---
title: 'Microsoft Azure Infrastructure Solutions AZ-305 Full Course 2026'
source: 'https://youtube.com/watch?v=zKWQbMruj2I'
video_id: 'zKWQbMruj2I'
date: 2026-08-08
duration_sec: 28919
---

# Microsoft Azure Infrastructure Solutions AZ-305 Full Course 2026

> Source: [Microsoft Azure Infrastructure Solutions AZ-305 Full Course 2026](https://youtube.com/watch?v=zKWQbMruj2I)

## Summary

This comprehensive course provides a deep dive into designing Microsoft Azure infrastructure solutions, specifically targeting the AZ-305 certification exam. It covers fundamental cloud concepts, identity and access management with Microsoft Entra ID, governance strategies using Azure Policy and RBAC, and a detailed comparison of compute services like Virtual Machines and App Service.

### Key Points

- **Cloud Computing Basics** [00:09] — Cloud computing delivers compute services (servers, storage, networking) over the internet on a pay-as-you-go model, eliminating the need for upfront capital expenditure on physical data centers.
- **Authentication vs. Authorization** [01:02:07] — Authentication verifies identity (e.g., username/password), while authorization determines what an authenticated user can do. Azure uses Microsoft Entra ID for both.
- **Zero Trust Model** [01:10:35] — The Zero Trust Model is a security framework based on 'never trust, always verify'. It requires continuous verification of every access request, regardless of origin.
- **Conditional Access Policies** [02:32:38] — Conditional Access is a premium Entra ID feature that allows you to create policies to grant or block access based on conditions like user location, device compliance, or sign-in risk.
- **Managed Identities** [03:10:37] — Managed Identities provide Azure resources (like VMs) with an automatically managed identity in Entra ID, allowing them to authenticate to other services without storing credentials in code.
- **Azure Key Vault** [03:42:18] — Azure Key Vault is a secure storage service for secrets, keys, and certificates, preventing sensitive information from being stored in application code or configuration files.
- **Azure Governance Hierarchy** [04:14:19] — Azure's governance hierarchy is Management Groups > Subscriptions > Resource Groups > Resources. Policies and RBAC roles can be applied at any scope and are inherited downwards.
- **Azure Policy** [04:58:45] — Azure Policy enforces organizational standards and compliance by evaluating resources against defined rules (e.g., restricting VM sizes or allowed regions).
- **Role-Based Access Control (RBAC)** [05:32:50] — RBAC (Role-Based Access Control) uses roles like Owner, Contributor, and Reader to grant granular permissions. Owner has full access, Contributor can manage resources but not assign roles, and Reader has view-only access.
- **Compute Services: VM vs. App Service** [07:36:24] — Virtual Machines (IaaS) offer full control over the OS and are ideal for legacy apps or custom configurations. App Service (PaaS) is a fully managed platform for web apps, where you only manage your code.

## Transcript

is important, but using them correctly is even more important. The real question is, is your cloud infrastructure secure, scalable, reliable or costefficient? Can your application handle more users? Can your
data stay protected? Can your system recover quickly if something goes wrong? Welcome to the session on a 305 designing Microsoft Azure infrastructure solutions. In this course, we will understand how businesses design cloud
infrastructure using Microsoft Azure. We will start with the basics of Azure infrastructure and understand why companies use cloud platforms to host applications, manage data and scale their services. Next, we will explore
important Azure concepts like subscriptions, resource groups, regions, availability, zones and governance. Then we will explore compute services like virtual machines, containers, app services and Kubernetes. These services
help businesses run applications based on their workload needs. Next, we will look at Azure storage and database solutions where businesses store files, backups, application data and structured information securely. We will also
understand networking concepts like virtual networks, subnets, load balancers, application gateways and private connectivity. These help cloud resources communicate safely and keep applications available. Finally, we will
explore monitoring, backup, disaster recovery, high availability and performance optimization because cloud architecture is not just about deployment. It is about designing systems that work reliably in the real
world. So before we begin our session, just a quick information guys. Simply learn offers a certification program in cloud computing and devops in collaboration with triple IT Bangalore. This program helps you master genai
devops and cloud tools across AWS, Azure and Google cloud through live online classes, integrated labs and real world projects. Here you will gain hands-on experience with tools like Docker, Kubernetes, Terraform, Genkins and
Cibible, AWS, Azure and Google Cloud and even build your portfolio with 30 plus hands-on project and three industry oriented capstone project. Here learners will also receive a program certificate and transcript from triple Bangalore
along with official Microsoft learn certificates in relevant Azure modules. The program also includes AI powered job assistance, rumé building, LinkedIn profile optimization, mock interviews and career support. All of this under
just one course. So now before we begin, let's have a short quiz question. And the question is, what is the main goal of Azure infrastructure design? And your options are option A to randomly deploy cloud services, option B to design
secure, scalable and reliable cloud solutions, option C to avoid cloud networking or the option D to remove security from applications. delivery of services. Now the first question that most of my student ask is
why do we need these services? Compute, storage. Do you guys know why do we need these services? Let's say there's no cloud. If there's no cloud and you want to host your website or an application, where do you host it?
application, where do you host it? So, if there's no cloud, we need to create a data center. Okay, we need to first have a data center before I or Windows Server, we need to have our data center. Now, what
do you think? How much charge or how much cost will I have to bear as a company or as an organization if I want to have my own data center? [snorts] First of all, I have to pay for the infra. I need to find a place and
infra. I need to find a place and imagine a uh imagine having a big big space in a city like Mumbai or Bangalore. How much you have to pay business? You'll have to pay for that infra.
You need to buy that that place first. You need to put your racks, your servers there. Then you need to think about the the power power supply. You need to
think about the redundant power supply since I don't want to rely on single since I don't want to rely on single power supply. Right? So this is the is power supply. Right? So this is the is the uh cost that you have to bear if you
do not go for cloud. But as Har is mentioned that we har is mention mentioning that we can go for colo. Yes you can go for collocation as well but for that as well someone has to have a data center. You can go for colo but
someone has to has a data center right? Someone should build a data center for you. Yeah. So that colo is like you're just renting spaces. So you're just renting the data uh you're just renting one or
two uh servers or you're just renting entire rack in that particular data center and you're putting your own servers there. So that's that is the meaning of co location right so that was also possible before cloud but after
that not everyone can afford of creating a or or developing or uh building a data center. So what happens the big companies like Amazon,
Google and Microsoft and there are a lot of others or all right so these big companies what they did they created data centers and they started providing the
and they started providing the computation services like compute storage database networking on rent. All right. So today when someone says that we need to move to cloud or we need to migrate to
cloud or we want to use cloud computing they're mostly mentioning that we want to use the AWS infra GCP infra Google infra or Microsoft Azure's infra or Oracle's infra depending on uh which part of world you are we need to use
their infra and deploy our computation resources all right so what is why do we need this computation resources compute resources like for example let's Say you have an idea and you need to use information
technology to bring that idea to life. That means you have a business. A simple example I can take is let's say Swiggy. So what is the idea behind this business? Deliver deliver food delivery service.
So when you use Swiggy, are you making the food? Obviously no. Someone else is making for you. So you're ordering it from their place, right? So what is this? This is like a food as a service. So it's again a uh cloud service right.
So you can say that it's it's a cloud kitchen from where you're ordering. So to build something like this whatever your idea is and you want to use uh your idea is and you want to use uh internet to deliver services.
So in order to use internet in order to develop or in order to bring my idea to life first of all what I need I need to hire a developer. Why do we need a developer? Developer
will write the application for me. So what is an application? Application is nothing but some files. So if you have ever developed a very simple HTML uh uh page or HTML website, static website, if you have developed that you know that an
application is nothing but list of files. There there will be a lot of files. If you're writing application inn net or Java or whatever you're just coding. If you're a developer, you might know better, but you're just coding. So
that code is saved in nothing but a file with some extension, with some extension, right? So in order to make sure that my right? So in order to make sure that my website is is is reachable to to my
customers or to my users who wants to deliver food or anything, whatever your idea is, I need need to keep this file somewhere and that somewhere is nothing somewhere and that somewhere is nothing but a server.
Now where will you place that server? You need to place that server in a data center. So as as Har mentioned, you can collo col you can get a collocation place in one of the data center. You'll be paying
one of the data center. You'll be paying some rent or you can simply launch the server on a cloud company. Now tell me what what what do you think what will be what what what do you think what will be the cost of buying a server from IBM or
from HP? What will be the cost of buying one server? Around $1,000, right? Around one lakh or two lakh or three lakh rupees depends on which company you go for and what configuration you want.
server, what server is? Server is nothing but a computer. So if you go today to buy a new laptop, what do you what do you see or uh which laptop you
buy? So what do you see in that laptop? You'll see the config, right? You'll see the storage, what is the SSD given, you'll see the processor, what processor is being used or being uh installed in
this laptop, right? You'll see memory, the RAM. So these are the three most important thing that we see. Similarly, server is like you can say a powerful computer which provides services. So you know the laptop is like for commercial
know the laptop is like for commercial use. That means for us just to uh do a use. That means for us just to uh do a meeting or do or or for entertainment purposes like I want to watch a movie, I can watch it on a on my laptop. I can do
some of my business business things. But you cannot host your website on laptop. Technically you can but your laptop is not as powerful as server to provide the services. Okay. So similarly similar to laptop you'll
server you'll be having some operating system in laptop you have an operating system right you have windows right so you you you go for Windows 11 nowadays
or if you're uh fond of Mac you'll go for Mac. So Mac has their own Macintosh. Apple has their own Macintosh operating system like or there's another uh
variant in market which is Linux right so on top of that server you'll be having an operating system what is an operating system operating system is the mediator between human beings and the uh hardware if I give you
a hard disk can you just see that hard disk and try to figure out what do we physically seeing that hard disk like Can you do that? [snorts] So right we need to connect that hard disk to the laptop.
How does the the laptop reads hard disk? Laptop has the operating system installed and that operating system can detect and read the hard disk and then we can identify what kind of files we have in that hard disk. Right? So
have in that hard disk. Right? So similarly here we deploy OS on top of similarly here we deploy OS on top of our server and then we keep our files.
like Swiggy and I also want to come up with a food delivery service, first of all I need to hire a developer or if you are a developer you can write your own code. But in order to host that application you need to have the server.
So using that server only you can host right now. In order to buy that server you have to spend a certain amount. let's say $1,000 and that amount is upfront cost. That is an upfront cost. When you say
upfront cost, that means I have to pay it now. Even before starting my business, I have to invest like $1,000 for one server. Now, tell me, you're buying one server and if that server goes down, what happens?
hosting your application on top of that you be able to reach your application or will your user will be able to reach the application? Obviously not right. If Swiggy is down, you won't be able to
anything from Swiggy. So I cannot rely on one server. Why do I need to buy another server? Just to make sure that if one server goes down, my application is reachable from the second server.
from the second server. So instead of $1,000, I need to spend $2,000 for two servers. So that's an upfront cost. And this upfront cost is nothing but capital expenditure for your business capex. Okay.
Now for for an individual user who or for an startup for a startup investing this amount could be huge. So what they can do they can simply launch portal.azio.com azio.com
portal.azio.com azio.com cloud create a server deploy their and that's all their their website is live. What is cloud computing? If you have a laptop and if you have an internet
laptop and if you have an internet connection you can get the server the storage the networking through that internet through the internet. That's all that's cloud computing. Cloud computing refers to the delivery of
inter delivery of compute services over the internet. services are nothing but you want in order to host a website you would need uh storage, you would need RAM, you would need CPU. So all these services
are given to you over the internet. You don't spend spend this much of amount up front. So you're saving already you're saving $2,000. Right? Now here you deploy two servers, five servers, doesn't matter. On cloud
you deploy two servers, five servers, 10 server. You're not paying $2,000 upfront. That means right now I'm not paying $2,000. So when I'll be paying, I'll be paying as per my use. Pay as you go. So this month, if I'm using five
servers, I'll have to pay for the five servers. Next month, if I don't require five servers, I'll remove two servers and I'll pay for three servers only. Pay as you go model. What is pay as you go? It's like your
electricity, right? So, every month do you get the right? So, every month do you get the similar bill for your electricity? Depends on your usage, right? In summer, we use air condition, uh coolers and all
those stuff. So, we pay more in summer, but in winter, do we pay more? Totally depends on your consumption, right? So, that's nothing but the pay as you go approach. Pay as you go. As much as you use, you pay for that. If you use
10 servers, 20 servers, for that much, you'll pay more. If you use only one server, you'll pay for only one server. Okay. I hope you have understood what cloud computing is and why do why you will be
using cloud computing. Okay. All right. computing? Cost optimization. As I mentioned that uh if you want to use two servers, three servers, you use that. So
depends totally depends on your requirement. You'll be using two servers, three servers, right? So it helps you to achieve the cloud uh uh achieve the cost optimization, right? Optimize the cost. I'm not paying up
front everything. I'll be paying according to my use. performance according to my use. performance efficiency very quickly you can uh get the performance increase the performance of your app right I want two
servers I want more CPU I can I can do that I want more RAMs I can change my change u the amount of RAM assigned to my compute service right so all those thing you can do very quickly apart from that accessibility
want to come up with your with your IT business or business using it. Where you'll be creating or deploying your server, you will be creating or
deploying your server depends on wherever you you are. You let's say I stay in Mumbai and I want to I have an idea and I want to come up with a service. So I'll be searching a place in Mumbai itself
and if my user base in is is in US I need to go to US and there I have to deploy my server in one of the data center right so with cloud it has become very easy I can deploy wherever I want depending on uh let's say I want to
deploy a server so in cloud it's it's quite is known as virtual machine so I'll click on create create virtual machine and And here you see if you want to deploy it in US you can select US,
east, US, west. If you want to deploy it in Australia you can select Australia. you need? You just need an internet connection and you can deploy wherever you want. Wherever Azure has it presence, right? I want to deploy in
Europe. I can go for Europe. I want to deploy in uh UK. I can go for UK. Right? So these are the different these are the benefits of using cloud computing. These benefits you cannot get when you're deploying everything on prem. Okay.
deploying everything on prem. Okay. Reliability uh flexibility. So cloud is reliable. Why it's reliable? Because they by default monitor it. Okay. Uh by default monitoring as in it's not like that they
will take actions on your behalf. Only if you configure they can take actions on your behalf but if you don't configure uh they'll not they'll not take that action right. So cloud is reliable, flexible, you can deploy where
similar to accessibility, you can deploy wherever you want. Whatever size of uh RAM, depends totally on your requirement. And security whatever data
you you are keeping on cloud uh by default is it is secured. You don't need to worry about security. Why? because what I'm putting in my uh
storage account in my storage Microsoft is automatically encrypting that. What is like uh a security algorithm
uh a security algorithm which is making your data unreadable. which is making your data unreadable. Okay, sorry. &gt;&gt; So sec uh encrypt encrypting is a way is a security algorithm which is making
your data whatever data you're putting on cloud unreadable that means when I'm putting a data in in your own laptop where do you add your where do you store your data we have hard disk right
solid state drive or hard disk in that hard disk we keep our data so if you remove that hard disk from your laptop and attach it to another laptop. Can you and attach it to another laptop. Can you read the hard disk or no?
If I remove the hard disk that I have over here, remove it from laptop number one and connect it to laptop number two, will I be able to read my data? Yes. Right? I'll be able to read my data. So, similarly, when I'm putting data in
nothing new. Cloud is also using hardress drive or solid state drive to keep your data. So, what happens when you keep your data in cloud? It goes to center, they'll be having servers or
sand storage. And in that storage, your data is stored. So if someone goes there who has the physical access to the data center, if someone goes to that hard disk, take out the hard disk, connect it to our laptop,
where's the security then? He or she will be able to read the data. Right? Similar to this scenario, if someone goes to the cloud, take out the hard disk where your data is stored, connect that hard drive to its to his own
laptop, he'll also be be able to read that data, right? So to avoid this situation, what every cloud provider is doing is encrypting your data. What is the meaning of encryption? Whatever you're writing, you're writing ABC. So
you're writing, you're writing ABC. So that is stored in an encryption format. Okay? So if someone is removing that hard disk and connecting that hard disk to its own laptop, he or she won't be able to read the data unless and until
able to read the data unless and until that data is decrypt. decryption, we require the encryption and decryption keys. So Microsoft stores
keys. The uh you have the option to use your own keys as well. Right? So this is one of the benefit that we have in the cloud. Even if the data is even if the device where your data is stored is stolen, the data is secure. No one will
be able to read it unless and until they decrypt it. Okay. encrypted. Doesn't matter what cloud provider you're using. [snorts]
Okay. Now what is Microsoft Azio? Microsoft Azio as you know is the leading cloud provider from Microsoft. So Microsoft is the owner and Microsoft So Microsoft is the owner and Microsoft has created lot of data centers and
those services are given to you as uh as a service. Whenever we talk about cloud you will be hearing something a term known as as a service. So Microsoft Azure is a cloud provider. It's a leading cloud provider which
offers 200 products and cloud services to you to the users so that they can to you to the users so that they can bring their own idea to life. Okay.
well. So you you might uh see me going uh mute a lot of time. Okay. So just bear with me. Maybe tomorrow I I'll I'll feel better. Microsoft Azure is a leading cloud
provider available in the market which offers around 200 products. So this is the second I mean if you go 5 years back Microsoft Azure was the second leading cloud provider but now if you see we have like 55 45 uh ratio in the market.
have like 55 45 uh ratio in the market. The competitor to Microsoft Azure is AWS. Depends on which area or which part of world you are. you would see that AWS is used more or Microsoft Azure is used
more depend on which part of land I I stay in Malaysia so in Malaysia I see a lot of opportunities for Microsoft Azure whereas if you stay in Bangalore side in India in Bangalore side you would see AWS requirement more so totally depends
on which part of area you are if if you are staying in Middle East Saudi or Dubai you would see Oracle being used for okay so totally depends on which part of area you are but it doesn't matter that uh
which cloud you are learning if you learn one cloud you'll automatically understand the second cloud cuz services are are are same the only difference is Microsoft might be having few different services AWS might be having few
different services the names for those services are changed like in Microsoft Azure we say virtual machine whereas in AWS they say uh elastic cloud compute
In Google they say compute engine. So totally depends uh which cloud you're using. Services are same the names are different. Okay.
whatever benefits we have we have discussed for cloud computing same benefits applies here. As you can see, security, cost effective, scalability, data recovery, flexibility. So all the benefits you'll get on every cloud.
You're using Microsoft as your same benefits. You have security, cost effective, data recovery, scalability, flexibility. But then the question arise flexibility. But then the question arise if all clouds have the same benefits
uh why should I use Azure over AWS or why should I use AWS over Azure or why should I use GCP or why should I learn Azure or why should I learn uh AWS so that question only I have only one
so that question only I have only one answer to that question that if you are already familiar with Microsoft product or let's say as a company if I'm already using Microsoft products which most company are. If I'm
already using Microsoft product, I can crack a good deal with Microsoft. If I want to use Azure, if you're using Microsoft products, it's possible that your company is already Microsoft partner. So they can crack a
good deal and they can get get a good discount uh with Microsoft uh they if if they want to use Azure right right AWS benefits you like uh if you are
already I mean Microsoft Azure started late as compared to AWS AWS was the first cloud in the market so that's why AWS has had lot of shares if you go 5 years back so if you are already with Amazon and if
your sales team can crack a good deal with AWS, your company might be using AWS. If your Microsoft partner in your company can crack a good deal with Microsoft Azure, they will be using Microsoft Azure. Another way is if let's
say your company is getting a new project and in that project they will be hiring few people. So they will be hiring people and those people are familiar familiar with Azure. So for that particular project, your company
will go with Azure. If your company is launching another project and they're hiring people and they see that yeah, we have lot of professionals who who understand AWS. So for that project, they'll go for AWS. I've seen this in
lot of companies. For my own company, we have few services When I raised this question to my manager, why do we why do I why are we using two different services? So they said that whatever developer we have in
this project they are familiar with Azure they're familiar with net so they are familiar or more aligned to white m towards Microsoft project so that totally depends on your on company by company scenario which cloud you'll see
company scenario which cloud you'll see more okay but AWS and Azure are the top more okay but AWS and Azure are the top contender GCP is also coming up right so these are three these three are the top contenders in the market so if you're
choosing Azure uh you'll definitely ely land a job and you'll get a good good land a job and you'll get a good good pay as well. Okay. So the two things that we didn't discuss in the benefit is scalability and data
recovery. So what is scalability? Scalability is a way to add or remove the instances from your solution. So let's say I have from your solution. So let's say I have a website.
host this website. How do I decide how many servers I should be uh launching on many servers I should be uh launching on Azure and on how many servers I should be launching my website or installing my website? How do I decide that? I can't
decide when when the website is new. You cannot predict the amount of traffic your product is going to receive. Can you predict that? Obviously no. So what you'll do, you'll start with less number of servers. Let's say I'll start with
two two servers and suddenly my marketing team has done and suddenly my marketing team has done a quite fantastic job and promoted my a quite fantastic job and promoted my website on on some on some popular show.
So as soon as my as my website was promoted, I saw the spike in the traffic. So in that case if the traffic is more can you u can your two servers handle all all
all that all that traffic obviously no depends on what what configuration you have right so as soon as the traffic as the traffic increases I need to add extra servers so
increases I need to add extra servers so that adding or removing of extra servers is known as scalability either adding the services or removing the adding the services or removing the services is known as scalability.
All right. So there are two types of scalability horizontal and vertical. So scalability horizontal and vertical. So you can increase the configuration that you can increase the configuration that means you can scale up.
Right now let's say you have 2 GB of RAM and uh four virtual CPUs. So you want to increase the config that means I want now 16 GB of RAM and eight virtual CPUs.
So this kind of scaling is known as scale up or scale down from 16 to 4 GB and two virtual CPUs. Right? So you are either increasing or decreasing. So that is known as scale up. If you're
increasing that is known as scale up. If you're decreasing that is known as scale Similarly, if you're adding the number of instances, that means you're adding extra servers. So, you're scaling out.
You're decreasing the number of servers. You're scaling in. Okay? When someone says scale up, that means you're increasing the size, the means you're increasing the size, the configuration, amount of RAM.
configuration, amount of RAM. If someone says scale in sorry scale down then you're decreasing the amount you're decreasing the configuration. When someone says scale out you are adding number of instances. Someone says
scale in that means you're removing the extra instances. Okay? Doesn't matter if you remember scale up scale out nothing. You just need to remember scalability. Scalability means adding extra instances or increasing the configuration or
decreasing the configuration. That's all. Okay. Data recovery. all. Okay. Data recovery. Uh by default there's no data recovery. You need to configure it. But when it comes to cloud, it's very easy to
configure the data recovery. So as we progress in our Azure journey, we will have one chapter where you'll understand how you can recover your data in case uh there's a failure or in the in case there's a loss of data, how can you
recover it? Okay. So data recovery is very simple when it comes to cloud. [snorts] Cost effective and security we have already discussed right. Salman is asking difference between scalability and flexibility. You are flexible to
deploy in any region. So any cloud gives you option to deploy your ser services in different regions like I can deploy in India, I can deploy
in US, I can deploy in Australia. So depends on my requirement I can deploy it anywhere wherever Azure has its presence. So that is flexibility. You're flexible enough to deploy in any region plus you are flexible enough to deploy
plus you are flexible enough to deploy in any size of of the server any configuration which is provided right. Scalability is removing the extra instances. Now a very good example of scalability
Now a very good example of scalability is the Amazon e-commerce website for uh shopping? shopping? So every year
Amazon comes up with a sale, right? What what that sale is known as? Great Indian what that sale is known as? Great Indian something
No, we have the sale, right? Great Indian festival or something, right? So during that sale, what do you think? The traffic will be more towards Amazon or traffic will be more towards Amazon or the traffic will be less.
platform, do you think the internet traffic will be high or will be low during the sale period? It will be high. Right? So when the sale when when sale is announced, you know that for 4 days we need extra servers.
Since that 4 days we have sales. So we might have lot of traffic. So we know we can predict. So if we have lot of traffic we can add the extra instances instances and then when sale is done after 4 days
obviously the traffic will reduce to normal we'll have normal traffic so we can reduce the number of servers now I don't know uh how old are you but the first sale that flipkart announced big billion something
the first sale was a flop why because flipkart didn't scaled its servers and it was it it failed for the first day. So they had to increase or add one
more day there. So they will be adding the scaling uh they they have to add the servers when when they are receiving lot of traffic. Okay, of traffic. Okay, [snorts]
screen. Okay. So these are the Microsoft Azure benefits to the business when they are opting out for the Microsoft Azure. Sisha is asking horizontal vertical scaling bins. I just explained scale up
scale out right. [snorts] So when you're scaling like this what is this horizontal right or sorry this is vertical right? So you're adding or you're increasing the configuration of your your server. So earlier you were
using let's say 2GB now you're using 4 GB that means you you now you're using 4 GB that means you you have added 2GB RAM extra so that is known as vertical scaling whereas horizontal scaling is you're adding
extra instances you had one instance you added two instance so now you have total three instance so now you have total three instance this is known as uh horizontal scaling
this is known as uh horizontal scaling here.
So, what skills are we going to cover in A305? Now, AZ305 has a study guide. So, A305? Now, AZ305 has a study guide. So, let me just launch.
If I go to a 305 here, not GitHub. exam I would ask you or I would encourage you to please uh go to this
website. Okay, this is the official page from Microsoft. So whenever you are sitting before sitting for the exam just go to this.
sitting for the exam just go to this. Okay just go to this page. So what this page is having this page if you go to this page you will see [snorts] the learn path.
Okay. What is this learning path? The learning path is the modules learning path is the modules the flow or the topics that Microsoft expects you to know before sitting for the exam. So what skills are we going to
cover? Now I'm not covering the skills from from the PPT. What skills I'm going to cover? I will be following this Microsoft learn path since this is up to Microsoft learn path since this is up to date as per the current exam. Okay. So
what are we going to cover? We are going to cover all this uh topics. Whatever is mentioned like if I go for the first module which is design, identity, governance and monitor solution. If I click on it, uh
this is what we are going to cover. So everything is mentioned here topic by topic what you should be knowing before sitting for the exam. sitting for the exam. Okay. Now if I go one page back and if
you see here somewhere you should see the study guide. So what is the study the study guide. So what is the study guide? The study guide is uh is again a guide? The study guide is uh is again a web page where Microsoft has defined
web page where Microsoft has defined uh what skills will be measured. Compute, network, storage, monitoring, security. If I scroll down, every skills is given certain percentage like every module is given a certain percentage. So
from identity governance and monitoring solutions you can expect around 30% of questions from storage you can expect around 20 25 from business continuity you can expect expect around 15 to 20 right similarly
from infrastructure solution you can expect around 35%. So what you should be knowing you should be knowing some logging solution like routing logs where you can keep the logs where you what monitoring solutions Azure has to offer
what is an authentication solution right so all this topic by topic is is is provided in this study guide now same thing is for any certificate that every certificate is mentioned over
preparing for before sitting for an exam, make sure you uh glance here to see if you know this, if you know this, if you know this, right? If you do not know this, please try to see what this topic is where you can see you can see
topic is where you can see you can see it in the learn path. Right? it in the learn path. Right? All right. So that's what this these are the skills that we are going to cover. Okay.
Everything whatever mention is here we we are going to cover. Now why I I ask you to visit here because if you see Microsoft keeps on adding or removing Microsoft keeps on adding or removing something from their exam
every 6 month or 1 year right so if you read this this note if you read this note says the exam will be updated on April 17 2026. When was the April 17th?
April 17 2026. When was the April 17th? Yesterday. So something is changed. is changed, you should review this study guide.
Okay. So if let's say next time, next year or after 6 month, if they don't year or after 6 month, if they don't want this particular topic uh in a 305, so they will remove it from from the study guide. So you don't need to need
that uh need to know that. So whatever Microsoft is making changes they will put that in the study guide. Okay. So I went through the old study guide and the new study guide but I don't see lot of things have been
changed. The only thing that Microsoft changed was audience profile. Okay. So it's a minor change from the syllabus wise. Nothing changed. Only audience profile change. So if you
see the audience profile here, you should have all the audience profile should have all the audience profile somewhere.
here. So this part is only changed. Now what Microsoft added as as far as I know Microsoft only added this. This wasn't part of the old study guide. Okay. But that's that thing which is added course wise nothing changed. your topic wise I
have went through the old and new study guide nothing is changed everything is guide nothing is changed everything is same from the course point of view okay uh there the link is shared if you see the chat box okay I already shared the
the chat box okay I already shared the link
now if you see the simply learn syllabus we have like uh we have divided this into 15 different topics but I'm not going to cover it topic by topic as defined here 15 everything I'll be covering or
summarizing in 10 or 11 topics okay whatever is mentioned over here everything is summarized in 11 topics since we have 10 days so I' I've summarized everything whatever we have
summarized everything whatever we have here from identity until uh infra everything I have sum summarized into 11 topics. Okay. Since we have to do the the the uh projects as well. So we need to
uh projects as well. So we need to complete everything in 10 days. Whatever Microsoft is asking me to cover, we will be covering everything which is defined in the study guide. Clear?
brings to you? the course uh is bringing you the u some projects some co-signed projects some assisted practices. So what these assisted practices are assisted practices is is the word documents that I'll be adding to the
LMS. So you will be having access to that. You can download it. It's like a stepbystep guide on how to do the demonstration on how to do the hands-on. So those assisted practice I'll be adding. We will be having case studies.
We will be having course and projects, ebooks. Microsoft has stopped providing ebooks. Microsoft has stopped providing ebooks. So your ebook is the learn path. So this is your ebook. Okay. The first link that I shared, please follow that
link. Uh or simply search for easy 305 in your search engine and you'll be landed to that page. Okay. So here you can find your learn path. Now why I'm
exam you have access to the learn path. So when you sit for the exam uh you can access the learn path learn path from there. So if you are stuck or if you
you can go to the learn path and you can try to read it there within the exam itself can try to find out the answer. So access is there. That's why I want you to go through the learn path. So you know in which page what service can get
me the answer. All right. getting with this course. Now when it comes to the exam a305
the name is design Microsoft as your infrastructure solution you will be having around 60 to 70 multiple choice question totally depends on your set of paper that you're getting. So when I set for the exam I had like
for 53 questions multiple choice question and rest of the questions were question and rest of the questions were under case studies. Okay. So total 60 to 70 questions you'll be having including case studies.
Then the um the time that you'll be getting is 2 hours. So you'll be getting 120 minutes to complete the exam. And then in order to pass the exam uh you'll have to get 700 that means 70%
of passing mark out of 100 you'll have to have you'll out of 100 you'll have to have you'll have to get 700 and uh have to get 700 and uh there and once you click on submit there
only you'll come to know the result you don't have to wait for the result okay everything is proctored everything is computer basis so once you submit uh it will calculate the software will calculate your percentage and you'll
pass you need to have 700 you need to get 700. Clear? different languages. English, Japanese, Chinese. So whichever language you
Chinese. So whichever language you prefer, you can uh book exam in that language. Now where to book the exam from? [snorts] So if you go to the 305 page from there itself you have the option to book the
exam. Okay. So if you are in India you select your region wherever you are. Then click on uh then click on schedule exam and from there it will take you to
exam and from there it will take you to the Pearson VE page and from there you can schedule you can select the date when you want to sit for the exam. All those stuff you can do in a Pearson VOE site.
