this user can deploy resources whatever resources required. Similar to this user, you have thousands of group you have thousands of users. They have some kind of access to this. [04:40:28] some some of them are having read access, some of them are having write access, some of them are having write access. Right? So all the access control have been managed over here. Now let's say once I have utilized my limit, I'm [04:40:40] buying another subscription. So what I'll have to do now again I need to see who is having what access here and I need to replicate the same thing in another subscription so that I'm not blocking my user from deploying [04:40:54] resources. Right now after a few years let's say I've utilized another limit I'm going for another subscription. So I have to replicate all the access control all the policies everything on this subscription as well. So to avoid that [04:41:08] Microsoft has created this management group. So instead of assigning access directly at the subscription level what you can subscription within the management group and you can control the access at the [04:41:23] management group level. So once you control the access at the management group level in future it doesn't matter how many subscriptions you add within that management group all the subscription will inherit the same [04:41:36] subscription will inherit the same access control that you have um you have provided or you have added or you have assigned to your users at the management assigned to your users at the management group level. So those access those [04:41:48] policies will be inherit downwards. All right. So management group is the top level obviously tenant root group is the top level within the tenant root group you have your management group you can create a management group like uh here [04:42:03] it's it's created as tailwinds that is nothing but the company name and within the tailwind you have like sales corporate IT within the IT you might be having production dev QA UAT right so all you can create as [04:42:18] per your requirement whatever you want to create it it because um Azure doesn't want you to follow this. If you want to follow this, you can. Different company have different use cases. So they follow according to their requirement. Like [04:42:32] I'll give you a real world example of my own company. So my own company we have like we create a subscription for our client. So if we have thousands of clients, all thousands of uh client all thousands of customer will have their [04:42:47] own subscription. so that it's easier for us for us to invoice them at the end of the billing cycle. So what we have done we have obviously we have this tenant root group so I'll write it as TRG [04:42:59] then we have uh two management group one for our company okay one for the customers every customer subscription will goes under this customer in our management group we have [04:43:15] rod we have uh UAT and then we have U staging Okay. Test. So these are I mean non-pro not staging non-pro. So we have this very simple and uh effective way so that [04:43:32] whenever new customer we want to onboard a new customer we just add our a new customer management group. So that's quite simple management group layers we quite simple management group layers we have created. Okay. [04:43:47] So what management group is in order to organize your subscription you can keep your uh subscriptions under this management group you can manage for access control as well. So whatever access I'll be applying at this level [04:43:59] that access will be inherited. Okay. So doesn't matter how many management group doesn't matter how many management group I have in my hierarchy. Whatever access I'm assigning here that will be inherited. You can also enforce policies [04:44:13] at different levels of management group. So if I have any policy here at tenant root group that will be inherited. If I have any policy at it since it will be having different kind of policy. So if I have any policy assigned at IT that will [04:44:27] only be inherited by the management group and the subscriptions within the IT management group. Okay. Any policy at IT will not impact the root group, tailwinds, corporate and sales. Okay. So management group is very important when [04:44:43] subscription. If you have single subscription, you don't need to bother about management groups and all. All right, you'll be having one tenant root group. Create one management group with your company name and within that [04:44:55] subscriptions. All right. And obviously if you have management group it is easier to uh attain the compliance compliance requirement for your company since I can assign the all company level policy at [04:45:08] tenant root group which should be uh which should be equivalent for every subscription every management group every resource. All right. So I think I group but in order to work with management I just need to search for [04:45:24] management group. So in in the search bar if I types type type management I should get this option management groups. I click on it and I'll I can see how many management group I have. Right? So this is the tenant root group. So [04:45:37] within tenant root group you'll be having everything all of your management group. All of your subscriptions will be within tenant root group. Right? So whatever I'll be assigning here at tenant root group will be inherited by [04:45:51] tenant root group will be inherited by by by all the management group within have? What is our hierarchy here? We have Azure training. This is my subscription. Right? You can see the type here. So this is the management [04:46:05] subscription. Rest two are the management group. So anything assigned here any policy or any arbback role assigned here at tenant root group will be inherited by Azure training subscription will be inherited by [04:46:20] subscription will be inherited by MG00003 will be inherited by MG00001. All right. If I expand MG003 now we have tenant root group at top. We have subscription that is within tenant [04:46:33] root group. We have MG00003 which is within tenant root group. And then we have another subscription pay as you go within MG00003. Now if I assign someone any access at MG00003 [04:46:47] if I assign someone let's say this is a user user 01 and I assign access to this user at MG00003. Whatever the access is let's say read access. Now tell me can this user user 001 read anything we have at Azure [04:47:02] training? Azure training is nothing but the subscription name. So if I assign a the subscription name. So if I assign a user 01 access read access at management user 01 access read access at management group 003 can this user read or or [04:47:16] deploy any resource at subscription which is name as a as your training so I'm getting the answer as no that's correct why because MG00003 is at different scope is at the within the tenant root group and this subscription [04:47:33] as your training is within tenant root group so anyone in my company wants to work with Azure training, I need to assign access at the subscription level, Azure training level or at the tenant root group level. [04:47:47] All right. But let's say another question to you. If I move this subscription from tenant root group to MG003, now what is going to happen? that user who was having the reader role at MG00003 [04:48:04] should have access the read access to Azure training or no. If I move Azure Azure training or no. If I move Azure training to MG00003 then obviously yes. So whatever access you have at MG0003 will be inherited to [04:48:18] all the subscription that you have within that MG00003. within that MG00003. All right. So this is very easy uh to manage. In order to move, in order to create, you just click on create and [04:48:30] create another management group. So let's say MC00004 uh management group display name and ID whatever display name you want. Display name is for you. ID is for Azure. So that when you work with management group [04:48:45] using commands like CLI or PowerShell, you can call this ID. You can keep whatever ID you want. Okay. So I click on submit here. on submit here. It will create another group MG00003. [04:49:07] here? Do you need to keep MG under subscriptions or subscriptions under NG? Okay. So you need to focus on hierarchy here. Hurry. You never put management group under subscription. That is not possible. Okay, management group is a [04:49:23] possible. Okay, management group is a logical container which is created to manage your subscriptions. So always subscriptions will go under management subscriptions will go under management group not vice versa. I cannot put man I [04:49:37] group not vice versa. I cannot put man I I cannot put subscriptions under subscriptions that's not possible. Okay. So always your subscriptions will go under management group. So if you see the uh the portal here [04:49:54] the uh the portal here this subscription Azure training MG00003 this subscription Azure training MG00003 MG00004 MG01 are all in the same line are all in the same hierarchy that means they are within tenant root group. Okay [04:50:08] now we just created MG00004. Now if I want to move this pay as you go, I can simply click on these three dots move and I can move it under wherever I want. Do I want to move it [04:50:21] wherever I want. Do I want to move it under MG00004, MG00001, MG000? Wherever you want to move, you select that management group and move it. That's will be moved. But whenever you are moving something at this level, you need [04:50:35] to understand that the permissions, the policies all will be affected. Okay. So, whatever policies and permissions you have under MG00004, [04:50:47] have under MG00004, those policies will be applied to now uh moved. So before moving this subscription was under MG00003. So whatever role policies were assigned to MG00003 [04:51:01] will be would would have been inherited by pay as you go. But now since we have by pay as you go. But now since we have moved whatever policy and rules access whatever you have at MG00004 will be inherited by pay as you go. All right. [04:51:16] So that's how you manage these things and that's how you create management group and move subscriptions within the management group. You can also move management group to management group. So as you can see here MG01 [04:51:32] as you can see here MG01 consist or contains M02 now. All right. So hierarchy within the hierarchy you can put management group within management group. So that is also possible. All right. [04:51:45] possible. All right. [snorts] subscription. I'll answer punk. Just wait. Okay. So I'll read your question. [04:51:57] uh answer. So what is a subscription? Subscription gives you access to Azure services. What do I mean by what does that mean? If I want to deploy anything in Azure, I need to have subscription. Without subscription, I cannot deploy [04:52:13] resources. I want to deploy virtual machine or or uh disk or storage account. Whatever I want to deploy, I need to have access. I need to have subscription in place. without subscription I I cannot deploy [04:52:27] subscription I I cannot deploy resources. Consider it like something uh Netflix. Okay. So in Netflix I can create the account without providing uh nowadays you need to provide the payment [04:52:41] details and all but I can keep my account. I can sign up. I can provide credit card. I'll still have my account there. my account will still be there but I won't be able to enjoy the the movies or the web series or or whatever [04:52:56] Netflix has to provide right so in order to watch movies web series what I need to do I need to subscribe to a certain plan uh in Netflix whatever plan they that plan similarly you can create as your account without subscription you [04:53:11] can have account without subscription but it does not make sense that means you won't have the option to deploy the services that means deploy the resources in Azure if I don't have the subscription I won't be able to deploy [04:53:27] the resources so what is subscription again subscription is a logical container for management and billing so Azure will charge you by looking at your subscription by looking at your usage so if I want to deploy resources I need to [04:53:43] a subscription I need to get a subscription from somewhere all Right. So subscription is a billing boundary. It's your isolation with other customers. So whatever resources you're deploying will be build or charged to [04:53:57] your subscription. All right. Again this is this is a level at hierarchy. So you can manage your resources and your access control at this level as well at subscription level as well. So if you if we go back to the hierarchy here [04:54:11] subscription is at the third level. First you have tenant root group then management groups and then you'll be having subscription. So most list will be sitting at the third level. So this at this level as well you can manage the [04:54:25] access control or the policies that you want to implement. In simple subscription is a billing boundary. If I want to deploy resources there's no subscription I won't be able to deploy resources. All right. [04:54:46] So I think we created one user right last time. User 01. So let me just go to the user section. I I'm just demonstrating you uh what what I explained just now that subscription is a billing boundary. So if you see [04:55:00] is a billing boundary. So if you see this user user 02 okay user 02. Let's login with that user. So I'll just copy the username and hopefully I remember the password. I'll open the in private window. I go to [04:55:14] portal.azio.com and login with this user. [04:55:43] This user doesn't have the LFA. Yeah, [04:56:27] 02. What do you see at the at the homepage? So this is the homepage. Can I deploy resource from using user 02. So I'm logged in using the user account user 02. And if I search for virtual machine here we at the homepage we have [04:56:42] the virtual machine. If I click on that virtual machine, you see where I'm landed, it's it's complaining that I might not have access or I I might not have the subscription. Okay, if you see the first page, it says welcome to [04:56:56] What is it? What it is complaining? Don't have subscription. That means this user doesn't have access to any subscription or doesn't have uh any subscription within its with within its account. Okay. So you see none of the [04:57:12] entries matched that means there's no subscription no access to the subscriptions for user 02. So in order to deploy resource I need to have subscription. Now if I do with another user so if you see this is another user [04:57:24] simply learn something something right simply learn at the rate domain name. So this user if I search for virtual machine see where I'm landed on which page I'm landed at least I can see the virtual machine here. I have the create [04:57:39] option that means I have some access to the subscription obviously a right access with this user account so that this user simply learn at the rate whatever it is can create the virtual machines apart from virtual machines can [04:57:52] create other resources as well. So in order to deploy resources you need to have subscription Azure will bill you according to your usage whatever whatever you have deployed within your subscription. All right. Once again, if [04:58:05] I go to the in private window where I have logged in with user 02, just focus on the screen user 02. And you see when I search for virtual machine, I'm landed to this page where I cannot see any virtual machine and I I'm getting this [04:58:20] screen which says welcome to Azure. Why this screen I'm seeing? Because I don't have access to the subscription. So next topic that we have is policy. Now we have done the hierarchy and uh while explaining the hierarchy sorry [04:58:45] we have seen the hierarchy and while explaining the hierarchy u I have been and all now we are coming to that policies and arbback okay so what is a policies and arbback okay so what is a policy policy in Azure is a way to [04:58:59] enforce enforce something. Enforce as in to mandate something, to do something mandatory. For example, um there is a user like for example, I'll take you guys okay, you're now learning [04:59:15] a 305 and you might have done a 104 as well. Some of you might have done a 104, some of you are directly here for a 305. So, doesn't matter which certificate you're doing, you're learning Azure. when you're learning Azure you are [04:59:29] getting uh introduced to lot of services which you can use for your own use for your own uh own work okay not for company work let's say for your own work so you're learning Azure now you have learned how to deploy virtual machine [04:59:44] let's say or how to deploy certain resources so when you have learned that you have you're a working professional let's say and you have access to your company's [04:59:57] and you have access to your company's Azure subscription. access to your company's Azure subscription. So in order to just to understand Azure what you will be doing, you have the access to your company's [05:00:13] deploy resources, right? What you'll be doing let's say just for just for understanding or just for learning. you deploy a virtual machine which is having 64 GB of RAM [snorts] [05:00:27] which is having 64 GB of RAM [snorts] uh eight virtual CPUs and so and so storage. So you deployed this virtual machine. Now tell me this virtual machine the configuration is hefty or not? Is it a [05:00:39] minimal configuration or it's a hefty configuration? 64GB of RAM. [05:00:51] configuration. So I'm learning Azure. I have access to this virtual machine. Who's going to bear the cost? Is it me as a individual user? Is it my company since I'm using my company subscription? So obviously [05:01:06] the cost will be for my company uh my company will have to bear the cost since company will have to bear the cost since I'm using their subscription. Right? So as a company or as an Azure administrator [05:01:21] I know while I'm I'm coming up with governance I know that I will never require 64 GB of virtual machine for my projects or for my products I I never require that since I don't deal in that those kind of project so I never need [05:01:35] the hefty machines. So if I simply ask my user my employees that please do not deploy this kind of heavy virtual machines I'll have to pay for that. Now tell me just telling them just asking them not to do uh is it 100% sure [05:01:52] asking them not to do uh is it 100% sure that they are not going to do it. or as a as your architect that please do not deploy hefty virtual machines. [05:02:05] Are they going to uh I mean are they going to listen and and they I'm I'm I'll I'll be 100% sure that they are not going to do this going to do this just asking them [05:02:18] obviously some of them will agree some of them will not touch some of them just for sake of of deploying and and learning things they'll go ahead and deploy and deploying is not not a problem the problem is they deploy and [05:02:32] then let's say they forget to delete it. So they deploy this and they forget to delete it. I'll still have to I I mean as a company I'll have to pay that as a company I'll have to pay that charge. So how to restrict our employees [05:02:45] charge. So how to restrict our employees from doing such things. So what Azure or Microsoft uh did they came up with Azure policies. So what Azure policy does they policies. So what Azure policy does they enforces certain things. Okay. what they [05:02:59] what you can do with Azure policy one one example I have given you like this one example I have given you like this you can restrict deployment of certain uh sizes of virtual machines like mentioned here so I can limit to certain [05:03:12] SKS I can restrict users from deploying this kind of heavy hefty virtual because I don't need it if I need it obviously I'll make amendments to the policies but if I don't need it I can limit that kind of uh things using [05:03:27] policies Okay. Now we just understood the tag. So we can enforce that as well. By default it's not mandatory to have tag to each on each and every resource. But with policies you can enforce that. You can [05:03:41] ask user to uh when they are deploying the resources. You can ask them using policies to to provide the tag. Without tag they won't be able to deploy the You can also restrict deployment in certain locations like uh Azure has its [05:03:58] presence all over the world. Okay, we have presence in India, Australia, US, UK. Uh but let's say for my organization, for my product, we are not dealing in US. So we can restrict deployment of certain resources in [05:04:13] certain locations. So that is also possible. Okay. You can enable auditing. possible. Okay. You can enable auditing. You can using policy you can uh deploy the the AAS antimmalware on on all of your virtual machines. Windows virtual [05:04:28] machines you can deploy. There's a lot of thing that you can do with policies. So policy is a way to enforce uh certain standards that you want to achieve. All right. Now where you can apply the policy at any level in the hierarchy. At [05:04:43] any level in the hierarchy you can apply the policies. Now where which policy should be applied? Let's say the 64GB one that I that I told that I that I mentioned is a policy that can go at the root group level. Tenant root group [05:04:57] level. Why? Because I want it to be applied for each and every subscription. So I can keep that policy at the tenant root group level. Certain policies like do not deploy in a certain location. I can keep the keep [05:05:10] them at the management group level. MG01 or MG02. Now let's say MG01 deals with every project that we have in India. So I'll keep the location deployment uh [05:05:22] policy at MG01 so that it won't impact other resource uh other management groups. Right? Enforce tag again I can keep it at the tenant root group level since I want tags to be enforced at each [05:05:36] and every level