All right. [snorts] From the Microsoft page itself, you can book the exam. So that's all about the introduction about cloud computing, about simply learn and about easy 305. Any questions on the basics yet?
platform as a service, and software as a service? Now this is uh important to understand uh it's a it's a basic cloud computing service model. Okay. Um
when you are dealing with different compute services you'll have to understand the different between is PA and SAS. All right. So what is before going on break let me answer this quickly uh
and then uh if I'm not able to complete this in in in the next 7 minutes we'll continue this since this is important to understand is pass and s
understand is pass and s is pass and s from for me is pass and s from for me or for you to understand is paz and s or for you to understand is paz and s from a305 point of view okay I'm not
going at the A900 level since this is something which we cover in a 900 uh and a 104 as well. I'm not going into that level. So I'm I'm explaining it to you level. So I'm I'm explaining it to you from a 305 point of view. Okay. [snorts]
The full form is quite simple. Infrastructure as a service, platform as Infrastructure as a service, platform as a service and software as a service. All right. Now what is infrastructure as a service? So in infrastructure as a
service your responsibility is more your as in you are the customer of Azure or any cloud provider. So your responsibility here is more in p your responsibility is less as compared to infrastructure as a service.
Uh we are not saying that there's no responsibility there is responsibility. Okay. So how does this is pas and sas are are defined is defined in a shared
responsibility model. People people think that since we are using cloud everything is cloud provider's responsibility. That's not correct. We are sharing responsibility with the
cloud provider. Okay. So what is our responsibility? What is cloud provider's responsibility? What is cloud provider's responsibility? that will be defined depending on the model depending on the service model you are selecting
infrastructure service pass platform service software service now just to explain this in a simple term [snorts] I just gave you an example of of suiki let's say you have an you have a similar idea and you want to use uh internet for
your business so what you need to do you need to come up with an application first what is an application in simple term application is nothing but collection of files where your developer or if you are a developer you will be
developing the application. So how do you write how do you code an app code an application? You simply open a file if whatever you are using you simply start writing your code and that code is
written in a in a file. So you'll be having multiple files or you having single file depending on how big your application is. Now in order to store this or save these files, I need a server.
Okay. So when I'm when I'm selecting cloud within the cloud, I have two options to select from. Infrastructure as a service or platform as a service. In infrastructure as a service, the hardware server
hardware server is cloud provider's responsibility. Okay. Uh if you remember the data center model where you have to spend $1,000 or
whatever the server cost is [snorts] you have to spend that up front. We are not using on-prem model right. So we are not going to spend this upfront. So what we are doing we are using cloud. See even in cloud there is a hardware server.
Someone has bought the hardware server. Who has bought? In our case it will be So if I'm using infrastructure as a service, this hardware server is cloud provider's responsibility. Now within that
hardware server, the cloud provider will be deploying their own operating system. So in case of Microsoft Azure, they are deploying
HyperV. HyperV is nothing but an operating system. It's a hypervisor which allows them to create multiple uh machines on or multiple virtual machines on top of this hardware server. Okay. So this HyperV is also their
responsibility. [snorts] All right. Now on top of this HyperV I will be creating my virtual server. This is a physical server which is cloud provider's responsibility. The operating system which is again cloud provider's
responsibility. on top of this hyperV I will be creating my server my virtual will be creating my server my virtual server let's call it virtual machine 01
responsibility now within this virtual machine 01 I will be deciding whether to go for Windows operating system or Linux operating system that's I'll have to decide as as a customer I have to decide this okay so here what uh what Microsoft
what we will do we will select let's say we select Windows operating system and on top of that Windows operating system you have to use the runtime or
the framework. So when you are writing an application your developer will write an application your developer will write that application ill in certain code in some code right he might be using Java he might be using python might be using
net whatever he's using you need to ask your developer or if you're a developer you should know that that there is framework I need to I need to use that language so in order to host the application I need to have this runtime
host my application where I want to add my files. So on top of Windows operating system, you will be deploying the .NET framework. Okay. And on top of that Net Framework, you
will then host your application. That means you will add your files. So what is my responsibility as a user here? My responsibility is the operating system that I'm choosing, Windows operating system. My responsibility is
the framework that I'm choosing,Net. My responsibilities is to take care of my application. That means I have to either hire a developer or if I'm a developer hire a developer or if I'm a developer I'll have to develop the code.
Now tell me every month Microsoft launches the update right? you know the update update patching
receive the update for the applications that you have installed right every that you have installed right every month or every week whatever so since this is hosted on cloud the Windows operating system on my virtual
machine who will be responsible to patch that your responsibility. You as a user, Azure will not patch it
for you. Okay? Yes, there are way to ask Azure to patch. Uh but Azure by default operating system. So you have to patch it. Then if there is a new version available for net, who will be installing that new version? Again you.
So whatever above HyperV is our responsibility. So infrastructure as a service model requires more responsibility uh from from the user. Whereas PA model is same there will be
physical hardware server on top of it there will be any on top of it there will be any hypervisor like HyperV or ESXi whatever cloud providers is using. There will be virtual machine there will be a
virtual machine there will be a framework like net java whatever when I'm using p all this stuff becomes the cloud provider's responsibility what is my responsibility when when I'm using p the
the application code is my responsibility so if I'm a developer p is something that I'll be choosing why because I'll get more time to focus on the development the virtual machine whether it's Linux
or operate or Windows it's Microsoft responsibility to patch your responsibility uh reduces when you use the paz model the p service model clear
entire software is given to you as a service like M365 Microsoft 365 you're using Google Drive. So Google Drive is a software as a storage service given to you. What are your responsibility when you are using Google Drive?
What is your responsibility when you're using Google Drive? Just adding data and sharing that data with whoever you want. That's all. That's your responsibility. So you're using that software entirely. Do you know where Google is hosting?
Where Google is saving? Whether it's saving in India, Australia, US, wherever how Google is storing that is is that something we need to bother about as a user obviously not so software as a service what is your
so software as a service what is your responsibility reduced entirely zero. using free version you can store up to 15 GB. If you need more you just subscribe for a plan that's all software as a service. Netflix software as a
service. Are we paying for each movie separately? No, we are buying a plan. Do we need to keep a CD of all the movies? No. We just subscribe to a plan. We watch our our content, right? Software as a
service. What is the infrastructure as a and a platform part of Netflix? Do you know CDVD was CDVD? What what what was required?
We need the CD player or the DVD player, right? So, we need to buy it. So, I am responsible for the hardware. I am responsible for bringing the CD or DVD. I'm responsible for placing that CD DVD within the DVD driver uh DVD reader and
then I can enjoy my movie. If I don't have a CD of one particular movie, I don't have the CD. Right? The CD DVD player becomes the infrastructure as a service part in case of movies and all. What could be the
platform as a service part? Uh I cannot think of any here. Okay. you go for infrastructure service model. Who will do the service of CDVD? Obviously I have to do as a as a as as a owner of that. Right. In Netflix,
however they are hosting it, I don't care. I just pay them. I enjoy their service. That's all. Clear? Any questions on this? We will revisit this when we are on the compute section. Okay.
So let's move on to our first topic which is uh authentication and authorization. So from the study guide we will we are from the study guide we will we are covering uh this topic
this module design identity and governance and monitoring solutions and there we are covering authentication and authorization. This is the uh these are the topics that we are going to cover. Okay.
Okay. And from the learn path covering this one design identity governance and monitor solution. So
first three topic will be identity and governance. Monitoring we'll cover once we have done uh covering all the services. So at the end of the uh I mean monitor solutions. Right now we are
starting with identity and governance. Okay. [snorts] Now before I start I need an answer from you. How many of you have worked with uh adds active directory domain services or if you're from the Linux back background uh how many of you
Linux back background uh how many of you know what LDAP server is? What are these two services? And those who uh who are freshers please uh wait I'll explain what I'm uh what this topic is about. Okay. Okay. So what
is ADS? Those who have worked with active directory what is this? So what are these services? Adds an LDAP.
Okay, never mind. Those who don't know, please pay attention. Okay, those who haven't worked with any of these services, you might have uh these services, you might have uh account right in OTT platforms like
Netflix or Amazon Prime. Do you hold the account? Amazon Prime. Do you hold the account? How many of you have account in Netflix?
order to access or watch any any web series or a movie, what do you do first? You go to dubdubdubnetface.com, right? If you're using uh laptop, you go to this website. What happens? First thing what it ask does it allow directly
to watch the movie or there is something which we need to do? Login, right? So we need to provide our credentials. login we need to provide our username and password. So what happens when we provide username
and password? Netflix service checks your username and password. It checks whether you are providing correct username and password. If you're providing correct username and password, you are allowed.
If you provide wrong username and password, it may deny deny you the entry and you won't be able to access those services. Right? So this process of providing username and password and identifying that username and password
is known as authentication. That means That means I am not I am Netflix is authenticating me checking me whether the credential that
I have provided is correct or not. Okay. So what is authentication? Okay. So what is authentication? Authentication is a way to to check someone with a certain credential. Apart from credential, how you can check
someone? You can check them with with their card, smart card. If let's say you work, you go to your office. When you go to your office, there is a door. In that door, you have to there's a reader where you
you have to there's a reader where you have to place your your smart card. Those who are working might know Right? You have to place your smart card. Without smart card, there's no entry. You cannot go in. Right? Unless
your company has no security. Most of the company do have security and they do provide the smart card to their uh employees. And in order to enter the building, you need to place that smart card. So when you place that smart card,
the identity service that is deployed within that building checks whether your smart card is valid or not. If it's valid, you can go in. If it's not valid, valid, you can go in. If it's not valid, you cannot go in. Okay. So, what runs
you cannot go in. Okay. So, what runs behind uh behind that authentication is this kind of services adds or LDAP. They runs behind the services and they checks whether your username or password
is correct or not. You use your laptop, you [snorts] use your company laptop or provide your username and password correct or not. We need to provide
nowadays Microsoft has made it made it compulsory to enter your [snorts] address. So once you provide your email address and password then only you can enter your laptop and do whatever changes you
want. So this part of verifying the user the application or whatever you have whoever needs access
is known as authentication. Authentication is a is a is a process of verifying a person person is nothing but a user or application to see whether the
credentials provided are correct or not. Okay. So that authentication is done by the services. Then
once you are in once you're inside the building which flow you can access which flow you cannot access that path that part is cannot access that path that part is known as authorization.
[snorts] different plans, right? You subscribe for different different plans. We have mobile plans, we have standard plan, and then we have HD plan, right? I don't know the current plans, but this was the plans we we had, right? So you
have uh mobile plan where when you log into Netflix, you can only watch Netflix within I mean within your mobile app. Then you have standard plan where you can uh watch in two different screens
uh at at the same time and then you have some plan where you can watch in four some plan where you can watch in four different screen. So once you log in once Netflix authenticates you once you're inside the application that means
you have got the access now it totally depends on the plan that you have subscribed to depends on that you're authorized to watch either on mobile or on two screens at a time or on four screens at a time. So that part of
application and then checking what you are authorized to do, right? So like in cloud world, cloud world you are logging into Azure portal. So that login thing is nothing but
authentication and then once you are logged into that application, what you can do? Can you create another user? Are you authorized to create another user? Can you delete the existing users? Are you authorized to do that? So to check
what you can do, what can what you cannot do is known as the process of checking what you can do, what you cannot do is authorization. Okay? Clear? What is authentication? What is
authorization? Is that clear? Now this is basic of any identity uh any identity and access management system.
All right. [snorts] So, authentication and authorization. If you want to implement in your organization, you need some kind of identity and access management system. If I want to implement authentication
and authorization in my organization, I need some kind of AM service. AM stands for identity and access management. Okay. So if I want to uh
implement that [snorts] let's say I'm not using cloud I'm using on-prem network. So in my on-prem data center I can either use active directory center I can either use active directory domain services or if I'm good with
domain services or if I'm good with Linux I'll be using LDAP services. How do you use these services? You need to have a server first hardware server or or a virtual server whatever if you're using on-prem
server on top of that hardware server depends on whether you are using virtualization or directly physical server you'll have to have Windows OS if you want to use ADDS or Linux OS if you if you want to
use LDAP okay on top of that on top of Windows operating system you'll be deploying the active directory domain services role and there on top of it services role and there on top of it you will be promoting this server to
creating your domain and once it's promoted and your domain is ready then promoted and your domain is ready then you can go ahead and create your users users groups whatever you want you can add computers and all right [snorts] so
this is all all all the stuff you need to do when you're doing onrem that means to do when you're doing onrem that means your own data enter everything you need to do. You need to bring a server. You need to install the
or uh install the operating system. Then you need to install the adds role on top need to promote it to domain controller. Once everything is done, then only Once everything is done, then only you'll be able to create users and
uh groups and uh add computers. groups and uh add computers. Okay. Now if you want to use Azure for IM, Azure has Microsoft Entra ID which is
Azure has Microsoft Entra ID which is nothing but a cloud-based AM service. When we say cloud-based I uh AM service, we don't need to bother about all this stuff. We don't need our own server. We don't need to install Windows operating
system. We don't need to install ADS on top of it and then promote it to domain. top of it and then promote it to domain. Everything will be handled by Microsoft. What we can do if you're using Microsoft Enra ID, as I mentioned, Microsoft Enra
Enra ID, as I mentioned, Microsoft Enra ID is a cloudbased AM tool. You sign up and start using it. You just sign up for Azure service for Azure portal and start creating your users. Don't need to bother about all this stuff.
scratch, then you you are responsible for everything from scratch. If you want to go for cloud, we have we [snorts] can sign up and we have access to Microsoft enter ID. We can start creating users
uh directly. Okay, [snorts] is IM clear? It was just basically just giving you an It was just basically just giving you an overview of IM. So what is ZTM? ZTM
stands for zero trust model. Yeah. Now zero trust model is not a service. It's zero trust model is not a service. It's not a policy. It's just a framework uh based on the principle of never trust always verified. [snorts]
Now if you go back few years like before cloud if you go back 10 years cloud if you go back 10 years how do we used to consider the security? If you go back 10 years, if you go 10 years back, uh at that point in time, we
had the parimeter network where you used to keep the firewall, uh IDS, IPS, all these devices we used to keep in a parimeter network before anyone can get into our network, uh the traffic was verified by these devices. And once the
traffic considered as safe, then it can go inside our network. then it can access our servers whatever servers we had right so this is how we used to keep not using firewall now we still using firewall but back in the days the
were kept in the demilitarized zone in the parimeter zone here but now we need to protect
we need to protect our identities Since if everything is cloud now uh 90% of the workload is in cloud only the banking the airport the airline those mostly are still using onrem but 85 to 90% traffic is already
uh in the cloud. Now if someone logs in and if he is authorized to do something and if let's say the login credentials are compromised then we are gone right.
So with the changing pattern a new model came in which is known as zero trust model. So what zero trust model does it's just a framework which based on this
principle never trust always verify. You have to always verify whatever request is coming in. Okay. So what are the key principles? We And in order to implement this zero trust model, you need to have certain IM
trust model, you need to have certain IM service in place in your organization. So zero trust model based on this principles like verify the request first. So every access request whatever request is coming in. So if someone is
entering your building, you need to verify that you need to verify uh him or her. How do we verify? We use smart card, we use biometrics, whatever. Right? We need to verify that. Then second principle we have is least
privilege. What what is least privilege? Now in in an organization or in an office building, we have different different areas like we have common areas like cafeterias, like gaming zone, right? And
then we have some sensitive areas. So in IT we have data center, right? &gt;&gt; In airport, if you go to airport, we have immigration. Then before immigration, we have the check-in area. So check-in area is not
sensitive area. Anyone can go there and and and do the check-in. So it's like a and and do the check-in. So it's like a common area. So we need to provide the least privilege to the users. Like common areas everyone can go but
common areas everyone can go but sensitive areas only authorized person should go. So when we are using smart card based authentication we will divide the smart card into different types like everyone will have in uh whoever has the
smart card they will have access to the common areas whereas only authorized people will have access to the sensitive areas like data center building itself right like [snorts] knock room what is knock room is network
operation center where from where you can monitor your your client's network, your own network. So those areas are sensitive. Why? Why? Because no rooms have access to the servers, remote access to the servers.
So I cannot allow everyone to go to the knock room. So we need to uh give the lease privilege that means only people belonging to the knock team they can enter the knock rooms. Lease privilege,
right? Micro segmentation. Micro segmentation is like dividing the [snorts] uh area or the network into smaller uh area or the network into smaller smaller uh VLANs or smaller smaller
segments so that we can keep our monitoring uh continuous. We need to divide our area into smaller segment. Like [snorts] here we can have
certain CCTVs. Here we can have certain CCTVs. Here we can have certain CCTV. So this is my one area. This is another area. This is another area sensitive area where I can have multiple CCTVs. Uh this is knock room. So within that room
we can have uh three or four different uh CCTVs from different different uh CCTVs from different different angles. Right? So I need to divide my angles. Right? So I need to divide my uh let's say network or areas into micro
segments. All right. So that I can have a continuous monitoring. So these are few principles that we have uh in zero trust model. Now again I'm saying zero trust model is not a
saying zero trust model is not a security uh policy or is not a a tool it's just a framework which defines some principles and you need to make sure when you're implementing IM or you're designing IM you need to keep these
things in mind all right verific
have a team who can continuously monitor and always assume breach. What do you mean by assume breach? We have to do continuous monitoring and we have to assume assume breach and continuous monitoring works hand in
hand. Assume breach as in let's say we have applied all the zero trust models that doesn't means you are secure. Why it doesn't means we are secure. It's possible that someone who has the access has lost the credential.
has uh the credentials he was he or she was having uh was compromised and some person who should not be having his or her credential has got the credential and now roaming freely everywhere. Right? So every time we need to assume
breach now how do we assume breach? What what is the meaning of this assume assume breach? [snorts] How many of you uses uh Gmail?
you users? I'm sure 90% of people are using Gmail, right? So, have you ever tried logging into Gmail from a different device, from a from a totally new device? Back in the days, we used to have cyber cafe, but I don't know if we
we still have the cyber cafes. But let's say you change your mobile and you log in from from a new mobile. So, what happens when you log into your Gmail account from a new mobile? You get a message right? you tried uh
from a different mobile please uh please uh approve your notification in already existing mobile or your YouTube application or or wherever right so we get that kind of message so what is that Gmail is assuming
that it's not you who's trying to login so it's not you who's trying to login so that's why Gmail is uh sending you that popup please notify uh please uh approve please approve so that's That is the
please approve so that's That is the meaning of assume breach. Okay. So even though you have applied all the principles of zero trust model, you need to make sure or you need to assume breach so that
breach so that wrong person or a hacker cannot get into your account. It's possible that my username is compromised since Gmail we have used or we have given our email id to lot of people. So email id is already
compromised. Now what hackers can do they can launch different kind of different kind of attack against the username since username is already uh public right everyone knows my email id obviously not everyone knows but who I
have shared my email ID with banks with e-commerce applications with Netflix with with different different service providers who knows who's selling my data right so if someone is has sold my data my uh uh email ID is already in
public so hackers can get that get my email id and try to launch different different kind of attack so that's why we have to assume reach if you log into your Gmail from a new location from a new device you would see that popup
new device you would see that popup all right so in order to make sure that [snorts] your data is secured your access is secured you need to follow the zero trust model framework so what does zero trust model says in
so what does zero trust model says in short Never trust always verify right even though when you're logging into logging in from new mobile you're providing correct username you're providing correct password still
providing correct password still Gmail is popping uh popping up to you to Gmail is popping uh popping up to you to approve that that login right even though you have provided correct username password Gmail is thinking that
it's it might be a breach clear so So that's what zero trust model is. Now how to implement zero trust model? You need to have some kind of IM service. So in Azure we have Microsoft Entra ID. [snorts] So what is identity
and access management? Identity and access management is just a service which helps you to implement authentication and authorization. It al it also gives you a way to manage accounts. Uh some IM also gives you the
way to do the reporting right. I want to fetch a report of my users who log in when from where. So all those stuff identity and access management gives you. In simple what is identity and access management? You have an identity
access management? You have an identity that identity is is some object which that identity is is some object which requires the access to your resources. Okay. Simple ter Identity is a is an object which requires access to the
resources. In basics [snorts] of cloud computing, we understand we understood what cloud computing is. What is cloud computing? I'm again going back to the basics. Cloud computing is a way to deliver
cloud uh to deliver the compute services over internet. Why you will be using over internet. Why you will be using cloud? to deploy the resources. What those resources are? You need to deploy server. You need to deploy database. You
need to deploy storage. So these are your resources. Now how are you going to deploy these resources? You are deploying these resources. So you are the object who is deploying these resources. So you are
the identity. Whether or whether you can deploy or cannot deploy, we need to first identify this guy who wants to deploy. So he needs to go to portal.azio.com com and our AM service will identify
that user will identify that identity will identify that object who's trying to coming into our uh system right after
identifying we will authenticate I mean not we the identity and access management service will authenticate that user whether the username and password provides provided are correct or not okay Then the authorization kicks
or not okay Then the authorization kicks in. Once you are inside the cloud, deploy server? Can you deploy database? Can you deploy storage? Can you do that? Authorization
account management. You want to create few new users. You can do that using any IM service. Whatever IMC services you have developed, access control. what a user can do, cannot do, you can define that using access control. Okay. And
then auditing and reporting. Any IM service uh most of the IM service gives service uh most of the IM service gives you the auditing and reporting them. So what is IM? Is that clear? Now in Azure,
we have Microsoft Enra ID. So Microsoft Enra ID is the service uh which is a cloud-based identity service. So as I mentioned earlier, you don't need to deploy a server or anything. You just sign up for uh Azure
anything. You just sign up for uh Azure and you have your Microsoft Entra ID. We to sign up for Azure. That means you need to create your account on Azure and once you have created your account, you already have Microsoft Entra. So it's a
cloud sorry it's a cloud-based identity and access management solution. All right. So it gives you centralized centralized single Microsoft Entra tenant, you can simply use that tenant and start
creating your users. Right? If someone is already using Active Directory domain synchronize their users with Microsoft Enter ID. So, Microsoft enter ID
previously known as Azure Active Directory it was launched in Directory it was launched in 2013 or 15 I'm not sure on the exact year but during that time it was launched before that Microsoft had this
service active directory domain services which uh the short form for that is adds which people were using on prem cloud started people were using on prem cloud started gaining prop popularity after 2010 or
2011. I think 2006 or 7 AWS got launched and I think 2006 or 7 AWS got launched and 101 Microsoft came in and by 15 it was 101 Microsoft came in and by 15 it was all popular 1516. Okay. So before that
when cloud was not there people were already using ADDS for their on-prem identity and access management services. So those those organization who are already having ADDS and they want to use Microsoft Enra ID
then which identity and access management service will do the authentication will do the authorization will do the verification. So you have adds you have Microsoft enter ID both are IM service which will
enter ID both are IM service which will do the authentication which will uh if you are resetting password which will be considered as as the uh having the highest control. So all those question were arises arised if you use two
services. So what Microsoft did Microsoft created Microsoft entra connect. So it's a tool which you can install on your on-prem server and using
that you can synchronize your on-prem users to Microsoft Entra ID. Okay. So if I have hundreds of users on prem and if I use Microsoft Entra
connect all hundreds of user will be synchronized to Microsoft Enra ID. Okay. So whatever user you have over here, all users will be synchronized.
Instead of recreating user in Microsoft Enra ID, you use this tool and synchronize your users. That's all. All right. [clears throat] So that option
Microsoft uh gave to the people who are already using Microsoft uh active directory domain services. Microsoft created a tool. You deploy that tool on a server and you start synchronizing your user. If you create a
new user, that new user will also get synchronized. All right. [snorts] So, Microsoft Enra ID in short is a cloud-based identity and access management solution that you can use
once you sign up to the Azure. It's free of cost. Obviously, there are different plans and pricing, but uh when you start, it's free of cost. Okay. So how to see Microsoft enter ID in action. [snorts]
[snorts] If I go to uh Azure portal. All right. [snorts] Now in Azure portal before I show you the Microsoft Endra ID let me show you the Microsoft Endra ID let me just explain or give you the tour of
Azure portal. Okay. So I'll do it from scratch. Let me Okay. So I'll do it from scratch. Let me sign out.
thing that you need to do whenever you want to interact with Azure platform, want to interact with Azure platform, you need to go to portal.azure.com.
be going when you want to log into Azure or when you want to interact with Azure or when you want to interact with Azure portal. when I click on uh when I press enter first thing that Microsoft Azure portal or Microsoft is doing is what
it's asking what is this process I went to portal.asure.com your.com and it directed me to this what it is doing right now authentication. right now authentication. Okay, it is asking me to prove my
Okay, it is asking me to prove my identity. So this step that we are going that we are doing right now is authentication. All right. So authentication is the process of
verifying and identifying the identities. This is my username. How do we usually authenticate? We ask for the username. So my username is already selected here. Already mentioned here. If it's not
mentioned, I can simply provide my email ID. Whatever my email ID is, right? So this is my email ID. For example, I'm providing that. I click on next. It will ask me for the password. I provide the password. I click on sign in. Okay. Once
If my username and password are correct, I'll be inside. So I'll I'm in my application. All right. Now this is Azure portal. Now
those who do not have access to Azure portal, what you can do is [snorts] either if you want to use your own account uh unrestricted account, you can sign up for free tier.
You search for Azure feed free tier and you will see uh the Microsoft Azure page in Google or Bing. You just search for Azure free tier.
providing and there you'll be having a button which says get started with Azure. Click on it. Once you go once you click on it, you can click on try Azure for free. Once you click on try Azure for free, it will
you click on try Azure for free, it will ask your email ID and your password. Right? So, you need to provide your uh Microsoft email ID. If you do not have one, you can create one from here. So, whatever email ID you have, you provide
that. Now, in my case, I have already utilized. So, if I enter my email address, uh it will trigger it will say that I'm not eligible. Why? because I've already used it. Okay.
it will say I'm not eligible. So, uh in order to utilize Microsoft Entra ID, sorry, in order to use Azure free tier, you
need to have a unique email address that you have not used before, right?
email address that you have not used before. Right. [snorts] So here it says I'm not eligible. Why? Because I've already utilized it. So I can sign up for a pay as you go go pricing. I cannot sign up for a free tier. What I'll do?
I'll see if I have any other email address. But I'm not signing up since apart from email address, you also need a unique credit card, right? So I don't have a credit card. I've already utilized all my credit card. So if I
have any other email address, I can use that. So let me see. [snorts]
able to demonstrate how you can come up with the but it it's very basic you just provide your email address once you provide the email address you can then uh provide your details like your mobile number that should also be unique, your
email address that should also be the one that you have never used before and the credit card which you have never used before. So, Microsoft Azure has this restriction where you cannot [snorts] use the same email twice to
avail the free services. So, you need to use new email every time. But with new email, you need to have a new credit card as well as you need to have a u a different mobile number that you have never used before.
All right. AWS I think doesn't have that issue. With AWS, you just need a new email address. You can use the same credit card again. Okay. So that's how you can sign up for a free tier from here. Once you have the
free tier um you can then sign into portal.azio.com. So once you get your free tier you can then sign in by going to portal.azio.com
providing your email address that you use to sign up and your password. That's all. All right. Now let me introduce you or give you a tour to Azure portal. So [snorts] the first thing that you see on left hand side here
uh where where you see nine dots. So this nine dots is a cloud menu. Okay. What what do what what is the cloud menu? This is a newly uh uh new feature or or a new option that Microsoft has added where you can launch different
Microsoft portal directly from here. So let's say I want to work with GitHub. So the GitHub. I want to work with Intune, I click on Inune, it will take me to the Intune. Right? So different different portals. shortcut to that portal
portals. shortcut to that portal Microsoft has just added here doesn't u it is helpful when you want to switch between different u different portals if you want to uh go to GitHub from here
click on this shortcut and go to that right after the cloud menu the second thing that you that you see with the three lines uh is known as [snorts]
uh portal menu. So if I click on it, you'll see the menu over here from where you'll see the menu over here from where you can go to you create any resource. Uh some shortcuts are given, right? Go to homepage, go to dashboard page, uh go
to Microsoft Enra ID, go to monitor services, right? So shortcuts are given. So you can launch whichever service you want. I want to work with virtual machine. I click on this portal menu. I launch the virtual machine and I go to
Similarly, any service that that we want to use, we we go there and we can use it. Okay. [snorts] Next, after that, you have this it's the brand name. So, if you click on it, you'll be landed to the homepage.
Whatever page you have selected, you'll be landed to there. All right? It's just uh a shortcut to go to the to the homepage or to the dashboard whichever you have selected. Then, if you go right hand side, you have the search bar.
If I want to, we will be using this search bar every time we want to work with any service. So this search bar will help me to search for different resources. Like if I just type virtual, it will list out all the services which
has uh virtual in it. Like I want to work with virtual machine. I search for click on virtual machine. It will be landed to the virtual machine page. From here I can create virtual machine. I can stop existing virtual machine if I want.
start, restart, whatever. Right? Similarly, if I search for database, so anything related with with this particular keyword will be uh placed over here, right? Database watcher, SAP solution, whatever I search
for SQL, all the SQL related services will be provided. Right? So, this is just the search bar, a shortcut you can say to search and go to any service that you want. Then if you go on again on right hand side you
you go on again on right hand side you have copilot. What is copilot guys? So copilot is a gen AI tool from Microsoft right. So if I click on co c co c co-pilot within the browser itself I will get a way to chat with the
co-pilot. So if I have any issue like I want uh copilot to answer any of this any of the question like I just uh added hi it it gave me the response right I want copilot to create an ARM template
want copilot to create an ARM template for me me a give me a response depending on my prompt. So the better the prompt is the
better the response will be right. So it is now generating the template. I can use that template then right [snorts] apart from that it also has few bots kind of question already created. So if you click on it that will be the
prompt for for your copilot. So copilot option is is given there. If you want to utilize it for anything you can want to utilize it for anything you can utilize. So uh nowadays Gen AI is quite
utilize. So uh nowadays Gen AI is quite smart. Okay. So if you see this, it have created a template for me. I can now use this template. If I don't know how to deploy the template, I can again ask the copilot how do I deploy this template?
copilot how do I deploy this template? It can help me. Right? So anything I I It can help me. Right? So anything I I need
on your prompt. how good your prompt is, it will give you the answer. Now, obviously, I'm not saying that it's it's perfect. It can make uh mistakes, right? perfect. It can make uh mistakes, right? So, whatever you're using, uh use it
uh try it and then if it's wrong, ask it. Ask the copilot or the chat GPT again. Right? So, you see how how to deploy this. It has given you the the the steps, right? So nowadays it has become very easy to do the hands-on by
use by using chat GPT or copilot or whichever geni tool you prefer. Right? whichever geni tool you prefer. Right? So it's just a simple way instead of launching copilot in a different tab Microsoft has given you that uh option
within the portal itself. Then after copilot the next option or the next icon that we have is the cloud shell. So what is cloud shell? So if I
click on the cloud shell, it will launch the command line interface within the portal itself. So within the graphical portal.azio.com,
I have the option to launch the cloud shell directly. So what is this cloud shell? It will allow me to interact with the Azure platform using the commands. virtual machine, I need to use certain command. Now what that command is uh you
command. Now what that command is uh you need to uh rely on Microsoft documentation to get the command or you can take help as well. Right? So type help to learn more. Type a to use Azure CLI. Right? A VM stop and then the VM
name and all. If I give it will simply stop that VM. So these are the required stop that VM. So these are the required field. If I want to stop any a VM, it's just a way to interact with the Azure portal or Azure platform we can
say using command line. So you can use either the bash shell, the Linux shell or if you're more comfortable with power p PowerShell, you can switch to
PowerShell as well. Okay. So now if you see I have clicked on switch to PowerShell. this button right now it's showing as switch to bash but when you are in bash it will show switch to powershell so I clicked on that and now
I am in powershell so I can run the powershell commands now to interact with us your portal all right now if you want to restart the terminal I mean the cloud terminal you can click on restart and it will give
can click on restart and it will give you a new uh terminal right as as soon as I clicked on restart it is now requesting a new cloud shell requesting a new cloud shell All right. Then the next option that you
have is manage file. So you can upload or download files uh to cloud shell. So if I want to work with file, I can simply click on manage file upload. And if I want to upload any local file, I can upload it like for
example template.json. I want to upload it. It's uploaded right where it is it. It's uploaded right where it is uploaded to this path. So if I do ls now uploaded to this path. So if I do ls now here which is list you see template zone
here which is list you see template zone right. So this option gives you the way to upload or download. Now new session will simply give you a new powershell a new portal and then within that portal you'll get new cloud shell session.
Okay. So that's the option as well. Now after that we have a very basic visual studio editor. So if I click on editor, a visual studio will open. It's a very
basic visual studio editor. Okay, it's a file editor. So if I want to edit my files from here, I can do that. I don't need to switch between the desktop and the and the portal. I can simply if I if I have obviously it's
not featurerich. It's a very basic cloud shell that uh sorry file editor that you have. If you want to make any changes you can do from here, right? So if you want to close you go over here and you can close it.
You have the web preview as well. So for web preview uh if you let's say have deployed any basic application here and you want to see how it will look like when someone launch it from from from browser how it will look like you can
simply use the web preview from here. Okay. Then the settings like you just Okay. Then the settings like you just want to change text size, font or uh theme you you want dark theme, light theme. So all those things you can
change from setting. Then there's help like I want to see all the PowerShell command, all the all the CLI command. So I click on that. It will take me to the Microsoft documentation and here I see all the CLI related command. Okay, I
want to work with uh virtual machine. So I search for VM and it should give me I search for VM and it should give me the the VM related command. So this is you scroll down you'll see all the command that that are that you can use
for for VM. Okay. cloud shell we have a very simple notification uh tab. So what this
notification uh tab. So what this notification tab does um let's say I'm I'm working with or I'm deploying anything. So I'm deploying uh I'm I'm creating a resource group. Don't ask me what
resource group is. I'll I'll cover that in detail when we are on that topic. But I'm just explaining the notification tab right now. Okay. So if I search for resource group [snorts] and I create a new resource group or I delete an
existing one. So a notification will trigger like for example RG02 central India click on review create and click on create. So once the creation is
completed you see resource group create a notification will be triggered. So if I delete the same resource group another notification should trigger another notification should trigger which says resource group deleted.
come in like right now it's deleting resource group. Once the deletion is completed it will trigger delete. So whatever you are doing uh and if you want to monitor that you can come over here and you can see that all the events
that whatever you have you have the option to dismiss as well also no notification you cannot see the history there's no way to see the history okay then you have uh settings uh for the
then you have uh settings uh for the portal itself if you want to if you if you're part of multiple Microsoft entra ID You will see all the Microsoft Enra ID over here. If you want to switch between
switch from here. Right now I'm only part of one. If you're part of multiple, I have seen people who are part of multiple directories. I can show you that in my another account. So if I go to another account and click on
settings, you see I'm part of two different uh tenants, two different Microsoft Enter IDs. So if I want to switch between any of the Microsoft Enra ID, I can do that. How I can do that? I click on settings.
Settings will land me to this page and I can click on switch. It will be switched can click on switch. It will be switched to a new um the other directory. Right? So that you can do from settings. Apart from that you can you can uh change the
appearance like I want a dark theme. So a dark theme will be applied over here. I want a light theme. Light theme will be applied. This is just a normal language and region like you want English or any other language. Uh your
information like your email id and all if you want to uh get a notification right uh sign out and notification uh if you're not doing anything and if it's idle do you want to sign out when when inactive after 15 minutes if you're not
doing anything for 15 minutes it will automatically sign out. All right. So all those stuff you can do from the settings tab from the settings option. Then you have support and troubleshooting. So if you have any
issue with Microsoft Azure portal, you can search for it if they have the documentation. You'll see the documentation over here or from here also you can raise the ticket as well. So let's say my subscription is not
allowing me to deploy any resource. I can raise a ticket and I can ask Microsoft Azure team why it's not allowing me to deploy the resource. So they will come up with an answer like maybe your subscription is not eligible
or you don't have the kota kota whatever right. So you just uh can raise a ticket from here. Now remember this thing where to raise a ticket from you can either raise from support and troubleshooting option or you can raise it from uh your
subscription itself. All right. Now why I'm asking you to remember this because in interview if you are fresher uh the interviewer might ask how to raise a support ticket to Microsoft Azure team. Okay [snorts] then
if you want to provide any feedback to Azure team you can provide like I'm you're liking you're not liking it what you're not liking. So this feedback will you're not liking. So this feedback will will go to Microsoft team. Okay. Then
the last option that you have within the portal itself is your username. So this is your username. Uh you can switch directory or switch Microsoft enter ID from here as well. You can view your Microsoft account from here as well. All
right. So just to summarize, you have the shortcut to go to uh uh uh go to any other portal outside Azure. You have the option within Azure. If you want to
launch any service, there's a shortcut. If you want to go to homepage from any other uh page like for example, I'm here in the network page. I want to go back Azure here. It will take me to the homepage. Then you have the search bar
shortcut to reach any service. For example, I want to go to health page. I want to see the health. If I have access, I will be able to see it. Right? So, whatever shortcut uh to the services, you search for it and you go
to that service. Then you have copilot. You have cloud shell which is like a You have cloud shell which is like a like a uh an option to interact with azure platform using command line. You have
notifications. You have settings your appearance your language and all you can select in the settings or you can change in the setting. You have uh support and troubleshooting from where you can raise tickets related to Azure
portal itself. Then you have feedback and then you have your user detailing. right the user that you have logged in from right it's just a short tour to from right it's just a short tour to Azure portal how which will help you to
Azure portal how which will help you to navigate from u uh within the Azure portal itself right all right so now where do I see the Microsoft enter ID question for you guys I want to go to Microsoft enterra ID
I want to go to Microsoft enterra ID page how to go [snorts] how do I go to Microsoft enterra ID page page, right? We have the search option. We can search for Microsoft Enra ID from here
and go to Microsoft Enter ID or you have the portal menu here. From here, you can the portal menu here. From here, you can simply uh click on Microsoft Enra ID and you can go once you sign up for Azure, you have to
do nothing. You'll get Microsoft Entra ID for free. You don't have to pay ID for free. You don't have to pay anything. Okay.
identity and access management system which is free of cost. If you see here license, I have got the free license. So you have I have got the free license. So you have the Microsoft Entra ID free of cost. Uh
obviously with free of cost you'll have less features. There are different licenses available for Microsoft Enra ID. If you're going for free, there is certain limitation like I think you can create uh half a million records only
that that means half a million objects only. If you want more if you want to go above that you need to go for Microsoft Entra ID premium. Entra ID premium. So if I search for Microsoft Enra ID
this is the page where Microsoft has mentioned uh different features available in different plans. So there are like three or four plans. If you see we have premium P1, we have P2 and then Microsoft Entra suite. So these are the
three different plan. By default it's free. You don't have to pay anything. But if you want to use certain premium plans then you need to go for P1 or P2 or suite depending on what features you want. Now if I scroll down here you see
if you want Microsoft enter ID protection it's available here in P2 or Microsoft Enra ID suite. It's not available in free tier. All right. So
whatever is checked over here is available on the on on that particular available on the on on that particular plan not on free. Okay. So here are the plan not on free. Okay. So here are the limitation that you see with free tier.
[snorts] Uh it supports multiffactor authentication. It supports the single sign on. It supports the basic reporting. You can manage users and groups. Uh it also
supports the self-service password reset. It can also allow you to sync your on-prem directory users with Microsoft enter ID. So this can be done. But if I want let's say verified ID, it's not mentioned here. I won't be able
to use that. If I want to use identity protection, it's not mentioned there. I cannot use it with the free TM. Okay. So all these are premium uh plans. All these are premium features. So if you want to use those
features, you need to sign up for a features, you need to sign up for a premium t. All right. So in order to interact with Microsoft enter ID, I can search for Microsoft
Enra ID and I landed to that page. Okay. what what license I have whether Okay. what what license I have whether it's a it's a free license or a uh premium license will be mentioned under under your overview page uh within the
license section. Okay. So that's what Microsoft Entra ID Okay. So that's what Microsoft Entra ID is. Now Microsoft Enra ID comes with two is. Now Microsoft Enra ID comes with two different flavors B2B and B2C. Now since
it's 10:40 already I have only 20 minutes. So I'll cover B2B. I'll explain B2B and then we will stop for the question and answers. question and answers. Okay. So what is Microsoft Enra ID B2B?
Okay. So what is Microsoft Enra ID B2B? B2B stands for business to business. what does it mean business to business? Uh you have your Microsoft Entra ID. So
once you sign up for Azure, you'll get Microsoft Enter ID and you have a partner company who will be developing certain products or certain softwares for you. So you have your own enter ID. So this is your entry ID [snorts]
and you have your partner company who will be developing certain products for you. Now when you're developing certain when they are developing certain products you want them to host those products.
When I'm saying products I mean websites. So when they are developing that website for you you want to host you want them to host that website on your resources. So they will have their their developer
here. Now tell me this developer who belongs to the partner company the user account for their developer
will reside where in our entra ID or their entra id when you join a company let's say you join xyz company so that xyz company has its own IM service and
there's another company ABC company they have their own IM service so when you are joining XYZ company your account will be created in XYZ or ABC
so my account should be created in XYZ when I'm signing up for Netflix my account will be created in Netflix it's not going to be created in prime video right so similarly these three developers who are
developers who are uh employees of partner company their created in the partner company's entra and this is my entra our entra ID now if
and this is my entra our entra ID now if these guys wants access to my resources I have a virtual machine here I have storage here I have a database here they want to develop an application for me a product for me a website for me and they
need access to my resources So with zero trust model how are you going to provide the access? How can you access or let's say you want
to log into your enter ID and you want to access what happens first? What is trigger? First thing if I want to provide them the access what I need let me explain it from the portal. Okay. So if I go to the
portal, this is my entra ID with the name as your trading. So this is my entra ID. Okay. If I go to the manage section here, in the manage section, you see users. So if I click on users here, I'll see all the users which are part of
I'll see all the users which are part of my tenant which are part of my entra ID. These are all the users who are part of my entra ID. Okay. So this is Azure training which is my entra ID and these are the users who are part of it.
are the users who are part of it. I have another entra ID of my friend let's say my partner and they're good in development. So I want them to develop a re or develop a software for me but I want them to host that software in my
resources in my virtual machines. the virtual machine that we have now in order to provide them the access they have their account in partner entra ID they don't have account here so what I need to do first
what I need to ask what I can do one way is to create their account so what I'll do let's say this is user one this is user two this is user three so I'll come over here you see new user I click on new user I
create account user 01, user 02, user 03. So I can create an account for them. That's the one way. But now think from user point of view. Think from the user
point of view. If I create additional account for them, account for them, what is going to happen? The user needs to remember two different set of credentials.
they need to remember these credentials which they they are going to use to access my resources plus the they need to uh
remember the credentials for their own enter ID as well. enter ID as well. Now tell me as a security team member or Now tell me as a security team member or as an IM solution or IM team member is
it good to ask your employees or your users to remember more than one set of credential. Is it a good idea?
forget password. They can forget password. They can forget user ID. Since I might be using a different kind of user ID like if you see here I have different kind of user ID. Some company uses first name, last
name at the rate their company domain. Some uses first name and then surname different different companies have different different ways of coming up with the user ID. Right? So I don't want them to to remember two set of
credentials. What I can do? I can use B2B. This is my business. This is their business. So I'll use B2B here. What is B2B? Business to business. Microsoft Entra ID business to business. I can invite their user
to join my tenant. I can invite their user. If you click on I can invite their user. If you click on new user here, we have two options. new user here, we have two options. Create new user and invite external
Create new user and invite external user. So this invitation or inviting an external user will create an account here in my tenant. They don't need to remember two set of credentials. They can use the same email ID that they are
using, same user ID that they are using in their own tenant. They can use that and once they use that they can log into my tenant. How I uh well when I'm I'm I
was giving you the the tour I demonstrated this directories. Directories are nothing but the entra ID. You have your one
directory here. Apart from that you can have another directory as well. So once I invite them they will have the option to switch between the directories.
Okay. So what is B2B? B2B is a way or sorry external identities external object external users to your own tenant
to your own directory. Okay. So why we have B2B here to make things easier for the external employees. I don't want them to remember different set of password. They can use the same
password and they can log in uh to multiple tenants. Now it's possible that the partner company is developing software for different different clients software for different different clients like TCS. TCS develop what is TCS? TCS
is a consultancy consultancy firm, right? So they develop software for multiple partners. Now imagine you are asking your developer to remember password for all the tenants is going to first of all forget all
is going to first of all forget all forget most of the passwords right so to make it easier Microsoft came up with this B2B business to business now what is business to business how does it work we don't have to bother about it
why because we are using this as a service what what Microsoft is doing behind the scenes is not something we need to bother. Okay. But yeah, if you want to come up with your own B2B, you don't want to use Microsoft Enra ID, you
don't want to use Microsoft Enra ID, you you're using onrem services, you have active directory domain services, you need to create something known as federation server. So it works in the same way but uh lot of work is involved.
Microsoft has made it quite simple. Uh when it come to Microsoft Enra ID B2B, we just need to click on new user, invite external user, uh provide proper
email address, whatever the email address is and once the user accepts, he address is and once the user accepts, he or she will become part of my 10. All right. All right guys, so that's all about B2B.
need to cover. Obviously we cannot cover today so we will cover it tomorrow. Now what these topics are just to give you an overview. Uh apart from B2B we have another type of uh tenant in Microsoft entry ID which is B2C. I'll explain what
B2C is tomorrow. Then we have few premium features like conditional access, identity protection, access reviews. So these are the these are the premium features. If I go to the Microsoft Entra plans and and pricing uh
premium feature. It's not available with free tier. So in order to use conditional access you need to have premium at least premium P1. premium at least premium P1. Okay. Then there is identity protection.
So identity protection is also part of uh premium tier. Then access whatever we are discussing tomorrow uh is is uh falls under the premium features. In order to use that you need to have premium in place.
Then then we will discuss identities for uh applications. So manage identities discuss as your keyboard. So for the first half tomorrow we will able to complete our Microsoft uh entra ID and then we will discuss the
case study. Okay. So make sure you're re-watching second half of today uh before you're coming for the tomorrow's class so that you know the basics of
identity and access management uh what is entra ID what is B2B right all right is entra ID what is B2B right all right so what we have covered so far uh basics of cloud computing we have covered yesterday where we understood what cloud
computing is why do we need it in simple cloud computing is just the delivery of comput services. What are those compute services? Those compute services are servers like you can get CPU, RAM, storage, all those stuff. Apart from
that, you can get network, you can get databases, you can get uh different managed services. So all of the services you get as a service from cloud from cloud provider. So we see we saw that in the first half. In second half we jump
to Microsoft Entra ID where we understood understood what AM is. Why do we need AM? IM stands what AM is. Why do we need AM? IM stands for identity and access management where
if you want to manage your objects, your your ids, your identities. Identities are nothing but the users or the groups who requires access to your resources. So if you want to manage them, you have AM which stands for identity and access
management. Before seeing identity and access management, we covered the uh uh module the framework which defines how your identity and access management should be. ZTM stands for zero trust model. So it's just a framework which
defines how you can secure your AM solutions. Then we saw if we want to do uh if we want to implement identity and access management on cloud on Azure specifically what service we have? We have Microsoft Entra ID. So what is
cloud-based identity and access management service. You can call it as identity as a service. You don't need to deploy your server. You don't need to deploy the uh EDDDS on top of your
it to the domain controller. Everything is done for you. Everything is managed for you. Okay? So everything is managed and you're getting that as a service. Then Microsoft Enra ID comes with two different uh flavors B2B and B2C. We
have covered what B2B is. B2B stands for businessto business. So if if I have a company, this is my Microsoft Endra ID tenant and I want to invite or or provide access to a partner company or let's say I have company A, B, C and
XYZ. So these are the two companies I have. XYZ is my company. Whereas I uh have. XYZ is my company. Whereas I uh bought or uh I I bought ABC's business. So ABC is also my company. Now I want to provide all the users access to my
tenant. So I can use B2B here as well. This is another scenario where I can use B2B. All right. The next thing that we are going to discuss today is B2C. So let's go to the next topic which is Azure ADB2C. B2C
stands for business to consumer. All right. Before doing B2C, let's just uh right. Before doing B2C, let's just uh see the invitation one that we covered yesterday. Like if I want to invite any uh user who's not from my tenant and I
want to invite a user who belongs to another company. Doesn't matter if that another company. Doesn't matter if that company is using uh Microsoft Tendra ID or any other identity platform. The required thing is they should have their
users should have a valid email address. That's all. If they have the valid email address, we can invite them. All right. So how to invite? If I go to Microsoft Enra ID from the start menu from the portal menu if I click on Microsoft
Endra ID I'll be landed to this page. This is the homepage of Microsoft Enra ID. From here under manage section I can see users group. So if I want to manage users, create users, delete users, modify users, I have to go under the
manage section. So within that manage manage section we have users and groups. All right. So if I click on users here, I'll see I'll I'll get a list of all the talent. Okay. Now this is the user
Okay. Now this is the user who is an external user. This one if you see this user root cloud easy, this is an external user. Now you consider the same scenario which I dis which we discussed yesterday that
we can invite any user who belongs to any company doesn't matter whether they are using entra ID or they are using Google workspace or they are using AWS uh AM services we can invite anyone as long as they have a valid email. Okay.
So to see that in action, what I'll do? I'll simply delete this user. whenever you delete a user from Microsoft Endra ID, the user is there
for for 30 days. It's not getting deleted uh permanently. So you have to delete that permanently if uh if you know that you don't need that user account. Okay. In our case right now, this is just uh a a tenant, a test
tenant. It's not a production tenant. So, I deleted that user. Right? Now, I go back to all users. And in order to invite any user, I click on new user. Here under the users section, we have all users. There we have new user. So, I
click on new user. I click on create new user. If I want to create a user uh within my tenant within my Microsoft Enra ID, if I want to any external user from any other organization, I select this
option. All right. So I click on invite external users. I just provide the email external users. I just provide the email address.
providing that email address. Doesn't matter whether it's your company uh whether they are using Microsoft Enter ID, Google Workspace or it's a normal ID, Google Workspace or it's a normal email id. We can invite them. All right.
create. That's all. Your user will be invited. So you see here notification user invitation in progress. So a mail will be sent to user from your Microsoft Enra ID. Now if you see here uh in some time if you refresh you should see that
time if you refresh you should see that user here now how to verify whether this user is part of your tenant or uh external
tenant how to verify that so if you see this user type here you have different types of users this is important to understand member Member user that means your own your tenants user. This fabric admin is a member
user. This fabric admin is a member user. This is my tenants user. You see this one this is a guest user that means uh this is an outside user whom you have invited to your tenant. All right. Similarly root cloud easy. This is a
guest user outside user who you have invited to your tenant. All right. So remember there are three types of users. These questions often lands in the uh
exam. You have member user, you have guest user and you have uh ad sync user. All right. So there are three types of users you can see when you are dealing
with Microsoft enter. Member user, your own user, your company's user, your own user, your company's user, your tenants user, guest user, outside user, uh ad sync user, if you have an active directory domain services and you are
synchronizing that with Microsoft Enra ID, the users who have been synchronized ID, the users who have been synchronized will be the type of that user will be ad All right, clear.
clear. Then uh inviting a user is one step. The user who have you have whom you have invited should accept the invitation. If invitation, he or she won't be able to use the temp. Right? So what I do right
now, I go to Gmail, I log into my account.
Microsoft invitation. So similarly that user will also receive the invitation and he or she needs to accept that. So if I click on it I need to accept it. So in order to accept what I'll do I'll go to the in private window. I'll copy the
to the in private window. I'll copy the uh link Now why I'm doing this in in private so that uh in in the in this session I've
already logged in with the simply learn user. Okay. Okay. So I don't want to use the same session. So that's why I have triggered or open the in private window. All right. So it it's saying it will send me a a code to my email in order to
can click on send code and I'll receive the code in my Gmail account.
multiffactor authentication. like a confirmation that the person who's trying to log in is the same person. So 583 439. So I just go there and enter 583 439. So I just go there and enter it. 583
Okay, that's all. Now I will be logged in to uh
from here and just to confirm I have logged into the same tenant uh from from where I was invited to confirm that how how you can confirm you can go to Microsoft Enra ID. Now one more thing you need to remember
whenever um a new user account that's been created or new user who has been invited to your tenant has to complete the multiffactor authentication. So before I I give some information let's understand
many of you already know what multiffactor authentication is?
What is multiffactor authentication? Multiffactor authentication is like an additional form of authentication. Okay, I hope you know u what authentication is, right? You know what authentication is. Authentication is a process of
verifying the identities, right? So, how do you uh verify the identities? You that's what we provided here. Username and password already provided. But it's possible that username and password are compromised. So in order to avoid
uh allowing access to an unauthorized user, what do we do? We add an additional form of authentication, two form authentication or multiffactor authentication, one extra form of authentication.
Username and password you have to provide. Apart from that, prove your provide. Apart from that, prove your identity by entering the OTP or approving the authentication in the authenticator app
or if you have a gate or something where you have the fingerprint reader, you can ask them to provide the biometric authentication as well. authentication, MFA stands for multiffactor authentication. From
October 2024, Microsoft has made this mandatory. So you don't have to do nothing. I mean, you don't have to enable multiffactor authentication. It's by default enabled for all the users within your tenant.
Before October 2024, we had to enable multiffactor authentication from each and for each and every user. After October 2024, it has been made After October 2024, it has been made mandatory for all the users. Okay. So
whenever user logs in, Microsoft's collects some extra information from that user. Most probably it would be uh adding an account in Microsoft authenticator or any other authenticator app that you that you want to use. All
right. So whenever I create a new user, I need to do this setup every time whenever I'm uh logging in from a new user. So I click on next.
file. Let me log in again.
information that I need to install Microsoft authenticator. It's not mandatory that you need to use Microsoft authenticator. You can use another authenticator app as well. There are lot of authenticator apps available in the
market like Google authenticator, um, octa, last pass. There are a lot of lot of there but this is the simplest one since we are using Microsoft product. Let's go with Microsoft authenticator. Then I
click on next. Here after clicking on next, I need to go on my phone. Now I am not I cannot share the phone screen here but within in my phone I should have the authenticator app and I should be adding the work or
you read it's quite simple it's saying if prompted allow notification then add an account work or school and then scan the QR. When I click on next it should give me a QR. So I'm scanning that QR in
give me a QR. So I'm scanning that QR in my authenticator app and once that is done I can click on next. It should send me a approval notification or a number that I have to enter within my phone. I don't know if you can see. Okay. So, I
need to enter that name here. Uh sorry, number here.
entered, it should uh refresh and it should allow me to login. Okay, now I'm inside portal. So this MFA setup is something that uh
every new user needs to do once when when they are logging in. All right. Now if you see I'm logged into Azure portal. If I go to Microsoft Enra ID as root cloud easy to just confirm that this is the same tenant where uh now obviously I
don't have access because I I am authenticated but I don't have the access to do anything with Microsoft enter ID as a root cloud easy user. If you remember we only just we only invited this user. We did not provide
any permissions to this user. All right. So now this user can login but in order to confirm obviously we cannot confirm over here. It doesn't uh give any detail which tenant this user belongs to. Okay. But if I go back to the browser where
I've logged in with a user who has the access like simply learn user who has the access and if I see rootcloud a from here he uh is part of this email id is part of my tenant. All right. What is the type of user? It's a guest user.
Clear? So that's MFA and that's how you you work with the external users who are you work with the external users who are not part of your tenant. Okay, not part of your tenant. Okay, clear guys? B2B
mentioned yesterday do not do the de uh the lend hands on uh alongside me. Okay, you you you can do it in your free time. All right. So B2B clear or no? Uh quick
answers guys we have to cover a lot of topics.
Har is asking in organization I assume you use org MFA software it's not org software what is IM whatever IM service you are using that IM service now MFA is very basic topic which is included in all IM services. So if if you're using
active directory domain services or you're using AWS IM service, they already have MFA. Okay, that totally depends on you which uh AM service you're using, your organization is using.
All right, next topic that we have is B2C business to consumer. Active Microsoft Enterra ID business to consumer. Now B2B
works when you want to invite users to your tenant like you have two different tenants and you want to invite your invite external users to your tenant. B2C works in a totally different uh manner. Okay. Uh what is that totally
diretory tenant also a Microsoft entra ID tenant where you have an application
you have that application and you want users to log that application so when you are authenticating a user within that application you need to have an
identity module you need to create or you need to develop it yourself you need to ask your developer to come up with an identity module and before providing an login they need to prove their authentication they need to prove their
identity so in that case what you can do let me just give you the real world example here if I go to lms simplylearn.com
asking users to do we asking users to authenticate here I need to provide my email address and password right I have to enter my email address and password then only I can login now this simply learn this is an application
lms.simplearn.com simply.com. This is an application where we are asking the end users to login. Now tell me that end user are I mean the end users are they user are I mean the end users are they our employee
the end users like you guys who are accessing our LMS learning platform you are not not simply learns employee right so does it make sense for the nonmp employees to create an account within our tenant
does it make sense let's say we have like in one batch we have uh hundreds of uh students, hundreds of candidate. It doesn't make sense for me or my my AM administrator to go here and create users for each and every uh account. Uh
we cannot do that, right? I mean we can do that but it it doesn't make sense to do that since in one batch we have hundreds of user. Imagine we deliver like parallelly we deliver like 10 batch a weekend. So 100 into 10 is,000 users.
I cannot create thousand users every month. Right? So it doesn't make sense. So we should not be creating their user should not be creating their user account or end users user account
within our B2B tenant within our Microsoft enter ID tenant or what what's Microsoft is doing? Microsoft is providing another set of another tenant providing another set of another tenant which is B2C business to consumer. So if
you have an application and you want to handle identity that means authentication for that application then you can rely on Microsoft Android IDB2C where you can come up with signup flows what information you want to collect
from users like if you see here we have given the option to sign up right we have the option to sign up so when you click on sign up you need to provide things we are collecting we are collecting first name last name email
address so this is known as Signup flow. So you can create signup flows and all what information you want to collect. This information will be kept in Azure This information will be kept in Azure Active Directory B2C tenant. All right.
So for your end users, for your customers, you can use B2C. For your own employees, you can use B2B. Clear where you'll be doing B2C and where you'll be doing B2B. Now how to create a B2C tenant? I'm not
going to create B2C tenant. B2C talent are not free. Uh you'll have to pay, right? But if you want to create in any point in time, you can click you can see within your Microsoft Entra ID page, you have this manage tenant. So I click on
manage tenant and I can click on create a new tenant and from here I can select Azure AD B2C. Okay. So this is something that we can Okay. So this is something that we can use to create a B2C tenant.
All right. &gt;&gt; [snorts] &gt;&gt; Now you have to remember one thing uh as uh as mentioned here from May 1, 2025 it's already one year a uh B2C tenants are no longer available for sales that
means if I go ahead and create a new B2C tenant it won't let me uh create the B2C tenant. Why? Because it's it's not there. Okay. So what is the uh
what is another method? If I want to use something similar to B2C, you can uh click uh you can rely on this uh app registration thing where it is this one. So this also works in the similar way as B2C.
Okay. There you have the option to create uh signup flows and all. Okay. Kalashnat is asking who typically uses B2C. I just give an example. If you have
an application, you will be using B2C. Okay. So if I have this application like we have this application, we are not using B2C but we can use B2C since we have the application and we want authentication module for that
application. Now who uses obviously Microsoft didn't disclose their customer who are using B2C. uh if you have an application and you want to you don't want to bother about creating another authentication module
just for your end user to login. How does it work in real world? You have an application you want your user to authenticate. Obviously you want your user to authenticate, right? We do not have a a
very simple website here. We have the LMS portal where we have our content. This recording goes to the LMS portal. So we don't want to provide access to anyone who can login. We want users who have enrolled for our courses. Only they
should be able to uh watch the recordings. So what do we want? We want authenticate what I need to do, I can ask my developer to create an identity module and then add the username and password of all users in one of the
databases. So I can come up with a database. I can uh ask user to sign up from here. Whenever user is signing up all the information is uh collected in a database. Now when user is trying to login in uh login this application will
checks the username and password in the database. If username and passwords are correct we are allowing them to login. If username and password is not correct we are not allowing them to log. But why should I be using B2C? Let's say
my company don't want to manage this database. Managing database, you need database administrator, right? You need an extra personnel who knows how to uh create a database and how to integrate that
database with the application. You need a backend uh developer as well. All this stuff, I can go with simply with B2C. So if you if your organization don't want to manage, you can go for the B2C. Who uses is Netflix can use it.
Netflix also has the identity and access management. Right? If I try to go to netflix.com, I need to log in first. So Netflix is nothing but an application. Netflix is nothing but an application. So in order to watch any movie or any
show, you need to sign in. So when I'm clicking on sign, it's possible then clicking on sign, it's possible then Netflix might be using uh B2C. There are lot of applications who uses IM and if they don't want to manage
their own database separate database only for identity and access management only for identity and access management they can simply use B2C. Okay. [snorts] All right.