each and every resource. All right. So policies is that that a policy is something that you can uh use to enforce whatever standards you want to want to have. All right. Now when you work with policy [05:05:54] I'll show you two demonstration in in this hands-on this hands-on is uh applying tags and and policy. So is uh applying tags and and policy. So what I'll do I'll first go and create a [05:06:07] resource group. Okay. So you see in order to create a resource group you should you can search for resource group over here and you can see a resource group right. So in order to create a resource group I click on resource [05:06:19] groups here and then I click on create. Okay, when I click on create, I have Okay, when I click on create, I have like two things that I need to provide. Subscriptions doesn't matter whether you're creating a resource group, um a [05:06:32] virtual machine, a disk, whatever. A re subscription should all always be provided. So, you have to provide the subscription and the resource group name. Okay. So, what would be the resource group name for this? So, I'll [05:06:44] resource group name for this? So, I'll go for a 305 RG02. All right. And then the region. So what is a region? Region is the physical location where your resource will be deployed. So if you see the drop-down, [05:06:57] Azure has its presence uh in all of these uh uh regions like uh in all of these uh uh regions like South Africa, Australia, India, uh East Asia, Indonesia, Japan, East, West, [05:07:12] Korea, Malaysia. So we have all these location all these Azure has its location all these Azure has its presence in all of these uh regions the physical location the physical data center is present in all of these [05:07:25] locations. So you can select whatever you want okay unless you have a policy which is restricting you to deploy resources from so and so location. Now I select central India over here. Mostly I'll be using central India to [05:07:38] deploy uh resources. Okay. So I select central India over here. Now what we subscription, we have provided resource group, we have provided region. Remember the region is central India. Okay. Then the next tab that you see is tags. So [05:07:55] here you can provide the tags. So what is tag? Tag is just an extra metadata. Okay. You can provide anything like Okay. You can provide anything like uh environment [05:08:11] broad. Okay. owner whoever is deploying Imran right so you can provide whatever you want it it's totally up to you one resource can have like uh 50 tags so this one resource can [05:08:26] have like 50 tags so you can provide around 50 tags to one resource okay but for now let's not provide the tag so even if I don't provide the tag I can click on review create and I can click on create remember I created resource [05:08:40] on create remember I created resource group with the name AZ305 RG01. So you should see the resource group in some time here. [05:08:53] without tag. Remember we created it in central India. All right. Now let's create a policy. Let's create a policy. Right? Now there's no policy. So let's create a policy. This policy will restrict [05:09:06] deploying resource group in central India. So if now people try to deploy resource in central India, the policy should in central India, the policy should restrict it and this policy will uh will [05:09:20] be applied at at at subscription level. Okay. So let's see how we can use policy. Now I I just demonstrated that I was able to create the resource group and that resource group was created in central India. Okay. Now using policy [05:09:35] will restrict that. So let's quickly do that. So in order to work with policy I can search for policy and I can go and select policy here. [05:09:47] Okay. Now if I have any policy or if I don't have any policy I can see over here. If you see on left hand side you have all the required options. All right. So you see here under assignments you can see all the policy which are [05:10:01] you can see all the policy which are currently assigned to your uh to at any any at any scope if you have any policy which is assigned. So right now it's zero that means no policy is assigned. Okay. Now in order to assign you can [05:10:13] click on assign policy. So if you see here you have two different options assign policy and assign initiative. So what is the difference between policy and initiative? Quite important from uh interview point of view. policy is like [05:10:27] a single policy. Okay. If I want to create a group of policy and assign those policy at once, then I have to click on assign then I have to click on assign initiative. I can create like multiple [05:10:41] initiative. I can create like multiple policies as a group at once and uh at one polic as one policy and I can assign that as an initiative. So if I click on initiatives. If I go back over here and if I go to [05:10:55] the definitions uh and if I click on uh if you see here these are all the policies that we have available as of now. Okay, these are all the inbuilt policy that that Microsoft has created and kept that. But if you see here the [05:11:09] and kept that. But if you see here the type the type mentioned here definition type if you see the type which is mentioned here will will will uh confirm whether it's a single policy or whether it's an initiative right now whatever [05:11:25] you see is a single policy but if you scroll down you see there are uh multiple pages that you can go and if if we go to the last page if you go through we go to the last page if you go through each page one of one of the type should [05:11:39] initiative as well. Okay, there are a lot of lot of pages. These are all the inbuilt policy or initiative that Microsoft has already created for you. You can come up with your own policy as well. Sometimes it happens that even [05:11:52] though we have so many policies inbuilt policy that Microsoft has created, we do not find a specific policy for our use case. So what you can do, you can come up with your own policy. You can create your own policy. All right? So in order [05:12:07] to create your own policy uh somewhere you should have policy definition create a policy you click on policy definition. If you want to create an definition. Initiative is like multiple policies at once. Okay. In order to [05:12:22] assign policy you need to go to assignments. In order to define policy or create policy you need to go into the definitions. Now in order to create policies obviously you need to be well versed [05:12:35] with JSON and you need to understand the different uh services that Azure has to provide Azure provides right for example this is the virtual machine related thing. So this policy can audit all the virtual machines which does not have the [05:12:49] disaster recovery configured. So you can use that policy and you can see how this policy is defined. So this policy is defined like this as I mentioned that in order to work with policy or anything in cloud specifically any cloud you need to [05:13:03] be well versed with JSON. Okay. So whatever Azure or any any other cloud provider will be mentioning is mentioning is will be mentioned as a JSON format. Okay. So what we are going to do let's go back [05:13:17] So what we are going to do let's go back to our topic where we have to deploy a policy which will restrict the deployment is of resource group in deployment is of resource group in central India that means uh nobody will [05:13:30] should be able to deploy a resource or a resource group in central India. Okay. So let's go to the assignment. Let's click on assign policy. And here the first thing that you need to define is scope. The scope is the [05:13:45] to define is scope. The scope is the hierarchy that we we discussed. So any scope at any scope you can apply the policy provided you have the access. Okay. So if you see here at the scope on this three dots if I click on this three [05:13:58] dots I can select the subscription I can select the resource group. Now you might ask the question why I can't see the management group here. So remember I have logged in as simply user. It's possible that this simply learn user [05:14:12] doesn't have access to the management group. So I don't see the management group here. You can assign policy at the management group. If you have access to the management group. Okay. So if I switch the browser and go to the user [05:14:26] which has access to management group uh like my personal user Iran Ketani. So if I search for policies here, if I click on assign assignments and if [05:14:40] I click on assign policy just to see the scope, if I click on scope here, you see I can see the management group. So if you have access, group. If you do not have access, you won't be seeing it. All right. [05:14:57] Now how to assign the access and how to see this is something we will discuss in in the next topic which is arbback. So right now we are on on policy. So let's complete the policy first. Now I'm switching back to the browser where I [05:15:11] have logged in with simply learn user who does not have access to uh management group. Okay. So here we'll keep the scope as subscription and I'm not selecting any resource group. I'm just selecting subscription that's all. [05:15:26] All right. And I click on select. So whatever now we are going to define whatever now we are going to define within this policy will be uh will be impacting this subscription only and within this subscription [05:15:41] creating whatever resources you'll be deploying only those uh resource or resource group will be impacted. So let me just explain this again. So if [05:15:53] you see this hierarchy this is let's consider this is the subscription Azure training and we are applying policy at this level now okay so if you go ahead and create a resource group within this policy [05:16:09] then only the policy that within this subscription then only that policy which subscription then only that policy which you are applying will be evaluated. If you're creating resource group within another subscription then that policy [05:16:21] will have no impact. Okay, that's why understanding hierarchy is important in understanding hierarchy is important in Azure. Okay, let's go back to the browser. Uh within this subscription, if you want to [05:16:33] this subscription, if you want to exclude anything, you can exclude that. or more resource group which is for R&D purposes. So if I want to exclude, I can exclude. Okay, that option is given. Then here you can select the policy [05:16:48] definition. So I click on this three dots and there are a lot of policies. So if you see there are like thousands of policies that Microsoft has already created. You need to select your own your policies [05:17:03] according to your categories like I only want to work with virtual machine. So I select let's say compute. So I select compute and all the compute So I select compute and all the compute related policies will be filtered out. [05:17:16] So I'll see only the compute related policies. Okay. policies. Okay. You see the VM, VMs, all the VM related policies will be will be uh shown. Okay. Now what we are interested is [05:17:32] restriction of location. So I search I randomly search for location randomly search for location or maybe allowed location. Okay. [05:17:47] this term allowed location. So you see there are three policies with that name. The first policy is specific to Cosmos DB. So Cosmos DB is a resource in Azure or database in in in Azure. So if you want to impact or or restrict deployment [05:18:04] of Cosmos DB from certain location, you can select that. Okay. What we are interested here is in resource group. So before deploying the policy I deployed a resource group right in central India and that was allowed but right now let's [05:18:18] restrict that using uh using this policy. Okay allowed location or resource group. So I select that policy and after selecting that policy we need to go to the next uh tab which is parameter. So in parameters you have to [05:18:34] define which location you want to allow. Okay. So there are all the locations that is mentioned. What I don't want to allow is deployment in central India uh west India and south India. So I untick south India, west India and [05:18:50] central India from here. Apart from that every other location is allowed. So let's say that's my scenario that's my that's my uh requirement. So only central India, West India and South India is unticked. Apart from that all [05:19:06] other locations are allowed. Now next remediation is something which doesn't require we don't require for this policy but let let me explain what the remediation is. What is a remediation? Remediation is a way to uh [05:19:22] to make sure or to make that that resource compliant. Okay. For example, resource compliant. Okay. For example, your policy is evaluating um and evaluating whether the anti-malware [05:19:37] and evaluating whether the anti-malware is installed or not in Windows virtual machine. So you have let's say thousands of virtual machine and your VAP team of virtual machine and your VAP team vulnerability assessment team wants to [05:19:50] make sure that antimalware is installed on all of the Windows virtual machine. So what we can do we can use a policy. So that policy will evaluate whether the antimalware is present or not. If antimalware is not present, install it, [05:20:05] download it and install it. So that download and install it is nothing but remediation. Something is not present, you're asking Something is not present, you're asking policy to deploy it. So when your policy [05:20:17] is deploying, it process of deploying things is known as remediation. we are remediating which is which is not present there. All right. So obviously but there are some policies which might which might have this option of [05:20:32] which might have this option of remediation. So you can enable it. Okay. need now uh I have a question now uh I have a question what is the meaning of remediation? [05:20:47] The remediation is something which will make sure deploy if not exist. You see this word deploy if not exist. So if something is not deployed like for example antimmalware or any other software that you are evaluating if that [05:21:02] is not deployed deploy it. If it's not exist deploy it now tell me we are asking a policy to deploy things on a virtual machine. So this is a virtual machine Windows virtual machine and policy is going to [05:21:17] deploy that thing in the virt on the uh I mean within the virtual machine. So what process is required here? Uh is the virtual machine automatically will the virtual machine automatically will allow the policy to deploy the things? [05:21:35] machine will allow the policy to deploy the thing. Policy is a separate application. Virtual machine is a separate resource. Both of these are separate resource. Now policy is trying to make some [05:21:47] changes within the virtual machine install a software. Tell me is the virtual machine going to allow the policy to install the software or what as a engineer or administrator what we need to do? [05:22:06] the next step. What is manage identity? Policy is an application which trying to make some changes to the virtual machine. It's an application which is trying to make some changes to the application. [05:22:19] Think from the security point of view. Is the virtual machine going to allow the application as is without asking anything without doing anything? anything without doing anything? Is it going to allowed or not? [05:22:36] firewall not on then not deployed the VM. Firewall has has nothing to do with it. Okay. The app the request is not coming from outside your network. We are [05:22:48] within the same tenant. Okay. Policy that we are applying is in the same subscription whereas the virtual machine that will be evaluated will also be in the same subscription. So firewall u doesn't come in this [05:23:03] picture at least for this example. Okay. So Chaitan is saying we need to register the app. Hurry is saying the policy is and post. Yes. Okay. You you policy is and post. Yes. Okay. You you guys are forgetting one simple [05:23:18] uh mechanism you can say is authentication. mechanism you can say is authentication. I uh is this policy how the VM is going to authenticate this policy and how the VM is going to [05:23:31] policy and how the VM is going to authorize that policy. have to define the location where to download and install. [05:23:43] download and install. Uh that's secondary. Yes. Okay guys go back to IM go back to identity and access management. What is identity and access management? It allows you to [05:23:55] authenticate your user and authorize your user. It's not only for user, it's also for application. If you remember, we understood two different terms. Manage identity and service principle. Now tell me what is manage identity. [05:24:13] Suresh is saying user account should own admin right. Okay. U policy is deploying things on a virtual machine. User account where where is the user coming in here? Policy is kind of an application. [05:24:28] Virtual machine is kind of a resource. This application needs access to the resource to make some changes. User account is not required here. Consider it like this. You have an application which requires access to the database. [05:24:41] So here we we we do not include the user account when application is accessing the database. What what is manage identity? Come back. What what is manage identity? Come back. I'm I'm giving you the answer as well. [05:24:59] statement or words. What is manage identity? [05:25:18] you to please rewatch the AM section. All right. Now let's come back to the policy here. Now just answer yes or no. Is the basic step clear? In basic step, you're just defining your your scope where you want to apply the policy and [05:25:32] then you are selecting the policy definition which you want to apply allowed location for resource group. And selected which location to allow, which location not to allow. So we allowed [05:25:45] free location we allowed we we unticked few location where uh which will be denied. All right. Now for our policy we don't require remediation but I explain what remediation is now. Answer do you understand what remediation is? [05:26:05] Okay. So remediation is something where if uh if something is not present it will deploy. So in our policy it doesn't make sense to uh to enable remediation. using any policy where remediation is required. One policy that I provided is [05:26:21] uh example I provided is antimalware which is not installed in a policy will all the virtual machines. You have thousands of virtual machines. Okay. You [05:26:34] have thousands of virtual machines. policy will evaluate all the Windows virtual machine and see whether the anti-malware is installed or not. If it is not installed then using the remediation option we will install it. [05:26:47] user are not going to install it. That's why this policy is in place. Policy will automate things for you. Okay? So it will install on your behalf. So you will not ask me for the user account or or anything. So with remediation what I [05:27:04] can do? I can install this software. Antimalware is what? It's nothing but a software. Right? So I can install this software. I can ask my policy to install the software if it is not present. Right? Now policy is behaving as as a [05:27:19] authoritative application which will deploy something which will install a deploy something which will install a software inside a virtual machine. So in order to install that software virtual machine [05:27:32] should be authenticating the policy, right? It's possible that someone outside of my network triggered a script targeting this virtual machine triggered a script installing a a software. So this virtual [05:27:47] machine will allow that that person that script to to install the software. Obviously that virtual machine will have to authenticate this traffic where it is to authenticate this traffic where it is coming from. whether this traffic is [05:28:00] authenticate to install whether this traffic is authorized to install certain software or not. Obviously this virtual machine will authenticate and authorized right. So same goes for policy as well. [05:28:14] cloud, same account but virtual machine check whether this policy is authorized to deploy antimalware or not. Understood or not? So in order to [05:28:27] authorize what we are going to do in the next step is create a manage identity next step is create a manage identity for the policy. Clear or not? What I explained when we were discussing about manage identity? [05:28:42] Manage identity is an object ID is an identity for your application. When that create manage identity for that application. And then when that application requires access to the database or the storage the database or [05:28:56] storage will authenticate that application using that manage identity authorized yes allowed if it's not authenticated do not provide the access similarly for this policy the policy that requires the remediation you needs [05:29:12] to create the manage identity as well for our policy we don't need it for a certain policy where you need to remediate certain things in that case as well. All right, I hope what I was trying to [05:29:27] All right, I hope what I was trying to explain is clear. in basics tab you just selected the policy and the scope. So this is the [05:29:39] policy and the scope. So this is the scope I selected u my subscription and then the policy definition that I selected allowed location for resource group that's all in parameters tab we selected what [05:29:51] location should be allowed which location should not be allowed in remediation for our policy doesn't require but for certain policy if required you can enable this okay when you are working with remediation you can [05:30:05] create manage identity as well without manage identity ity remediation will not work. Okay, your remediation will fail. So once the manage identity is created, So once