Yeah. Next topic we have any questions before I move to the next topic.
need database for maintain paid subs. Obviously you need database. Okay. Uh modules as well. Different application have different kind of authorization modules. Authorization authorization is not something that you can uh use
Microsoft Enra ID for for your application. Okay. For Azure portal obviously you can use Microsoft enter ID for authorization use Microsoft enter ID. For that you need to come up with your own uh within
your uh application module you need to come up with the authorization. Okay. All right. Next thing is conditional access. So conditional access is
a premium feature. You cannot use it with the free tier. Uh yesterday uh we discussed the different plans and pricing of Microsoft Android ID. So this conditional access is a premium feature. So if I want to use conditional access,
I need to have the premium P2 premium P2 license. If I have premium P2 license, conditional access. So what is conditional access? As the name conditional access? As the name specifies depends on certain conditions
the access will be defined depends on certain conditions uh the policy will define whether to grant the access or to block the access
or to enable the multiffactor authent or to ask for the multiffactor All right. So on depends on certain conditions whatever you define in your policy you either grant the access ask the user to
prove the authentication using multiffactor or you block the access. Now what that condition can be that conditions can be anything like you just conditions can be anything like you just want to block a a particular user or a
want to block a a particular user or a part a group of users or you want to uh block users from non-compliant device. Okay. Uh what is non-compliant device? Non-compliant device is a device which is let's say not joined to your domain
or the device which is which does not belong to your company. then on on on depends on certain locations as well like uh my company let's say is based in
India and if someone is trying to connect uh my application or Microsoft Azure portal from any other location let's let's say Singapore I don't want them to
uh login right so all all these are conditions so depends on you what you're defining what is your compliance requirement you can take certain actions requirement you can take certain actions like allow the access or ask user to
prove the authentication using multiffactor or simply block the access. All right. Now um if you're a working professional you might have noticed if you're using uh iPhone you might have noticed even in Android uh and if you
use if you have downloaded outlook your your company's outlook your company's outlook uh email within your phone uh teams within your phone you are not allowed to access it unless and until you are on
the secured iOS platform I think this is the latest one so you might see that if up with this they use conditional access for that okay so conditional access is a
way depending on certain conditions you will be defining whether to provide them the access or not now you're not going to monitor this uh manually every now to use conditional access you'll be coming up with policies
you will create conditional access policies and that conditional access policies in that conditional access policies you will define If so and so user, so and so group logging in from so and so device uh from
certain locations, allow them or deny them. So that's what you'll be defining. conditional access comes with the premium feature uh is a premium feature and if in order to use that you need to have Microsoft Enra ID premium uh
have Microsoft Enra ID premium uh license.
pricing then if I want to see uh with which tier or which premium license Microsoft conditional access comes with. You can come over here and you can see that conditional access comes with P1. So in
order to use conditional access you need to have at least uh Microsoft enter ID P1. If I go back to the portal where I have logged in what license do I have? I have a free license so I won't be able to use the conditional access. Now I
to use the conditional access. Now I have another tenant which is uh P2. So I can go to that tenant and in that tenant
Okay. So now I've logged into this tenant where we have the P2 license. So for conditional access I can make use of this.
have the P2 license. Now Har is asking why different tenants to be used. You don't have to use different tenant as I mentioned. If uh one company should only have one tenant in any case uh if you have multiple tenants then you need to
switch between the tenants. Okay. Here you need to switch between the tenants if you are part of multiple tenants. All right. You don't need to have All right. You don't need to have multiple tenant but most of the uh
companies who did not follow the best practices initially when Azio was new they might be having more than one tenant. more than one tenant unless and until you are uh
you're taking over another another company. So in that case obviously you'll be having more than one tenant. So I can switch from here.
I can make use of uh this tenant and premium P2 is not a free license. You have to pay. So that totally depends on your company whether they approve or
not. But obviously since this is these are the security features uh your company should approve the budget and you should be able to use [snorts] you should be able to use [snorts] uh the premium uh gear. Okay. All right.
So in order to use conditional access I need to go to Microsoft Enra ID and there if I go under manage section somewhere I should have the uh security
option. Uh within security if I go to protect you should see the conditional access. How does it work? Conditional access is just a policy. You need to define your own policy. What are what are the conditions that you want to
evaluate and what actions you want to take. The conditions are take. The conditions are users, groups, devices and locations. The actions are allow throw multiffactor authentication challenge or block the
access. Okay. If I go back to the browser where I have logged in with uh P2 uh tenant. You see here conditional access.
from from last patches. So if you see here I have a policy which says block access to Azure portal from Malaysia. In order to create a new policy you can click on new policy here and you can
create a policy. All right. Now I I use this but let me just walk you through the uh creation uh steps. So conditional access policy I click on new policy. Here are few few things that I
need to provide like what is the name of policy. So you want to block access allow access whatever the name should be descriptive enough so that uh anyone visiting the conditional access policy should be able to understand what this
should be able to understand what this policy is doing. Then users whom which user you want to target. Do you want to target a specific user, all users or selected users. All right, you want you you can target
all users. But remember if you are targeting your all users, this policy will impact you as well. Even if you are the administrator and you are targeting all users, this policy will lock you. If you're locking, if you're defining a
policy which is locking the access to a particular resource or a particular application, you are locking yourself out as well. If you target all users, right? So, how to avoid that thing? If you click on all all user, make sure you
excluding one or two users like who who are admin. So, in case if you want to change the policy, at least you can login. Okay. So you can add your username. Whatever your username is, you can provide your username. I don't know
if I have my same account here, right? So I can select my account. I can select. So this user won't be impacted with the policy. All other users will be impacted. All right. So I click on include uh and [snorts]
I'll just select a particular user. I might have user 01 here. Okay. So this user will be impacted whatever I'll be defining next. So what
we are defining here block access this is the user user 01. So this policy will only impact user 01. Then target resource. Target resource is something which is the application that you want to uh
select. Okay. So what we are defining this is my policy. There is a user this is the target user. So whenever this user is trying to log in or whenever this user is trying to do anything as of now we have only created policy and we
have selected that user we have not defined what what condition what this doing that's that's something that we are defining here in target resource. So in target resource you are defining the condition this user is trying to login
let's say a simple example for this user is trying to log into portal.azio.com This user is trying to log into portal.azio.com. That's my condition. So this is portal.azio.com is my target resource. So that's what we are defining
over here. Target resource. Okay. So what we can select in the target resource we can select [snorts] the specific resources like I want to uh
select all the admin portals in Microsoft all the Microsoft admin portals. So these are the these are all the Microsoft admin portals. So if you want to evaluate for this portal that means user 01 is trying to loging into
this portal. So these are the target portals right [snorts] uh you just want portals right [snorts] uh you just want to target uh Microsoft 365 you want to target Azure active directory reporting you want to target uh Azure perview or
whatever you want to target. So you can select uh that from here. All right. Now in order to target the Azure portal we have something known as Windows API uh Windows Azure service management. So
this is the application which is equivalent to portal.azio.com. So if I equivalent to portal.azio.com. So if I select that it says this policy impacts Azure portal. So they have changed the name into Windows Azure service
portal.azure.com. So what we have defined so far we have So what we have defined so far we have defined user 01 target resource is then you can define network as well. If this if this user is coming from so and
so network so you can define that as well. Okay. So how to define the network? In order to define the network u you need to select any network or any u you need to select any network or any location all trusted networks. So if you
have added certain IP address as trusted IP address that will fall under all trusted network. Okay. You can also select uh networks and locations like I just want to uh block from a certain location only from one country or uh two
countries or three countries. So I can select that as well. But in order to define the networks and all we need to do that beforehand before defining the do that beforehand before defining the policy. So where we can do that within
the conditional access policy you have one [snorts] uh option where you can define the trusted or untrusted location. So if I go over here uh go to the security go to the conditional access and here
under manage you have named location. So here you can define the named locations like I define country's location depending on on exact country like I don't want to allow people or I want to allow people uh to log in from uh so and
so location. So I can create country's location over here. I need to switch since I logged into uh different tenant. So I need to switch
you see named location. So here you see the option is available in in last tenant uh in my default tenant is not this option was not available because I had the free tier. Right. So here you can define your uh name location. Here I
can create on the basis of countries or on the basis of IP IP ranges. So if I let's say I have a VPN I can define click on IP ranges and provide certain IPs like if I click on IP ranges I can provide IP addresses here like only uh
this IP address should be allowed only one IP address should be allowed. So I I can mark that as a trusted location. So if traffic is coming from this and this IP that's what we are defining in the conditional access policy. [snorts]
Okay. I already have the name location over here. So I'm not creating a new but in in case you want to create you can create on the basis of IP ranges or in the basis of countries. So let's say you want to block traffic or allow traffic
only from Afghanistan, uh Alan Island, Albania, Algeria. So you select all of your location which you feel trusted or untrusted. Okay. So I can select Barbados, Bellarus. So I can select all this which
Bellarus. So I can select all this which I want to define as as a white list a blacklist countries from where I want to block the traffic. I can select that. So with this name location you're you're only selecting location that's all.
create. Obviously I need to provide a name. So once I provide the name I I'll get that option uh to create that particular location. So that location will be created here. Similarly, I created uh a new a location in my last
created uh a new a location in my last patch uh with the name Malaysia. Okay. So, this is named location Malaysia and here I have only selected Malaysia. So, if you see all other countries are not selected only Malaysia is selected,
right? So, that [snorts] is selected. So, I can use that. So, if I go back to the to the page where we were defining the policy here, I can select Malaysia. Okay. Click on save. So what we have defined we have only defined the
conditions as of now. We have defined the user who is our target user. The resource the target resource where user is uh user [snorts] will be trying to login. Then we have defined the network. All right. Then you
can define the conditions. So here I can go to the conditions and here I can go to the conditions and here I can define whether I want to uh allow or or deny or whatever. Right? Right. So I've selected the network here and then if
you scroll down here you have the access control whether you want to grant the access. So you click on grant. So here you can define block access. That means you can define block access. That means if user one which we selected here is
trying to log into Azure portal from Malaysia then you defining block access or grant access but ask for the multiffactor authentication multiffactor authentication right or grant access and ask user to
change the password or grant access and ask the user to or grant access and ask the user to login from from so and so network. You compliant device. That means a device which is connected to your or a device
which is provided which your company has provided to the user. So that device will be marked as a compliant device. Right? So whatever you want to select, you can select. Just to keep it simple, I'll do a block access. Okay. Before
applying the policy, I want to show you that if we do not apply the policy, the user 01 should be able to login. So before doing anything with the policy, let's go back to the users section
[snorts] and let's confirm that we have user 01. If you see here, we have user user 01. If you see here, we have user 01. Uh hopefully I know the password. So I copy the user 01's credential. I mean I copy the user 01's user ID. I open in
I copy the user 01's user ID. I open in private window. Go to portal.azio.com. just want to show you uh what is the location from where this traffic is
going. So if I type what is my IP address, I should know what is my address, I should know what is my location, right? So I if I click on what is my IP address? Oh, it's this.
address, you should see the location from where this traffic is generating. If you see this Kola Lampur, where is Kalur? Kalur. Colola Lampur is in Malaysia, right? You know, you guys know or know. If you see this is the
Malaysia. If I if I just minimize uh or maximize, you see the name right? So when I'm trying to go into portal.io.com, my traffic is going from
Malaysia. All right. So I copied the username. I paste it here. Uh I need to provide the password. Hopefully I remember it.
okay, this doesn't have the MFA seems. it has. So [snorts] I need to provide the code as well.
policy, if you see I am able to login. You see I was able to login and this is the same tenant where uh if you see the tenant name is the same tenant as your tenant name is the same tenant as your training premium P2. If I switch to the
uh if I switch you see the same tenant Azure premium P2 so without applying the policy user can login right now let's go back to the page where we are defining the policy so we have defined user 01 target resource is Microsoft as your
portal network [snorts] is Malaysia condition is uh same uh same network selected right and the uh grant the access control is block. I
select block and then I enforce the policy and I click on create. So new policy is being created and I'm enabling that policy. Report only will only report when there is such traffic. It won't uh directly block of your
turning of the policy that means policy is not in effect. All right. There are three uh there are three options when you go to enable policy. Report only will only report when such traps such uh requests
are coming in. On you are turning on the policy. Off is your policy is completely off. It's not doing anything. All right. So if I go here I should see my policy. If you remember we only provided the name as block access. So this is the
policy that we just created. All right. that policy is on. The the other policy which I created in last batch is is is off. All right. [snorts] So this policy is on. Now when that user is trying to log in that user should be blocked
condition access policy on the basis of certain conditions user will be allowed or blocked depending on whatever you have selected. Now obviously one thing you need to keep in mind the existing session will not be impacted only the
next session when user is trying to log in that will be impacted. All right so in order to see that in action I'll sign out after signing out I'll try to sign in again and conditional access should take
again and conditional access should take effect and block this traffic. MFA. It's saying your sign-in was successful but does not meet the
criteria to access this resource. What we applied in our conditional access we applied in our conditional access policy, we applied if user 01 is trying to logging into portal.io.com block the access from Malaysia. If
trying to logging in from portal.asure.com from Malaysia block the access that's what is defined in my policy. All right. But if this user tries to loging in from any other location, it
should be allowed. Now I don't have uh any other location over here. Uh if I have that location, uh it should allow. All right. So now it's blocked. Now where you can implement this in real world. U tell me how many of you uses
hot star and Indian hotar. Okay. In India we have Jio hot star right? It was Disney hot star but then Jio took over. So now it's Jio hot star. Have you ever traveled and tried to access the hot star from
outside India? Have you ever tried that? Yeah. So I I stay in Malaysia and uh if you know IPL is going on right and IPL is broadcasted in hot star. I cannot watch it. Why? Because Indian content on Jiohostra can only be accessible from
within India. So if you are in India then only you can consume the Indian content. If you're outside India, you cannot uh consume that content. So this
is like a conditional access. Now I'm not saying that hotar is using Microsoft enter conditional access but they might be using similar kind of policies. All right. So that's one. Same goes with any any OTT content. Even prime video I
cannot watch Indian content from here. Even uh Netflix Obviously Netflix is available here. Hot star is available here but the only thing is I cannot consume the Indian content. All right. Now people are
asking work with VPN and all. Obviously it will work with VPN. What VPN does? VPN changes your location. Right. So if I use NVPN or ExpressVPN and connect to any Indian server [snorts] technically I'm in India
right from Malaysia. If I use NodeVPN or ExpressVPN and if I change my location connect to Indian server, what will be the traffic the source traffic from where it will be generated?
Computer only understand the source IP address, destination IP address, all those stuff right. So if I launch NodeVPN or ExpressVPN and connect to NodeVPN or ExpressVPN and connect to India and then try to access Hot Star or
Prime Video, what will Hostar uh what will the application uh sees the source as the traffic the traffic source? Obviously the Hotstar will see my source is India. So India if your source is India you are allowed to watch right? So
that should be allowed. So VPN is a technology or a network which changes your location which hides your original location. So if you're your original location. So if you're connecting any uh using NVPN to any part
of the world, your source traffic will change to that part. So if I use NodeVPN and connect to Australia, my source will be Australia. So my whatever I'm trying be Australia. So my whatever I'm trying to access, the target will will will
identify my source as Australia, not as Malaysia. Okay. So obviously you can bypass this kind of thing using VPN and all but [snorts] this is something that you can apply in your corporate corporate
network. Now I just gave an example of hot star but that's not uh like a confidential resource and all right but for your corporate network let's say you
work for a finance company so for corporate network corporate network keeping uh uh keeping in compliance keeping uh uh keeping in compliance makes matter it it matters right like I
don't want my people to access my data from so and so location. For this kind of scenario, I can use access from Australia. Why? Because my business doesn't I I don't have any
business in Australia and I don't want my people to travel to Australia and and my people to travel to Australia and and uh during the work time and access my uh my my my resources. I don't want them to do. So what I can do? I can simply block
from Australia. What I can do? I can create another policy and only allow Malaysia you are allowed. Outside Malaysia you're not allowed. So those kind of thing you can you can uh you can do using uh conditional access. All
right. Hopefully conditional access is is is cleared. [snorts] Let's move on to the next topic. Now identity protection. Uh there's no demo for identity protection but it's another premium feature that we have with
Microsoft. Next topic that we have is identity protection. So what is identity protection? It's another premium feature. If I go to the plans and pricing, uh identity protection again falls under
premium feature. Okay. So, if you want to use identity protection, you need premium P2. If you do not have premium P2, you won't what [snorts] is identity protection?
Let's try to understand. As the name specifies, it has something to do with with your uh identity. It's something to do protecting your your something to do protecting your your identities. Okay. Identity protection is
again a cloud-based uh premium service in Microsoft Entra ID uh which helps in Microsoft Entra ID uh which helps your identities to log in uh within your your identities to log in uh within your system uh securely. So what it does it
system uh securely. So what it does it detects the risk risk detection it detects whether or it analyzes when when your user is trying to sign in uh that your user is trying to sign in uh that sign in is risky or not. Right? [snorts]
You can do the risk based conditional access. If the user or the sign in is we can apply the conditional access policy over there. Right? You can see policy over there. Right? You can see the risk reports and insight. You can do
the automated remediations. You can integrate identity protection with different security solutions. Now what it does in real world, it only analyzes it does in real world, it only analyzes your users for their risk.
What do I mean by risk? If you have used the banking application, you might know banking application from any other location apart from your usual location, location apart from your usual location, u either they will send or or block your
uh access, right? Either they will uh allow you the access by only approving or approving uh MFA. That means they will send a notification to your mobile app and they'll ask you to approve, right?
uh if they detects that your traffic is coming from anonymous IP that means a IP which is already blacklisted and if your traffic is coming from that IP uh that is considered as a user at risk or the
sign in that user is trying to do is risky. So identity protection is a tool is a security feature in Microsoft Endra ID which detects this uh risky behaviors
involving with your identity and depending depending upon the risk uh criteria whether that risk is a low, medium or high depending on that whatever you have defined block or a law it will take that action. All right.
Now, unfortunately, we do not have any demonstration for this since this this works automatically. Okay. So, what you can do, [snorts] you can simply uh set up the identity protection policies. Like if I go back to security over here,
you have another tab or another blade here which says identity protection, right? So, when I click on it, you'll see you have three different policies. If I go under protect, you have
three two different policies user risk policy sign in risk policy. All right. You have you can integrate identity protection with with conditional access. You can also register MFA from here. Now obviously MFA Microsoft has made
mandatory. So this MFA registration policy [snorts] uh is by default require for every user. Okay. We we don't have to do anything for this. The user risk
policy if your user is at risk let's say the the the password that user is using is compromised so user become a risky user if user is trying to logging in from anonymous IP that means the sign in that user is trying is risky sign in
right so all those stuff you can define over here now you don't have to do anything you just have to come over here and define what users are the targeted user if you want to select few users you can select if you want to apply to all
users you can select all users And then the risk. And then the risk. What risk? High risk uh medium and above risk or low risk. Even if there is a low risk like [snorts]
[snorts] uh user logs in the the the regular login of user is from 9 to 5. user never logs in after 5:00 p.m. But sometimes logs in after 5:00 p.m. But sometimes let's say um so what this identity
protection does it learns the pattern that user whatever the usual pattern of that user whatever the usual pattern of user is is recorded by Microsoft enter user is is recorded by Microsoft enter ID so every time user only logs in 9 to5
from this particular browser now let's say user changes the device when user is changing the device again logging into the same time 9:00 a.m. But device is C, the browser is C. So that is detected detected as risky. Okay.
Why it is risky? Because Microsoft enter ID never saw this user coming in from this browser from a new browser. So that can be an unusual browser. So that can be an unusual location that can be an unusual uh login
location that can be an unusual uh login that can be detected as as a low risk or medium risk or high risk. Sorry. So you just have to come over here and define
if you want to block or allow access even for low risk sorry for high risk or for medium and above risk. That's all you want to define. Okay, [snorts]
that's all. Now, we cannot see the demo here since this totally works uh alongside with Microsoft threat intelligence. All right. So what they do they regularly see the threat um coming in from thread detection and
depending on that they they consider whether the signin is risky or whether the user is at risk and depends on that whatever access you have defined block access allow access. So that that thing will be considered and uh if you have
blocked the access user will be blocked from logging in. If you have allowed the access, user will be allowed. All right. So that's will be allowed. All right. So that's what identity protection is. Clear. Now
remember one thing uh as as the information is mentioned over here. Uh in order to work with identity protections from October 1, 2026, you need to align that with conditional access policies. So if I go back to the
conditional access policy here [snorts] you have the conditions within that conditions you have the identity protection as well user risk signin risk right so all this stuff are already here
all right Clear.
Clear guys. [snorts] the real world we use identity protection. Every application is using identity protection. I log into Gmail from a new browser. Their identity
protection is working and they're asking me to uh confirm. That means they are using multiffactor authentication right. So when when they are they when they are uh when they're doing or they are
configuring their identity protection they're not completely blocking you. So if I go to the security and identity protection here they're not completely blocking me. So here you have the control. You have the option to allow
the access or the block the access. But when you are allowing the access you're asking user to change the password or you are asking user to uh to rec to to prove their identity using multiffactor authentication. So when we work when we
log into Gmail from a new location they are doing this thing. when I'm logging from a new location Gmail obviously tracking my login activity if I'm using my regular mobile application they
I'm sorry they will not trigger for MFA but when I'm using a browser within the same mobile but browser is a new session they will detect that as a unusual login
unusual IP address or unusual login and then they will trigger they will ask me to confirm my identity using the multiffactor authentication that's what they're using. Okay. All right. Similar your banking applications
even your uh if you're working professional you might know that you need to use the company provided laptop for all of your uh outlook your teams. If you're using
SharePoint you need to use that right. If you're using your own laptop try try using your own laptop. you'll get an get a call from your cyber security team, a call from your cyber security team, [snorts] right? Cuz they're tracking in
everything automated. So you can use user risk policy or sign in risk policy want to entirely block access, just access and ask user to provide multiffactor authentication, you use
that. All right. Now, just for simplicity, I I'll disable it. I don't want any of my user to get impacted with this. So, I'm I'm disabling it, [snorts] but if you enable it, it should uh work behind the scenes. All right.
access review. What is access reviews? [snorts] So, next topic that we have is managed identities. So, what is managed identities? So far
whatever we have discussed what were were mostly related to the user or group were mostly related to the user or group based identities. So you have user and he wants he or she wants access to the resources. So you create their user
account and provide them the access. Okay. Now in case an application Okay. Now in case an application requires an access tell me how an application is going to access the resources.
user how how do you authenticate yourself? You provide your username and password. Right? [snorts] So your identities is created within any IM solution. Your identities get created and that IM solution
username and password or whatever identity uh mechanism you're using MFA and all. But in case any application requires an access how you going how that application is going to be authenticated
using that IM service should be authenticating the application and then providing the access. We are not going to provide access to our back-end to provide access to our back-end services like SQL or storage direct
access to any of the application right we need to authenticate that application. So what could be the way SSO is not the So what could be the way SSO is not the way MFA is not the way uh the way is one
of the way that we have in Azure is managed identities. managed identities. So what does manage identities do? It creates an object ID for your application and then you can use that
object ID to provide access to the backend services like storage or or SQL or whatever. [snorts] All right. Now if I go to the portal whatever user we have I go to the portal whatever user we have created if I go to Microsoft enter ID
and if I go to the users if you see here let's say I I I I pick up any random user fabric admin. If you see this, this user is having an object see this, this user is having an object ID. What is this object ID? This object
ID is the reference or the identification for this particular user identification for this particular user within my tenant within my entra ID. Okay. So this object ID is the identification
identifier for this particular user. So when this user is trying to logging in as a user what it will be providing? this user will be providing the username this user will be providing the username but the IM service will identify this
user with this object ID. [snorts] Okay. So similarly when an application requires an access we need to register an object ID for that application. So
remember from yesterday's class yesterday's discussion uh application is nothing but some files right people will develop the code will write the code that code is written in one of the file or or uh multiple files and that that
files is stored somewhere in one of the server. So this is my server in in on top of this server I am hosting my application. Now this application requires access to the backend services like database like storage. But before
providing the access I need to authenticate this application. So how to authenticate this application? So if this application is hosted on Azure this application is hosted on Azure virtual machine or Azure app service or
Azure or any uh service any compute service Azure any compute service of service Azure any compute service of Azure then you can create manage identity for that service and that manage identity registers an object ID
for your application. That means in simple term a user gets a user ID gets created for your application and when you create the user ID then it becomes quite easy to provide access to
becomes quite easy to provide access to the resources to the required resources. Okay guys is the screen visible? I see that Baba is saying screen is most visible. What do you mean by most visible
connection. Please rejoin. [snorts] It's visible for everyone. Not visible to you only.
an access for real world scenario you have this application. This lms.simplearn.com simply.com is an application right when I go to continue application right when I go to continue learning
should see your live classes here but when I go to the past classes sorry it's not this one let me show you with a 104 if I go to a 104 when I go to the live
Now this is my application. ls.simplearn.com is my application. Now tell me [snorts] do we keep the assets like videos and images within the same server where our application is
the same server where our application is hosted. separate our front end with our back end. Front end is something that user see you lms.implearn.com you can login and you can see you can interact with
our application but if you want to access any backend service like the storage like we have files whenever I upload file that file will be visible here right if I click here I should I should be able to see
the files that have been uploaded right so this application lms.simplearn.com simply.com is hosted on a compute service like virtual machine. So lms.simplearn.com will be hosted here. But the actual
video, the recording of the live class is not stored on the same virtual machine. We don't store it here. Imagine we have running 10 classes parallelly every weekend. If we keep on saving all the videos in the same virtual machine,
require. So we can't keep it in the same virtual this with our back end. So we might be using storage service, storage account. recording that you see over here that will be stored in the storage service.
needs to access that video. When someone clicks on this video obviously the application will run that video, will play that video. So when any user is clicking on this video the application will play that
video but in order to play application itself needs an access to the storage account. Storage is a separate service. The compute is a separate service. So when application is trying to access the storage. Now tell me whether storage
will do the authentication and authorization or not. Storage is the service in Azure. So Microsoft enter ID will first authenticate this will first authenticate this lms.simplearn.com simply.com whether the
lms.simplearn.com simply.com whether the object ID is present or not the username password provided by this application is correct or not so all those thing will be checked and if it's correct then it will see whether this
application is authorized to see or run or play this video or not. So for user it's quite easy we create the user user gets username and password but what about application? So application you can create credentials
for your application in Azure by using manage identities. All right. So manage identity is the way to create an identity for your application. Okay. I just gave you an example of uh
lms.simplearn.com. You can take any example. Every application works in the same way. most popular video streaming service YouTube. So YouTube what you see is the front end youtube.com you see all the videos and
all everything when you click on any video the YouTube application is communicating with their backend service wherever they are storing the video and that backend service is responsible for storing the video. It could be a
storage service any storage service that Google is using YouTube is using. All right. So in order to provide the identity to your application within Now there [snorts] are two types of manage identity. System assigned and
user assigned. In order to understand system assign manage identity and user assign manage identity, you need to answer me a question where group. What is the difference between user and group?
connection please. You need to uh turn off and and rejoin. You should be able off and and rejoin. You should be able to see the screen. Okay.
users. So if you have multiple users, you create a group and you put all the users within the group. So system assign and user assign is is the is is based on the similar concept. System assign is an individual identity for one application.
So when you use system assign, one object ID will be created and that object ID will be assigned to only one uh application. Whereas when you create user assigned
manage identity that user assigned manage identity is shared across multiple applications. So if you have let's say 10 applications and all these 10 applications require similar kind of access. So instead of creating 10
different system assign identity, you create one user assigned manage identity and then you assign that user assign manage identity to all other VMs or app service or whatever. Okay. So it's similar to group and
individual user. System assign consider it as an individual user. So you create when you create system assign manage identity a single object ID is created application. Whereas user assigned manage identity is
like a shared manage identity which can be shared with multiple applications. So if I have five applications which require similar kind of access, I'll create one user assigned manage identity. I'll associate that one user
assigned manage identity with five different applications and then all that similar access. Okay, that's the difference. Now where don't have any VMs or all but I have existing VMs. So if I search for the VMs
it's not only for VMs it's can be for any compute service. So if I have app service we will have a separate topic uh module on compute service where you'll get an introduction to all compute services. So whichever compute service
you are using every compute service has a manage identity feature. Okay. So let's say uh this is my uh Linux VM OpenVPN 2 and this Linux VM needs access to the backend service. So what I can do I can create a manage identity for this.
If I go to the security there I should see identity and within that identity we have system assigned or user assigned. So if I select system assign then that would be an individual identity for this
VM only. Okay. So I click on on and then I click on save. So it will create a manage identity for this particular virtual machine that manage identity is
not shared across multiple virtual machines. Okay. So as soon as I click on on it should once it is done it should create the manage identity. So you see an object ID is created. Right. Now you can use this object ID to assign
whatever role you want. Like this virtual machine needs an access to storage. So you can use this object ID and assigned access to the storage. Okay, I don't need it. I click I I turn it
off. Okay, let's wait.
identity. Once this is done, I'll go to that tab. it on, it creates an object ID for that particular uh instance for this virtual
machine. when you turn it off, it dregistered the same object ID from dregistered the same object ID from enterra ID. Okay, that's what's happening behind the scenes. Now, if you want to use user assign, uh I need to
want to use user assign, uh I need to wait until uh it won't it won't disable. [snorts] [cough]
Hurry is asking where do we use that object ID? Okay, where do you use this object ID? Okay, where do you use this object ID? If I go to uh portal.asio.com object ID? If I go to uh portal.asio.com azio.com
user every group all of them are having the user ID
if I go to Microsoft Entra ID. If I if I select any user, we use this object ID as I mentioned when before starting the manage identity
that every identity within your Microsoft Entra IM solution has this object ID when this object ID is used when this user is trying to log into any azure.com
azure.com the IM service is identifying this user as this object ID we are not directly using this object we as a user we are not directly using this object ID if I ask you to remember this
object ID will you be able to remember the object ID let's say you are this user fabric admin obviously you won't be able to remember this right for you for us as a human being it's easy to remember the the names fabric admin at
whatever my domain name is. So I can remember that. So for for me I will be providing fabric admin at whatever my domain name is. I'll be providing that and then I'll be logging in. But for IM service, how that im service will
identify this user IM service will see this object ID. So behind the scenes when we are when the data is being sent or or received by the IM service, they will be using this object object ids. Okay. So when I registered when I
created an system assign object system assign manage identity an object ID got created it got registered in the Microsoft entra ID as mentioned here.
Okay. So Microsoft entra ID will identify the openVPN2 virtual machine as identify the openVPN2 virtual machine as that whatever object ID was created. identity it's an individual identity for
that particular virtual machine. When you use user assign you will have uh you you use user assign you will have uh you can use that user assign manage identity to share across multiple resources across multiple uh virtual machines.
across multiple uh virtual machines. Okay. assigned manage identity. So I need to first create it. So if I search for manage identity on top I should see manage identities and there I can create
manage identities and there I can create the user assigned manage identity. Okay.
Once this identity is created, multiple VMs can share it.
to the resources. So I go back to the virtual machine. I go back to the identity. Hopefully I can use it since I created it in central India and my VM is in different region.
somewhere in US, South Central US and identity was created in central India. I am not able to see that identity. Okay. So in order to use the user assign
that user assigned manage identity is created in the same region. All right. I cannot see it because it's in different region. If I go back to user uh if I go back to manage identities, I see this shared user
manage identity created in central India. That's why I cannot use it. Okay. If I create it in another manage identity somewhere in
So both the identities and the resource who wants to use the identity should be who wants to use the identity should be in the same region. [snorts]
back to identity. Click on user assign. Give it some time. I should be able to see. Just wait for some time. You should be able to see. [snorts] Okay. If you're not able to see, just give it some time.
see that we should be able to see it. Okay, that's it's not showing it takes some time. If we did not receive any error while creating the manage identity and and we are not seeing it, just give it some time. [snorts]
it some time. [snorts] Okay. Or better we go to the uh identity Okay. Or better we go to the uh identity and check the type of identity this is.
see. We should be able to see that user assign manage identity and we will be assign manage identity and we will be able to assign it to the uh OVM South central US identity is also in South Central US.
the identities now, right? So I can select this shared user 02 which we created in the same region. I click on add. And once I click on add, this add. And once I click on add, this openVPN will have that identity with
that object ID. Similarly, I can go to another VM in the same region and I can add that as a user identity for that VM. Okay. [snorts]
this, let's me go back to very basic. Tell me what is authentication? Have you understood what authentication is? There are users who wants to log in. Why? Why do you want users to login? I want user to login to make sure that the
user who he is claiming to be is the same user. So I need to verify. So in order to verify I have an IM solution. I need some kind of IM solution in place. Right? Have you understood that basic?
So in order to assign access to the users I need IM solution in place. Before assigning access I need to create an user ID for access I need to create an user ID for that user. Is that clear?
explaining manage identity I went to the lms.simplearn.com. I showed you the uh where it is. Okay, I showed you this. Okay, so what is lms.simplearn.com? Hopefully you you you know this is an
application. Okay, it's a web application since you're accessing it via web. It's a web application, not a desktop application, not a mobile application. It's an application.
Now when it comes to application, you design application in different tiers. You have front end. Front end is something that your user, your end user sees. You have back end. Back end is something which is separated from the
front end because we don't want our users to get the direct access to the download the video and you'll be able to spread the video right imagine Netflix what we can do we can download that movie and then we can share it on
torrent and all that is known as piracy similarly we want to protect our assets right so what do we do we separate front end everyone every application has this concept back end and front end. So front end is something uh which is accessible
to the user and user end user and user sees application in that form. Now when you are separating these layers front end and back end can your front end your directly access the back end without authentication or authorization. Is that
safe? Obviously not safe. Why it's not safe? Front end is also ours. Back end is also ours. So when front end wants to access access without doing the authentication or authorization.
Why we are not doing this? Because when as a end user you click on this this as a end user you click on this this video link a new uh a new uh browser will be open and your video will be played there. So if someone some hacker
is listening to your traffic and if you do not have any authentication or or or anything that hacker can uh track or can can hack the session and can get into our back end can download all the videos that we have. So for that reason we want
authentication and authorization between front end and back end as well. But this this application? Application is not a user. So when it's not a user, it doesn't have the username and password. So how do I authenticate this guy? This
application, this application is hosted somewhere, right? Might be hosted on virtual machine, might be hosted on app service or container wherever it is hosted somewhere. So if it is hosted somewhere
that virtual machine I can provide access uh I can provide identity to that virtual machine. So in Azure we have this managed identity concept. You can create a manage identity for your virtual machine
where your application is hosted. Once I create the manage identity that object ID gets registered to the entra ID. Why it's registered to the entra ID? How entra ID is going to identify a particular object? So in
Microsoft enter ID we uh they create the they create something known as object ID they create something known as object ID like in Windows you have uh SID in Linux you have some different identifier. So in every platform you have an identifier
object ID is nothing but an identifier how entry ID is going to recognize or verify or identify that particular identity. Identity is nothing but a an identity. Identity is nothing but a an object which requires an an access.
So in Azure we have something known as managed identity. So when I create the manage identity an object gets registered. So as soon as I created the manage identity shared user 02 an object gets registered within my uh entra ID.
Obviously I won't be able to see it here but when you are trying to assign the access since it's not an since it's not a user I won't be able to see it under users. You won't be able to see it here since
we are under user section. Okay, there's no separate section for application where you can see the object ID. But object ID is a way how entra ID is recognizing or verifying or identifying that particular ID.
When you create manage identity, there are two ways. So let's consider this open VP VPN 2 is a virtual machine where my lms.implearn.com simplylearn.com is my lms.implearn.com simplylearn.com is hosted
my back end because application is hosted on this virtual machine and that application requires access to the back end. So how do I provide the access in order to provide the access one way that we have
within Azure is manage identity. So when I create the manage identity an object ID gets created for that particular man for for that particular virtual machine. when it's created. Let's say now I want to assign an access to the storage. This
is my storage account. Now that application requires an access to the application requires an access to the storage account. So I go here, assignment and I provide whatever role is required like reading. So if if it
requires a reader role, I select reader role and then I select manage identity. I select that object ID that that got created. So this is the user assigned manage identity that we have. This is the one that we assigned to OpenVPN 2.
Click on select. Now OpenVPN 2. Once I click on review and assign, OpenVPN 2 will have access to the storage. And when application request the access, this object ID, this manage identity will be used for authentication and
authorization. Hopefully, it's cleared now. Clear for you. You just need to remember if you want the manage if you want the access for if your application wants the access to the back end and if your application
is hosted on Azure you can use manage identity. Okay. Is it clear har? Yeah. It's similar to service account but it's not service account. Service account is a windows based uh solution. Okay. To the similar
thing, right? That's a similar similar concept.
manage identity the limitation is you can only use when it's if if when your application is hosted on Azure. If your application is hosted outside Azure then you cannot use manage identity. If my application is hosted on AWS or onprem
application is hosted on AWS or onprem or uh GCP not in Azure any anywhere not the solution for you. Why? Because managed identity as the name specifies managed identity as the name specifies it's managed within Azure for you. Okay.
In that case if your application is hosted outside Azure you cannot use manage identity. Then what we can use? So we can use something known as service principle. Service principle similar concept the only difference is your
application is hosted outside Azure. So if your application is hosted outside Azure you cannot use manage identity. You need to use service principle. Okay concept is similar application requires an access to backend services
like storage account and SQL. Your back end is still within Azure. You are using Azure storage service. you're using DB SQL DB in Azure but your application
itself the front end is hosted somewhere else for any reason. So if that's the case then I'll be using service principle. Okay, in this case I'll be using service principle. Service principle will also create an object ID
principle will also create an object ID within that entra uh ID and then you can use that object ID to assign whatever access is required. The only difference between manage identity and service principle is
outside Azure you will be using service principle. Where do you see service principle. Where do you see service principle? Same if you go to enterra ID there you have app registration. Okay. So you register your application
Okay. So you register your application here. Uh this name can be anything. random name. All right. And then once I click on register, an object will be
created. So you see object ID see an object got created for this as well. Now I can use the same object to assign whatever access I want. Okay. So I can go again go back to the storage. I can click on uh access control IM. I can
click on add add role assignment. Now instead of manage identity I'll select here service principle. Okay. You see the first option it says user group or service principle. So I I use the first option and then I search for the name
that I use dubdubdub.simplylearn.com. So now this object ID will have access the reader access to whatever service I'm providing to. Okay. All right. I don't need it. So I'll I'll delete it or maybe later I'll delete it.
Let's let's proceed. Okay. All right. The next thing then last topic that we have for today not for today I mean this topic is this for today I mean this topic is this module is Azure key vault. So Azure key
module is Azure key vault. So Azure key wault is a is a service is a storage wault is a is a service is a storage service for storing your secrets keys and certificates. Okay what are the secrets keys and certificate?
Secrets are like password. So if you want to store password or configure uh want to store password or configure uh connection strings or keys uh within as your key somewhere then you can make use of Azure key wault. So it helps you to
store password secretly. It helps you to store keys secretly. It helps you to store certificates secretly. Now why [snorts] do we need to keep secret keys and certificate within Azure keyword? Why why can't we keep it [snorts] within
the application itself? What could be the reason? Now, in order to explain the reason? Now, in order to explain that, I need to go to my uh GitHub. that, I need to go to my uh GitHub. Okay.
If I go over here, first of all, answer me. Do you guys know what GitHub is? Since since we have like 40 50% of people who are freshers, do you know what GitHub is? [snorts]
GitHub as a central place where your developers will be pushing code. Code is nothing but your application code. Okay, it's a repository or a place where your developers will be pushing the
code. So [snorts] when you push the code, that code is your application code, that code is your application code. All right. So if you see here, code. All right. So if you see here, this is my uh GitHub and if I go to uh
the application and if I go to the application app. py you see here in my code itself I have placed the connection string storage connection string now we are going to
use this application uh letter when we are on on this particular topic okay but for for simplicity just to help you understand what keywalt is and where you understand what keywalt is and where you use keywalt storage uh uh uh GitHub is a
so this is one of my application written in Python now this application needs needs to interact with Azure storage needs to interact with Azure storage account. How do I
account? So, one way is to keep the storage connection string here. storage connection string here. Connection string is a way uh is an is a is like a password for your application to access whatever you have within the
storage. So, if I provide the connection string over here, then my application app. py can access storage account directly. Okay, you don't need manage identity. You don't need service principle. If you
keep connection string directly here, you can access directly. Doesn't matter where your application is hosted. So, connection string is like a password for the storage account. Okay. Similarly, there are lot of
services like service bus, event hub. Now, tell me is it safe to keep the connection string within the code and push it to the GitHub? Is it is it safe if I just give you this link? Try accessing this link. Can you
link? Try accessing this link. Can you see can you uh see the link? Let me just provide you the link. You don't need to login nothing. Just just don't need to login nothing. Just just launch that link. [snorts]
this link, I'm not logging with any any credential or anything. But I can see whatever whatever we have here. So if I put connection string over here and if this link uh since this is public anyone can access like you guys are accessing.
So if I keep my connection string over here you know my connection string then so if you know my connection string what you can do you can add anything to my storage account remove anything from my storage account
delete my storage account. So is this safe? Keeping storage connection string safe? Keeping storage connection string here. Is this safe? Are you going to ask your developer to push the secrets directly within the
GitHub? Obviously, it's not safe. Right? So what we do, we store or save this connection string in Azure keyword as a secret. So Azure key is a way to to
keep your connection string your password as a secret within Azure key. password as a secret within Azure key. So now instead of accessing the storage account directly I have another application over here.
Who is the application? I didn't push the application I think. [snorts] another application here. Program.json. Here if you see this application is not
C car C car C car C car C car C car C sharp. Okay. Now here if you see we are not adding the connection string. If you know how uh how C# works or hown net
works it's very simple. Okay. What it is doing? It is connecting to the key vault. It is connecting to the storage account. Within storage account, you might be having some container. So, it's connecting to that container. And then
connecting to that container. And then it is getting the secret from the Azure key vault. Okay. We are not adding the the key directly here in the code itself. Do you see connection string here or or
uh a secret here or or or a key here? What we are doing? We are declaring a variable. That variable is reading the secret value from the Azure keyword.
Okay. So instead of keeping everything within the uh code itself, we separate it. We secure it by putting all of our keys,
secrets and certificates within Azure keyword. keyword. All right. Any questions on keyword?
not not today uh tomorrow during your free time just go to this uh repository go to day one authentication and authorization
and within day one I have readme file inside the day one folder I have readme file just follow whatever is mentioned here everything is given to you step by step even application is created
step even application is created Okay, just follow this step by step and you'll understand where your your key how how key volt key works. Okay, so it's [snorts] very simple demonstration that you can do on your own. You don't
that you can do on your own. You don't need me. Okay, but I I have created this uh I have developed this application. It's a very simple application which is demonstrating you how uh you can interact how your application
can interact with Azure keyword. Okay. Uh if you see we have the templates here parameter.json template.json. So how to deploy that is mentioned in the readme
should know you should already know that. If you don't know the command is given over here deploy infrastructure. Okay. Then assign permission. So you you you can assign permission by going to this. All right. And then uh you can
this. All right. And then uh you can also see the keys by by this command a storage account keys list. Now where to run this command? That's why it was important to give the tour of Microsoft Azure portal. You can run all this
command here. You don't need to install anything on your machine. Okay? You choose bash or powershell whatever you want. Select that bash or powershell and run your command. Now this here I don't have the subscript. Uh here I don't have
that error. Okay. [snorts] Select whatever you want powershell or bash and run that command. Do not run it on your local machine since it's possible you local machine since it's possible you might not have uh things installed in
your local machine. So it's better to run directly within the cloud shell. All run directly within the cloud shell. All right. And you might uh get some issues. You might uh get some issues like something is not installed. Right? If
you if you go to the readme file, you should see none of this one. A lot of tabs are open. Let me close
GitHub. If you go to this readme file, uh I have mentioned net run. So net run is something which helps to run the application locally. But you don't need to do this since net run might not run
to do this since net run might not run directly on your cloud shell. So you can skip step number six. You can follow step number seven. Okay, this is for local. So if you have net installed locally in your machine, then only this
this particular command will run. All right. So that's all about authentication and authorization. Keys are changed frequently. That's correct. You have to change keys every now and then. That's why you need to
keys are changing, you need to go to the key wault and change the key manually. Okay? Or you can use PowerShell or Python scripts to change the key as soon as you're changing it in your storage
account or database or wherever. Okay. All right. So there are no questions. Let's see the case study.
authentication and authorization solution. So just go to this link read solution. So just go to this link read the case study. Kyash is asking how do we manage certificate expiry? What what do you
mean by manage? If certificate is expired, you replace the certificate in the keyword. That's all. What what what's there to manage? I need to buy the certificate first. Right? If uh if my HTTPS SSL certificate is
expiring, I need to get a new one from the provider and I need to add it to the keyword. That's all the new one. [snorts]
going to do? They're going to buy a new one and then they install on their web server the new one. That's all. Similarly, if you're keeping your certificates in key volt if certificates are expiring, you need to remove the old
are expiring, you need to remove the old certificate, add new certificates. where you can keep your certificates. Key volt is not giving you some kind of
rotate the keys or automatically change need to rely on your your scripts or your PowerShell scripts or Python scripts or whatever scripting language you're using or scripting method you're
It's just a place. It's just the storage service to keep your things secretly. service to keep your things secretly. So instead of keeping everything on on the code itself, you're keeping it in in in keyword. That's all. Okay. [snorts]
in keyword. That's all. Okay. [snorts] All right guys. So uh again key volt is just a place to store the data. It does not have any
additional way to remind you or send you an email about the expiry. No, it won't do that. For that you still need to rely on monitoring system or your scripts. Okay. So if you have a PowerShell knowledge you can create a PowerShell
script which will which will check the expiry date of all the assets of all the secrets or all all the keys that you have here. You can run that PowerShell send an email or however you want to
notify uh will notify the stakeholders that this certificate is going to expire or or or things like that. For that you still need to rely on something. Okay, it's just the storage service that's
it's just the storage service that's all. All right guys, case study. Let's come back to the case study. So I have shared the link of case study. So let's uh get through it. Design authentication and
authorization solution. So this is the requirement. So we have a fictitious uh company Tailwind traders who wants to expand their workforce. They have successfully acquired an online retailer
in sports apparel space. The company has also located a partner to outsource marketing literature. Tailwind traders is using Entra ID for user and groups accounts. Here are two specific initiatives the IT department would like
initiatives the IT department would like to would like your help uh with. So you &gt;&gt; [snorts] &gt;&gt; The online retailer acquisition will add 75 employees to the Tailwind traders. All the new users have on-prem account
in the retailer's existing domain. Okay. So, what do you understand by this? What service are you going to use? The online retailer acquisition. That means Tailwind Traders uh is acquiring online retailer and they
already have active directory domain services. The online retailer already have active directory domain services and 75 user accounts there. So how are you going to bring that 75 users to Microsoft entry ID? What
service you can use? Entra ID connect. That's correct. So here I'll be using entry ID connect and I'll be bringing those or synchronizing those 75 users those or synchronizing those 75 users with my entra ID. All right.
The new marketing partners. So they're all or they're also uh acquiring the marketing partner. So the new marketing partner will initially have 15 employees who will need corporate access. So these employees
already have Microsoft Entra identities in the partner Microsoft Entra tenant. So what service or feature we can use? So it's like you have two tenants
marketing partner and your own tenant Tailwind traders. So here we can use B2B since these are our partner and we want to uh collaborate with them right so we
just use B2B here then the new employees are located at need account privileges for their new job roles some changes to the existing employees roles are expected geographic
locations what what do you think over here what services you can use conditional access and identity protection. Right? These two services we can use here to make sure that whatever
identities are are logging in [snorts] uh are protected. Right? So conditional access we can define only those geographic locations from where the access is required. Okay. The IT department wants to take this
opportunity to include new identity security features. So whatever features we have learned conditional access, identity protection, access reviews, you can implement all those stuff. They haven't mentioned which one to use or
haven't defined which one to use. They have mentioned all the new features. So have mentioned all the new features. So you can implement all. Okay. Then the next thing is new application access. So application also requires some kind of
access. So the business development team has an application running on Azure virtual machine and data stored in Azure SQL database. They need to securely allow the VM to query the Azure SQL database. How how you can achieve that?
database. How how you can achieve that? [snorts] hosted on Azure VM database is stored in Azure SQL database. Now this VM should be securely able to query the SQL database. So what we can use we can
assign manage identity to this Azure VM and provide access to the Azure SQL database. Then whenever query is running the Azure SQL database will identify the using the manage identity and if access is granted or not. Okay. So here we can
is granted or not. Okay. So here we can use manage identity. They also need an on-prem server to be able to securely access SQL database without storing credentials in the application code or configuration file. It's an on-prem
server. Here you can use service principle and you can use Azure keyword principle and you can use Azure keyword to store the SQL database uh connection string within Azure keyword and then on-prem server can access SQL database
by reading the credentials from Azure keyword. So here we need to use service keyword. So here we need to use service principle plus Azure keyword. All right. Why service principle? Because the server where application is hosted is on
prem. It's not on Azure. If the server would have been on would have been on in it would have been easy. Just simply use manage identity, right? But it's not on All right. Then these are the tasks. So
need to discuss. But these are the task for you guys. So you need to diagram the process. Okay. Like what you need to diagram use the same tool that I'm using
draw io. If you just search for draw io, it If you just search for draw io, it should uh take you to the draw io website. So this is the tool that I'm using. All right. Now here uh we have
using. All right. Now here uh we have the shapes. So if you add more shapes, we have azure here somewhere. We should see azure. All right. Now you need to diagram the diagram whatever you want to diagram the
process of bringing in the acquired user accounts. 75 user accounts were acquired. Okay. So what I do here then I go to Azure identity. So this is Azure identity. Here you should see active directory. Now uh Microsoft enter ID
directory. Now uh Microsoft enter ID icon is still not there. So you can use active directory. This one this is like a Microsoft enter. The previous name was Azure Active Directory, right? We can add a text here. If I want to add a
add a text here. If I want to add a text, I can add text like this is the text, I can add text like this is the Tailwind traders font and all from here. So just so that uh you can read it
Telin traders tenant. They're acquiring 75 uh users. So they are running on ads. So you can search for ads here or domain you can search for ads here or domain services. So it would give you uh
services. So it would give you uh some server image this is the on-prem active directory domain services for the online retailer.
domain services for the online retailer. Right? So you can just label it.
what you what you can do here? You can simply use arrows and all. So I just use simply use arrows and all. So I just use uh arrows here. I uh pull the arrow and then I search for
entra connect. So somewhere you should see the entra id connect. Again within the identity you should see the entra id connect. Okay. So this is entra ID connect. So I keep it over here. And then again I label it
it over here. And then again I label it 75 users by keeping text a little low.
that. Okay. So you need to come up with this this kind of uh uh designs and this is what Microsoft expects you guys to to do to design things. Okay. We can't do do to design things. Okay. We can't do that uh within class. Okay. Since I need
to cover the theory and then uh certain demos. So case study is something I leave. We will discuss the case study but this design thing is on you. All right. So you can use this app.dagramgram.net
add Azure as a shape and you'll get all the Azure shapes. Okay. Then you have marketing retailer. So you can uh what is mentioned about that marketing retail marketing partner. So they're
also using Azure Active Directory or Microsoft Enter ID. So you can copy the same and you can label is that marketing partner and between the partner and partner and between the partner and Tailwind traders. What you can do is
Tailwind traders you can create like an arrow and you can use as your active directory B2B. If you search for B2B if we have any B2B uh icon you can directly use that but I don't think so we have B2B icon.
here B2C is there B2B is not there so you cannot use any uh icon but you can simply add a label there B2B 15 members okay so I want something like this once
okay so I want something like this once you are done you can share it with me over my email so I'm sharing my email id here okay and then I'll review and give you the reply over the email
the reply over the email clear guys is are you clear how to do the case study? We have only covered authentication and authorization. I was planning to complete the governance as well but uh doesn't matter
since this is the first weekend. uh we need to buckle up and and speed up the the things here. So this is the link
the the things here. So this is the link sur.
&gt;&gt; Yeah. Then it in related to manage identity identity &gt;&gt; and you go to the VM option. Okay. where &gt;&gt; and you go to the VM option. Okay. where you uh created the object ID first first
option and after that you go to the manage identity where you created the another object ID. &gt;&gt; Okay. &gt;&gt; Yeah. I'm unable to correlate that because in the when you open VM uh open
VM uh BPN02 you created object ID and after that you go to the MAR identity and also you created the an object ID and go to you
go to the storage and you manage the uh attach the object ID &gt;&gt; from the manage identity. I'm unable to understand that. Have you understood the concept of manage identity? &gt;&gt; Yeah, I have understood the manage
&gt;&gt; Okay. Can can you answer what manage identity is? &gt;&gt; Manage identity is the ID which is generated to authenticate between the data. &gt;&gt; Okay. Right. How many types of manage
&gt;&gt; We have two types of manage entities. System assigned and user assigned. &gt;&gt; Correct. Okay. What is the difference? System assign is based on the single single type user and user assign is
based on the multiple type user. Correct. Suppose that we have some &gt;&gt; Okay. Uh system assign is like for single resource. Okay. &gt;&gt; Yes. Yes. &gt;&gt; It's an individual identity. So if I
create system assign uh this VM will get an object ID and that object ID will belong to this VM only. single individual. Okay. When I create user
assignide manage identity, I can share that manage identity across multiple VMs. So I have 10 VMs. All those 10 VMs requires the same access. So what I can do instead of creating individual identity, I create one user assigned
[snorts] &gt;&gt; Okay. for individual system assigned manage identity you can create it from the v uh from the resource itself that mean I can go to virtual machine I can go to identity
and then I can create the system assign manage identity if I click on on here and save system assign manage identity will be created which is which will be will be created which is which will be associated with openvpn02 only.
&gt;&gt; Okay. If I want to create the user assigned manage identity, I cannot create it from within the resource itself. I cannot create user assigned from here. So what I need to do? I need to search for manage identities.
I need to go there. I need to create a new one. Here I'm creating user assigned manage identity. And then I can use that user assigned manage identity to user assigned manage identity to associate to as many VMs as I want.
So when I when I switched when I &gt;&gt; yeah that's the difference. So you in order to create user assign manage identity you need to create it like manage identity you can create from resource itself.
&gt;&gt; Okay. Now it's clear sir. &gt;&gt; Okay. All right. &gt;&gt; Okay. All right. &gt;&gt; Thank you.
are no uh questions, let's proceed with the next uh topic. We'll just cover the basics since it's already 10:34. All right. Those who are leaving, I see people are leaving. Uh I see participants only 50. Before leaving,
please make sure you're providing the feedback. All right. Now we are moving feedback. All right. Now we are moving on to the second part of uh authentication and authorization. Moving to the second part of AM. All right.
Identity and access management. So far whatever we have discussed was related to identity. That means we were creating users, we were managing users, we were modifying users, we were creating identity for applications like manage
identity or service principle. So we were just creating identity. We were not assigning any role or we don't know which role to assign, right? We don't know how to manage or how to assign access to the users or resources. So
that's something which we will cover in the governance topic. What res what role we can assign, which role is powerful, which role is not powerful, what is reader role, what is owner role. So all those stuff we will
be covering in this topic. Okay. So far whatever we have discussed is related to related with the identities creation or management only. [snorts] We haven't assigned any access to any user yet. We created one user, right? We invited one
user in our identity in our Microsoft Enra ID. We ass we we invited this root cloud a user. Remember at the start of the uh session today, we invited this
user. But we haven't assigned any role to this user. So when I log in with this user, this user cannot do anything. So in order for this user to do something, we need to assign a role. So which role we can assign that's what we will be
we can assign that's what we will be discussing in this topic of governance. Okay. [snorts] So what is governance? Governance is a way to come up with with certain control over
come up with with certain control over your your system or over over your uh uh uh infra you can say or platform you can say in general term what is governance you we live in India let's say and in India we have certain policies certain
rules right certain laws that we have to abide so every country uh will have their own governance policies, their own own laws, right?
Similarly, every companies or organization will have their own governance mechanism or own own policies. So, governance is just a way which provides a mechanism and process to maintain the access control over your
resources, over your applications, over your users in Azure. [snorts] So how to maintain the control that's what this topic is about. Okay.
All right. So you have a user that user requires an access. So for authentication we are using IM. Now after authentication what this user can do can this user access the virtual machines? Can this user access the SQL
machines? Can this user access the SQL database? Can this user delete the uh delete the SQL database? So what he or she can do that's what we are defining using governance. All right.
So what is governance in general? Is that clear?
just to secure authentication of resources or to provide connectivity. Manage identity does not provide the connectivity. That is something network you uh network should be doing. Okay. Manage identity does not provide the
connectivity. It does not connect your virtual machine to the storage account. The connectivity is a network part. So you need to define the connectivity. We have fourth chapter where we'll be discussing network.
authentication. Whatever we have discussed so far is related to All right. So what is governance? Governance is just uh a mechanism where
you can define certain policies. You can define access control which user or which application can access what right now how to achieve that in Azure that's what we are we are going to discuss in this chapter. Now this thing hierarchy
is important to understand when it comes to Azure. Okay. So Azure has this hierarchy. Now what is this hierarchy? This hierarchy is nothing but a scope where you can
define the access control. All right. Hierarchy is nothing but the scope the level where you can define the access control or you can define the access control or you can define the policy or you can define the uh tagging.
hierarchy. What is this hierarchy? At the top of the hierarchy you have a management group tenant root management group. Then within that tenant root management group you have you can keep different
management group within the tenant root management group. Then management group is like a container logical container where you can keep your subscriptions. Subscription again is a is a billing boundary. Okay. So using the
boundary. Okay. So using the subscription Azure will will charge you subscription within subscription after the subscription the scope that we have the level that we have is resource groups. So resource group is again a
logical container where you can keep your actual resources. Okay. So this is the hierarchy. Now I'm not explaining each in detail because if you see we have a separate slide for that. All right. For now for this slide
you need to remember the hierarchy. What is the hierarchy? At top of the hierarchy we have the first group which is the default group. So even if you're not creating the management group, Azure will create
one for you by default and that group is known as tenant root group. Now what is a management group? Management group is a way to manage your subscriptions. So within your management group, you can keep your as many subscriptions as you
want. What is a subscription? It's a billing boundary. For now, you just remember it's a billing boundary. Then within the subscription, you will be creating resource groups. So resource group is a way to keep uh in Azure it's
mandatory to create resource group. Without creating resource group, you cannot keep your resources. So resource group is a way to organize your resources. Now tell me when you buy a laptop [snorts] within the laptop we
have certain components right we have uh LAN card you know what LAN card is the network interface card where you connect your interface card where you connect your LAN cable right then we have hard disk
nowadays we have solid state drive we have processor right so a lot of things you when you buy a laptop lot of components you get obviously you you don't see it but uh those components are there within the
laptop [snorts] similarly when I create a virtual machine so it's not a physical machine it's a virtual machine you can't touch it so in Azure when you want to create a server you create a virtual machine with the virtual machine you get
the virtual disk a disk get created a virtual nick gets created network interface card the LAN card okay if you have assigned IP address or public IP IP gets created. So all this stuff get
created with the virtual machine itself. So where if if you scattered this in different different groups, it will be very hard for you to come up with an inventory and all those stuff. So what do we do? Whenever Azure is creating
machine, Azure keeps all these resources in one resource group. So that within that resource group, you can see all of your resources. If I show you the resource group in action, if I go to the resource group, any resource
group where I have my VM, this is one of the resource group that I this is one of the resource group that I have. And if you see my Windows 11 VM has the disk, has the public IP, has the virtual link. So whenever I create a VM,
virtual link. So whenever I create a VM, all this gets created with the VM So if you see the resource type over here on on on second row if you see the resource type it's a virtual machine it's a disk it's a public IP it's a
network interface. So when we create a virtual machine everything gets created. So you can keep them in same resource group. So we'll keep them in the same them in the same resource group? Because these resource are related resources. So
what I can do I can create multiple resource groups like prod resource group, dev resource group, UAT resource group and keep all the resources belonging to that particular environment in each resource group. So it will be
easier for me to manage. Okay. So resource group is one of the uh Okay. So resource group is one of the uh uh level in the hierarchy in Azure. The act the main way is it's it's it's a logical container where you contain
which contains your resources. That's all. Subscription is a billing boundary. Without subscription, you cannot create or or deploy resources in Azure.
Okay. And then the root the management group is a way to organize your subscriptions. So it's [snorts] it's bound to happen that you will be having more than one subscription within your tenant. Why? because every subscription
comes up with certain limits. So within a subscription there there might be limit that I can deploy only 25,000 VMs. So if I need more than 25,000 VMs. So if I need more than 25,000 VMs, what do I do? So I I buy
another subscription then. Okay. So what is a subscription? It's a billing boundary in Netflix. When you sign up for Netflix, you need to subscribe to their plan, right? without subscribing to their plan will you be able to watch
any movie or any any web series? No. Right? We need to subscribe. So similarly in Azure we have subscriptions. We need to buy subscription, you cannot deploy the resource.
Okay. Let me give you the demonstration very quickly here. So if I go here and I have logged in with this user. If you see the uh name simply learn at whatever the domain name is. If I search for virtual machine
I am landed to this page and I have the option to create and I can click on create virtual machine and I'm landed to the create virtual machine page. Once I provide all these detail virtual machine will be created.
will be created. Okay. But if I log in with another user the user that we invited, if I log in with that user,
I login with this user which we invited at the start of the uh
Okay. So, I've logged in with root cloud a guest user that we invited.
in if I search for virtual machine
a virtual machine when I when I search virtual machine from another user from this user I'm landed to this page where I have the option to create. I can virtual machine and then I'm I'm I'm going to the create virtual machine
page. But when I log in with rootcloud a I don't even have that create option here. Why I don't have because this user root cloud a doesn't have any subscription. So in Azure when you want to deploy
resources you need subscription. Without subscription you cannot deploy resources. So this user doesn't have any subscription that's why he cannot deploy the resources. The other user has the subscriptions. If
I switch back to the browser to a different browser and search for subscription here I have the subscription. have the access to the subscription I can deploy resources. If I don't have
the subscription I cannot deploy the resources. Okay. So in Azure subscription is a way for Azure to bill you. It's like a billing boundary. Clear? Any question guys?
Resources are the actual resources where your where your workload will be running. Resource group is like a container where your resources will be. So if you do not have subscription, you cannot create or deploy resources in
Azure. Management group is a way to manage your subscription. That means you can keep the subscriptions within the management group. All right. So let me show you the management group here from another account since that account
doesn't have access. Let me switch to the management group I should be seeing all the management group that I have within
the management group that I have within my tenant. management group that I have. So if you see the first management group that we have is tenant root group. This is by default. This is created by
Azure. Microsoft Microsoft Azure. As soon as you sign up for Microsoft Azure, you'll see tenant root group. Okay.