the manage identity is created, you can also provide the uh def uh sorry [05:30:19] permissions to the policy as well. All right. And then next non-compliance right. And then next non-compliance message. So in our policy uh we need to add a non-compliance message like please deploy in any other region [05:30:36] [snorts] apart from India. So what this non-compliance message will do it will help user whenever user is trying to deploy the resource group and if that resource group is failing it will help [05:30:49] user to understand why the deployment is failing. All right, please deploy in any other region apart from India. And then that's all. Once that is done, you can click on review create and then you can click on create. So now your policy is [05:31:03] in place. Now remember before applying the policy, I deployed the resource group in India. Remember right now let's try again. Now before trying obviously it's better to sign out and sign in again to take the token or the the new [05:31:19] token or the new policy. By default, it's uh it should be uh in in effect as soon as you apply, but sometimes it doesn't work. So, it's better to relog in. Okay. So, I logged out and then log in [05:31:35] Okay. So, I logged out and then log in again. resource group in central India. So, I search for resource group. I click on [05:31:48] create. I give it a name a 305 RG03 and then central India is by default selected but if you see there is the non-compliance message that you added in the policy is is popped up please deploy [05:32:04] in any other region apart from India so this is affected by the policy policy will not allow the deployment of this resource group in central India but if you select any other region apart from central India like Canada east or [05:32:19] something it should allow the pop-up is gone. Okay. So now uh it's confirmed that using policy we can enforce certain requirement that that is required uh by our company. So we can implement or enforce those kind of requirement. [05:32:35] Next topic that we have is arbback. Now this is important topic to understand. Okay. So far we were discussing about the hierarchy and I mentioned that we have different scopes in the hierarchy. uh within that scope you can apply the [05:32:50] access control or you can apply the policies policy we have already seen how policies policy we have already seen how to apply and we selected subscription as one of the scope similarly arbback is something which will allow your user to [05:33:03] something which will allow your user to give them certain rights rights like reader right so they can read something uh contributor right so they can contribute something to your subscription or uh owner rights owner is [05:33:17] subscription or uh owner rights owner is like a full right okay u then you have uh there are different roles available built-in roles available in Azure that you can use to provide certain access in simple terms arbback stands for role [05:33:32] simple terms arbback stands for role based access control so based access control so as from the ZTM you need to make sure that least privilege access should be should [05:33:44] be assigned to whoever wants the access. All right. So for that you need to understand arbback. Arbback is role based access control. Okay. I see Ram is asking for break. Break will take in half an hour. Okay. 9 at exactly at 9. [05:34:00] Okay. We'll go for half an hour of break that We'll go for half an hour of break that time. All right. Or you guys tell me do you do you all do you all agree for break right now or [05:34:13] break right now or later? So, ARBback ARBback stands for role based access control. So far what we [05:34:27] have what we have seen we have seen the hierarchy here also it's mentioned right you have management group subscription resource group resource. So this is the resource group resource. So this is the hierarchy. Now who can do what? You will [05:34:39] be having thousands of users. You'll be having u uh thousands of applications. what that application could can do. How how as an administrator I assign them the access. So in order to assign them the access [05:34:52] you need to assign them the arbback role. Arbback stands for role based roles different different roles depending on what they want to do. Assignments assignments can be at any scope. So you need to assign those roles [05:35:06] at any scope whatever scope is preferred for you. Okay. You want some some control at subscription level, some companies like to manage at the companies like to manage at the management group level. If you want low [05:35:19] management overhead, you go with management group. If you want more management overhead, that means uh every time there's a new subscription, you assign the same role to same set of groups and and and things, then you go [05:35:31] at the subscription level. Okay. So different scopes at different scopes you'll be assigning different roles and you can come up similar to policies you can come up with different custom roles as well. There are lot of built-in roles [05:35:46] by Microsoft Azio they have already created lot of built-in roles but at certain point in time you feel that built-in roles are not enough. So you can create your own custom roles as well. In easy 104 we have one practical [05:35:59] as well where we where we show how to create a custom role. Okay. So what is ARBback? Arbback stands for rolebased access control. So in order to see arbback, you can go to any scope, [05:36:13] management group, uh subscription, resource group. So I I'll show you that at the resource group level. So I'm at the resource group level. If you see uh any point in time if you want to see at at which level I am. So you can see that [05:36:27] at which level I am. So you can see that here. Okay, it says resource group. here. Okay, it says resource group. If I go to the subscription, [05:36:40] subscription, you can see at what level you are. So you are at subscription you are. So you are at subscription level. So at any level arbback can be assigned that's why we have the hierarchy. Okay. So in order to see [05:36:53] where I can assign the arbback or who is currently having what role you see this blade access control I am this blade is present at almost all resources all resource groups all subscriptions all [05:37:09] management group. So whichever resource management group you you are at you can see this blade access control IM from here you can manage the access control. All right. Now, if I go back to any resource group as well, you should see [05:37:24] the same access control ion. If you go to management group, you will you will see the same. So, doesn't matter uh from where you want to control. I would prefer for my company, we prefer management group. Why? Because we have [05:37:39] lot of subscription. We don't want to keep doing the same thing over and over again. Assign once at management group level and you're free. Okay? then doesn't matter how many subscription you add there all subscription will inherit [05:37:52] those particular role so best way and the best practice that Microsoft also recommends is to manage the access control at the management group level okay that would be easiest but doesn't matter at what level you are you should [05:38:06] see this account uh sorry access control and there you should see all the access now let's come back to access control IM and here you can see the role assignments so this role assignment tab apps provides you the current [05:38:21] apps provides you the current uh access that users are having uh access that users are having right all the users who has access to what access what level at this particular uh resource group level so if [05:38:33] particular uh resource group level so if you see I'm at role assignment here you see I'm at role assignment here my hotmail account is having the owner my hotmail account is having the owner role and if you see the scope here [05:38:45] role and if you see the scope here sorry if you see the scope subscription inherited. What does it mean? What is the meaning [05:38:57] of inherited? What level I am? At what level I am? explain the role. Please hold on. I'm what I'm trying to explain. Plus see [05:39:11] that. Okay. I'll explain the role as well. Don't worry. Resource group level. What level I am at? I am at resource group level. I AM access control blade. And here if you see this is one of the user account, [05:39:25] Hotmail account. This user account is having this particular role owner. Scope is what? What is the meaning of inherited? [snorts] Arback assigned at subscription level. [05:39:39] Right? This is not directly assigned at the resource group level. It is being inherited from subscription. That means Hotmail account has got this role at the subscription level. That's why it's inherited. [05:39:55] level. We haven't I mean administrator haven't gone directly at the resource group level and assigned the role. It was inherited from the subscription. So that's why it's important to define the scope first where you want to [05:40:10] at the resource group level go uh assign role at that particular level okay clear uh punkage is asking me to explain all the role obviously it's not possible to [05:40:25] are the important role I'll be explaining that okay now on the right hand side the next tab is the ro roles so here you see all the role now tell me is it possible to explain all the roles you see the number of roles you [05:40:41] you see the number of roles you and you have like 890 roles total. Okay. So it's not possible for me to explain all the role but I'll be explaining the important roles that you now what what what all these roles are. If you know we [05:40:55] have storage account in Azure in future topic we will be explaining storage So if you just search for that particular uh service like storage. So some roles are storage related roles. Some roles are we have seen keyword [05:41:11] right? Some roles are key volt related roles. So if I just type keywalt and search for it I should see the keyword related roles somewhere. So similarly for database you'll be having certain roles. For virtual machines you'll be [05:41:25] having different different roles depending on that particular service. Now which roles are important for you to understand from the exam point of view and from the interview point of view are these roles [05:41:39] interview point of view are these roles owner reader and there's one more role with the name user administrator or user [05:41:52] access administrator. Okay. So, let me just search for that. [05:42:09] just explain these roles and then we can go on break. I'll take 5 minutes to explain these roles. Quite simple. Owner as the name specifies you can do whatever you want. So if someone is having owner role that means he can do [05:42:22] he or she can do whatever uh he or she want to do with that particular subscription or that particular management group. So understand if I give someone the manage owner role at the management group level he can do [05:42:35] whatever he wants at all the subscription within that management group. So if you have thousands of subscriptions within this particular management group and you give someone owner role, he gets the owner role of on [05:42:48] all that thousand subscription at the end on all the resource group at the end on all the resources. So owner is like administrator in Windows. So he or she can do whatever they want. Okay. If any point in time [05:43:02] particular role is doing, you can read the description here. So what this description says grants full access to manage all resources. So he or she can do whatever they want. Right? Next contributor. So what is [05:43:18] contributor? It is also similar to owner. If you see grants full access to manage all resources but does not allow you to assign roles in Azure Arbback. What does it mean? So let's take an example here. You have user 01. You have [05:43:34] example here. You have user 01. You have user 02. User 01 is owner user 02. User 01 is owner and user 02 is contributor. Okay. Now there is another user coming in joining in today. Now this user needs [05:43:47] an access to virtual machine or resource group whatever. So owner can assign group whatever. So owner can assign access to this user 03 to any resources he wants. Whereas contributor cannot do that. So [05:44:01] Whereas contributor cannot do that. So that's the only difference. Owner full access can can assign or invite any other user as well. Not invite but can assign access to other users as well to any of the resources. [05:44:15] Whereas contributor can do everything. Can delete resource, can manage Can delete resource, can manage resource, can create resource. The only uh only thing that contributor cannot do is assign access to other resource other [05:44:28] is assign access to other resource other users. That's the only difference. All right. Next reader. Quite simple as the name specifies. If user 03 is a reader, he can read everything but cannot modify, [05:44:42] can read everything but cannot modify, cannot delete, cannot do any anything else. Okay. The last role that I mentioned was user access administrator. [05:44:58] administrator he or she can assign access to any other user. So if I am UAA user access administrator I can assign any role to [05:45:11] third user any role whatever role they they need. So if tell me now if someone is having contributor and user access administrator both what is going to administrator both what is going to happen? [05:45:29] contributor he can do anything whatever he wants to do plus he's getting another role user access administrator that means user access administrator g uh gives the ability to this user to assign any role to any other user [05:45:44] okay so these are the four role that you should be aware of and quite important from the exam point of view from the interview point of view and any conf confusion on this roles you just need to remember four roles as of now. Owner, [05:45:59] contributor, reader, and user access administrator. Owner like administrator can do whatever he wants. Contributor like similar to [05:46:11] owner but doesn't have the ability to assign access to other users. Reader as the name specifies can read whatever he or she wants to read. User access administrator has the ability to assign access to other users. So if I am user [05:46:26] access administrator, I can assign any role to any other user whatever use whatever role he or she wants like he wants to manage virtual machine. So I can provide virtual machine administrator role to this user if I am [05:46:39] a user access administrator. All right. Clear? [05:46:52] user access administrator that's like equivalent to owner. Okay. All right. Now tell me I have a question. I get an owner role. [05:47:04] Can I create a new user in in Microsoft enter ID? I I I got an owner role. See if I go back to the role assignments here. My back to the role assignments here. My account [05:47:23] create a user account when I have the hotmail account? I mean if I have the account? People are saying yes. Okay. Now here it comes uh here you need to understand in [05:47:39] Microsoft Azure the there are two types of roles. Okay, arbback roles. So whatever we have discussed so far, owner, contributor, [05:47:52] user access administrator, reader, these are related to arbback. Okay, arbback is mostly for managing the resources. [05:48:04] So I can only manage the resource if I have the arbback role. I cannot manage the Microsoft entra ID. Remember these things. Okay. Microsoft Enra ID user [05:48:16] creation user deletion is part of which is is is part of governance or is it is is is part of governance or is it part of uh IM entra ID as part of enter ID. Okay. So there are two types of roles in Azure arbback role and the uh [05:48:31] Microsoft entra ID role. So in order to work with Microsoft entra ID I need to go to Microsoft enter ID. And here also if you see there are roles and administrators tab. If I want to work with Microsoft Enra [05:48:44] ID, there are separate roles. If I want to work with resources, there are separate roles. Okay. So, which role is important in Microsoft Enra ID? Similar to RBback role, there are lot of roles again available here. Okay. Uh [05:48:59] it's not possible to go through each and every role. But which roles are important for you to understand is global administrator. So global administrator is like full access at your m at your Microsoft enter [05:49:15] ID. So if you have global administrator role that means you can do whatever you role that means you can do whatever you want to do. Okay. If you have the global reader role you can read whatever you want but you cannot modify anything. [05:49:28] want but you cannot modify anything. So if you get global administrator plus owner then you have full access at the tenant tenant plus at the governance level okay at the [05:49:40] arbback level. So you can manage resources you can do whatever you want. Similarly if you're global administrator you can do whatever you want at the tenant level at the Microsoft enter ID level. Okay. [05:49:54] Apart from that there are few roles that you should know is password reset administrator. So if you see somewhere you have password administrator which gives you access to reset password. So if there is a helpex team [05:50:09] who just need to reset the password then you can provide this role to them. you can provide this role to them. Helpex team right. And then there are uh Helpex team right. And then there are uh there is user administrator role similar [05:50:22] to user access administrator. So if you want someone to manage the assignment of want someone to manage the assignment of uh user roles in Microsoft entry ID then this role is is something that you can assign. [05:50:35] Okay just remember there are two roles in Azure Arbback role and Microsoft entra ID roles. Four roles, four important role that you should know from arbback side. Owner, contributor, user access [05:50:51] administrator and reader. Main roles in in Microsoft entra ID is global administrator. It's like full role, full access at enter ID level, uh [05:51:03] global reader, full read reading capabilities, user user administrator similar to user access administrator but at the at the entra side level at the entra tenant level that means if I have user [05:51:18] administrator role I can assign whatever role I want at the tenant level. Okay, I administrator role, someone global administrator, someone whatever as per their requirement. Clear? The last topic that we have about [05:51:33] governance is landing zones. Now whatever we have discussed so far, management group, subscription, resource group, tagging, policy, arback. So out of this tagging, policy, arbback are the three important uh features that helps [05:51:47] you to achieve the governance. The rest is just the hierarchy. Okay. Rest like resource is nothing but the hierarchy. This actually won't help you to uh [05:51:59] implement the governance. To implement the governance you have tag, policy and arbback, right? So using policy we can restrict certain things and we can make sure that we are meeting our compliance requirement. Using tag we can organize [05:52:12] our cost or automation and using arbback we can organize or maintain our access control. So what is this this last topic this landing zone is a is a is a concept [05:52:25] this landing zone is a is a is a concept where you can create your Azure platform you can uh maintain or configure your Azure platform before landing your workload that's the only meaning of landing zone okay like for example I [05:52:39] landing zone okay like for example I want to uh land a want to uh land a airplane in my city so I need to build a air airport first that airport within that airport we have runway. So runway [05:52:51] is nothing but the landing zone for that airplane. Right? Similarly, if I want to let's say uh have a shop in my mall. So I need to first build entire mall and then within that mall we will have different uh area [05:53:08] squaret of of shops and according to the requirement of the c of the users or of requirement of the c of the users or of the uh uh the shop owner they will buy their own shop. So in order to make sure that shop uh is is available we need to [05:53:23] first build entire mall first. Similarly uh in the airplane in the airport terminology we need to make sure the runway is there so that my plane can land. Similarly in Azure we have landing zone concept where you can define all of [05:53:40] your policies, define all of your arbback rules, define your ARM template, define everything and then deploy your application, then bring your application. Okay, so landing zone is just a concept in Azure where you can [05:53:55] prepare Azure platform before landing your workload. So how to prepare? Obviously you need to define the policies that you want to come up with. You need to define who will have what rules. You need to [05:54:08] define if you want to use tags and all. Right? So in Azure a simple everything is blended into this and you can create your own landing zone. So in Azure we call this as blueprints. So if I go to blueprints and there you can see [05:54:24] >> um uh you can create a blueprint and there you can see all the landing zones. Okay. You can start scratch and you can define your own policies or Azure has given you some some uh samples like foundational [05:54:41] landing zone, migration landing zone. Okay, common policies that it's like a best practice policies that you should be using. If your company wants to be be using. If your company wants to be ISO 2000 27,01 compliance, then you can [05:54:55] use this landing zone. If your company wants to be have a shared services right if you want to create resource group with certain arbback so you can create this kind of landing zone. So if I select the foundation one I'm just [05:55:10] showing you uh this is nothing but the best practice landing zone that Azure has created. So you just have to give it a name like for example foundation a name like for example foundation landing zone. Okay. And then where you [05:55:23] want this uh location to be. So you can select management group or or subscription. So I'll select subscription here. Okay. I I don't see management group since this user simply learn user doesn't have access to that. [05:55:36] Next in the artifact tab you can define all of the policies. So within subscription if you expand you see this policies append cost center tag. So tag will be mandatory uh tag will be mandatory for [05:55:49] resource group. You will you are enabling monitoring. You will define allowed locations for your resources. You'll define allowed locations for resource group. So these are nothing but all the policies. So what landing zone [05:56:01] is come up with different come up with whatever policy you want. If you want to add any policy later, you can add that as well. Like click on add artifact, select artifact type policy, then select what policy you want to you want to add [05:56:15] whatever you want to do. Okay. So that policy is added. So what we are doing with lending zone we are making sure that we are compliant since we are asking people to add tag. So whenever people are creating [05:56:28] is assigned since this policy will make it mandatory. Then we are enabling monitoring for all of our resources. We are defining which location to deploy the resources in. So these are all the [05:56:41] policies. You can add as many policies as you want. Apart from that you're creating a resource group for shared services. So resource group will be created where key volt will be deployed, log analytics will be deployed, right? [05:56:56] where all of your virtual networks will be deployed. Another resource group where you will be having identity service. So if you have uh domain controller or any other identity service, you can deploy it there. And [05:57:09] then when you when everything is deployed there is an additional resource group where you'll be deploying your first application. All right. So landing zone is just a way or or or a way where you are you are [05:57:25] um blending or adding all of the stuff that we have learned today like we are creating resource groups. We are making making the tag mandatory. we are applying certain policies that require for our u [05:57:41] our compliance then we are providing the arbback rule. So landing zone is just a logical you can say a logical way of making sure that your infrastructure is ready your platform is ready before you start [05:57:57] adding the application. All right. If I want to provide any arbback role at at any point at let's say this resource group. So I can select the artifact type role assignment and I can provide owner role to any uh user or [05:58:14] or any group or I can add it later as well once the resource group is created. All right. So that's something that you can defide beforehand before bringing your application. Now initially when [05:58:27] people started using Azure this was this concept was not there but uh Microsoft concept was not there but uh Microsoft introduced is introduced it very um in in a year or so when Azure Azure was there. So initially people were people [05:58:43] were not aware of this landing zone thing. So they started deploying resources without considering the compliance and all. So blueprint is a way where you can define your landing zone first and once you have defined [05:58:56] your landing zone you can bring your application. Remember landing zone is to be done uh before bringing your workload. Once you have deployed your workload [05:59:11] after that if you are bringing the landing zone you can still bring it but working. All right landing zone should be created first. It's like just consider it's like your plane in order to land the the airplane you first need [05:59:25] to have runway. If you do not have runway you cannot land your plane right? So similarly landing zone is something that you should be uh creating first or deploying or making sure it's ready first before you bring your resources. [05:59:39] All right. So that's about a landing zone. Yeah, you can create custom landing zone whatever you want to whatever you want. So you just need to go to blueprint and there you need to click on create. Okay, [05:59:53] here you can define whatever you want. I selected the foundation one. It you have the option to start with the blank. Okay, just name it uh provide the uh location the definition location and start adding your artifacts. So I'll add [06:00:08] what I want. I want policy, I want role, I want ARM template or I want resource group whatever I want. So if I want policy, I select policy from here. Add then again add artifact policy. Then I add again another policy whatever I [06:00:23] add again another policy whatever I want. Okay. So you can select your own want. Okay. So you can select your own uh blueprint your own uh landing zone as uh blueprint your own uh landing zone as well. [06:00:35] Debbra is asking what is the use of landing zone in real scenario. Okay. is? Forget about what is the use as of now. landing zone is? All right. So what we are doing in landing zone? We are just [06:00:50] defining the policies. We are just defining the arbback. Have you understood what is the uh requirement or use case of policy arbback in in real world to meet compliance you need to meet [06:01:05] compliance what landing zone is giving landing zone what we are doing in landing zone we are just comprising or blending all this thing in into one thing instead of doing this separately every now and then what we are doing we [06:01:18] creating a landing zone and we are adding all this stuff at once so if you're adding all this stuff at once what when and after adding all this stuff and creating landing zone once you on once you're deploying your resources [06:01:32] you're deploying VM storage account or whatever now tell me these resources will be compliant to your requirement or no [06:01:45] this resource will be compliant to your requirement or no [snorts] they will be compliant right so what is the use of lending zone to make sure compliant. So next year when there is auditing uh audit auditor will will come [06:02:00] compliant to whatever certificate we want whatever compliance requirement we logical thing where you are just comprising all of your policies that you want into one landing zone. So at future point in time if you want to see all the [06:02:15] policy you can see all at in central place what is assigned what is not assigned. Okay. [06:02:27] landing zone is. So when I deploy any resource that resource will be compliant to whatever I'm defining over here. Now every company will have their own requirement. Every company will have their own compliance requirement. [06:02:39] requirement, you'll be adding policies over here. Whenever people are deploying resources, that resource should already be compliant. Why it's compliant? Because if that resource is not meeting certain policy, the landing zone will [06:02:54] not allow that user to deploy that particular resource without meeting the compliance whatever you have defined here. Okay. [snorts] [06:03:12] zone. Foundation landing zone is just just for you to understand what landing zone is. I'm not saying that you need to apply the foundation lending zone at your organization. Okay? You need to understand first what lending zone is. [06:03:25] Lending zone is a blueprint of your Azure platform of your cloud platform. Within that blueprint, you're defining what I should be deploying, what I should not be deploying. So if I go here, I can define the location. This is [06:03:38] my subscription where landing zone is being applied. I click on next artifact. And here I'm defining what policies I want to deploy. So I select all the policies. For example, I don't want to deploy high configuration virtual [06:03:55] machine. So I restrict that using a policy. I want to make sure that tagging is in place. So I select any policy related to tag. I select that and I add tag over there. So what I'm doing here? I'm preparing my platform. This is my [06:04:10] Azure platform. I'm adding certain restriction. So and so VM is not allowed. So and so location is not allowed. So and so uh skew is not allowed. Making sure monitoring is enabled. Making sure we [06:04:24] defined here as a landing zone. Landing zone is not a physical thing which I can touch and see. Okay. Now once I have defined all this thing then my team whoever is responsible for deploying [06:04:37] resources when they start deploying the resources that resource will be evaluated against all this policy and all this requirement which is defined over here. If it's meeting that policies and that requirement then only the [06:04:50] resource deployment will be allowed. If it's not meeting it will throw some error and ask the user to fix and then user will deploy. Okay. So why why we sure that whatever resources is being deployed is compliant [06:05:07] compliant to the requirement. Okay, that's what the the meaning of lending that's what the the meaning of lending zone. [06:05:21] a project. It's just an example how you can use landing zones in real world. All can use landing zones in real world. All right. [06:05:38] traffic enters. See traffic is is a network part right? Landing zone is just def definition of policies and all where you're defining everything. Now where traffic will enter that will define at your network level. These are not the [06:05:52] network related policy. These are the governance related policies. [snorts] Suresh is saying okay you means to say if I select 27,0001 the compliance will meet according to 27,0001 [06:06:06] or else it won't allow us to create as we like in 27,0001 what is defined what is required to meet that particular certificate that particular ISO certificate. So if I select that there will be certain policy which Microsoft [06:06:20] will be certain policy which Microsoft has already defined. Okay. So uh first I subscription and when I go to the artifacts [06:06:35] added certain policy which will make sure you're meeting ISO 27,01. So whatever is defined in that policy if you're when when you're deploying your resource if that meeting that criteria you're allowed to deploy. If it's not [06:06:48] allowed. So if the resource is not deployed obviously the auditing is is not in the question here. Okay. If resource is deployed and it's not meeting certain criteria then you're not compliant. Your your whatever you're [06:07:02] doing is non-compliant. And when ISO team comes to audit your organization or your platform they'll see that you're not compliant. So if you're using this will make sure that whatever resource you are using is compliant to this [06:07:16] particular policy. whatever is defined in that policy. in that policy. Okay, [06:07:28] subscription or the management group level. So it's it's nothing but policies arbback and everything. It's not something fancy or something new or you're deploying. It's not a physical resource a logical thing. Okay. So if [06:07:44] you see the definition location here, this is nothing but the scope. You can keep it at management group, at subscription, at resource group. Okay, management group and subscription, not at the resource group. Okay, [06:07:59] it's similar to what you do with policy. With policy, what you're doing where you can apply your policy at management group or at subscription? Same thing with the blueprint. Same thing with the landing zone. Okay, [06:08:13] thing with the landing zone. Okay, [snorts] rules or res uh predefined uh rules or conditions that this is [06:08:25] deploying your resources, those conditions will be evaluated. If your resources are meeting those conditions, resources will be allowed to deploy. If not, uh resources won't be deployed. there would be some error like [06:08:40] like I'm trying to deploy resource group right now and it's not allowing me right why it's not allowing me if I click on create resource group and I I put it in central India it's not allowing me to deploy why what is the reason why it's [06:08:54] to do is non-compliant to my organization what I'm trying to do I'm trying to deploy something at central India which that's why I'm not allowed to do similarly landing zone will do the same [06:09:07] thing it's not something you it's not something different okay it's just that you're blending your policies with your arbback with your arbback and uh with the if you want to deploy [06:09:21] anything in in in in uh freehand you can use ARM template and all to deploy blended together and it's called as landing zone that's all okay [snorts] clear. [06:09:41] the location. That's all. And now I'm compliant. [06:10:08] Okay. So case study is very simple for this. So if you can open this uh and go to governance. So here we have the case study. [06:10:41] uh I know this case study is asking you to design uh a governance solution for your company. So let's read through it. So, Tailwind Traders again this is the fictit fictitious company that we will [06:10:54] be using and Microsoft uses this name for defining anything right. So, some significant changes to their governance solution. They have asked for your assistance with recommendations and questions. Here are the specific [06:11:09] requirement. Cost and accounting. Telvin traders has two main business units that handles apparel and sporting goods. Each of the business unit consists of three departments product development, [06:11:22] marketing and sales. Each business unit and subunit will be responsible for tracking their Azure spend. At the same time, the enterprise IT team will be responsible for providing companywide Azure cost reporting. [06:11:37] project. The company has a new development project for customer development project for customer feedback. The CFO wants to ensure all cost associated with the project are captured. For the testing phase, [06:11:49] workload should be hosted on lowerc cost virtual machine. The virtual machine should be named to indicate they are part of the project. Any instance of the consistency rules should be automatically identified. [06:12:05] So these are the task. So for cost and accounting what are the different ways Telvin traders could organize their subscription and management group which requirement design two alternative hierarchy and explain your decision make [06:12:20] decision-m process. So what you need to do here is [snorts] you just need to come up with the management group hierarchy for cost and accounting for this Telvin traders. Okay. So what they have mentioned is you need to come up [06:12:35] with two alternative hierarchy and explain your decision-m process. Then for the new development project what are the different ways Telvin traders could track cost for the new development project. How are you ensuring compliance [06:12:47] with requirements of virtual machine sizing? Uh propose at least two ways of meeting the requirements. Explain the explain your final decision. So in simple you just need to come up with with a management group strategy. Okay. [06:13:03] How you'll be defining the management group. So what I'll be doing is the main tenant root group. Obviously you'll be having it behind within that tenant root group. I'll be creating a management group with Telvin traders. Then it's [06:13:20] totally up to you. You can divide it as per the the uh unit business unit apparel and sporting goods or you can keep everything in same business unit and divide it on on the uh subscription [06:13:34] level. Okay. So what I'll be doing here apparel this is one management group and then sporting unit this is another management group. Then within this business unit you have three department product development, marketing and [06:13:50] product development, marketing and sales. Each business unit has this uh this department. Okay. So what you can do you can again create three management do you can again create three management group if you want [06:14:04] having uh product development. Here you'll be having marketing. Here you you'll be having sales. Sim similar here product development, marketing and sales. And then you'll be having each sub each subscription depending on what [06:14:17] subscription is not mentioned over here. Okay, since they are saying that each responsible for tracking the Azure spend. So it's better to have a separate subscription for each or else you can have a single subscription [06:14:32] subscription you don't need to have three different management groups over here. So another strategy could be like this tenant root group Delvin traders and then two business unit apparel and uh sporting apparel and sporting and [06:14:48] then you can have one subscription each okay within each subscription in order okay within each subscription in order to track the cost. You can use tags and all okay in order to separate the talk if you're going with single [06:15:00] subscription. But here they they mention that uh each subunit will be responsible for tracking their Azure spend. So it's better to divide them into three different subscription which will be easier for you. Why it will be easier? [06:15:15] and you can simply put that in their cost center. Right? So I can have three subscription like this is for product development, this is for marketing, this development, this is for marketing, this is for uh for sales. Similarly in uh [06:15:29] sporting unit I'll have three different subscriptions. So either you can divide then I have one each one subscription each or you can simply put subscription within the main management group. All right. So these are the two different uh [06:15:44] hierarchy you can come up with. That's totally up to you which you want to go. Okay. Now in new development project, what are track the cost? So again, you can have a new management group here for uh new [06:16:01] development project. I I'll mention that as NDP. Okay. How are we going to ensure the compliance? Obviously, we need to use policy. So you can just mention here as your policy. Okay. And if you have any other way, you can come up with that [06:16:15] way as well. like you can put management group and then subscription or directly subscription totally up to you. All right, just go through this uh subscript uh case study and come up with a solution and uh I I did not get any [06:16:32] solution from you guys for the last case study. So you need to go to draw io and come up with a solution and send me that solution over the email over my personal email. All right. Like this. So you did not came up with [06:16:47] Like this. So you did not came up with any solution. management group. Same thing what what what I explained. [06:17:00] Same thing what what what I explained. Okay. [06:17:15] Somewhere you should have management groups. [06:17:42] be main management group. You can add a tagging or something. So you can add a text over here. So this is let's say my tenant root So this is let's say my tenant root group. [06:17:58] all that I leave to you. Okay. This is my tenant root group. Then I can copy We have the same thing here. This is my Telvin traders. Just rename. Then I can have additional management group. So just similar to what what you're seeing [06:18:13] over here. What what I what we discussed right now. You need to come up with that solution. Okay. Mustak is asking how to get Azure icon. So in order to get Azure icon you first go to draw ioappd diagrams.net net and [06:18:29] then from there you can simply click on more shapes here and here once you click on more shapes you should get Azure just stick check this box Azure and click on apply so you should get the Azure icon okay [06:18:45] all right any questions on case study or whatever we have covered so far if no questions we can move on to the next topic so next topic that we have is topic so next topic that we have is design compute service okay so if you go [06:18:57] design compute service okay so if you go to a305 5 study guide or a 305 to a305 5 study guide or a 305 uh learn path. This is this is the topic that we are covering right now. [06:19:09] So we have completed this except monitoring. So monitoring we'll be doing later uh once we have covered everything. So we have covered authentication and authorization. Monitoring is pending which we will [06:19:21] cover at the end once we have done with all the solutions. Now we are moving on all the solutions. Now we are moving on to the infrastructure solution. Design design infrastructure solution we are [06:19:34] and Azure compute solution. This is the this is the chapter topic which uh topic we we are covering right now. Okay. All right. So before we start I just need an answer from you what is a [06:19:49] compute service? Now we have seen uh in basics of cloud computing that cloud computing is nothing but the delivery of compute services over the internet. So what that compute service mean? What is compute service? [06:20:16] what only VM is compute service. What what is that compute service? what is that compute service? >> [snorts] someone says compute, compute is nothing but the computation [06:20:29] but the computation uh services like like memory which is uh services like like memory which is nothing but RAM. Okay. Uh CPU nothing but RAM. Okay. Uh CPU right and then u storage. So these are [06:20:41] the three thing which comprises of compute service. In simple if someone ask you what compute service is. So compute is just the home to your application. Okay. Compute service is nothing but [06:20:57] home to your application. Compute is actually where application lives. What is application? We have discussed is quite simple. Application is nothing but list of files. So when developer codes they codes in a file. So you'll be [06:21:09] having file like if developer is writing in Python they'll be having certain py. If they're writing in net, they'll be having some C related files, right? So application and in order to make sure your application run using a runtime, [06:21:25] you