You can create as many management group as you want like I have created MG01 and within this management group you can keep your subscription. Right now both of my subscriptions are within tenant root group. If you see the hierarchy,
hierarchy is like this. You have top management group. Then you can create management group. Then you can create MG00003, MG00002, MG00001, whatever. Right? And between the management group, you can uh uh move your subscription.
Like if I want to move pay as you go to another management group, I can move it. I can select which management group I want to move. MG00001, MG00002, MG00003.
Okay, I can select that and click on save. Once I click on save, pay as you go dev test will go to whichever management group I selected. Okay, [snorts] so if you see now, if you refresh, everything is okay. You don't
receive any error. You should see your subscription within MG00003. All right. [snorts] So if I expand MG00003 now pay as you go
is within MG00003. Okay. So you have tenant root group then you will be having as many management group as you want and then you'll be having your subscriptions. Okay. Now question may arise like I see
one question by prain that why do we need so many management group? What is a management group? Management group is as the name specified is used to manage the name specified is used to manage something. Right? as when I started the
governance topic why do we need governance to put certain policies to governance to put certain policies to put certain control right now in Azure top of the hierarchy you have tenant root group so if I assign any access
here to any user let's say this is the user I assign a full access to this user at tenant root group this user will have full access over the entire hierarchy
subscription number one, then this user will have full access only at the resources which is within subscription one. He won't be able to
access the resources at subscription two. But if I assign full access at the tenant root group, he will have full access over whatever subscription you have within the tenant root group. Let me explain it from here from the portal
itself. If anyone is having whatever access at tenant root group that access will be inherited downwards. So if I have let's
say this user Imran kitani@hotmail.com has complete access over tenant root group then that user will have complete access over azure training subscription complete access over mg003 complete access over pay as you go complete
access over mg01 but if I change my access from tenant root group to only mg01 so whatever I have inside mg01 I can I
will only be able to manage manage those resources which I have within MG01. So in this particular scenario, there's no subscription within MG01. So if to deploy resources. Why? Because I don't have access here on on the top
hierarchy. I only have access here at MG01. So why do we need so many management group is to control the access. You have group is to control the access. You have dev, you have test, you have UAT
environment, you have QA, you have staging environment. You'll be having multiple environments. So to divide the access, you can create as many management group as you want and you keep your resources there.
management group, that is also fine. Totally up to you. How do you want to come up with your own hierarchy? It's not mandatory to have multiple not mandatory to have multiple management group. only if you have uh
number of subscription then management group makes sense. If you have only one subscription then having multiple management group does not make sense. All right. So and if you are working from enterprise a large scale
organization you are going to have lots of subscription. In my previous company we used to have one subscription per client. So imagine we had thousand subscriptions. So how to divide how to manage the access control within the
thousand subscriptions? Are you going to provide access to all of your users at each subscription? If I create a new subscription uh and my team is is having access over this subscription. And if I create a new
subscription, assign the access. Then if I create another subscription, I need to subscription, I need to assign an access. Imagine how much time you'll be wasting just for assigning the access. So what is the better way? Create a
management group, put your subscriptions there and assign access at the management group level. So whatever access you have at the management group subscriptions within that management group level, that access will be
inherited. Okay, clear. Let's proceed with our topic governance. Before that I'll just do a 5 minutes or 10 minutes of quick
recap what we have covered so far. Okay. Uh so what we have covered so far we started with basics of cloud computing where we understood what cloud computing is. Why do we need cloud computing in
today's world and then we moved on to our first topic of a305 which was AM. IM stands for identity and access management where we discussed about if we need a service if we want to implement AM in our organization or our
projects then if do we have any service in Azure. So we have Microsoft Entra ID as the service in Azure which helps you to manage or implement in your own organization. Now Microsoft Enra ID comes with two
different flavors B2B and B2C. B2B stands for businessto business. So if you have a partner company or any other collaborators who want to collaborate with your company and they want to build something for
your company or you have hired someone to build but it's it's a it's generally a contractor let's say not a permanent employee of your company and you don't want to create account for them. So B2B is something that you can make use of as
long as the collaborator has a valid email address. You can invite them directly to your tenant to your directory to your Microsoft tender ID and then you can give them whatever access is required to accomplish their
role or their job. Then another flavor of Microsoft enter ID is B2C. B2C stands for business to consumer. So when you have an application let's say this is
your company's application and this application is open for your let's say application is open for your let's say end users or maybe your employees and you want to manage a separate authentication module for this
application. So in this scenario you can make use of B2C business to customers business to client. Okay. Then we saw a few premium features in Microsoft Entra ID like uh uh conditional access on the basis of certain conditions you'll
provide access or you'll throw a multiffactor authentication challenge. Uh conditions can be anything like uh uh traffic is coming from a certain IP whether should allow that traffic should deny that traffic you'll define
everything in that conditional access policy. If you allow the access will be granted if you deny the access will be denied. If you ask for multiffactor authentication, a pop-up will be sent to their authenticator.
After conditional access policies, we went to identity protection. So in identity protection, you have like three different policies that you can set up. Uh you have user risk policy, you have signin risk policy and you have
multiffactor authentication registration policy. User risk policy if user is at risk signin risk policy. If the if the sign in method that that have been opted is detected as anonymous or risky. So all
those things Microsoft threat intelligence works behind the scenes and uh learns the pattern of user behavior like when what that what what time user logs in which device user uses. If any of this pattern changes then uh it could
be uh assumed by my by identity protection that it's a risk and whenever that risk is detected depending on your policy whether you have blocked it whether you have th whether you have asked for user
have th whether you have asked for user to uh to prove the identity prove the authentication using multiffactor. So that will be triggered. So depend on how you have what you have configured in your policy that action will be taken by
identity protection. When it comes to identity protection you don't do much as a user as a administrator I don't do much I just define whether I want to allow I want to throw a multiffactor authentication or I want to deny the
access that's all. So those are the three uh radio buttons that one of the radio buttons I have to select. After IDP we went on to access reviews before starting of this uh demo. U pankage asked for that and and I have explained
it right. So what is access review? In simple access review is just a way to review as the name specifies to review the accesses that you have given to your the accesses that you have given to your your users. Right? So whenever user
and then that group will be having access to certain resources and then after every 3 months 6 month depending on whatever policy you have with your uh security team you will be running that access reviews and then the manager of
that group or whoever is the reviewer of that group will decide whether the user will have a continued access or uh the access will be revoked for that user for those particular resources. Then after access review review we moved
on to two types of identities that is required for that we can use for application like manage identity and service principle. When an application requires an access to the backend resources like storage, SQL whatever. So
you create a manage identity for that application. Manage identity is something that you can use and assign it. It creates an object ID. Object ID is nothing but the way how Microsoft Endra ID recognizes or verifies a
particular object or particular identity. So that object ID is it uh gets assigned to that resource where your application is hosted and then you can use that object ID to assign access to whatever resources you want. But
manage identity the limitation of manage identity is if your application is hosted on Azure then only you'll be able to use manage identity. If application is hosted outside Azure then obviously manage identity is not the option for
you. So what you can do then you can make use of service principle concept is principle the application is hosted outside Azure. It might be hosted on prem might be hosted in some other cloud provider but they need access to Azure
resources. So in that case we can make use of service principle. Then we saw one uh resource in Azure which is Azure keyword. So Azure keyword is a storage
service uh which we use to store our secrets. Secrets can be passwords or can be connection strings. We can generate or or import the keys the cryptographic keys in Azure keyword and we can also make use of certificates. So we can keep
key certificates and secret in Azure keyword so that our application can securely access the secrets or the passwords or the connection strings directly from Azure keyword. It's not a good idea to store the password secrets
good idea to store the password secrets uh connection strings or uh access keys directly on the application code. It's not a good idea. That's why you can move that to a separate uh vault and from there your application can read it. All
right. So that's what we have seen so far. After that we moved on to the next topic which is governance. So what is the governance? Governance is nothing but a set of processes, policies, access control that you can
policies, access control that you can apply on within your organization, right? And within that governance topic we saw the hierarchy. So this is important to understand from Azure point of view. We have a hierarchy. Azure
hierarchy. Why this hierarchy is created? So that you can manage access policies, access control policies at any of the scope that is visible for your company, for your organization depending
on the requirement of your organization. Now what is this hierarchy? In this hierarchy, you have five different scopes, five different levels. Okay? Now, if you see, I've only mentioned four. 1 2 3 four. But in actual, you
have five, right? So what is that fifth level? The first uh the first scope in the hierarchy is the tenant root group which is present by default. When you tenant root group even when you don't create it. So tenant root group is the
top is the stop in the hierarchy. Within that tenant root group, you can create as many management group as you want. management group. Then within that tenant root group, you can create as
what is this management group? Let's see that. So management group is is is a scope is a level in hierarchy where where you can organize your
subscriptions. So here I can organize if I have multi it's bound to happen. You'll be working with multiple subscriptions within your organization. Why? So if you have done easy 104 you might know that every subscription has
its own limit. I cannot use Azure subscription limitless. That means I cannot go and use one subscription and deploy like the like millions of virtual machines. There will be limit. Okay. So, Azure has limit to two uh subscriptions.
subscription you are using. Every subscription will have limit. So, it's bound to happen if subscription is having limit and if I'm uh if I have utilized all of that limit obviously I need to buy another subscription. So
when I'm buying another subscription, the access control and the organization is very important when I'm when I'm having multiple subscription. Why? Let's say I have this subscription where few of my users are having access and they
can deploy resources. So this user is having access and this user can deploy resources whatever resources required. Similar to this user, you have thousands of group you have thousands of users. They have some kind of access to this.
some some of them are having read access, some of them are having write access, some of them are having write access. Right? So all the access control have been managed over here. Now let's say once I have utilized my limit, I'm
buying another subscription. So what I'll have to do now again I need to see who is having what access here and I need to replicate the same thing in another subscription so that I'm not blocking my user from deploying
resources. Right now after a few years let's say I've utilized another limit I'm going for another subscription. So I have to replicate all the access control all the policies everything on this subscription as well. So to avoid that
Microsoft has created this management group. So instead of assigning access directly at the subscription level what you can subscription within the management group and you can control the access at the
management group level. So once you control the access at the management group level in future it doesn't matter how many subscriptions you add within that management group all the subscription will inherit the same
subscription will inherit the same access control that you have um you have provided or you have added or you have assigned to your users at the management assigned to your users at the management group level. So those access those
policies will be inherit downwards. All right. So management group is the top level obviously tenant root group is the top level within the tenant root group you have your management group you can create a management group like uh here
it's it's created as tailwinds that is nothing but the company name and within the tailwind you have like sales corporate IT within the IT you might be having production dev QA UAT right so all you can create as
per your requirement whatever you want to create it it because um Azure doesn't want you to follow this. If you want to follow this, you can. Different company have different use cases. So they follow according to their requirement. Like
I'll give you a real world example of my own company. So my own company we have like we create a subscription for our client. So if we have thousands of clients, all thousands of uh client all thousands of customer will have their
own subscription. so that it's easier for us for us to invoice them at the end of the billing cycle. So what we have done we have obviously we have this tenant root group so I'll write it as TRG
then we have uh two management group one for our company okay one for the customers every customer subscription will goes under this customer in our management group we have
rod we have uh UAT and then we have U staging Okay. Test. So these are I mean non-pro not staging non-pro. So we have this very simple and uh effective way so that
whenever new customer we want to onboard a new customer we just add our a new customer management group. So that's quite simple management group layers we quite simple management group layers we have created. Okay.
So what management group is in order to organize your subscription you can keep your uh subscriptions under this management group you can manage for access control as well. So whatever access I'll be applying at this level
that access will be inherited. Okay. So doesn't matter how many management group doesn't matter how many management group I have in my hierarchy. Whatever access I'm assigning here that will be inherited. You can also enforce policies
at different levels of management group. So if I have any policy here at tenant root group that will be inherited. If I have any policy at it since it will be having different kind of policy. So if I have any policy assigned at IT that will
only be inherited by the management group and the subscriptions within the IT management group. Okay. Any policy at IT will not impact the root group, tailwinds, corporate and sales. Okay. So management group is very important when
subscription. If you have single subscription, you don't need to bother about management groups and all. All right, you'll be having one tenant root group. Create one management group with your company name and within that
subscriptions. All right. And obviously if you have management group it is easier to uh attain the compliance compliance requirement for your company since I can assign the all company level policy at
tenant root group which should be uh which should be equivalent for every subscription every management group every resource. All right. So I think I group but in order to work with management I just need to search for
management group. So in in the search bar if I types type type management I should get this option management groups. I click on it and I'll I can see how many management group I have. Right? So this is the tenant root group. So
within tenant root group you'll be having everything all of your management group. All of your subscriptions will be within tenant root group. Right? So whatever I'll be assigning here at tenant root group will be inherited by
tenant root group will be inherited by by by all the management group within have? What is our hierarchy here? We have Azure training. This is my subscription. Right? You can see the type here. So this is the management
subscription. Rest two are the management group. So anything assigned here any policy or any arbback role assigned here at tenant root group will be inherited by Azure training subscription will be inherited by
subscription will be inherited by MG00003 will be inherited by MG00001. All right. If I expand MG003 now we have tenant root group at top. We have subscription that is within tenant
root group. We have MG00003 which is within tenant root group. And then we have another subscription pay as you go within MG00003. Now if I assign someone any access at MG00003
if I assign someone let's say this is a user user 01 and I assign access to this user at MG00003. Whatever the access is let's say read access. Now tell me can this user user 001 read anything we have at Azure
training? Azure training is nothing but the subscription name. So if I assign a the subscription name. So if I assign a user 01 access read access at management user 01 access read access at management group 003 can this user read or or
deploy any resource at subscription which is name as a as your training so I'm getting the answer as no that's correct why because MG00003 is at different scope is at the within the tenant root group and this subscription
as your training is within tenant root group so anyone in my company wants to work with Azure training, I need to assign access at the subscription level, Azure training level or at the tenant root group level.
All right. But let's say another question to you. If I move this subscription from tenant root group to MG003, now what is going to happen? that user who was having the reader role at MG00003
should have access the read access to Azure training or no. If I move Azure Azure training or no. If I move Azure training to MG00003 then obviously yes. So whatever access you have at MG0003 will be inherited to
all the subscription that you have within that MG00003. within that MG00003. All right. So this is very easy uh to manage. In order to move, in order to create, you just click on create and
create another management group. So let's say MC00004 uh management group display name and ID whatever display name you want. Display name is for you. ID is for Azure. So that when you work with management group
using commands like CLI or PowerShell, you can call this ID. You can keep whatever ID you want. Okay. So I click on submit here. on submit here. It will create another group MG00003.
here? Do you need to keep MG under subscriptions or subscriptions under NG? Okay. So you need to focus on hierarchy here. Hurry. You never put management group under subscription. That is not possible. Okay, management group is a
possible. Okay, management group is a logical container which is created to manage your subscriptions. So always subscriptions will go under management subscriptions will go under management group not vice versa. I cannot put man I
group not vice versa. I cannot put man I I cannot put subscriptions under subscriptions that's not possible. Okay. So always your subscriptions will go under management group. So if you see the uh the portal here
the uh the portal here this subscription Azure training MG00003 this subscription Azure training MG00003 MG00004 MG01 are all in the same line are all in the same hierarchy that means they are within tenant root group. Okay
now we just created MG00004. Now if I want to move this pay as you go, I can simply click on these three dots move and I can move it under wherever I want. Do I want to move it
wherever I want. Do I want to move it under MG00004, MG00001, MG000? Wherever you want to move, you select that management group and move it. That's will be moved. But whenever you are moving something at this level, you need
to understand that the permissions, the policies all will be affected. Okay. So, whatever policies and permissions you have under MG00004,
have under MG00004, those policies will be applied to now uh moved. So before moving this subscription was under MG00003. So whatever role policies were assigned to MG00003
will be would would have been inherited by pay as you go. But now since we have by pay as you go. But now since we have moved whatever policy and rules access whatever you have at MG00004 will be inherited by pay as you go. All right.
So that's how you manage these things and that's how you create management group and move subscriptions within the management group. You can also move management group to management group. So as you can see here MG01
as you can see here MG01 consist or contains M02 now. All right. So hierarchy within the hierarchy you can put management group within management group. So that is also possible. All right.
possible. All right. [snorts] subscription. I'll answer punk. Just wait. Okay. So I'll read your question.
uh answer. So what is a subscription? Subscription gives you access to Azure services. What do I mean by what does that mean? If I want to deploy anything in Azure, I need to have subscription. Without subscription, I cannot deploy
resources. I want to deploy virtual machine or or uh disk or storage account. Whatever I want to deploy, I need to have access. I need to have subscription in place. without subscription I I cannot deploy
subscription I I cannot deploy resources. Consider it like something uh Netflix. Okay. So in Netflix I can create the account without providing uh nowadays you need to provide the payment
details and all but I can keep my account. I can sign up. I can provide credit card. I'll still have my account there. my account will still be there but I won't be able to enjoy the the movies or the web series or or whatever
Netflix has to provide right so in order to watch movies web series what I need to do I need to subscribe to a certain plan uh in Netflix whatever plan they that plan similarly you can create as your account without subscription you
can have account without subscription but it does not make sense that means you won't have the option to deploy the services that means deploy the resources in Azure if I don't have the subscription I won't be able to deploy
the resources so what is subscription again subscription is a logical container for management and billing so Azure will charge you by looking at your subscription by looking at your usage so if I want to deploy resources I need to
a subscription I need to get a subscription from somewhere all Right. So subscription is a billing boundary. It's your isolation with other customers. So whatever resources you're deploying will be build or charged to
your subscription. All right. Again this is this is a level at hierarchy. So you can manage your resources and your access control at this level as well at subscription level as well. So if you if we go back to the hierarchy here
subscription is at the third level. First you have tenant root group then management groups and then you'll be having subscription. So most list will be sitting at the third level. So this at this level as well you can manage the
access control or the policies that you want to implement. In simple subscription is a billing boundary. If I want to deploy resources there's no subscription I won't be able to deploy resources. All right.
So I think we created one user right last time. User 01. So let me just go to the user section. I I'm just demonstrating you uh what what I explained just now that subscription is a billing boundary. So if you see
is a billing boundary. So if you see this user user 02 okay user 02. Let's login with that user. So I'll just copy the username and hopefully I remember the password. I'll open the in private window. I go to
portal.azio.com and login with this user.
This user doesn't have the LFA. Yeah,
02. What do you see at the at the homepage? So this is the homepage. Can I deploy resource from using user 02. So I'm logged in using the user account user 02. And if I search for virtual machine here we at the homepage we have
the virtual machine. If I click on that virtual machine, you see where I'm landed, it's it's complaining that I might not have access or I I might not have the subscription. Okay, if you see the first page, it says welcome to
What is it? What it is complaining? Don't have subscription. That means this user doesn't have access to any subscription or doesn't have uh any subscription within its with within its account. Okay. So you see none of the
entries matched that means there's no subscription no access to the subscriptions for user 02. So in order to deploy resource I need to have subscription. Now if I do with another user so if you see this is another user
simply learn something something right simply learn at the rate domain name. So this user if I search for virtual machine see where I'm landed on which page I'm landed at least I can see the virtual machine here. I have the create
option that means I have some access to the subscription obviously a right access with this user account so that this user simply learn at the rate whatever it is can create the virtual machines apart from virtual machines can
create other resources as well. So in order to deploy resources you need to have subscription Azure will bill you according to your usage whatever whatever you have deployed within your subscription. All right. Once again, if
I go to the in private window where I have logged in with user 02, just focus on the screen user 02. And you see when I search for virtual machine, I'm landed to this page where I cannot see any virtual machine and I I'm getting this
screen which says welcome to Azure. Why this screen I'm seeing? Because I don't have access to the subscription. So next topic that we have is policy. Now we have done the hierarchy and uh while explaining the hierarchy sorry
we have seen the hierarchy and while explaining the hierarchy u I have been and all now we are coming to that policies and arbback okay so what is a policies and arbback okay so what is a policy policy in Azure is a way to
enforce enforce something. Enforce as in to mandate something, to do something mandatory. For example, um there is a user like for example, I'll take you guys okay, you're now learning
a 305 and you might have done a 104 as well. Some of you might have done a 104, some of you are directly here for a 305. So, doesn't matter which certificate you're doing, you're learning Azure. when you're learning Azure you are
getting uh introduced to lot of services which you can use for your own use for your own uh own work okay not for company work let's say for your own work so you're learning Azure now you have learned how to deploy virtual machine
let's say or how to deploy certain resources so when you have learned that you have you're a working professional let's say and you have access to your company's
and you have access to your company's Azure subscription. access to your company's Azure subscription. So in order to just to understand Azure what you will be doing, you have the access to your company's
deploy resources, right? What you'll be doing let's say just for just for understanding or just for learning. you deploy a virtual machine which is having 64 GB of RAM [snorts]
which is having 64 GB of RAM [snorts] uh eight virtual CPUs and so and so storage. So you deployed this virtual machine. Now tell me this virtual machine the configuration is hefty or not? Is it a
minimal configuration or it's a hefty configuration? 64GB of RAM.
configuration. So I'm learning Azure. I have access to this virtual machine. Who's going to bear the cost? Is it me as a individual user? Is it my company since I'm using my company subscription? So obviously
the cost will be for my company uh my company will have to bear the cost since company will have to bear the cost since I'm using their subscription. Right? So as a company or as an Azure administrator
I know while I'm I'm coming up with governance I know that I will never require 64 GB of virtual machine for my projects or for my products I I never require that since I don't deal in that those kind of project so I never need
the hefty machines. So if I simply ask my user my employees that please do not deploy this kind of heavy virtual machines I'll have to pay for that. Now tell me just telling them just asking them not to do uh is it 100% sure
asking them not to do uh is it 100% sure that they are not going to do it. or as a as your architect that please do not deploy hefty virtual machines.
Are they going to uh I mean are they going to listen and and they I'm I'm I'll I'll be 100% sure that they are not going to do this going to do this just asking them
obviously some of them will agree some of them will not touch some of them just for sake of of deploying and and learning things they'll go ahead and deploy and deploying is not not a problem the problem is they deploy and
then let's say they forget to delete it. So they deploy this and they forget to delete it. I'll still have to I I mean as a company I'll have to pay that as a company I'll have to pay that charge. So how to restrict our employees
charge. So how to restrict our employees from doing such things. So what Azure or Microsoft uh did they came up with Azure policies. So what Azure policy does they policies. So what Azure policy does they enforces certain things. Okay. what they
what you can do with Azure policy one one example I have given you like this one example I have given you like this you can restrict deployment of certain uh sizes of virtual machines like mentioned here so I can limit to certain
SKS I can restrict users from deploying this kind of heavy hefty virtual because I don't need it if I need it obviously I'll make amendments to the policies but if I don't need it I can limit that kind of uh things using
policies Okay. Now we just understood the tag. So we can enforce that as well. By default it's not mandatory to have tag to each on each and every resource. But with policies you can enforce that. You can
ask user to uh when they are deploying the resources. You can ask them using policies to to provide the tag. Without tag they won't be able to deploy the You can also restrict deployment in certain locations like uh Azure has its
presence all over the world. Okay, we have presence in India, Australia, US, UK. Uh but let's say for my organization, for my product, we are not dealing in US. So we can restrict deployment of certain resources in
certain locations. So that is also possible. Okay. You can enable auditing. possible. Okay. You can enable auditing. You can using policy you can uh deploy the the AAS antimmalware on on all of your virtual machines. Windows virtual
machines you can deploy. There's a lot of thing that you can do with policies. So policy is a way to enforce uh certain standards that you want to achieve. All right. Now where you can apply the policy at any level in the hierarchy. At
any level in the hierarchy you can apply the policies. Now where which policy should be applied? Let's say the 64GB one that I that I told that I that I mentioned is a policy that can go at the root group level. Tenant root group
level. Why? Because I want it to be applied for each and every subscription. So I can keep that policy at the tenant root group level. Certain policies like do not deploy in a certain location. I can keep the keep
them at the management group level. MG01 or MG02. Now let's say MG01 deals with every project that we have in India. So I'll keep the location deployment uh
policy at MG01 so that it won't impact other resource uh other management groups. Right? Enforce tag again I can keep it at the tenant root group level since I want tags to be enforced at each
and every level each and every resource. All right. So policies is that that a policy is something that you can uh use to enforce whatever standards you want to want to have. All right. Now when you work with policy
I'll show you two demonstration in in this hands-on this hands-on is uh applying tags and and policy. So is uh applying tags and and policy. So what I'll do I'll first go and create a
resource group. Okay. So you see in order to create a resource group you should you can search for resource group over here and you can see a resource group right. So in order to create a resource group I click on resource
groups here and then I click on create. Okay, when I click on create, I have Okay, when I click on create, I have like two things that I need to provide. Subscriptions doesn't matter whether you're creating a resource group, um a
virtual machine, a disk, whatever. A re subscription should all always be provided. So, you have to provide the subscription and the resource group name. Okay. So, what would be the resource group name for this? So, I'll
resource group name for this? So, I'll go for a 305 RG02. All right. And then the region. So what is a region? Region is the physical location where your resource will be deployed. So if you see the drop-down,
Azure has its presence uh in all of these uh uh regions like uh in all of these uh uh regions like South Africa, Australia, India, uh East Asia, Indonesia, Japan, East, West,
Korea, Malaysia. So we have all these location all these Azure has its location all these Azure has its presence in all of these uh regions the physical location the physical data center is present in all of these
locations. So you can select whatever you want okay unless you have a policy which is restricting you to deploy resources from so and so location. Now I select central India over here. Mostly I'll be using central India to
deploy uh resources. Okay. So I select central India over here. Now what we subscription, we have provided resource group, we have provided region. Remember the region is central India. Okay. Then the next tab that you see is tags. So
here you can provide the tags. So what is tag? Tag is just an extra metadata. Okay. You can provide anything like Okay. You can provide anything like uh environment
broad. Okay. owner whoever is deploying Imran right so you can provide whatever you want it it's totally up to you one resource can have like uh 50 tags so this one resource can
have like 50 tags so you can provide around 50 tags to one resource okay but for now let's not provide the tag so even if I don't provide the tag I can click on review create and I can click on create remember I created resource
on create remember I created resource group with the name AZ305 RG01. So you should see the resource group in some time here.
without tag. Remember we created it in central India. All right. Now let's create a policy. Let's create a policy. Right? Now there's no policy. So let's create a policy. This policy will restrict
deploying resource group in central India. So if now people try to deploy resource in central India, the policy should in central India, the policy should restrict it and this policy will uh will
be applied at at at subscription level. Okay. So let's see how we can use policy. Now I I just demonstrated that I was able to create the resource group and that resource group was created in central India. Okay. Now using policy
will restrict that. So let's quickly do that. So in order to work with policy I can search for policy and I can go and select policy here.
Okay. Now if I have any policy or if I don't have any policy I can see over here. If you see on left hand side you have all the required options. All right. So you see here under assignments you can see all the policy which are
you can see all the policy which are currently assigned to your uh to at any any at any scope if you have any policy which is assigned. So right now it's zero that means no policy is assigned. Okay. Now in order to assign you can
click on assign policy. So if you see here you have two different options assign policy and assign initiative. So what is the difference between policy and initiative? Quite important from uh interview point of view. policy is like
a single policy. Okay. If I want to create a group of policy and assign those policy at once, then I have to click on assign then I have to click on assign initiative. I can create like multiple
initiative. I can create like multiple policies as a group at once and uh at one polic as one policy and I can assign that as an initiative. So if I click on initiatives. If I go back over here and if I go to
the definitions uh and if I click on uh if you see here these are all the policies that we have available as of now. Okay, these are all the inbuilt policy that that Microsoft has created and kept that. But if you see here the
and kept that. But if you see here the type the type mentioned here definition type if you see the type which is mentioned here will will will uh confirm whether it's a single policy or whether it's an initiative right now whatever
you see is a single policy but if you scroll down you see there are uh multiple pages that you can go and if if we go to the last page if you go through we go to the last page if you go through each page one of one of the type should
initiative as well. Okay, there are a lot of lot of pages. These are all the inbuilt policy or initiative that Microsoft has already created for you. You can come up with your own policy as well. Sometimes it happens that even
though we have so many policies inbuilt policy that Microsoft has created, we do not find a specific policy for our use case. So what you can do, you can come up with your own policy. You can create your own policy. All right? So in order
to create your own policy uh somewhere you should have policy definition create a policy you click on policy definition. If you want to create an definition. Initiative is like multiple policies at once. Okay. In order to
assign policy you need to go to assignments. In order to define policy or create policy you need to go into the definitions. Now in order to create policies obviously you need to be well versed
with JSON and you need to understand the different uh services that Azure has to provide Azure provides right for example this is the virtual machine related thing. So this policy can audit all the virtual machines which does not have the
disaster recovery configured. So you can use that policy and you can see how this policy is defined. So this policy is defined like this as I mentioned that in order to work with policy or anything in cloud specifically any cloud you need to
be well versed with JSON. Okay. So whatever Azure or any any other cloud provider will be mentioning is mentioning is will be mentioned as a JSON format. Okay. So what we are going to do let's go back
So what we are going to do let's go back to our topic where we have to deploy a policy which will restrict the deployment is of resource group in deployment is of resource group in central India that means uh nobody will
should be able to deploy a resource or a resource group in central India. Okay. So let's go to the assignment. Let's click on assign policy. And here the first thing that you need to define is scope. The scope is the
to define is scope. The scope is the hierarchy that we we discussed. So any scope at any scope you can apply the policy provided you have the access. Okay. So if you see here at the scope on this three dots if I click on this three
dots I can select the subscription I can select the resource group. Now you might ask the question why I can't see the management group here. So remember I have logged in as simply user. It's possible that this simply learn user
doesn't have access to the management group. So I don't see the management group here. You can assign policy at the management group. If you have access to the management group. Okay. So if I switch the browser and go to the user
which has access to management group uh like my personal user Iran Ketani. So if I search for policies here, if I click on assign assignments and if
I click on assign policy just to see the scope, if I click on scope here, you see I can see the management group. So if you have access, group. If you do not have access, you won't be seeing it. All right.
Now how to assign the access and how to see this is something we will discuss in in the next topic which is arbback. So right now we are on on policy. So let's complete the policy first. Now I'm switching back to the browser where I
have logged in with simply learn user who does not have access to uh management group. Okay. So here we'll keep the scope as subscription and I'm not selecting any resource group. I'm just selecting subscription that's all.
All right. And I click on select. So whatever now we are going to define whatever now we are going to define within this policy will be uh will be impacting this subscription only and within this subscription
creating whatever resources you'll be deploying only those uh resource or resource group will be impacted. So let me just explain this again. So if
you see this hierarchy this is let's consider this is the subscription Azure training and we are applying policy at this level now okay so if you go ahead and create a resource group within this policy
then only the policy that within this subscription then only that policy which subscription then only that policy which you are applying will be evaluated. If you're creating resource group within another subscription then that policy
will have no impact. Okay, that's why understanding hierarchy is important in understanding hierarchy is important in Azure. Okay, let's go back to the browser. Uh within this subscription, if you want to
this subscription, if you want to exclude anything, you can exclude that. or more resource group which is for R&amp;D purposes. So if I want to exclude, I can exclude. Okay, that option is given. Then here you can select the policy
definition. So I click on this three dots and there are a lot of policies. So if you see there are like thousands of policies that Microsoft has already created. You need to select your own your policies
according to your categories like I only want to work with virtual machine. So I select let's say compute. So I select compute and all the compute So I select compute and all the compute related policies will be filtered out.