need a home for that. So that home is nothing but the compute. Now that can be anything that can be a virtual machine, can be a physical machine, can be app service, can be a container. So there are different different compute [06:21:39] services available in Azure. That's what we are going to see uh in this topic in this chapter. All right. So in simple compute is home to your application. Now remember one thing whatever we will be learning and for whatever reason the [06:21:55] whatever reason the infrastructure background is out there is because of applications in the world if there are no web app there are no desktop app then [06:22:07] it is not required. Okay. Business can can happen physically by by making a physical uh building a physical shop and asking customer to come physically there. Right? If there's no app, we are not required. Cloud is not required. [06:22:23] whatever we are doing is for the app. All right? So application can leave you need to have a compute service in place. And in Azure what [06:22:35] compute services we have that's what this topic is about. We have a lot of this topic is about. We have a lot of compute services. So just to describe or compute services. So just to describe or or make you uh [06:22:47] services. These are all the compute services we have in Azure. Virtual machine app service Kubernetes service Azure function Azure batch logic [06:22:59] app. One is missing which is Azure container instance right ACI. So if you see every compute has its own dedicated section. So I'm not explaining each and every service here. I'll keep it to it own uh dedicated slide. All right. for [06:23:18] this slide. Is it clear what compute service is? For me to keep an application, for me to make sure that my application uh can be accessed by the people or my application actually can run, I need to [06:23:33] have compute service in place. All right. So in that compute service which is nothing but home to my application, I'll keep my application and application nothing but files. Is that clear guys? What compute is [06:23:52] comput service, not all comput service are meant to keep the application. Okay. Uh not all comput service are meant to host the application. Like out of this [06:24:05] six services, the first three services Azure virtual machine, Azure app service and Kubernetes service are the services where you you'll actually deploy your application. Okay. rest are are different. They're not they're not mean [06:24:19] different. They're not they're not mean to host the application. Okay. So, we'll see what is the difference and what what each compute service is used for. So, which compute service to choose from? There's a there's a long or or a [06:24:33] big uh you can see a flowchart that Azure has created. Now, which one to Azure has created. Now, which one to choose at at what point in time? Uh this flowchart will help you to decide. But apart from that if you sit until the end [06:24:47] of this comput obviously today uh I don't think so we'll be able to complete or or cover all the services but tomorrow we we will be done with this compute section. So tomorrow once once we are done with the compute section [06:25:01] we are done with the compute section you'll be able to identify or define or uh take a decision on which compute service to use for your for your work or for your use case. All right, but let's go through this flowchart and see which [06:25:15] compute service to choose at what point in time. So from here you are starting. All right, the first question is are you migrating from on-prem or I mean from anywhere not only onrem or you are [06:25:27] building new. Okay, so if you are migrating go this way if you're building new go this way. All right. So let's say we are migrating since when I started my Azure career most of the customers were migrating and [06:25:43] I helped my second or third company to migrate. We had the uh everything in in data center in Australia. So we migrated it to Azure since we were going global. So if you're migrating these are your [06:25:58] options. Okay. So let's come over here and see. Now once you say yes we want to migrate. So th this way you need to go left side and here are you doing a lift and shift or you are doing cloud optics lift and shift is like whatever your [06:26:13] application's condition today is you're just using asis and you are just not changing anything okay you're just lifting your application from onrem AWS wherever it is however it is it's [06:26:27] written in old u old format or old framework you're just using that framework and shifting it to Azure. That's all. Okay. So, if your answer to lift and shift is yes, you'll go this way. If your answer to cloud optimize is [06:26:44] yes, you'll you'll go this way. Okay. So, let's consider lift and shift. So, I'll I'll go I'll go this way. Now, once you're lifting you're using lift and shift, is your container using uh I mean is your application containerized? That [06:26:59] means are you using container platform? So if you're using container platform you go this way. If you're not using container platform you go this way. So platform. So if you're not using container platform we have two options [06:27:12] to choose from. Azure app service or Azure virtual machine. Okay. Now when this yes and no is happened is whether your application is is web app or API. So if your application is just a API or web based [06:27:28] you can go to app service. If it's not, you can go to virtual machine. If your application is containerized, you again have two or three options. You can go have two or three options. You can go for Kubernetes services. You can go for [06:27:41] Azure app service again with container option or you can go for Azure container Okay, it's mentioned here somewhere here. All right, so these are the three options you have when your application is containerized. [06:27:55] are migrating you have this these options. When you are migrating your application to Azure you have these options. You can make use of virtual machine. You can make use of Azure app service. You can make use of Kubernetes [06:28:09] service or you can make use of Azure app service with container. These two doing containerized application. That means you're using Docker or any other container platform and you have containerized your application and [06:28:23] you're deploying it as a container. So either you can use EKS as your Kubernetes service or Azure app service. If it's not containerized then you have left with virtual machine or Azure app service. Okay. [snorts] [06:28:37] you're building new. So if you're building new obviously you have all the building new obviously you have all the options. Now which option to choose when do you need full control? Do you need a full control on operating [06:28:49] Do you need a full control on operating system? Do you want to make u uh control system? Do you want to make u uh control your operating system like every month you have patching? So if you're using Windows operating system, you have [06:29:01] patch it. So do you want those kind of full control? If yes, virtual machine is the option for you. Okay, as I mentioned, your application is not hosted on Azure batch service. But do you require the HPC workload? HPC stands [06:29:16] for high performance compute. So do you need that kind of workload? Uh do you require high performance? Mostly you'll be using it for for when you are processing big huge amount of data. So for your big data pipeline and all [06:29:30] you'll require HPC. Do you require that kind of workload? Then you go for Azure batch service. Are you using microser architecture? application? Okay. Microser architecture. If yes, you have a zero [06:29:45] container instance, service fabric or Kubernetes services. Okay. Uh if no, if if you want to go with eventdriven architecture, you have Azure functions or logic app. Okay. Logic app is not mentioned here, but that is also used [06:30:01] mentioned here, but that is also used for for event driven. Okay. And the last one which is Azure app service. It's like a platform as a service. uh platform as a service that that that you can use like you don't want to have you [06:30:17] operating system that means you you want to uh outsource the patching and all to Microsoft so in this case you can make use of your app service now I see it's it's overwhelming obviously you can't get entire workflow or entire flow chart [06:30:33] in in just 5 minutes but as soon as we go to go through each service uh we'll revisit this this flowchart again at the end and at that point in time obviously it will make sense for you. Okay. So before I move on to the first compute [06:30:49] service for now? You just need to understand that compute service is the understand that compute service is the home to your application. That's all. Any questions on this before I move to the first service that we have? [06:31:03] the first service that we have? [snorts] you mean by storage also? See we are not uh [06:31:17] understanding so storage as of now we're just understanding the compute that means where my application will be running or hosting okay question is related to migrate we we are not migrating storage as of now okay for [06:31:33] storage we have a dedicated chapter you your questions will be cleared there uh your questions will be cleared there uh how storage is handled when it comes to hosting an application. Okay. So under lift and shift we are not [06:31:48] migrating storage as of now. It's just application related things. All right. So let's go on to the first topic which is Azure virtual machine. This is the simplest uh [06:32:01] you can say simplest compute service available in Azure that you can use to host your application. Now I'm I'm damn sure that everyone here might have worked with Azure virtual machine or if not you might have worked with uh EC2 M [06:32:17] not you might have worked with uh EC2 M uh MS Amazon web services EC2 right or you might have worked with HyperV virtual machine or VMware virtual machine if you haven't worked with any just consider this virtual machine as [06:32:29] just consider this virtual machine as your own laptop but running on Azure like it's not a physical laptop it's a virtual laptop running somewhere on virtual laptop running somewhere on Azure your data center. Okay. So what is [06:32:41] virtual machine? Virtual machine is software computer running on Azure as the name specifies virtual it's not a physical thing. It's a virtual machine. All right. So it's a virtual software sorry software computer. So what this [06:32:55] virtual machine gives you this virtual machine gives you the storage like in our laptop what do we have? We have hard disk right? So what that hard disk does it allows us to store something. Similarly this virtual [06:33:09] machine gives me storage where I can keep certain files like operating system obviously my operating system will be there. Apart from operating system I can add additional discs and I can keep my application related file if I want to [06:33:24] and that's not mandatory. You can keep your I mean OS will be the uh the default disk that you'll be getting. Apart from the default disk, if you want to add additional disk, you can add to keep your application data. Right? So, [06:33:39] cloud-based ondemand scalable computing instance that uh you can deploy whenever you want. You can decommission or delete it whenever you want. So, it's an ondemand compute. You [06:33:56] need it, deploy it. You don't need it, just delete it. Okay. So what are the just delete it. Okay. So what are the features? Virtualized computing. You don't need to have a physical computer at your home and then create a virtual [06:34:08] machine. You simply go ahead and create the virtualized. Just deploy it using Azure portal, PowerShell or CLI whichever is whichever you prefer prefer. The usage is to host an application. So you'll be having OS. So [06:34:22] it supports Linux as well as Windows. Whichever is your preference. You when you are creating or deploying a virtual machine you just mention Azure that I need Windows or I need Linux and once you have Windows or Linux installed on [06:34:36] top of it you can deploy your applications okay scalability for it's scalable as this is one of the feature or benefit of cloud computing so any [06:34:48] or benefit of cloud computing so any point in time if I feel that 2 GB RAM is not enough for me I can scale it to 4 GB or 8 GB whatever according to my requirement. So scalability is the feature that you get when it comes to [06:35:01] compute virtual machine networking. I have the option to uh define who can connect, who cannot connect. Okay, who as in which IP can connect, which IP cannot connect. So that's something that we can define. So [06:35:16] networking is attached with it. management you can manage like login you can take a remote access of this virtual machine and manage it or certain management like changing the size and all you can do it directly from Azure [06:35:30] portal or cla powershell okay billing is a pay as you go so you will be build hourly hourly so if I keep my virtual machine deployed [06:35:45] uh for let's say 24 hours so I'll be paying for 24 hours. Okay. Next day I stop my virtual machine. I'm not running it. So I won't pay for the virtual machine for the compute. For storage obviously you'll be paying. Okay. With [06:35:59] storage the the disk that that is that is deployed. So for disk I'll be paying but if I keep it stop I won't be paying for the compute. All right. So it's pay as you go. Apart from pay as you go you can reserve virtual machine for like 3 [06:36:15] years. So there are reserve plant. So if I if I want to reserve I can reserve the virtual machine. So I can go to reservation and reserve. Obviously my subscription doesn't support it. But if your subscription [06:36:29] supports it, you can reserve virtual machine for 3 years. Yeah. Right now my subscription won't support. So it won't it won't show but you can reserve it for subscription is not eligible. So my subscription doesn't support it. But if [06:36:43] I reserve it, I'll be saying saving around 40% of the pay as you go cost. Can see this uh Can see this uh here. [06:37:06] And if you see here if you see here if you go for reserve plan so everything which size you are choosing you go for 1 GB RAM this is the normal cost this is [06:37:22] the saving plan this is again threeear saving plan so if you go with threeear saving plan you'll be having around 54% of savings okay this question from Mustach when should be reserve and when to pay as you go. [06:37:39] Okay. Do you want to save money [snorts] money? So if you want to save money, go for reserve plan. You'll save around for reserve plan. You'll save around what 54%. Now when to decide whether we [06:37:52] should go for reserved or not. You ask your project manager is this project going to be running for at least 3 years? If he says yes, then go for threeear saving plan. So you'll save you'll save 54%. If they're not certain [06:38:08] that we might close this project in one one year or so. So don't go for saving plan. Pay as you go. Okay. Totally depends on project by project basis. Are you going doing are you deploying a [06:38:23] virtual machine for just quick test? If yes, don't go for reservation plan. Go for pay as you go. Since I'm I'm I'm doing it for testing and I'll be decommission decommissioning or deleting it in in after 3 months 4 months [06:38:36] whatever right so at that point in time just go for pay as you go okay [06:38:48] why it's reserved if you want if you are sure if you know that it you you are not going to use it for 3 years reservation is not for you okay just go for pay as you So since reservation uh you can't cancel it. If you can there will be [06:39:04] certain cost. Okay. Uh so it will charge you more as pay as you go if you cancel you more as pay as you go if you cancel it before the contract. All right. [06:39:21] I'll take the questions later. VM sizes. So there are different types or family of VMs uh available in Azure. All right. First one is general purpose. So general [06:39:33] purpose is mostly like for not for production use. Okay. You can use it but it's not recommended for production use. It's used for uh dev test uh [06:39:45] demonstration like the trainers are are are encouraged to use general purpose VMs for demonstration purpose. you will be deploying virtual machines. So you should use general purpose for or your [06:39:59] hands on right. So this general purpose are for dev test or demonstration or those kind of things. Compute optimize will get a powerful CPU uh to memory ratio. Okay. So you'll get more processing power as compared to [06:40:16] memory. So you'll be getting a good CPU as compared to memory when you go for compute optimize. Okay. In memory optimize you'll be getting powerful memory. So your memory processing would be more as compared to CPU. So where [06:40:30] you'll be using memory optimize. So memory optimized can be used when you want to host a database. So you need to create a database server. So we know that we need a powerful memory for database. So SQL DB, MySQL, whatever [06:40:45] database engine you want to install on a VM at that uh for for that scenario. If you're using a virtual machine then you go for memory optimized virtual machines. Compute optimized when you need more processing power like you want [06:40:58] to host an application. So we know that uh in order to host an application we need more compute we need more CPU. the CPU can process those requests quickly, right? Or else if you're using a virtual machine for a solution where you are [06:41:14] encrypting or decryptting or you're working with SSL quite often, then you go for compute optimize since encryption removing encryption working with those algorithms requires a more CPU. So we go for CPU for that. CPU compute optimize [06:41:29] for that storage optimize where your IOPS input output operations per second uh will be optimized. So if you go for storage optimize so where you can use storage optimize for example my company is [06:41:43] coming up with something some service like Google drive where I'll be storing people's data. So when I'm storing people's data when they are trying to access I need to make sure that data is readily available. So in that point in [06:41:58] time I I would be using storage optimize or let's say my company is creating a SAN kind of solution for my internal software or for my internal environment software or for my internal environment or organization. So sand kind of [06:42:13] uh solution requires good throughput and So at that point in time you can go for storage optimized. Okay. Then you can go [06:42:26] for GPU. GPU stands for graphic processing unit. So when you are when you want to work with graphical images or videos where you want to make sure that whenever people are rendering something it should be fast. So at that [06:42:42] point in time you can you can go for GPU like for example gaming servers or um nowadays uh uh artificial intelligence right llama or something you want to right llama or something you want to host so you can go for GPU. [06:42:57] Uh then the last one we have is HPC which stands for high performance compute. So if I need high performance compute like I'm coming up with my own big data pipeline and I want to use virtual machine for that. So I can go [06:43:11] for HPC kind of size of virtual machines. Apart from that there are lot of lot of other sizes available in the in in the Azure portal or in the Azure platform. But these are some sizes that you should you should know. Okay. Once [06:43:28] again you have general purpose which is for dev test kind of environment not meant for production. Compute optimize where you need high CPU right I need more CPU power. For example I'm hosting my application and that application is [06:43:41] working with something known as encryption decryption and application want to process that very quickly. So I need high CPU there. Memory optimize when you need more memory. Okay, I mean powerful memory, not more memory. [06:43:55] Powerful memory. Uh so if you're hosting a database kind of thing u where you require more memory then you can go for uh memory optimized storage optimized where you need good storage like for example you're coming up with sand [06:44:10] of thing or Google drive kind of thing where people are storing and you need a where people are storing and you need a quick read access to that to to to that data which is written over there. So you can go for storage optimize GPU graphic [06:44:24] processing unit where you need more more graphics like gaming servers, AI rendering, marketing materials, HPC higherformance compute where you want to all kind of things and you want compute for that you can go for HPC uh type type [06:44:40] of Azure virtual machine. Okay. Then if you want to create clusters of virtual machines then in Azure we have something known as virtual machine scale sets. So virtual machine scale sets are like deploying virtual [06:44:54] machines as a group of virtual machine like a cluster. So you'll be deploying more than one instance. Why we have scale sets over here? If let's say I'm hosting my application in one virtual machine and if that application goes [06:45:07] down what is going to happen? My application will be impacted. Right? So if I don't want to do that what I can do I can deploy that virtual machine scale set instead of single virtual machine in instead of individual virtual machine I [06:45:19] deploy more than one virtual machine as a scale set and in that case Azure will make sure that if one virtual machine goes down another one will be created by availability which means if one of my virtual machine [06:45:34] going down it's not impacting my application since my application can still serve the requests coming in from user uh using additional instances. All right, more on this later we have a dedicated slide for virtual machine [06:45:47] scale sets as well when