So I'll see only the compute related policies. Okay. policies. Okay. You see the VM, VMs, all the VM related policies will be will be uh shown. Okay. Now what we are interested is
restriction of location. So I search I randomly search for location randomly search for location or maybe allowed location. Okay.
this term allowed location. So you see there are three policies with that name. The first policy is specific to Cosmos DB. So Cosmos DB is a resource in Azure or database in in in Azure. So if you want to impact or or restrict deployment
of Cosmos DB from certain location, you can select that. Okay. What we are interested here is in resource group. So before deploying the policy I deployed a resource group right in central India and that was allowed but right now let's
restrict that using uh using this policy. Okay allowed location or resource group. So I select that policy and after selecting that policy we need to go to the next uh tab which is parameter. So in parameters you have to
define which location you want to allow. Okay. So there are all the locations that is mentioned. What I don't want to allow is deployment in central India uh west India and south India. So I untick south India, west India and
central India from here. Apart from that every other location is allowed. So let's say that's my scenario that's my that's my uh requirement. So only central India, West India and South India is unticked. Apart from that all
other locations are allowed. Now next remediation is something which doesn't require we don't require for this policy but let let me explain what the remediation is. What is a remediation? Remediation is a way to uh
to make sure or to make that that resource compliant. Okay. For example, resource compliant. Okay. For example, your policy is evaluating um and evaluating whether the anti-malware
and evaluating whether the anti-malware is installed or not in Windows virtual machine. So you have let's say thousands of virtual machine and your VAP team of virtual machine and your VAP team vulnerability assessment team wants to
make sure that antimalware is installed on all of the Windows virtual machine. So what we can do we can use a policy. So that policy will evaluate whether the antimalware is present or not. If antimalware is not present, install it,
download it and install it. So that download and install it is nothing but remediation. Something is not present, you're asking Something is not present, you're asking policy to deploy it. So when your policy
is deploying, it process of deploying things is known as remediation. we are remediating which is which is not present there. All right. So obviously but there are some policies which might which might have this option of
which might have this option of remediation. So you can enable it. Okay. need now uh I have a question now uh I have a question what is the meaning of remediation?
The remediation is something which will make sure deploy if not exist. You see this word deploy if not exist. So if something is not deployed like for example antimmalware or any other software that you are evaluating if that
is not deployed deploy it. If it's not exist deploy it now tell me we are asking a policy to deploy things on a virtual machine. So this is a virtual machine Windows virtual machine and policy is going to
deploy that thing in the virt on the uh I mean within the virtual machine. So what process is required here? Uh is the virtual machine automatically will the virtual machine automatically will allow the policy to deploy the things?
machine will allow the policy to deploy the thing. Policy is a separate application. Virtual machine is a separate resource. Both of these are separate resource. Now policy is trying to make some
changes within the virtual machine install a software. Tell me is the virtual machine going to allow the policy to install the software or what as a engineer or administrator what we need to do?
the next step. What is manage identity? Policy is an application which trying to make some changes to the virtual machine. It's an application which is trying to make some changes to the application.
Think from the security point of view. Is the virtual machine going to allow the application as is without asking anything without doing anything? anything without doing anything? Is it going to allowed or not?
firewall not on then not deployed the VM. Firewall has has nothing to do with it. Okay. The app the request is not coming from outside your network. We are
within the same tenant. Okay. Policy that we are applying is in the same subscription whereas the virtual machine that will be evaluated will also be in the same subscription. So firewall u doesn't come in this
picture at least for this example. Okay. So Chaitan is saying we need to register the app. Hurry is saying the policy is and post. Yes. Okay. You you policy is and post. Yes. Okay. You you guys are forgetting one simple
uh mechanism you can say is authentication. mechanism you can say is authentication. I uh is this policy how the VM is going to authenticate this policy and how the VM is going to
policy and how the VM is going to authorize that policy. have to define the location where to download and install.
download and install. Uh that's secondary. Yes. Okay guys go back to IM go back to identity and access management. What is identity and access management? It allows you to
authenticate your user and authorize your user. It's not only for user, it's also for application. If you remember, we understood two different terms. Manage identity and service principle. Now tell me what is manage identity.
Suresh is saying user account should own admin right. Okay. U policy is deploying things on a virtual machine. User account where where is the user coming in here? Policy is kind of an application.
Virtual machine is kind of a resource. This application needs access to the resource to make some changes. User account is not required here. Consider it like this. You have an application which requires access to the database.
So here we we we do not include the user account when application is accessing the database. What what is manage identity? Come back. What what is manage identity? Come back. I'm I'm giving you the answer as well.
statement or words. What is manage identity?
you to please rewatch the AM section. All right. Now let's come back to the policy here. Now just answer yes or no. Is the basic step clear? In basic step, you're just defining your your scope where you want to apply the policy and
then you are selecting the policy definition which you want to apply allowed location for resource group. And selected which location to allow, which location not to allow. So we allowed
free location we allowed we we unticked few location where uh which will be denied. All right. Now for our policy we don't require remediation but I explain what remediation is now. Answer do you understand what remediation is?
Okay. So remediation is something where if uh if something is not present it will deploy. So in our policy it doesn't make sense to uh to enable remediation. using any policy where remediation is required. One policy that I provided is
uh example I provided is antimalware which is not installed in a policy will all the virtual machines. You have thousands of virtual machines. Okay. You
have thousands of virtual machines. policy will evaluate all the Windows virtual machine and see whether the anti-malware is installed or not. If it is not installed then using the remediation option we will install it.
user are not going to install it. That's why this policy is in place. Policy will automate things for you. Okay? So it will install on your behalf. So you will not ask me for the user account or or anything. So with remediation what I
can do? I can install this software. Antimalware is what? It's nothing but a software. Right? So I can install this software. I can ask my policy to install the software if it is not present. Right? Now policy is behaving as as a
authoritative application which will deploy something which will install a deploy something which will install a software inside a virtual machine. So in order to install that software virtual machine
should be authenticating the policy, right? It's possible that someone outside of my network triggered a script targeting this virtual machine triggered a script installing a a software. So this virtual
machine will allow that that person that script to to install the software. Obviously that virtual machine will have to authenticate this traffic where it is to authenticate this traffic where it is coming from. whether this traffic is
authenticate to install whether this traffic is authorized to install certain software or not. Obviously this virtual machine will authenticate and authorized right. So same goes for policy as well.
cloud, same account but virtual machine check whether this policy is authorized to deploy antimalware or not. Understood or not? So in order to
authorize what we are going to do in the next step is create a manage identity next step is create a manage identity for the policy. Clear or not? What I explained when we were discussing about manage identity?
Manage identity is an object ID is an identity for your application. When that create manage identity for that application. And then when that application requires access to the database or the storage the database or
storage will authenticate that application using that manage identity authorized yes allowed if it's not authenticated do not provide the access similarly for this policy the policy that requires the remediation you needs
to create the manage identity as well for our policy we don't need it for a certain policy where you need to remediate certain things in that case as well. All right, I hope what I was trying to
All right, I hope what I was trying to explain is clear. in basics tab you just selected the policy and the scope. So this is the
policy and the scope. So this is the scope I selected u my subscription and then the policy definition that I selected allowed location for resource group that's all in parameters tab we selected what
location should be allowed which location should not be allowed in remediation for our policy doesn't require but for certain policy if required you can enable this okay when you are working with remediation you can
create manage identity as well without manage identity ity remediation will not work. Okay, your remediation will fail. So once the manage identity is created, So once the manage identity is created, you can also provide the uh def uh sorry
permissions to the policy as well. All right. And then next non-compliance right. And then next non-compliance message. So in our policy uh we need to add a non-compliance message like please deploy in any other region
[snorts] apart from India. So what this non-compliance message will do it will help user whenever user is trying to deploy the resource group and if that resource group is failing it will help
user to understand why the deployment is failing. All right, please deploy in any other region apart from India. And then that's all. Once that is done, you can click on review create and then you can click on create. So now your policy is
in place. Now remember before applying the policy, I deployed the resource group in India. Remember right now let's try again. Now before trying obviously it's better to sign out and sign in again to take the token or the the new
token or the new policy. By default, it's uh it should be uh in in effect as soon as you apply, but sometimes it doesn't work. So, it's better to relog in. Okay. So, I logged out and then log in
Okay. So, I logged out and then log in again. resource group in central India. So, I search for resource group. I click on
create. I give it a name a 305 RG03 and then central India is by default selected but if you see there is the non-compliance message that you added in the policy is is popped up please deploy
in any other region apart from India so this is affected by the policy policy will not allow the deployment of this resource group in central India but if you select any other region apart from central India like Canada east or
something it should allow the pop-up is gone. Okay. So now uh it's confirmed that using policy we can enforce certain requirement that that is required uh by our company. So we can implement or enforce those kind of requirement.
Next topic that we have is arbback. Now this is important topic to understand. Okay. So far we were discussing about the hierarchy and I mentioned that we have different scopes in the hierarchy. uh within that scope you can apply the
access control or you can apply the policies policy we have already seen how policies policy we have already seen how to apply and we selected subscription as one of the scope similarly arbback is something which will allow your user to
something which will allow your user to give them certain rights rights like reader right so they can read something uh contributor right so they can contribute something to your subscription or uh owner rights owner is
subscription or uh owner rights owner is like a full right okay u then you have uh there are different roles available built-in roles available in Azure that you can use to provide certain access in simple terms arbback stands for role
simple terms arbback stands for role based access control so based access control so as from the ZTM you need to make sure that least privilege access should be should
be assigned to whoever wants the access. All right. So for that you need to understand arbback. Arbback is role based access control. Okay. I see Ram is asking for break. Break will take in half an hour. Okay. 9 at exactly at 9.
Okay. We'll go for half an hour of break that We'll go for half an hour of break that time. All right. Or you guys tell me do you do you all do you all agree for break right now or
break right now or later? So, ARBback ARBback stands for role based access control. So far what we
have what we have seen we have seen the hierarchy here also it's mentioned right you have management group subscription resource group resource. So this is the resource group resource. So this is the hierarchy. Now who can do what? You will
be having thousands of users. You'll be having u uh thousands of applications. what that application could can do. How how as an administrator I assign them the access. So in order to assign them the access
you need to assign them the arbback role. Arbback stands for role based roles different different roles depending on what they want to do. Assignments assignments can be at any scope. So you need to assign those roles
at any scope whatever scope is preferred for you. Okay. You want some some control at subscription level, some companies like to manage at the companies like to manage at the management group level. If you want low
management overhead, you go with management group. If you want more management overhead, that means uh every time there's a new subscription, you assign the same role to same set of groups and and and things, then you go
at the subscription level. Okay. So different scopes at different scopes you'll be assigning different roles and you can come up similar to policies you can come up with different custom roles as well. There are lot of built-in roles
by Microsoft Azio they have already created lot of built-in roles but at certain point in time you feel that built-in roles are not enough. So you can create your own custom roles as well. In easy 104 we have one practical
as well where we where we show how to create a custom role. Okay. So what is ARBback? Arbback stands for rolebased access control. So in order to see arbback, you can go to any scope,
management group, uh subscription, resource group. So I I'll show you that at the resource group level. So I'm at the resource group level. If you see uh any point in time if you want to see at at which level I am. So you can see that
at which level I am. So you can see that here. Okay, it says resource group. here. Okay, it says resource group. If I go to the subscription,
subscription, you can see at what level you are. So you are at subscription you are. So you are at subscription level. So at any level arbback can be assigned that's why we have the hierarchy. Okay. So in order to see
where I can assign the arbback or who is currently having what role you see this blade access control I am this blade is present at almost all resources all resource groups all subscriptions all
management group. So whichever resource management group you you are at you can see this blade access control IM from here you can manage the access control. All right. Now, if I go back to any resource group as well, you should see
the same access control ion. If you go to management group, you will you will see the same. So, doesn't matter uh from where you want to control. I would prefer for my company, we prefer management group. Why? Because we have
lot of subscription. We don't want to keep doing the same thing over and over again. Assign once at management group level and you're free. Okay? then doesn't matter how many subscription you add there all subscription will inherit
those particular role so best way and the best practice that Microsoft also recommends is to manage the access control at the management group level okay that would be easiest but doesn't matter at what level you are you should
see this account uh sorry access control and there you should see all the access now let's come back to access control IM and here you can see the role assignments so this role assignment tab apps provides you the current
apps provides you the current uh access that users are having uh access that users are having right all the users who has access to what access what level at this particular uh resource group level so if
particular uh resource group level so if you see I'm at role assignment here you see I'm at role assignment here my hotmail account is having the owner my hotmail account is having the owner role and if you see the scope here
role and if you see the scope here sorry if you see the scope subscription inherited. What does it mean? What is the meaning
of inherited? What level I am? At what level I am? explain the role. Please hold on. I'm what I'm trying to explain. Plus see
that. Okay. I'll explain the role as well. Don't worry. Resource group level. What level I am at? I am at resource group level. I AM access control blade. And here if you see this is one of the user account,
Hotmail account. This user account is having this particular role owner. Scope is what? What is the meaning of inherited? [snorts] Arback assigned at subscription level.
Right? This is not directly assigned at the resource group level. It is being inherited from subscription. That means Hotmail account has got this role at the subscription level. That's why it's inherited.
level. We haven't I mean administrator haven't gone directly at the resource group level and assigned the role. It was inherited from the subscription. So that's why it's important to define the scope first where you want to
at the resource group level go uh assign role at that particular level okay clear uh punkage is asking me to explain all the role obviously it's not possible to
are the important role I'll be explaining that okay now on the right hand side the next tab is the ro roles so here you see all the role now tell me is it possible to explain all the roles you see the number of roles you
you see the number of roles you and you have like 890 roles total. Okay. So it's not possible for me to explain all the role but I'll be explaining the important roles that you now what what what all these roles are. If you know we
have storage account in Azure in future topic we will be explaining storage So if you just search for that particular uh service like storage. So some roles are storage related roles. Some roles are we have seen keyword
right? Some roles are key volt related roles. So if I just type keywalt and search for it I should see the keyword related roles somewhere. So similarly for database you'll be having certain roles. For virtual machines you'll be
having different different roles depending on that particular service. Now which roles are important for you to understand from the exam point of view and from the interview point of view are these roles
interview point of view are these roles owner reader and there's one more role with the name user administrator or user
access administrator. Okay. So, let me just search for that.
just explain these roles and then we can go on break. I'll take 5 minutes to explain these roles. Quite simple. Owner as the name specifies you can do whatever you want. So if someone is having owner role that means he can do
he or she can do whatever uh he or she want to do with that particular subscription or that particular management group. So understand if I give someone the manage owner role at the management group level he can do
whatever he wants at all the subscription within that management group. So if you have thousands of subscriptions within this particular management group and you give someone owner role, he gets the owner role of on
all that thousand subscription at the end on all the resource group at the end on all the resources. So owner is like administrator in Windows. So he or she can do whatever they want. Okay. If any point in time
particular role is doing, you can read the description here. So what this description says grants full access to manage all resources. So he or she can do whatever they want. Right? Next contributor. So what is
contributor? It is also similar to owner. If you see grants full access to manage all resources but does not allow you to assign roles in Azure Arbback. What does it mean? So let's take an example here. You have user 01. You have
example here. You have user 01. You have user 02. User 01 is owner user 02. User 01 is owner and user 02 is contributor. Okay. Now there is another user coming in joining in today. Now this user needs
an access to virtual machine or resource group whatever. So owner can assign group whatever. So owner can assign access to this user 03 to any resources he wants. Whereas contributor cannot do that. So
Whereas contributor cannot do that. So that's the only difference. Owner full access can can assign or invite any other user as well. Not invite but can assign access to other users as well to any of the resources.
Whereas contributor can do everything. Can delete resource, can manage Can delete resource, can manage resource, can create resource. The only uh only thing that contributor cannot do is assign access to other resource other
is assign access to other resource other users. That's the only difference. All right. Next reader. Quite simple as the name specifies. If user 03 is a reader, he can read everything but cannot modify,
can read everything but cannot modify, cannot delete, cannot do any anything else. Okay. The last role that I mentioned was user access administrator.
administrator he or she can assign access to any other user. So if I am UAA user access administrator I can assign any role to
third user any role whatever role they they need. So if tell me now if someone is having contributor and user access administrator both what is going to administrator both what is going to happen?
contributor he can do anything whatever he wants to do plus he's getting another role user access administrator that means user access administrator g uh gives the ability to this user to assign any role to any other user
okay so these are the four role that you should be aware of and quite important from the exam point of view from the interview point of view and any conf confusion on this roles you just need to remember four roles as of now. Owner,
contributor, reader, and user access administrator. Owner like administrator can do whatever he wants. Contributor like similar to
owner but doesn't have the ability to assign access to other users. Reader as the name specifies can read whatever he or she wants to read. User access administrator has the ability to assign access to other users. So if I am user
access administrator, I can assign any role to any other user whatever use whatever role he or she wants like he wants to manage virtual machine. So I can provide virtual machine administrator role to this user if I am
a user access administrator. All right. Clear?
user access administrator that's like equivalent to owner. Okay. All right. Now tell me I have a question. I get an owner role.
Can I create a new user in in Microsoft enter ID? I I I got an owner role. See if I go back to the role assignments here. My back to the role assignments here. My account
create a user account when I have the hotmail account? I mean if I have the account? People are saying yes. Okay. Now here it comes uh here you need to understand in
Microsoft Azure the there are two types of roles. Okay, arbback roles. So whatever we have discussed so far, owner, contributor,
user access administrator, reader, these are related to arbback. Okay, arbback is mostly for managing the resources.
So I can only manage the resource if I have the arbback role. I cannot manage the Microsoft entra ID. Remember these things. Okay. Microsoft Enra ID user
creation user deletion is part of which is is is part of governance or is it is is is part of governance or is it part of uh IM entra ID as part of enter ID. Okay. So there are two types of roles in Azure arbback role and the uh
Microsoft entra ID role. So in order to work with Microsoft entra ID I need to go to Microsoft enter ID. And here also if you see there are roles and administrators tab. If I want to work with Microsoft Enra
ID, there are separate roles. If I want to work with resources, there are separate roles. Okay. So, which role is important in Microsoft Enra ID? Similar to RBback role, there are lot of roles again available here. Okay. Uh
it's not possible to go through each and every role. But which roles are important for you to understand is global administrator. So global administrator is like full access at your m at your Microsoft enter
ID. So if you have global administrator role that means you can do whatever you role that means you can do whatever you want to do. Okay. If you have the global reader role you can read whatever you want but you cannot modify anything.
want but you cannot modify anything. So if you get global administrator plus owner then you have full access at the tenant tenant plus at the governance level okay at the
arbback level. So you can manage resources you can do whatever you want. Similarly if you're global administrator you can do whatever you want at the tenant level at the Microsoft enter ID level. Okay.
Apart from that there are few roles that you should know is password reset administrator. So if you see somewhere you have password administrator which gives you access to reset password. So if there is a helpex team
who just need to reset the password then you can provide this role to them. you can provide this role to them. Helpex team right. And then there are uh Helpex team right. And then there are uh there is user administrator role similar
to user access administrator. So if you want someone to manage the assignment of want someone to manage the assignment of uh user roles in Microsoft entry ID then this role is is something that you can assign.
Okay just remember there are two roles in Azure Arbback role and Microsoft entra ID roles. Four roles, four important role that you should know from arbback side. Owner, contributor, user access
administrator and reader. Main roles in in Microsoft entra ID is global administrator. It's like full role, full access at enter ID level, uh
global reader, full read reading capabilities, user user administrator similar to user access administrator but at the at the entra side level at the entra tenant level that means if I have user
administrator role I can assign whatever role I want at the tenant level. Okay, I administrator role, someone global administrator, someone whatever as per their requirement. Clear? The last topic that we have about
governance is landing zones. Now whatever we have discussed so far, management group, subscription, resource group, tagging, policy, arback. So out of this tagging, policy, arbback are the three important uh features that helps
you to achieve the governance. The rest is just the hierarchy. Okay. Rest like resource is nothing but the hierarchy. This actually won't help you to uh
implement the governance. To implement the governance you have tag, policy and arbback, right? So using policy we can restrict certain things and we can make sure that we are meeting our compliance requirement. Using tag we can organize
our cost or automation and using arbback we can organize or maintain our access control. So what is this this last topic this landing zone is a is a is a concept
this landing zone is a is a is a concept where you can create your Azure platform you can uh maintain or configure your Azure platform before landing your workload that's the only meaning of landing zone okay like for example I
landing zone okay like for example I want to uh land a want to uh land a airplane in my city so I need to build a air airport first that airport within that airport we have runway. So runway
is nothing but the landing zone for that airplane. Right? Similarly, if I want to let's say uh have a shop in my mall. So I need to first build entire mall and then within that mall we will have different uh area
squaret of of shops and according to the requirement of the c of the users or of requirement of the c of the users or of the uh uh the shop owner they will buy their own shop. So in order to make sure that shop uh is is available we need to
first build entire mall first. Similarly uh in the airplane in the airport terminology we need to make sure the runway is there so that my plane can land. Similarly in Azure we have landing zone concept where you can define all of
your policies, define all of your arbback rules, define your ARM template, define everything and then deploy your application, then bring your application. Okay, so landing zone is just a concept in Azure where you can
prepare Azure platform before landing your workload. So how to prepare? Obviously you need to define the policies that you want to come up with. You need to define who will have what rules. You need to
define if you want to use tags and all. Right? So in Azure a simple everything is blended into this and you can create your own landing zone. So in Azure we call this as blueprints. So if I go to blueprints and there you can see
&gt;&gt; um uh you can create a blueprint and there you can see all the landing zones. Okay. You can start scratch and you can define your own policies or Azure has given you some some uh samples like foundational
landing zone, migration landing zone. Okay, common policies that it's like a best practice policies that you should be using. If your company wants to be be using. If your company wants to be ISO 2000 27,01 compliance, then you can
use this landing zone. If your company wants to be have a shared services right if you want to create resource group with certain arbback so you can create this kind of landing zone. So if I select the foundation one I'm just
showing you uh this is nothing but the best practice landing zone that Azure has created. So you just have to give it a name like for example foundation a name like for example foundation landing zone. Okay. And then where you
want this uh location to be. So you can select management group or or subscription. So I'll select subscription here. Okay. I I don't see management group since this user simply learn user doesn't have access to that.
Next in the artifact tab you can define all of the policies. So within subscription if you expand you see this policies append cost center tag. So tag will be mandatory uh tag will be mandatory for
resource group. You will you are enabling monitoring. You will define allowed locations for your resources. You'll define allowed locations for resource group. So these are nothing but all the policies. So what landing zone
is come up with different come up with whatever policy you want. If you want to add any policy later, you can add that as well. Like click on add artifact, select artifact type policy, then select what policy you want to you want to add
whatever you want to do. Okay. So that policy is added. So what we are doing with lending zone we are making sure that we are compliant since we are asking people to add tag. So whenever people are creating
is assigned since this policy will make it mandatory. Then we are enabling monitoring for all of our resources. We are defining which location to deploy the resources in. So these are all the
policies. You can add as many policies as you want. Apart from that you're creating a resource group for shared services. So resource group will be created where key volt will be deployed, log analytics will be deployed, right?
where all of your virtual networks will be deployed. Another resource group where you will be having identity service. So if you have uh domain controller or any other identity service, you can deploy it there. And
then when you when everything is deployed there is an additional resource group where you'll be deploying your first application. All right. So landing zone is just a way or or or a way where you are you are
um blending or adding all of the stuff that we have learned today like we are creating resource groups. We are making making the tag mandatory. we are applying certain policies that require for our u
our compliance then we are providing the arbback rule. So landing zone is just a logical you can say a logical way of making sure that your infrastructure is ready your platform is ready before you start
adding the application. All right. If I want to provide any arbback role at at any point at let's say this resource group. So I can select the artifact type role assignment and I can provide owner role to any uh user or
or any group or I can add it later as well once the resource group is created. All right. So that's something that you can defide beforehand before bringing your application. Now initially when
people started using Azure this was this concept was not there but uh Microsoft concept was not there but uh Microsoft introduced is introduced it very um in in a year or so when Azure Azure was there. So initially people were people
were not aware of this landing zone thing. So they started deploying resources without considering the compliance and all. So blueprint is a way where you can define your landing zone first and once you have defined
your landing zone you can bring your application. Remember landing zone is to be done uh before bringing your workload. Once you have deployed your workload
after that if you are bringing the landing zone you can still bring it but working. All right landing zone should be created first. It's like just consider it's like your plane in order to land the the airplane you first need
to have runway. If you do not have runway you cannot land your plane right? So similarly landing zone is something that you should be uh creating first or deploying or making sure it's ready first before you bring your resources.
All right. So that's about a landing zone. Yeah, you can create custom landing zone whatever you want to whatever you want. So you just need to go to blueprint and there you need to click on create. Okay,
here you can define whatever you want. I selected the foundation one. It you have the option to start with the blank. Okay, just name it uh provide the uh location the definition location and start adding your artifacts. So I'll add
what I want. I want policy, I want role, I want ARM template or I want resource group whatever I want. So if I want policy, I select policy from here. Add then again add artifact policy. Then I add again another policy whatever I
add again another policy whatever I want. Okay. So you can select your own want. Okay. So you can select your own uh blueprint your own uh landing zone as uh blueprint your own uh landing zone as well.
Debbra is asking what is the use of landing zone in real scenario. Okay. is? Forget about what is the use as of now. landing zone is? All right. So what we are doing in landing zone? We are just
defining the policies. We are just defining the arbback. Have you understood what is the uh requirement or use case of policy arbback in in real world to meet compliance you need to meet
compliance what landing zone is giving landing zone what we are doing in landing zone we are just comprising or blending all this thing in into one thing instead of doing this separately every now and then what we are doing we
creating a landing zone and we are adding all this stuff at once so if you're adding all this stuff at once what when and after adding all this stuff and creating landing zone once you on once you're deploying your resources
you're deploying VM storage account or whatever now tell me these resources will be compliant to your requirement or no
this resource will be compliant to your requirement or no [snorts] they will be compliant right so what is the use of lending zone to make sure compliant. So next year when there is auditing uh audit auditor will will come
compliant to whatever certificate we want whatever compliance requirement we logical thing where you are just comprising all of your policies that you want into one landing zone. So at future point in time if you want to see all the
policy you can see all at in central place what is assigned what is not assigned. Okay.
landing zone is. So when I deploy any resource that resource will be compliant to whatever I'm defining over here. Now every company will have their own requirement. Every company will have their own compliance requirement.
requirement, you'll be adding policies over here. Whenever people are deploying resources, that resource should already be compliant. Why it's compliant? Because if that resource is not meeting certain policy, the landing zone will
not allow that user to deploy that particular resource without meeting the compliance whatever you have defined here. Okay. [snorts]
zone. Foundation landing zone is just just for you to understand what landing zone is. I'm not saying that you need to apply the foundation lending zone at your organization. Okay? You need to understand first what lending zone is.
Lending zone is a blueprint of your Azure platform of your cloud platform. Within that blueprint, you're defining what I should be deploying, what I should not be deploying. So if I go here, I can define the location. This is
my subscription where landing zone is being applied. I click on next artifact. And here I'm defining what policies I want to deploy. So I select all the policies. For example, I don't want to deploy high configuration virtual
machine. So I restrict that using a policy. I want to make sure that tagging is in place. So I select any policy related to tag. I select that and I add tag over there. So what I'm doing here? I'm preparing my platform. This is my
Azure platform. I'm adding certain restriction. So and so VM is not allowed. So and so location is not allowed. So and so uh skew is not allowed. Making sure monitoring is enabled. Making sure we
defined here as a landing zone. Landing zone is not a physical thing which I can touch and see. Okay. Now once I have defined all this thing then my team whoever is responsible for deploying
resources when they start deploying the resources that resource will be evaluated against all this policy and all this requirement which is defined over here. If it's meeting that policies and that requirement then only the
resource deployment will be allowed. If it's not meeting it will throw some error and ask the user to fix and then user will deploy. Okay. So why why we sure that whatever resources is being deployed is compliant
compliant to the requirement. Okay, that's what the the meaning of lending that's what the the meaning of lending zone.
a project. It's just an example how you can use landing zones in real world. All can use landing zones in real world. All right.
traffic enters. See traffic is is a network part right? Landing zone is just def definition of policies and all where you're defining everything. Now where traffic will enter that will define at your network level. These are not the
network related policy. These are the governance related policies. [snorts] Suresh is saying okay you means to say if I select 27,0001 the compliance will meet according to 27,0001
or else it won't allow us to create as we like in 27,0001 what is defined what is required to meet that particular certificate that particular ISO certificate. So if I select that there will be certain policy which Microsoft
will be certain policy which Microsoft has already defined. Okay. So uh first I subscription and when I go to the artifacts
added certain policy which will make sure you're meeting ISO 27,01. So whatever is defined in that policy if you're when when you're deploying your resource if that meeting that criteria you're allowed to deploy. If it's not
allowed. So if the resource is not deployed obviously the auditing is is not in the question here. Okay. If resource is deployed and it's not meeting certain criteria then you're not compliant. Your your whatever you're
doing is non-compliant. And when ISO team comes to audit your organization or your platform they'll see that you're not compliant. So if you're using this will make sure that whatever resource you are using is compliant to this
particular policy. whatever is defined in that policy. in that policy. Okay,
subscription or the management group level. So it's it's nothing but policies arbback and everything. It's not something fancy or something new or you're deploying. It's not a physical resource a logical thing. Okay. So if
you see the definition location here, this is nothing but the scope. You can keep it at management group, at subscription, at resource group. Okay, management group and subscription, not at the resource group. Okay,
it's similar to what you do with policy. With policy, what you're doing where you can apply your policy at management group or at subscription? Same thing with the blueprint. Same thing with the landing zone. Okay,
thing with the landing zone. Okay, [snorts] rules or res uh predefined uh rules or conditions that this is
deploying your resources, those conditions will be evaluated. If your resources are meeting those conditions, resources will be allowed to deploy. If not, uh resources won't be deployed. there would be some error like
like I'm trying to deploy resource group right now and it's not allowing me right why it's not allowing me if I click on create resource group and I I put it in central India it's not allowing me to deploy why what is the reason why it's
to do is non-compliant to my organization what I'm trying to do I'm trying to deploy something at central India which that's why I'm not allowed to do similarly landing zone will do the same
thing it's not something you it's not something different okay it's just that you're blending your policies with your arbback with your arbback and uh with the if you want to deploy
anything in in in in uh freehand you can use ARM template and all to deploy blended together and it's called as landing zone that's all okay [snorts] clear.
the location. That's all. And now I'm compliant.