we go to the high availability uh concepts. Okay. But like a group of virtual machines that you're deploying together and if one virtual machine goes down, you still have uh other virtual machines which [06:46:01] have uh other virtual machines which will serve your requests. Okay. [snorts] Now main thing when to select Azure virtual machine quick test you want to do a very quick test of your application whether it will be running or not. What [06:46:15] issue can what issue you can have right HPC kind of workload. So if you want high performance compute then obviously you cannot go for other compute instances. Obviously batch solution supports it. Apart from batch solution [06:46:28] other will not be able to support it. So you can go for a virtual machine. Legacy you can go for a virtual machine. Legacy app. Legacy app is old applications app. Legacy app is old applications which are not supported in [06:46:41] which are not cloud native or cloud optimized. So you can go for virtual machine in that case and you need a full control over operating system. So with can log into the virtual machine and you can install whatever software you want. [06:46:57] So you have full control over the operating system. Okay. Now this is the operating system. Okay. Now this is the excerpt from from that flowchart. So when you will be using virtual machine when you are building a new [06:47:10] application or you're migrating uh and using lift and shift. So if you're require full control go for virtual machine. When you're migrating and using lift and shift can you containerize it? If no can [06:47:24] you use web app or API app? If no then you go for solutions. Okay. This is the you go for solutions. Okay. This is the same ex excerpt from this flowchart. All right. So before I go to the portal, any questions on this? [snorts] [06:47:49] for dev and uh dev environment. So dev environment, you go for virtual machine, environment, you go for virtual machine, [snorts] shutting it down during non-b businessiness hours. So which will save [06:48:05] machine doesn't matter whether it's general purpose or any other family size uh any other VM family. If you keep it running for 24/7 you'll have you'll pay extra even when you're not using it. So it's better for dev test environment you [06:48:21] use virtual machine and then uh use general purpose virtual machine and then make sure it's shut down when it's not in use. [06:48:33] Okay. Mustach is saying VPS are cheaper. Okay, which probably [06:48:53] installed in VM after OS in real that's up to you what applications you wants to install. By default there won't be any. By default when you create a VM when I'm creating a VM only OS will be installed that's all apart from OS nothing else [06:49:08] will be installed so what application you need you can deploy that is the meaning of full control okay so when you go for virtual machine you have full control you can deploy whatever you want [06:49:22] all right so by default there won't be anything so if I select Windows OS only installed softwares will not be installed If I need additional softares, I can install it afterwards once I have access to the V. [06:49:36] Okay, any questions before I move on to the portal. [06:49:51] central India. same things since I want to uh okay before I delete if you see the overview page here you should this you [06:50:03] compliance the meaning of compliance is what our policy is saying our policy is saying that you should not have resources in central India west India and south India but if you see the policy compliance I have three resources [06:50:18] out of which two are compliant one is non-compliant that means one is still in So that's the kind of audit or compliance report you get when you use uh policy. Now since we only have one policy, I see this kind of compliance. [06:50:33] You'll be having multiple policies. So you'll be seeing percentage kind of you'll be seeing percentage kind of thing like for example here 14%. thing like for example here 14%. All right. So this is where the uh [06:50:45] policy comes in place to define or to see your compliance level before the audit obviously. So you can make sure that you are uh 100% compliance to [06:50:57] whatever requirement your your company or your clients are giving to you. All right. So let me remove this policy now. I don't need it. [06:51:15] have any compliance in in some time this compliance will go away since you don't compliance will go away since you don't have policy. Okay. All right. Now let's see our first demo of compute section. So here what I'll be doing I'll be [06:51:27] deploying a virtual machine and within that virtual machine we'll deploy a very simple application. It's not an application it's a simple uh static website. So I'll be deploying that. So let's see that and I'll be using same [06:51:39] static website to deploy it in all compute services whatever we are going to cover whatever demo demo we are going to see. Okay. So let's see that quickly. [06:51:51] So what I'll be doing in order to create a virtual machine, you need to uh search for virtual machine and then click on virtual machine and then click on create. Okay. So as usual uh with any resource the [06:52:07] first two things will be will be common and mandatory. So you need to provide subscription and then you need to provide resource groups right. So which subscription Azure should Azure should charge you and which resource group you [06:52:19] want this virtual machine to be part of. Okay. So I'll be selecting Azure training subscription and that's the subscription I have access to. And resource group I can create new if I don't have one but if you remember we [06:52:33] created a resource group with the name A305 RG02. So I'll be selecting that resource group. Okay. You can select whatever resource group you want. But remember one thing when you deploy a virtual machine [06:52:46] everything will be deployed under this resource node. Now with laptop when you buy a laptop what do you get when I buy a laptop with this laptop within this laptop we have a keyboard here we we have a CPU installed on the motherboard [06:53:01] right we have the storage so we have some SSD or HDD and then we have virtual uh sorry physical nick as well the network card so network interface card is also added to to the keyboard. So similar to sim similar to laptop here [06:53:16] similar to sim similar to laptop here also you will see the disk is getting uh created with disk you will be having virtual nick since this is a virtual machine you'll be having virtual network interface card right and then uh CPU [06:53:31] will also be allocated the virtual CPU will also be allocated to this virtual machine so all those stuff will be in the same resource group then next thing machine name so So I'll go with a simple [06:53:44] name. So let's consider this is my web server. So I'll give it a web server 01. world, what name you'll be giving? Totally depends on your naming convention. Whatever what I have seen in the real world is [06:54:01] people use uh the environment pro. What this server is? This server is web server. So they use web SRV. And then what is the number of this web server 1 zero some some people add the [06:54:16] region as well like for example this is deployed in central India so CI gets deployed in central India so CI gets added and then the number 01 so that's how uh the naming convention would totally depends on company to company [06:54:28] basis so someone can have like this proderver right so some some have this some have just broad Web server totally depends. [06:54:43] So we will keep it simple and we'll go with web server 01 or web server. All right. Then region. What is the region? Region is a physical location where you are deploying the virtual machine. Now you're using Azure portal. [06:55:01] So this is the cloud portal which we are using to deploy our virtual machine. But this virtual machine is not sitting in my home. Sitting at my home. What we are doing? We're deploying it somewhere on Azure data center. Okay, it's cloud. [06:55:14] What is cloud computing? Your data on someone else's data center. Your data and someone else's computer. So, we are deploying this virtual machine in Azure's data center. So, Azure has data center all over the all over the world. [06:55:28] So, central India is one of the region in Azure. So, that's what we are see we are selecting here. Okay. Then availability option. uh I'm not right now since we have the high availability [06:55:43] availability uh topic later when we do the network thing. Okay. So we have that topic so we'll cover it there. But uh you can high availability. If I want to deploy more than one virtual machine of the [06:55:57] same thing then I can make use of these availability options. All right. availability options. All right. Security type. If you want to make uh you want to have basic security, you want to have like [06:56:09] >> uh TPM, TPM is used for Bit Locker, you want to have secure boot, right? You want to have more security against uh the type of attack that is being machines. So if you want to have if you want Azure to protect it against those [06:56:23] kind of attack, you can go for trusted or you want to have totally confidential uh virtual machine, you can go with with this as well. Okay. Now for our use case we can go for trusted launch and in real world as well [06:56:37] you can go for trusted launch since that's quite secure and trusted launch that's quite secure and trusted launch gives you the option to encrypt the the discs the virtual disk that you're going to get. Okay then image. So this image [06:56:51] will help you define whether you want the uh Windows operating system virtual machine or Linux operating system. Now there are a lot of images like if you see we have Windows server, we have Ubuntu, we have SQL server, we have [06:57:06] again 2022 Windows server. Okay, apart from this you can also click on see all images and you'll see all the images available in the marketplace. You can come up with your own image as well. You can create your own image, push it to [06:57:20] the gallery and you can select your own image as well. [snorts] have. These are all the marketplace images. Some images uh might have extra cost. So cost will be mentioned over here. Okay. Like for Red Hat the license [06:57:36] is included or not. Once you select it, it will tell you whether the cost is not compatible with the security type that I have selected. So I need to change the security type. Okay. And at the cost page once I go to the review [06:57:50] create it will tell me whether uh the cost is separate or uh the license cost is separate or or it will be included in the images itself. Okay. So I'll go for Windows Server 2025 data center since we want the Windows machine. So I I'll [06:58:06] select the Windows Server 2025 data center which is the latest server operating system from Microsoft. All right. And then you have size here. Okay. What is size? Size will decide how many CPUs you are going to [06:58:22] get and what amount of RAM you're going to and what amount of RAM you're going to get. 8 GB. Okay. 8 G. And then there's a virtual machine running for 24/7, how much you'll be paying? All right. So [06:58:37] much you'll be paying? All right. So I'll go for B2MS or or D2 SV3. These are the options I have selected. Then once I create the virtual machine, you have your laptop. Uh in order to go into the laptop and do any changes, you [06:58:52] need to provide uh um username and password, right? So that's the safe username and password you need to keep here. So I'll go for simple Azure user and my default password so I don't forget it. [06:59:09] Okay. And then the network rule. So which port you want to allow or deny. All right. What these ports are? These are the TCP ports. So if you keep 3389 [06:59:24] are the TCP ports. So if you keep 3389 open, what happened with 3389? Now this is the basic thing. Uh not part of 305 but I'll explain. Okay. Anyone knows what is this 3389 remote desktop right? So those who are [06:59:38] experienced in taking remote connections of Windows they would know. So this is of Windows they would know. So this is the port number where we send request to this virtual machine. So I'm sitting here somewhere in in Malaysia. Okay. And [06:59:51] my virtual machine is sitting somewhere in Azure data center central India. So we are not connected physically. We are not connected directly. So what I'm internet. I'm sending request over internet to this virtual machine that I [07:00:05] internet to this virtual machine that I want to take your control. allowed or not because I'm I'm sending the request on port number 3389. So it will check whether the port number is allowed or not. So if you don't allow [07:00:20] the port number here, if I just go ahead and untick this, I won't be able to take the control. So I just want to take the control, that's why you need to keep 3389 open. Okay. So this will allow your virtual machine to to to accept your [07:00:35] request. And then next you have disks. So here you can define the disks. So if you're using simply learn subscription, make sure you're changing this disk to uh standard HDD. Okay. So if you're using simply learn [07:00:49] subscription, make sure you change it otherwise your VM deployment will fail. So if you're not changing this to standard HDD your deployment will fail because of our policy the simply learn policy which is in place clear. Now [07:01:02] since I'm not using simply learn policy I'll go with premium SSD. It doesn't uh it it should not restrict me from deploying next uh quite [07:01:15] understandable. So if you see the networking topic do you want to have a public IP? Do you want to create another virtual network? Do you want to have subnet? We have a network topic but obviously we're not [07:01:27] going to discuss everything in in in deep. Uh we will be discussing it from a doing when you're creating a virtual machine a new network is also getting machine a new network is also getting created. Okay. So if you see the new [07:01:41] uh word here in the bracket that means a new virtual network will be created. within that virtual network a new subnet will be created and a new public IP will be created. Similarly, new network [07:01:55] will be allowed. The port that we have defined there 3389 will be allowed. Okay. So, we have a network topic where most of the things will get clear. For [07:02:07] now, just know that whenever you are creating a virtual machine, a network is also getting created. All right, that's all. Once that is done then you have the management section where you can define uh whether you want to assign manage [07:02:22] whether you want to login using Microsoft enter ID or no whether you want to auto shutdown your virtual machine so if you're using dev for dev test it's better to keep auto shutdown on so automatically VM will be shut down [07:02:38] at so and so point in time whenever you want 700 p.m. UTC or 700 p.m. a whatever. Okay. Then monitoring. So if you want to enable monitoring, you can have we have a dedicated chapter for monitoring. So [07:02:52] we are not doing any changes here. Then in advance if you want to run any script after the VM is getting deployed. So you can give that script here and Azure will execute your script once the VM is deployed. Okay. Then tags and review [07:03:06] create. If you want to have tags for your virtual machine like uh environment fraud, you can add the tag and then review create. Okay. Now, Kailash is asking what happens if we select enter ID login. It doesn't [07:03:21] yet. When you create enter ID, you're not creating domain. Okay. So, if you select Microsoft Enra ID, this will give you the option. When you select this, it [07:03:33] will allow you to use your enter ID credentials to log into this virtual machine. So this enter ID credentials. So anyone having the so-called uh role like virtual machine administrator login role or virtual machine user login role [07:03:49] uh from the arbback to this virtual machine they'll be able to login using their enter ID credentials. It's not joining domain. It's not creating joining domain. It's not creating domain. Okay. [snorts] [07:04:06] create uh and then create so it will start deploying the virtual machine. provided the subscription resource group the virtual machine name region uh image image will help you decide whether you [07:04:20] machine. Then you need to provide the size of your virtual machine 8 gig or two or 4 G whatever you want and then two or 4 G whatever you want and then username password uh inbound role that's [07:04:32] all rest even if you're not making any change and you click on review create it change and you click on review create it should it should work okay so rest are just non-mandatory things which Azure is automatically selecting [07:04:45] for you and then I click on create so it will start deploying the virtual machine it will take around 2 minutes to 3 minutes for the virtual machine to be deployed. Okay. [07:05:35] machine is deployed. Now in order to connect definition of cloud computing we just put the definition of cloud computing. [07:05:49] What is the definition of cloud computing? delivery of compute services over internet. Now my question is where is this virtual machine sitting? [snorts] [07:06:01] You have all the information in front of you. Where is this virtual machine deployed or sitting central India and where I am? I am in Malaysia or even if where I am? I am in Malaysia or even if I'm in India, I'm not sitting or I'm not [07:06:15] I'm in India, I'm not sitting or I'm not inside the Azure data center. Okay. So Central India is not Nagpur Hurry. Central India is uh Pune for Azour. Okay. For us is it's Nagpur but it's it's the data center is actually in [07:06:29] Pune. Okay. So I'm sitting in Malaysia. Now delivery of compute services over internet. So if I want to connect to this web server machine, what I need? I just need an access to internet. That's all. And the [07:06:42] IP address and the credential of this virtual machine. Okay. So let's connect. virtual machine. Okay. So let's connect. In order to take a remote access of this virtual machine, what I'll be doing, I'll be [07:06:56] right click. I'll do a right click on my start button of my laptop. So if you see, I'll do right click and then I go to run. And after run, I'll do MSTSC. [07:07:12] a shortcut to open the remote desktop connection wizard and here you need to provide the IP address the public IP address which is mentioned here in the uh on on the screen. You see the public IP address here. So I just copy this [07:07:27] public IP and I paste the public IP here and then I click on connect. So once I click on connect it asked me the credentials. So I provide the credentials. [07:07:40] the credentials that we provided at the first page when we were creating the virtual machine. Okay. Then click on yes and it will give me access. Now I'm inside my virtual machine. So whatever software or install [07:07:56] installation I'll be do doing that will be impacting my virtual machine not my laptop. Okay. I'm connected to the virtual machine. You can see the public IP of the virtual machine. similar to what you see here 20.219.24.129. [07:08:14] Okay. Okay. You can see [snorts] that here. [07:08:45] 2025. So let's start with our uh let's continue our compute journey where if you remember uh when we were when we completed the yesterday's session uh we deployed a virtual machine and on that [07:09:00] virtual machine we hosted one single a very basic website okay so uh since the deployment of website was very quick so what I have done I've already created [07:09:13] what I have done I've already created the same virtual machine web server 01 which we had yesterday. So I'll be connecting to that web server 01 and then I'll be deploying the web server role and after that I'll be hosting the [07:09:25] website. Okay. So I'll copy the public IP. This is something we covered at the IP. This is something we covered at the last uh yesterday uh at the last half an hour. So I'll copy the public IP of my virtual machine. This is my virtual [07:09:38] public IP and I'll connect to this Windows virtual machine, what I have to do? I have to connect it using RDP and I need to make sure that port number 3389 is open which we discussed yesterday. [07:09:53] All right. So if I scroll down here, you see port number 3389 is open. So I can copy the public IP and then connect to this virtual machine. So I copy the this virtual machine. So I copy the public IP. I I press Windows R on my [07:10:06] laptop and I type MSTSC which is the shortcut to Microsoft uh sorry to RDP to RDC connection to remote desktop connection. So once I type MSTSC and press enter it will open this run uh this dialogue box this wizard where I [07:10:21] can paste the public IP of my machine and then I can click on connect. So once I click on connect it ask me for the credential. These are the credential which we provided when we created the virtual machine. All right. So I'll go [07:10:34] virtual machine. All right. So I'll go with the credential that I used credentials are okay then I can u click on yes and it should [07:10:48] uh connect me to the virtual machine that is deployed on uh in central India that is deployed on uh in central India on Azure platform. [07:11:01] any service? This is nothing but a server, right? So we deployed a Windows server operating system. If you see this, if you see the operating system here, this is nothing but the Windows server 2025 data center. So it's a [07:11:13] server operating system. The operating system that you have in your laptop which is for commercial use is is a client operating system. You might be having Windows 10 or Windows 11. So that is a client operating system. What is [07:11:25] client? Server provides some kind of service and client accesses those those So if you want to host your application or you want to host your website then you need a server operating system. You can't do that with client operating [07:11:40] system. All right. So that's why here we have selected Windows Server 2025 which would give us the capability to deploy whatever service we want. As of now we are focusing on deploying a website. Okay. So in order to deploy a website I [07:11:54] need to deploy web server role. In Microsoft Windows you have web server role known as IIS. If you're working with Linux Linux has different flavors with Linux Linux has different flavors like you can install Nix. Ninx is [07:12:08] another web server. So you can use that. So let's say instead of Windows operating system you deploy uh Ubuntu. Ubuntu is a distribution in Linux. So Ubuntu is a distribution in Linux. So for that I need to deploy ngx on top of [07:12:21] Linux operating system or you can make use of HTTP also known as Apache. We can use Apache as well. So Apache is another web server that you can deploy on top of have deployed Windows server operating system. So we will touch the uh we will [07:12:38] install the IIS role. All right. Now in order to install the ISO role I have to connect to my virtual machine which I have connected remotely. Right. So once I connect to that virtual machine there in every windows uh virtual machine in [07:12:52] every windows machine not virtual in every windows machine you have something known as server manager. Now there are different ways to deploy the role or different ways to deploy the role or service on windows uh machine like you [07:13:05] have graphical way you have powershell way you have cmd way. So there are different different ways available. Now since we have uh 40 50% of freshers here so I'll be sticking to GUI way since that would be easy to understand okay [07:13:20] instead of doing it via PowerShell and all [snorts] all [snorts] by default in Windows machine or Windows server operating system you should see this server manager which should open [07:13:32] automatically even if you don't uh open it it should uh open its wizard automatically if it's if if you see let's Say for in your case if server manager is not popping up what you can do you can you can go to the start [07:13:45] button in the in virtual machine and here also you can see server manager. So if the server manager windows or or dialog box is not opening you can click here and it should open right this is the first page that I should see [07:14:00] whenever I connect to my virtual Windows virtual machine. Now I have to wait. You see this blue line which is uh collecting some inventory. So I need to wait. It won't let me do anything until this is gone. Okay. So what it does, [07:14:13] it's preparing your server, collecting inventory data like what is the IP all those stuff it's collecting. So this is Windows specific. I need to wait until this is gone. So if I click on add roles and feature it won't let me do [07:14:27] okay. So it's letting me do that means it has already collect collected the data. You see now that blue line which was which was traveling is gone. Okay. It's gone. That means now I can work with my server. [07:14:39] Okay. So what I did on the homepage on the dashboard itself I clicked on add rules and features and from here you can select whatever service you you want to provide you want your server to provide like if I click on next next here you [07:14:55] have the tab known as server role okay what this server role is if you let's say we discuss about active directory domain service right so if you want to uh have this server behave as an identity server you can install active [07:15:08] directory domain service. If you want this server to behave as a DNS server, you can install the DNS server. Right? Now, what we are interested here, we are interested in the web server role. So, if you see here W under W, you have web [07:15:22] server IIS. So, this is the role which you use uh to host the websites or web applications. Okay. So, I selected web server and then I do nothing. I just click next, next, next, install. That's all. [07:15:37] So now it will start installing the server role for me. All right. Which installing web server. Once the role is installed, I'll simply copy paste my application files and this [07:15:51] uh this machine, this web server or this uh Windows machine should host my website and I should be able to access that website. That's where we stopped yesterday. Okay. So I'm continuing from there since this was very quick [07:16:04] there since this was very quick yesterday. That's why I'm repeating. So I'll have to wait until the installation is done. Okay. I see Ram is asking today's topic. Uh I think I already covered today's topic is is the [07:16:18] same. We are continuing our compute journey. So we only saw one compute as of now virtual machine we still have other compute services to to see. Okay. Once that is done we will start with our networking topic. So these are the two [07:16:35] plan topic in the agenda for today. All right. [snorts] So I'll have to wait until this is done. Once the installation is complete, I just have to copy the files. That's all. Where I'll be copying the [07:16:48] file. Since this is Windows machine, I have a file system here. Uh where I can navigate to C uh inet and here you have dubdubdub. So this is the folder where your application lives. All right. So I [07:17:03] select dubdubdubdub the are these are the default files. So if I don't change anything a default website would be loaded to wait until the installation is done and then only copy. [07:17:32] The steps are important to understand what we did. We first deploy the uh the virtual machine and while deploying the virtual machine we selected that we want Windows OS. You can select Linux if your pref if your preference is Linux. After [07:17:47] installing the Windows OS what we did we added the role the web server role known as IIS. And after the IIS is installed we are copying our files. So this is the the the steps these are the steps that we [07:18:02] are taking. All right. Virtual machine created virtual machine. Uh while creating virtual machine we selected Windows operating system. Windows server operating system. On top of it we deployed IIS. On top of it we will be [07:18:16] copying our files. Once the IS installation is done. already installed. So instead [snorts] of waiting let's just okay it's done. If [07:18:29] you see installation succeeded says it says installation succeeded on web server 01. So once that is done you can close it right without changing anything. If I hit the IP address the public IP address of the server uh it [07:18:42] should load the default website. Okay I just hit the public IP address. This is the default website. So if I navigate or go back to the server, you should see this is what is being loaded. [07:18:57] So if you open this with paint or something, if you open this with paint, this is what is being loaded. So if I replace this with my own website, I should be able to uh see my own website. Okay. So [07:19:11] I made some changes. Click on save and then minimize the virtual machine and refresh the the page. So you see the changes are reflected instantly right. So now if I copy my simple uh app. So if I go to downloads and copy [07:19:34] website. So I copy all this file go to the same location where the default website is located. Remember the location the path is cetpdw. Okay. So I delete this thing the default one and I copy I paste all the files [07:19:51] that I have for my website. Okay. Now if I minimize the virtual machine and uh refresh the browser now it should load my website. All right. So it's it's it's that simple. But uh if you want to learn more [07:20:07] on how it's it's it's not this much on on web server. There's a lot that you can do with web server. Okay. Now since we just want to understand how compute works so we are doing this. All right. Now you can just [snorts] go to the [07:20:21] public IP of this machine and you should be able to see the same website. Okay. which step you want me to repeat what what what we did is we installed or we [07:20:35] >> [snorts] >> We selected Windows OS and then we installed IIS. This is clear. Okay. So the address where you make changes is within the virtual machine [07:20:52] changes is within the virtual machine Cetp. This is C drive. C drive inet. So this is the folder where you have your website. Okay. [07:21:14] we install in this server. Uh this is not something at easy 305 level. You can not something at easy 305 level. You can install as many as you want. Uh depends on the configuration that you have selected. Okay. So I have selected uh [07:21:27] four uh 8 GB virtual 8 GB memory. Okay. So if my web app is is is lightweight web app, lightweight traffic, light traffic is coming in, I can install as many as my server can support. Okay, there's no proper limit. You can install [07:21:43] whatever you want. If you want more, you just change the size here and you install hundreds of web app. It should work. Okay. work. Okay. All right. [07:21:59] Okay. So pankage this is not uh something uh we should cover in uh uh something uh we should cover in uh uh a305 okay it's IIS related. So if you want to learn more on server thing then I would recommend you to go for a 800 or [07:22:12] a 8001 okay so these are the courses where you cover where we cover the uh server related thing but if you want to do that that you need to do from the IIS uh management console. So if I search for IIS here [07:22:32] another website. All right. So here if you see I have one site this is the add additional website but this has nothing to do with a 305. So I'm not covering this here. Can give it a name. You can give physical path where your [07:22:47] application is wherever you want to store. Mostly you'll be storing it in pub. You add additional site here with the name whatever name you want to give my site or something you select that you add your files there and and it and you [07:23:02] should run it. Okay. So this is how you do it but this is has this has nothing to do with a305. If you want to learn more on this uh I If you want to learn more on this uh I would encourage you to go for IIS [07:23:15] course or server level course. Okay. But remember one thing uh on port 80 my default website is running. So I cannot use the same port for a second website. So that's the catch there. So you need to do some routing here. And instead of [07:23:32] to do some routing here. And instead of uh reaching out to server over port 80, you need to use the naming the host name uh base host name routing here instead of port numbers. All right. So here whatever host name I'll be giving that [07:23:46] host name this server will be listening for port number 80. for port number 80. All right. So let's not complicate it. [07:24:00] demonstration how you can uh host a web app or a website on on Windows server. app or a website on on Windows server. All right. [07:24:14] So next compute service that we have is Azure batch solution or Azure batch service. Now Azure batch service is not something uh similar to what we just saw. It's not a virtual machine where you can host your application. It's a [07:24:28] totally different compute service where you can run large scale batch processing. What is the meaning of batch processing? When you want to process multiple files parallelly. Okay, many files parallelly at once. So if you have [07:24:43] that kind of requirement then Azure batch uh Azure batch solution is the batch uh Azure batch solution is the service for you which you can use to run multiple processes or multiple files. You want to process lot of files at once [07:24:57] parallelly. So if you want to process that kind of thing, you need large compute, heavy compute. So Azure batch solution is for you. Okay. Now what is the uh advantage of using Azure batch service? As I just mentioned batch [07:25:10] processing. If you have anything where you require HPC, HPC stands for high performance compute. You want to do distributed computing. Okay. I want to uh process certain files for uh in two virtual machines and certain files in [07:25:25] three virtual machines. So I can do that kind of uh thing. It also helps you to do the orchestration. uh you can optimize cost by uh you can optimize cost by by uh combining different sizes of [07:25:38] obviously you can integrate it with any other Azio service. Now where where in real world it's it it's being used. Okay. So I give a very simple example of uh YouTube. Okay. So what is YouTube? [07:26:02] please share the today and all past topic. Sorry. Sorry. What you mean M? I don't understand what you're trying to ask. So I'm trying to explain batch solution. So please focus here. All right. So I'm [07:26:15] explaining batch solution here. What is batch solution? Batch solution is a service in Azio. It's again a compute service in Azio which helps you to uh do a batch processing. So let's take an example of YouTube. What is a YouTube [07:26:27] service guys? YouTube is a service where you can stream videos, right? You can stream videos. So what what I can do? I can stream videos. It's a video service, a video streaming service. Apart from video streaming service, what you can do [07:26:41] channel, right? You can create your YouTube channel and you can upload videos. Anyone here who is a YouTuber or I'm I'm I'm damn sure that 50% of people might have tried YouTube and they might have [07:26:57] their own channel there and they might be uploading videos as well. So anyone here who knows how YouTube works. So what you do you create a channel and then you upload your videos. Now tell me are you the only person in the world who [07:27:10] has the channel and who is uploading the video how many videos are being uploaded on on YouTube at this point in time 7:26 p.m. [07:27:23] YouTube at this point in time 7:26 p.m. day. What do you think? How many videos day. What do you think? How many videos are being uploaded? Come on, quick. Just take a guess. How many videos in 1 second? How many videos are getting [07:27:36] uploaded to YouTube? Million billions of videos, right? There's no count. Millions of videos are being uploaded. Now, when you upload a video to YouTube, what YouTube does? YouTube processes [07:27:50] what YouTube does? YouTube processes your video. Right? If I go to YouTube, I your video. Right? If I go to YouTube, I upload my video. If I have a channel, [07:28:03] video, you have different options to play like you you can play that in 1K, play like you you can play that in 1K, 2K, 3 uh 4K, right? So 1080 pixels. So there are different different uh once anyone is uploading the video, YouTube [07:28:18] it's available in different different resolutions, right? It's not loading. I don't know why but let's come come back to the topic. So when someone is uploading at at any point in time thousands or millions of people are [07:28:33] uploading videos. So millions of videos are getting uploaded to YouTube. Now tell me when YouTube is processing YouTube has certain kind of application YouTube has certain kind of application which is processing this video. [07:28:49] being uploaded and YouTube needs some service which can process this millions of videos parallelly at the same time. Now imagine you are uploading the video and your video is in queue. After the million videos only your video will be [07:29:04] it will take for that video to be available on your channel. Right? So I need some kind of service as a YouTube I need some kind of service which can process this this millions of [07:29:16] videos parallelly and quickly. So Azure batch solution is the service which can batch solution is the service which can helps you to achieve this kind of thing. So if you have any application where you require batch processing then Azure [07:29:29] batch solution is the service for you. Another example, you have your marketing team in in your uh company. What does marketing team do? They come up with videos. Has anyone here work with editing or anything? So when you edit a [07:29:45] editing a video, what do we do? We cut our uh I mean we we record a raw footage first. Once you record a raw footage, you then take that footage, put it in [07:29:57] any of the editing tool and then you cut the unwanted footage. So when you when you cut unwanted footage, that means you are uh you just [07:30:09] like final after the final cut. Right? So when we are finally there I mean we have cut all the unwanted footage and now we have uh [07:30:21] added all the all the clips of footage that we need. So that means this is my final cut. After the final cut what do we do? We export our video. Export is nothing but this is my final video export it in in a full video kind of [07:30:35] video what that what does that editing tool do? Have you heard the term render? So the what this editing to tool is doing it's rendering your video that means it's making your full video [07:30:49] whatever final cut you have come up with it's making that into a single video since you have cut your raw footage and you have change entire changed your entire video and when you click on export it it starts rendering your video [07:31:01] that means it's exporting that video to a full video like maybe you have used MP4 or whatever format you have used now imagine imagine your company is [07:31:14] your company is creating or editing thousands of video uh in one day. So at that point in time I'll I I'll require the HPC the high performance compute to render my video since this rendering takes a lot of [07:31:27] time. So if that's my requirement I can rely So if that's my requirement I can rely on Azure batch solution service. Okay. U so these are the two examples from the real world that I can came up with. All [07:31:39] right. I don't have any demonstration for Azure batch solution since I don't have any application which can do this kind of stuff. Okay. But Azure batch solution how it works behind the scenes. You create Azure batch pool and whenever [07:31:53] there is a there is a task which is coming in the compute will be will be anything. You're doing this kind of stuff where you are processing videos. you are rendering videos or you're working with 3D modeling. So in 3D [07:32:09] performance compute kind of thing. That's why you might see that any editor That's why you might see that any editor mostly uh any editor who who is working on editing and all they they use the Apple uh Mac Mac studio or or Mac Pro [07:32:26] Apple uh Mac Mac studio or or Mac Pro right why? Because th those PCs those Mac PCs are built for this kind of work. So similarly if I want to process now now Mac is like built for one single kind of thing like I'm I'm I'm an editor [07:32:40] and I'm processing or rendering or creating or developing a video and I want to edit that. So I'm working on one video at a time or mostly two video in in a day. So I'm doing that. So for that kind of work Mac is okay. But if you [07:32:52] want to do in batches that means multiple or many videos at at at uh in a single day or in a single minute and that point in time you'll require something which can handle the batch processing. So Azure batch solution is [07:33:06] that solution is that service where you can uh which you can use to do this kind All right, clear. Any questions on batch processing [07:33:18] or or sorry a batch solution? [snorts] uh scientific research where you need like like for example weather weather [07:33:31] prediction models where you need to work on large amount of data from previous days and then you need to come up with a uh with with a prediction what what can be today's weather tomorrow's weather. So that's where Azure bath solution uh [07:33:48] perfectly fits. Okay. [snorts] I don't have any demonstration mir okay since you need an application which can which can do the batch processing and you need to send data in batches so that you can see that in live I don't have [07:34:04] that what I can show is just creation of batch solution which will not make any sense okay I don't have any any demonstration for that all right [07:34:20] Azure app service as your app solution. This is another compute service. Okay. It's not like ETL run. Okay. Batch processing. Yeah, you can use it for ETL as well. So if you're doing any uh extract, transform, load kind of thing, [07:34:35] you can use batch solution for that. So it's similar to that. All right. But main job of this is is to mostly where I have seen bath solution is implemented have seen bath solution is implemented is uh in in in in the in in the [07:34:49] is uh in in in in the in in the marketing uh team. So I've seen my friend working in a company uh and they have implemented this as your batch solution for their marketing team. Okay. But it's similar to ETL [07:35:03] right where you will be taking data that data will be triggered and that data will uh triggered your compute your compute will process that data and then that you can integrate it with any other service to load that data somewhere. [07:35:17] service to load that data somewhere. All right. next compute service that we have in Azure is Azure app service. Now, Azure [07:35:29] app service is also a service where you can host your application. All right. So, if you want to host your web app, uh you can make use of app service. Uh the infrastructure for this is managed totally. So, fully managed [07:35:43] infrastructure. Uh you have the option to scale it out or scale it in depending available. You can integrate it with DevOps. uh it gives you the option to [07:35:56] compliance. By default, your data will be secured. Okay. Then you can integrate Azure app service with with other Azure services since this is an Azure service. integrate it with Azure other Azure services and it has support for [07:36:11] containers as well. So main main thing that you need to understand for Azure app services this is mainly used for hosting web apps or website. Okay. Or [07:36:24] APIs if you're creating if you're working with APIs. So you can host these working with APIs. So you can host these three things. Now question may arise for freshers that here also I can host web app. In virtual machine also I can host [07:36:37] web app. So what is the difference between these two? The difference between these two is virtual machine is infrastructure as a service. Okay. Where you have the full control over operating system. So I can [07:36:52] as as you saw that I logged into the virtual machine and then I can make any change instead of web server. If I want to make this as a DNS server, I can do that. I have that flexibility or that option or that capability to make this [07:37:04] as a DNS server. Okay, I can make it as a DHC DHCP server as well. So I have Whatever I want to install, I can do that. So that uh instead of just keeping this as a web server, I can install all these roles as [07:37:19] server, I can install all these roles as well. So that uh benefit we get when we in when we use Azure virtual machine. Whereas when you're using Azure app service you do not have control over the operating system. If you remember from [07:37:33] operating system. If you remember from from the uh basics from the first uh session we discussed infrastructure as a service and platform as a service. What as a service and platform as a service? In infrastructure as a service, you have [07:37:47] In infrastructure as a service, you have full control over the operating system. So when I use infrastructure as a service model, I am deploying a virtual machine. I'm selecting an operating system and I have full control over that [07:38:00] operating system. When I'm selecting platform as a service, I can select which operating system I want whether Windows or Linux. But I don't have That means when I say I don't have [07:38:12] control I'm I cannot log to that virtual machine when I'm using platform as a service model. So what uh what pass can help you to do is host your web app website or uh web app [07:38:28] website or API but you won't be able to log the v operating system that you have selected whether it's Windows or Linux. Okay. Now when you don't have control over the operating system, what advantage you have? [07:38:42] When I don't have control over operating system, I am not responsible for the patching of the Windows OS. So if I'm using infrastructure as a solution and I'm deploying everything in VM, I am responsible for the patching. So if I go [07:38:56] to the settings and Windows update, I need to make sure whenever a new update is available, I need to make sure that I have installed it. like these two updates are already there in my virtual machine. So I should be the one it's not [07:39:09] responsibility since I had deployed the virtual machine. So this should be installed by me as a as a user as a consumer. Okay. Whereas in path service responsibility. So underlying virtual machine will be [07:39:25] patched by Microsoft. All right. So that's the advantage that that you get. Now the question may arise which one to use? If you are a developer the best option for you is app service. [07:39:40] If you want more control on the infrastructure and you are infrastructure admin and you want more control then infrastructure as a service is the option for you. That's the best uh bet for you. All right. like you just [07:39:53] within the same virtual machine you need to install some other softwares and some other uh uh roles like DNS, DHCP whatever you need for your infrastructure. So you can install that that option you will not [07:40:08] get in app service. All right now whenever you want if let's say uh in interview you get a question explains the difference between p and I so you just remember this table. So with IAS infrastructure as a service you have [07:40:26] IAS infrastructure as a service you have more responsibility you as the as the uh consumer you have more responsibility when you're using IAS model when you're using pass model you have less responsibility [07:40:40] less responsibility okay so just remember this box what this let's say you want to deploy an application what option you have uh [07:40:52] I'll I'll draw one more box for onrem okay on premises that means your own data center so what options you have when you want to host an application when there is there was no cloud the [07:41:05] only option that we had was on-prem right so what you used to do when when you were when when we were using on-rem you had to had your own server physical server right on top of that server you'll have to deploy the operating [07:41:19] operating system or Linux operating system whichever. On top of that you need to deploy a runtime. What is a runtime? Runtime is a runtime. What is a runtime? Runtime is a is a is a framework which is used to uh [07:41:32] run your application in simple terms. Okay. So your developer might be writing Okay. So your developer might be writing application inn net or java or python whatever or or node. So there are different different runtimes available [07:41:45] right. So if my developer is writing uh the application inn net I need to have net framework installed net runtime installed. Okay if my developer is writing application in java I need to have java installed similarly python or [07:42:00] node whatever so this also I have to install net if my application is written in net and on top of that I'll be having actual files of my application. So when you're using on-prem you're responsible for everything from bringing physical [07:42:15] server installing operating system on top of it installing net framework on top of it and then bringing your files that means copying or adding your files responsibility when you go for on-prem now when cloud introduced cloud was [07:42:30] introduced in different uh models like infrastructure as service pass as a service so behind the scenes we still have the physical server and infrastructure service we still have the physical server. What is this physical [07:42:43] whose responsibility? Uh when you're using cloud physical server is the responsibility of the cloud provider. If you're using cloud the physical server is the responsibility of cloud provider. All right. Now you have the option you [07:42:58] have the flexibility to choose whether you want to use Windows OS or Linux OS. OS. So if you're using infrastructure as a service, Windows OS is my responsibility. That means the license which which is required for Windows [07:43:13] The monthly patching that I'll be doing is my responsibility. The runtime that Let's say I go forn net or java whatever. Okay. So, net installation of [07:43:25] net is also my responsibility. Then again files obviously the application go for infrastructure as service out of the four boxes the three boxes are your responsibility. The operating system, the framework and the files. [07:43:39] Okay. Then if you move to p platform as a service, the physical server the the state setup will be same. The physical server is still there. Now it's it machine or what. Right? And then operating system is still there. You [07:43:55] just have to tell the provider that I want to use Windows or Linux. The framework is still there. What your responsibility as a when you're using p model is only the files. So you just focus on development that's [07:44:09] So you just focus on development that's all the last box the I mean from the top the first box only the files is your responsibility rest three are the responsibilities of the provider so when you use on-prem [07:44:24] everything is your responsibility from scratch when you're using cloud uh or infrastructure as a service the physical server becomes the provider's the operating system is your respons responsibility. The framework that you [07:44:39] The files that you want to install on top of uh uh files are nothing but the want to install or deploy on top of that Windows operating system or Linux operating system is your responsibility. In p you are only responsible for [07:44:55] development. The infrastructure, the entire infrastructure, the platform is the provider's responsibility. Okay. So that's the difference between virtual machine and app service. App service is a path service. So what we [07:45:09] are responsible for is the the files that we need that we need to uh deploy. You create an Azure app service and then just push your files into that app [07:45:22] All right. Pankage is saying please explain runtime. Runtime is the framework punkage. Okay. So runtime is the framework as I mentioned here net java python node. So in order to install or [07:45:37] host any application your developer will be writing an application in certain language right in simple term it's a language which your developer is using uh to to write your application he can be use he might be using python he might [07:45:50] be use he might be using python he might be using net car might be using java host that application I need to have that framework installed that runtime installed on my machine and if I install [07:46:03] that runtime runtime is like a run time which helps your application to run. All right. Clear. Okay. So what we did when we installed the virtual machine we provided we we [07:46:20] informed the server the service provider the cloud that we need Windows operating system and then on top of it whatever we had to do we did like we installed IIS then we copied our files. Right now next month when there's patching I will be [07:46:34] physical infra is still uh cloud provider's responsibilities. So now now let's see uh demon let let me demonstrate how you can use Azure app service to host the same application that we are hosting on a machine on on a [07:46:49] virtual machine the same application which is hosted here. Now I'll host the same application on an app service. All right. So in order to create an app service, you need to search for app service in the s search bar. So I'll [07:47:03] search for app service here. All right. I click on app service. This is the first one app service. So I'll click on the app service and then I app. [07:47:16] All right. Now as usual whichever resource you are deploying on Azure where Azure will be charging and a resource group where this where the resources for this service will be deployed. So I select AZ305 RG01 where [07:47:32] my resources will be deployed. Then the instance name instance name is the web app name okay so what web app name you want. Let's go with simply learn. This should be globally unique. Okay. So if I go for simply learn, you [07:47:44] see uh this name is not available. That means someone has already deployed a web app with this name. All right. So what I do, I just add some random number uh on on on front of it. All right. And this is the runtime stack that I was saying [07:47:59] whether you want to use net, you want to use Java, you want to use Python. All you need to install when you want to host an app. But when you're using a pass service, you just need to tell the provider that I want this runtime Python [07:48:16] and they will install Python. I want this runtime node and they will install node. So they are making sure that your platform is ready. You just need to bring your code. That's all. So if I [07:48:28] select net 10, net 10 will be installed on top of Windows operating system. So what I'm telling the provider is install Windows operating system. on top of that install.net. All right. And then the region where [07:48:41] your uh where you want to deploy the app service. So I I'll be mostly I'll be using central India for all of my servers. Sorry all of my services. So I'm using central India here. Okay. And then there is a plan. Plan is the skew [07:48:57] on um on the basis of which Azure will decide uh how much to charge. So there are different plans available. So there are different different plans available. You [07:49:10] can select whatever you want. So if I click on explore pricing plan, these are the different plans available. So it decides how much RAM you'll be getting, how much CPUs you'll be getting, right? You can go for premium plan which will [07:49:24] give you one virtual CPU and four uh GB requirement, you can choose whatever you want. All right. uh for some [07:49:36] plans the the prices are also the estimated prices are also mentioned. All right. Now since this is just for demo purpose so I'll go for standard or uh basic since that that that will cost me less. So we have standard plan as well. [07:49:52] less. So we have standard plan as well. Standard S1 now consider this plan as just the amount of RAM you'll be getting amount of uh CPUs you'll be getting. All right. and how much it will charge you how much Azure will charge you for that [07:50:07] particular uh RAM it's not like that once you choose and it will it will stay like this if you in future if you want to change the plan you can change it let's say I'm not satisfied with [07:50:20] standard the performance of standard S1 so if I want to go for premium I can go okay I can switch any point in time that's the that is the the benefit that you get in cloud so you see the benefit Benefit number three, the feature number [07:50:34] three, scalability. So right now when I'm deploying the service, I'm selecting a different plan and in future if I need a different plan, I can do that. Okay. All right. So I I'm selecting standard S1 for low cost as of now. All right. [07:50:49] And this is the name of plan. So this is the name. You can uh give whatever name you want. So this is the default name or uh a random name that name that Azure is name, you can you can give. So this is my simply learn uh app service plan 01. [07:51:06] Okay. You can give whatever name you want. All right. Now once that is defined that's all. If you don't want to touch any other uh uh tab that's fine. [07:51:18] You just click on review create and your app service will be created. But you can associate or create database here. If you want you can uh so you can have your uh CI/CD pipeline as I mentioned here key features DevOps integration. So if [07:51:35] you have a CI/CD pipeline you can integrate uh with C CI/CD pipeline as well. If you want to integrate it with network you can do that. All right. If you want to have uh a different service which will be monitoring uh this web app [07:51:51] you can uh enable that. I'm not enabling it. We have a dedicated chapter for monitoring. So I'll keep it for that. All right, that's all. You can associate it with database, you can associate it with CI/CD pipeline here, right? If you [07:52:05] have a network and you want to integrate your app service with network, you can do that from here. If you want to enable monitoring, you can enable it from here. anything. Just I'm going with the default setting. I just uh in the [07:52:20] monitoring section I just u change the radio button to no that's all and then I can click on review create and I click on create all right so it will start deploying my app service [07:52:49] I want to select standard or maybe basic. [07:53:03] standard now and uh it's it's now going to the deployment page. In 5 minutes your app service will be up and ready. All right. So I can browse my app service from here. As a end user if you want to go to YouTube how do you go? You [07:53:17] type dubdubdubdub.youtube.com on your browser. Right? So this is where this is the address where YouTube lives. Similarly for your app you have an address uh where your application is is living. Here you can see the domain. So [07:53:31] this is the address where your application is living. Simply learn 5689.eites.net. So here we have our app running. Okay. In sometime you should see your app. Now what we have done we have just made sure [07:53:44] that platform is ready. We still haven't pushed our code. We have not added our code. What did we do when we when we uh worked with virtual machine? We deployed the virtual machine right on top of it. We deployed the in uh IIS [07:54:00] role and then we copied our file. So, so far in app service what we have done, we have done this part. We still have not copied our files. So, we need to copy that. All right. We need to copy that. [07:54:15] So you see when I browse that that endpoint that URL it says my web app is running but waiting for the content. So I still haven't published my content yet. Now for web app there are different different ways to publish the content. [07:54:30] One one way is to use the DevOps way of of publishing the content. Another way is to use the CLI to publish the content. So there are different different ways to publish the content but for our use case uh it's a simple [07:54:46] website which which we are using. So what we can do we can use the graphical way app service editor. I can open the editor. So it gives me the access uh [07:54:58] access to the file system where I can simply upload my files. Remember what we did with virtual machine. We deployed the IIS and then we copied our files. So we have to do the same thing with with the app service as well. So I need to [07:55:10] copy that file. So in order to copy what what Azure has done, Azure has given you the access to the file system. So under the development tools you have app service editor and from here you can open the editor and uh you can copy and [07:55:27] paste your files here. Okay. So let we have to wait until this is So let we have to wait until this is fully loaded. It takes s some time and in any point in time if you want to change the plan the app service plan you [07:55:41] have the option here under app service plan you have scale up scale out. Okay. So when you want to scale up you can change from basic to share to basic 2 to basic 3 to premium. So if you feel that the traffic which is coming to my [07:55:55] the traffic which is coming to my application uh is not served properly or served very slow. So that could be because you only have 1.75 GB of RAM. So it might take lot of time for processing a particular request. So [07:56:10] if you feel that at any point in time you can change your your plan. Now remember if you go for premium plan the cost will increase okay depending on which plan you are choosing and the amount of memory you're getting your [07:56:24] amount of memory you're getting your your cost may increase all right so now as you can see it's loaded and this is where did we copied our file under dubdubdub root right in virtual machine if I go to the virtual machine [07:56:37] we copied all of our file to dubdubdub root right similarly here also you have the dub dubdubdub root folder from where you can to where you can copy your file. [07:56:49] So what I can do I can delete this one the the default one and then I can right click and I can upload my simp my simple app files. So if I go to download and app files. So if I go to download and search for simple app [07:57:08] it. So this copy will be uploaded the files will be uploaded here right the index.html html this is the file which will be loaded. Now if I refresh my my endpoint, I should see the similar uh application here. [07:57:23] Okay, same website which is being loaded from virtual machine. Now it's being from virtual machine. Now it's being loaded from the uh app service as well. Clear you can also try to browse this and you [07:57:36] should see the same website being loaded. What is the advantage of using getting the SSL certificate free of cost. I mean the cost it's included in HTTPS uh which I need to buy separately if I'm [07:57:52] my virtual machine traffic is not secured. In order to secure that I need to buy a SSL certificate and obviously I need to buy a domain name as well since I'm directly hitting that at the IP address. Right? That thing is that is is [07:58:08] benefit when you're using path service. you already have HTTPS plus you have a domain name. You don't you're not hitting the website on on a particular IP address. You're getting a domain name separately [07:58:20] separately free of cost. Okay. All right. So for deploying the code it's very simple. You can go and you can place your since my website is quite basic so I can do that from the app [07:58:32] service editor. But if you want to deploy an entire code uh in that case you can make use of a web app command from from from where you can deploy the code. So a easy web app deploy or easy web app uh deploy is [07:58:48] the is the command that you can use. So this is the command that can be used in order to deploy entire source code. Okay. So your source code can be in in Okay. So your source code can be in in jar file or in in zip file and you can [07:59:01] deploy your source code. The example is also given over here right. If you want to deploy a war file uh this is the this is the command. If you want to deploy a zip file this is the command right. So there are different different uh ways to [07:59:14] deploy the code. If you want to use uh the command line way then this is these are this this is the command that you have. Okay. Apart from command line, you can also deploy using uh something known as Visual Studio Code. So from [07:59:29] known as Visual Studio Code. So from here also you can deploy the the the the source code. Apart from Visual Studio Code, there is another software from another IDE from Microsoft which is Visual Studio. From there also you can [07:59:43] ways to deploy the source code. Since our application is quite simple uh it's just a website. So I deployed using the graphical way which will be easier for graphical way which will be easier for freshers to understand. All right. [07:59:57] Um in future we have advanced topic as well. So once we are done with database well. So once we are done with database once we are done with uh the app service architecture. In the app service architecture we are going to deploy a a [08:00:11] fully looking app uh application. Okay. Uh so that's that's where you will understand how to deploy an entire source code or entire application >> Now we have come to the end of our session on a 305 designing Microsoft [08:00:28] Azure infrastructure solutions. Thanks for watching and keep practicing because cloud architecture is not just about knowing services and do not forget to subscribe simply learn for more such valuable courses.