Okay. So case study is very simple for this. So if you can open this uh and go to governance. So here we have the case study.
uh I know this case study is asking you to design uh a governance solution for your company. So let's read through it. So, Tailwind Traders again this is the fictit fictitious company that we will
be using and Microsoft uses this name for defining anything right. So, some significant changes to their governance solution. They have asked for your assistance with recommendations and questions. Here are the specific
requirement. Cost and accounting. Telvin traders has two main business units that handles apparel and sporting goods. Each of the business unit consists of three departments product development,
marketing and sales. Each business unit and subunit will be responsible for tracking their Azure spend. At the same time, the enterprise IT team will be responsible for providing companywide Azure cost reporting.
project. The company has a new development project for customer development project for customer feedback. The CFO wants to ensure all cost associated with the project are captured. For the testing phase,
workload should be hosted on lowerc cost virtual machine. The virtual machine should be named to indicate they are part of the project. Any instance of the consistency rules should be automatically identified.
So these are the task. So for cost and accounting what are the different ways Telvin traders could organize their subscription and management group which requirement design two alternative hierarchy and explain your decision make
decision-m process. So what you need to do here is [snorts] you just need to come up with the management group hierarchy for cost and accounting for this Telvin traders. Okay. So what they have mentioned is you need to come up
with two alternative hierarchy and explain your decision-m process. Then for the new development project what are the different ways Telvin traders could track cost for the new development project. How are you ensuring compliance
with requirements of virtual machine sizing? Uh propose at least two ways of meeting the requirements. Explain the explain your final decision. So in simple you just need to come up with with a management group strategy. Okay.
How you'll be defining the management group. So what I'll be doing is the main tenant root group. Obviously you'll be having it behind within that tenant root group. I'll be creating a management group with Telvin traders. Then it's
totally up to you. You can divide it as per the the uh unit business unit apparel and sporting goods or you can keep everything in same business unit and divide it on on the uh subscription
level. Okay. So what I'll be doing here apparel this is one management group and then sporting unit this is another management group. Then within this business unit you have three department product development, marketing and
product development, marketing and sales. Each business unit has this uh this department. Okay. So what you can do you can again create three management do you can again create three management group if you want
having uh product development. Here you'll be having marketing. Here you you'll be having sales. Sim similar here product development, marketing and sales. And then you'll be having each sub each subscription depending on what
subscription is not mentioned over here. Okay, since they are saying that each responsible for tracking the Azure spend. So it's better to have a separate subscription for each or else you can have a single subscription
subscription you don't need to have three different management groups over here. So another strategy could be like this tenant root group Delvin traders and then two business unit apparel and uh sporting apparel and sporting and
then you can have one subscription each okay within each subscription in order okay within each subscription in order to track the cost. You can use tags and all okay in order to separate the talk if you're going with single
subscription. But here they they mention that uh each subunit will be responsible for tracking their Azure spend. So it's better to divide them into three different subscription which will be easier for you. Why it will be easier?
and you can simply put that in their cost center. Right? So I can have three subscription like this is for product development, this is for marketing, this development, this is for marketing, this is for uh for sales. Similarly in uh
sporting unit I'll have three different subscriptions. So either you can divide then I have one each one subscription each or you can simply put subscription within the main management group. All right. So these are the two different uh
hierarchy you can come up with. That's totally up to you which you want to go. Okay. Now in new development project, what are track the cost? So again, you can have a new management group here for uh new
development project. I I'll mention that as NDP. Okay. How are we going to ensure the compliance? Obviously, we need to use policy. So you can just mention here as your policy. Okay. And if you have any other way, you can come up with that
way as well. like you can put management group and then subscription or directly subscription totally up to you. All right, just go through this uh subscript uh case study and come up with a solution and uh I I did not get any
solution from you guys for the last case study. So you need to go to draw io and come up with a solution and send me that solution over the email over my personal email. All right. Like this. So you did not came up with
Like this. So you did not came up with any solution. management group. Same thing what what what I explained.
Same thing what what what I explained. Okay.
Somewhere you should have management groups.
be main management group. You can add a tagging or something. So you can add a text over here. So this is let's say my tenant root So this is let's say my tenant root group.
all that I leave to you. Okay. This is my tenant root group. Then I can copy We have the same thing here. This is my Telvin traders. Just rename. Then I can have additional management group. So just similar to what what you're seeing
over here. What what I what we discussed right now. You need to come up with that solution. Okay. Mustak is asking how to get Azure icon. So in order to get Azure icon you first go to draw ioappd diagrams.net net and
then from there you can simply click on more shapes here and here once you click on more shapes you should get Azure just stick check this box Azure and click on apply so you should get the Azure icon okay
all right any questions on case study or whatever we have covered so far if no questions we can move on to the next topic so next topic that we have is topic so next topic that we have is design compute service okay so if you go
design compute service okay so if you go to a305 5 study guide or a 305 to a305 5 study guide or a 305 uh learn path. This is this is the topic that we are covering right now.
So we have completed this except monitoring. So monitoring we'll be doing later uh once we have covered everything. So we have covered authentication and authorization. Monitoring is pending which we will
cover at the end once we have done with all the solutions. Now we are moving on all the solutions. Now we are moving on to the infrastructure solution. Design design infrastructure solution we are
and Azure compute solution. This is the this is the chapter topic which uh topic we we are covering right now. Okay. All right. So before we start I just need an answer from you what is a
compute service? Now we have seen uh in basics of cloud computing that cloud computing is nothing but the delivery of compute services over the internet. So what that compute service mean? What is compute service?
what only VM is compute service. What what is that compute service? what is that compute service? &gt;&gt; [snorts] someone says compute, compute is nothing but the computation
but the computation uh services like like memory which is uh services like like memory which is nothing but RAM. Okay. Uh CPU nothing but RAM. Okay. Uh CPU right and then u storage. So these are
the three thing which comprises of compute service. In simple if someone ask you what compute service is. So compute is just the home to your application. Okay. Compute service is nothing but
home to your application. Compute is actually where application lives. What is application? We have discussed is quite simple. Application is nothing but list of files. So when developer codes they codes in a file. So you'll be
having file like if developer is writing in Python they'll be having certain py. If they're writing in net, they'll be having some C related files, right? So application and in order to make sure your application run using a runtime,
you need a home for that. So that home is nothing but the compute. Now that can be anything that can be a virtual machine, can be a physical machine, can be app service, can be a container. So there are different different compute
services available in Azure. That's what we are going to see uh in this topic in this chapter. All right. So in simple compute is home to your application. Now remember one thing whatever we will be learning and for whatever reason the
whatever reason the infrastructure background is out there is because of applications in the world if there are no web app there are no desktop app then
it is not required. Okay. Business can can happen physically by by making a physical uh building a physical shop and asking customer to come physically there. Right? If there's no app, we are not required. Cloud is not required.
whatever we are doing is for the app. All right? So application can leave you need to have a compute service in place. And in Azure what
compute services we have that's what this topic is about. We have a lot of this topic is about. We have a lot of compute services. So just to describe or compute services. So just to describe or or make you uh
services. These are all the compute services we have in Azure. Virtual machine app service Kubernetes service Azure function Azure batch logic
app. One is missing which is Azure container instance right ACI. So if you see every compute has its own dedicated section. So I'm not explaining each and every service here. I'll keep it to it own uh dedicated slide. All right. for
this slide. Is it clear what compute service is? For me to keep an application, for me to make sure that my application uh can be accessed by the people or my application actually can run, I need to
have compute service in place. All right. So in that compute service which is nothing but home to my application, I'll keep my application and application nothing but files. Is that clear guys? What compute is
comput service, not all comput service are meant to keep the application. Okay. Uh not all comput service are meant to host the application. Like out of this
six services, the first three services Azure virtual machine, Azure app service and Kubernetes service are the services where you you'll actually deploy your application. Okay. rest are are different. They're not they're not mean
different. They're not they're not mean to host the application. Okay. So, we'll see what is the difference and what what each compute service is used for. So, which compute service to choose from? There's a there's a long or or a
big uh you can see a flowchart that Azure has created. Now, which one to Azure has created. Now, which one to choose at at what point in time? Uh this flowchart will help you to decide. But apart from that if you sit until the end
of this comput obviously today uh I don't think so we'll be able to complete or or cover all the services but tomorrow we we will be done with this compute section. So tomorrow once once we are done with the compute section
we are done with the compute section you'll be able to identify or define or uh take a decision on which compute service to use for your for your work or for your use case. All right, but let's go through this flowchart and see which
compute service to choose at what point in time. So from here you are starting. All right, the first question is are you migrating from on-prem or I mean from anywhere not only onrem or you are
building new. Okay, so if you are migrating go this way if you're building new go this way. All right. So let's say we are migrating since when I started my Azure career most of the customers were migrating and
I helped my second or third company to migrate. We had the uh everything in in data center in Australia. So we migrated it to Azure since we were going global. So if you're migrating these are your
options. Okay. So let's come over here and see. Now once you say yes we want to migrate. So th this way you need to go left side and here are you doing a lift and shift or you are doing cloud optics lift and shift is like whatever your
application's condition today is you're just using asis and you are just not changing anything okay you're just lifting your application from onrem AWS wherever it is however it is it's
written in old u old format or old framework you're just using that framework and shifting it to Azure. That's all. Okay. So, if your answer to lift and shift is yes, you'll go this way. If your answer to cloud optimize is
yes, you'll you'll go this way. Okay. So, let's consider lift and shift. So, I'll I'll go I'll go this way. Now, once you're lifting you're using lift and shift, is your container using uh I mean is your application containerized? That
means are you using container platform? So if you're using container platform you go this way. If you're not using container platform you go this way. So platform. So if you're not using container platform we have two options
to choose from. Azure app service or Azure virtual machine. Okay. Now when this yes and no is happened is whether your application is is web app or API. So if your application is just a API or web based
you can go to app service. If it's not, you can go to virtual machine. If your application is containerized, you again have two or three options. You can go have two or three options. You can go for Kubernetes services. You can go for
Azure app service again with container option or you can go for Azure container Okay, it's mentioned here somewhere here. All right, so these are the three options you have when your application is containerized.
are migrating you have this these options. When you are migrating your application to Azure you have these options. You can make use of virtual machine. You can make use of Azure app service. You can make use of Kubernetes
service or you can make use of Azure app service with container. These two doing containerized application. That means you're using Docker or any other container platform and you have containerized your application and
you're deploying it as a container. So either you can use EKS as your Kubernetes service or Azure app service. If it's not containerized then you have left with virtual machine or Azure app service. Okay. [snorts]
you're building new. So if you're building new obviously you have all the building new obviously you have all the options. Now which option to choose when do you need full control? Do you need a full control on operating
Do you need a full control on operating system? Do you want to make u uh control system? Do you want to make u uh control your operating system like every month you have patching? So if you're using Windows operating system, you have
patch it. So do you want those kind of full control? If yes, virtual machine is the option for you. Okay, as I mentioned, your application is not hosted on Azure batch service. But do you require the HPC workload? HPC stands
for high performance compute. So do you need that kind of workload? Uh do you require high performance? Mostly you'll be using it for for when you are processing big huge amount of data. So for your big data pipeline and all
you'll require HPC. Do you require that kind of workload? Then you go for Azure batch service. Are you using microser architecture? application? Okay. Microser architecture. If yes, you have a zero
container instance, service fabric or Kubernetes services. Okay. Uh if no, if if you want to go with eventdriven architecture, you have Azure functions or logic app. Okay. Logic app is not mentioned here, but that is also used
mentioned here, but that is also used for for event driven. Okay. And the last one which is Azure app service. It's like a platform as a service. uh platform as a service that that that you can use like you don't want to have you
operating system that means you you want to uh outsource the patching and all to Microsoft so in this case you can make use of your app service now I see it's it's overwhelming obviously you can't get entire workflow or entire flow chart
in in just 5 minutes but as soon as we go to go through each service uh we'll revisit this this flowchart again at the end and at that point in time obviously it will make sense for you. Okay. So before I move on to the first compute
service for now? You just need to understand that compute service is the understand that compute service is the home to your application. That's all. Any questions on this before I move to the first service that we have?
the first service that we have? [snorts] you mean by storage also? See we are not uh
understanding so storage as of now we're just understanding the compute that means where my application will be running or hosting okay question is related to migrate we we are not migrating storage as of now okay for
storage we have a dedicated chapter you your questions will be cleared there uh your questions will be cleared there uh how storage is handled when it comes to hosting an application. Okay. So under lift and shift we are not
migrating storage as of now. It's just application related things. All right. So let's go on to the first topic which is Azure virtual machine. This is the simplest uh
you can say simplest compute service available in Azure that you can use to host your application. Now I'm I'm damn sure that everyone here might have worked with Azure virtual machine or if not you might have worked with uh EC2 M
not you might have worked with uh EC2 M uh MS Amazon web services EC2 right or you might have worked with HyperV virtual machine or VMware virtual machine if you haven't worked with any just consider this virtual machine as
just consider this virtual machine as your own laptop but running on Azure like it's not a physical laptop it's a virtual laptop running somewhere on virtual laptop running somewhere on Azure your data center. Okay. So what is
virtual machine? Virtual machine is software computer running on Azure as the name specifies virtual it's not a physical thing. It's a virtual machine. All right. So it's a virtual software sorry software computer. So what this
virtual machine gives you this virtual machine gives you the storage like in our laptop what do we have? We have hard disk right? So what that hard disk does it allows us to store something. Similarly this virtual
machine gives me storage where I can keep certain files like operating system obviously my operating system will be there. Apart from operating system I can add additional discs and I can keep my application related file if I want to
and that's not mandatory. You can keep your I mean OS will be the uh the default disk that you'll be getting. Apart from the default disk, if you want to add additional disk, you can add to keep your application data. Right? So,
cloud-based ondemand scalable computing instance that uh you can deploy whenever you want. You can decommission or delete it whenever you want. So, it's an ondemand compute. You
need it, deploy it. You don't need it, just delete it. Okay. So what are the just delete it. Okay. So what are the features? Virtualized computing. You don't need to have a physical computer at your home and then create a virtual
machine. You simply go ahead and create the virtualized. Just deploy it using Azure portal, PowerShell or CLI whichever is whichever you prefer prefer. The usage is to host an application. So you'll be having OS. So
it supports Linux as well as Windows. Whichever is your preference. You when you are creating or deploying a virtual machine you just mention Azure that I need Windows or I need Linux and once you have Windows or Linux installed on
top of it you can deploy your applications okay scalability for it's scalable as this is one of the feature or benefit of cloud computing so any
or benefit of cloud computing so any point in time if I feel that 2 GB RAM is not enough for me I can scale it to 4 GB or 8 GB whatever according to my requirement. So scalability is the feature that you get when it comes to
compute virtual machine networking. I have the option to uh define who can connect, who cannot connect. Okay, who as in which IP can connect, which IP cannot connect. So that's something that we can define. So
networking is attached with it. management you can manage like login you can take a remote access of this virtual machine and manage it or certain management like changing the size and all you can do it directly from Azure
portal or cla powershell okay billing is a pay as you go so you will be build hourly hourly so if I keep my virtual machine deployed
uh for let's say 24 hours so I'll be paying for 24 hours. Okay. Next day I stop my virtual machine. I'm not running it. So I won't pay for the virtual machine for the compute. For storage obviously you'll be paying. Okay. With
storage the the disk that that is that is deployed. So for disk I'll be paying but if I keep it stop I won't be paying for the compute. All right. So it's pay as you go. Apart from pay as you go you can reserve virtual machine for like 3
years. So there are reserve plant. So if I if I want to reserve I can reserve the virtual machine. So I can go to reservation and reserve. Obviously my subscription doesn't support it. But if your subscription
supports it, you can reserve virtual machine for 3 years. Yeah. Right now my subscription won't support. So it won't it won't show but you can reserve it for subscription is not eligible. So my subscription doesn't support it. But if
I reserve it, I'll be saying saving around 40% of the pay as you go cost. Can see this uh Can see this uh here.
And if you see here if you see here if you go for reserve plan so everything which size you are choosing you go for 1 GB RAM this is the normal cost this is
the saving plan this is again threeear saving plan so if you go with threeear saving plan you'll be having around 54% of savings okay this question from Mustach when should be reserve and when to pay as you go.
Okay. Do you want to save money [snorts] money? So if you want to save money, go for reserve plan. You'll save around for reserve plan. You'll save around what 54%. Now when to decide whether we
should go for reserved or not. You ask your project manager is this project going to be running for at least 3 years? If he says yes, then go for threeear saving plan. So you'll save you'll save 54%. If they're not certain
that we might close this project in one one year or so. So don't go for saving plan. Pay as you go. Okay. Totally depends on project by project basis. Are you going doing are you deploying a
virtual machine for just quick test? If yes, don't go for reservation plan. Go for pay as you go. Since I'm I'm I'm doing it for testing and I'll be decommission decommissioning or deleting it in in after 3 months 4 months
whatever right so at that point in time just go for pay as you go okay
why it's reserved if you want if you are sure if you know that it you you are not going to use it for 3 years reservation is not for you okay just go for pay as you So since reservation uh you can't cancel it. If you can there will be
certain cost. Okay. Uh so it will charge you more as pay as you go if you cancel you more as pay as you go if you cancel it before the contract. All right.
I'll take the questions later. VM sizes. So there are different types or family of VMs uh available in Azure. All right. First one is general purpose. So general
purpose is mostly like for not for production use. Okay. You can use it but it's not recommended for production use. It's used for uh dev test uh
demonstration like the trainers are are are encouraged to use general purpose VMs for demonstration purpose. you will be deploying virtual machines. So you should use general purpose for or your
hands on right. So this general purpose are for dev test or demonstration or those kind of things. Compute optimize will get a powerful CPU uh to memory ratio. Okay. So you'll get more processing power as compared to
memory. So you'll be getting a good CPU as compared to memory when you go for compute optimize. Okay. In memory optimize you'll be getting powerful memory. So your memory processing would be more as compared to CPU. So where
you'll be using memory optimize. So memory optimized can be used when you want to host a database. So you need to create a database server. So we know that we need a powerful memory for database. So SQL DB, MySQL, whatever
database engine you want to install on a VM at that uh for for that scenario. If you're using a virtual machine then you go for memory optimized virtual machines. Compute optimized when you need more processing power like you want
to host an application. So we know that uh in order to host an application we need more compute we need more CPU. the CPU can process those requests quickly, right? Or else if you're using a virtual machine for a solution where you are
encrypting or decryptting or you're working with SSL quite often, then you go for compute optimize since encryption removing encryption working with those algorithms requires a more CPU. So we go for CPU for that. CPU compute optimize
for that storage optimize where your IOPS input output operations per second uh will be optimized. So if you go for storage optimize so where you can use storage optimize for example my company is
coming up with something some service like Google drive where I'll be storing people's data. So when I'm storing people's data when they are trying to access I need to make sure that data is readily available. So in that point in
time I I would be using storage optimize or let's say my company is creating a SAN kind of solution for my internal software or for my internal environment software or for my internal environment or organization. So sand kind of
uh solution requires good throughput and So at that point in time you can go for storage optimized. Okay. Then you can go
for GPU. GPU stands for graphic processing unit. So when you are when you want to work with graphical images or videos where you want to make sure that whenever people are rendering something it should be fast. So at that
point in time you can you can go for GPU like for example gaming servers or um nowadays uh uh artificial intelligence right llama or something you want to right llama or something you want to host so you can go for GPU.
Uh then the last one we have is HPC which stands for high performance compute. So if I need high performance compute like I'm coming up with my own big data pipeline and I want to use virtual machine for that. So I can go
for HPC kind of size of virtual machines. Apart from that there are lot of lot of other sizes available in the in in the Azure portal or in the Azure platform. But these are some sizes that you should you should know. Okay. Once
again you have general purpose which is for dev test kind of environment not meant for production. Compute optimize where you need high CPU right I need more CPU power. For example I'm hosting my application and that application is
working with something known as encryption decryption and application want to process that very quickly. So I need high CPU there. Memory optimize when you need more memory. Okay, I mean powerful memory, not more memory.
Powerful memory. Uh so if you're hosting a database kind of thing u where you require more memory then you can go for uh memory optimized storage optimized where you need good storage like for example you're coming up with sand
of thing or Google drive kind of thing where people are storing and you need a where people are storing and you need a quick read access to that to to to that data which is written over there. So you can go for storage optimize GPU graphic
processing unit where you need more more graphics like gaming servers, AI rendering, marketing materials, HPC higherformance compute where you want to all kind of things and you want compute for that you can go for HPC uh type type
of Azure virtual machine. Okay. Then if you want to create clusters of virtual machines then in Azure we have something known as virtual machine scale sets. So virtual machine scale sets are like deploying virtual
machines as a group of virtual machine like a cluster. So you'll be deploying more than one instance. Why we have scale sets over here? If let's say I'm hosting my application in one virtual machine and if that application goes
down what is going to happen? My application will be impacted. Right? So if I don't want to do that what I can do I can deploy that virtual machine scale set instead of single virtual machine in instead of individual virtual machine I
deploy more than one virtual machine as a scale set and in that case Azure will make sure that if one virtual machine goes down another one will be created by availability which means if one of my virtual machine
going down it's not impacting my application since my application can still serve the requests coming in from user uh using additional instances. All right, more on this later we have a dedicated slide for virtual machine
scale sets as well when we go to the high availability uh concepts. Okay. But like a group of virtual machines that you're deploying together and if one virtual machine goes down, you still have uh other virtual machines which
have uh other virtual machines which will serve your requests. Okay. [snorts] Now main thing when to select Azure virtual machine quick test you want to do a very quick test of your application whether it will be running or not. What
issue can what issue you can have right HPC kind of workload. So if you want high performance compute then obviously you cannot go for other compute instances. Obviously batch solution supports it. Apart from batch solution
other will not be able to support it. So you can go for a virtual machine. Legacy you can go for a virtual machine. Legacy app. Legacy app is old applications app. Legacy app is old applications which are not supported in
which are not cloud native or cloud optimized. So you can go for virtual machine in that case and you need a full control over operating system. So with can log into the virtual machine and you can install whatever software you want.
So you have full control over the operating system. Okay. Now this is the operating system. Okay. Now this is the excerpt from from that flowchart. So when you will be using virtual machine when you are building a new
application or you're migrating uh and using lift and shift. So if you're require full control go for virtual machine. When you're migrating and using lift and shift can you containerize it? If no can
you use web app or API app? If no then you go for solutions. Okay. This is the you go for solutions. Okay. This is the same ex excerpt from this flowchart. All right. So before I go to the portal, any questions on this? [snorts]
for dev and uh dev environment. So dev environment, you go for virtual machine, environment, you go for virtual machine, [snorts] shutting it down during non-b businessiness hours. So which will save
machine doesn't matter whether it's general purpose or any other family size uh any other VM family. If you keep it running for 24/7 you'll have you'll pay extra even when you're not using it. So it's better for dev test environment you
use virtual machine and then uh use general purpose virtual machine and then make sure it's shut down when it's not in use.
Okay. Mustach is saying VPS are cheaper. Okay, which probably
installed in VM after OS in real that's up to you what applications you wants to install. By default there won't be any. By default when you create a VM when I'm creating a VM only OS will be installed that's all apart from OS nothing else
will be installed so what application you need you can deploy that is the meaning of full control okay so when you go for virtual machine you have full control you can deploy whatever you want
all right so by default there won't be anything so if I select Windows OS only installed softwares will not be installed If I need additional softares, I can install it afterwards once I have access to the V.
Okay, any questions before I move on to the portal.
central India. same things since I want to uh okay before I delete if you see the overview page here you should this you
compliance the meaning of compliance is what our policy is saying our policy is saying that you should not have resources in central India west India and south India but if you see the policy compliance I have three resources
out of which two are compliant one is non-compliant that means one is still in So that's the kind of audit or compliance report you get when you use uh policy. Now since we only have one policy, I see this kind of compliance.
You'll be having multiple policies. So you'll be seeing percentage kind of you'll be seeing percentage kind of thing like for example here 14%. thing like for example here 14%. All right. So this is where the uh
policy comes in place to define or to see your compliance level before the audit obviously. So you can make sure that you are uh 100% compliance to
whatever requirement your your company or your clients are giving to you. All right. So let me remove this policy now. I don't need it.
have any compliance in in some time this compliance will go away since you don't compliance will go away since you don't have policy. Okay. All right. Now let's see our first demo of compute section. So here what I'll be doing I'll be
deploying a virtual machine and within that virtual machine we'll deploy a very simple application. It's not an application it's a simple uh static website. So I'll be deploying that. So let's see that and I'll be using same
static website to deploy it in all compute services whatever we are going to cover whatever demo demo we are going to see. Okay. So let's see that quickly.
So what I'll be doing in order to create a virtual machine, you need to uh search for virtual machine and then click on virtual machine and then click on create. Okay. So as usual uh with any resource the
first two things will be will be common and mandatory. So you need to provide subscription and then you need to provide resource groups right. So which subscription Azure should Azure should charge you and which resource group you
want this virtual machine to be part of. Okay. So I'll be selecting Azure training subscription and that's the subscription I have access to. And resource group I can create new if I don't have one but if you remember we
created a resource group with the name A305 RG02. So I'll be selecting that resource group. Okay. You can select whatever resource group you want. But remember one thing when you deploy a virtual machine
everything will be deployed under this resource node. Now with laptop when you buy a laptop what do you get when I buy a laptop with this laptop within this laptop we have a keyboard here we we have a CPU installed on the motherboard
right we have the storage so we have some SSD or HDD and then we have virtual uh sorry physical nick as well the network card so network interface card is also added to to the keyboard. So similar to sim similar to laptop here
similar to sim similar to laptop here also you will see the disk is getting uh created with disk you will be having virtual nick since this is a virtual machine you'll be having virtual network interface card right and then uh CPU
will also be allocated the virtual CPU will also be allocated to this virtual machine so all those stuff will be in the same resource group then next thing machine name so So I'll go with a simple
name. So let's consider this is my web server. So I'll give it a web server 01. world, what name you'll be giving? Totally depends on your naming convention. Whatever what I have seen in the real world is
people use uh the environment pro. What this server is? This server is web server. So they use web SRV. And then what is the number of this web server 1 zero some some people add the
region as well like for example this is deployed in central India so CI gets deployed in central India so CI gets added and then the number 01 so that's how uh the naming convention would totally depends on company to company
basis so someone can have like this proderver right so some some have this some have just broad Web server totally depends.
So we will keep it simple and we'll go with web server 01 or web server. All right. Then region. What is the region? Region is a physical location where you are deploying the virtual machine. Now you're using Azure portal.
So this is the cloud portal which we are using to deploy our virtual machine. But this virtual machine is not sitting in my home. Sitting at my home. What we are doing? We're deploying it somewhere on Azure data center. Okay, it's cloud.
What is cloud computing? Your data on someone else's data center. Your data and someone else's computer. So, we are deploying this virtual machine in Azure's data center. So, Azure has data center all over the all over the world.
So, central India is one of the region in Azure. So, that's what we are see we are selecting here. Okay. Then availability option. uh I'm not right now since we have the high availability
availability uh topic later when we do the network thing. Okay. So we have that topic so we'll cover it there. But uh you can high availability. If I want to deploy more than one virtual machine of the
same thing then I can make use of these availability options. All right. availability options. All right. Security type. If you want to make uh you want to have basic security, you want to have like
&gt;&gt; uh TPM, TPM is used for Bit Locker, you want to have secure boot, right? You want to have more security against uh the type of attack that is being machines. So if you want to have if you want Azure to protect it against those
kind of attack, you can go for trusted or you want to have totally confidential uh virtual machine, you can go with with this as well. Okay. Now for our use case we can go for trusted launch and in real world as well
you can go for trusted launch since that's quite secure and trusted launch that's quite secure and trusted launch gives you the option to encrypt the the discs the virtual disk that you're going to get. Okay then image. So this image
will help you define whether you want the uh Windows operating system virtual machine or Linux operating system. Now there are a lot of images like if you see we have Windows server, we have Ubuntu, we have SQL server, we have
again 2022 Windows server. Okay, apart from this you can also click on see all images and you'll see all the images available in the marketplace. You can come up with your own image as well. You can create your own image, push it to
the gallery and you can select your own image as well. [snorts] have. These are all the marketplace images. Some images uh might have extra cost. So cost will be mentioned over here. Okay. Like for Red Hat the license
is included or not. Once you select it, it will tell you whether the cost is not compatible with the security type that I have selected. So I need to change the security type. Okay. And at the cost page once I go to the review
create it will tell me whether uh the cost is separate or uh the license cost is separate or or it will be included in the images itself. Okay. So I'll go for Windows Server 2025 data center since we want the Windows machine. So I I'll
select the Windows Server 2025 data center which is the latest server operating system from Microsoft. All right. And then you have size here. Okay. What is size? Size will decide how many CPUs you are going to
get and what amount of RAM you're going to and what amount of RAM you're going to get. 8 GB. Okay. 8 G. And then there's a virtual machine running for 24/7, how much you'll be paying? All right. So
much you'll be paying? All right. So I'll go for B2MS or or D2 SV3. These are the options I have selected. Then once I create the virtual machine, you have your laptop. Uh in order to go into the laptop and do any changes, you
need to provide uh um username and password, right? So that's the safe username and password you need to keep here. So I'll go for simple Azure user and my default password so I don't forget it.
Okay. And then the network rule. So which port you want to allow or deny. All right. What these ports are? These are the TCP ports. So if you keep 3389
are the TCP ports. So if you keep 3389 open, what happened with 3389? Now this is the basic thing. Uh not part of 305 but I'll explain. Okay. Anyone knows what is this 3389 remote desktop right? So those who are
experienced in taking remote connections of Windows they would know. So this is of Windows they would know. So this is the port number where we send request to this virtual machine. So I'm sitting here somewhere in in Malaysia. Okay. And
my virtual machine is sitting somewhere in Azure data center central India. So we are not connected physically. We are not connected directly. So what I'm internet. I'm sending request over internet to this virtual machine that I
internet to this virtual machine that I want to take your control. allowed or not because I'm I'm sending the request on port number 3389. So it will check whether the port number is allowed or not. So if you don't allow
the port number here, if I just go ahead and untick this, I won't be able to take the control. So I just want to take the control, that's why you need to keep 3389 open. Okay. So this will allow your virtual machine to to to accept your
request. And then next you have disks. So here you can define the disks. So if you're using simply learn subscription, make sure you're changing this disk to uh standard HDD. Okay. So if you're using simply learn
subscription, make sure you change it otherwise your VM deployment will fail. So if you're not changing this to standard HDD your deployment will fail because of our policy the simply learn policy which is in place clear. Now
since I'm not using simply learn policy I'll go with premium SSD. It doesn't uh it it should not restrict me from deploying next uh quite
understandable. So if you see the networking topic do you want to have a public IP? Do you want to create another virtual network? Do you want to have subnet? We have a network topic but obviously we're not
going to discuss everything in in in deep. Uh we will be discussing it from a doing when you're creating a virtual machine a new network is also getting machine a new network is also getting created. Okay. So if you see the new
uh word here in the bracket that means a new virtual network will be created. within that virtual network a new subnet will be created and a new public IP will be created. Similarly, new network
will be allowed. The port that we have defined there 3389 will be allowed. Okay. So, we have a network topic where most of the things will get clear. For
now, just know that whenever you are creating a virtual machine, a network is also getting created. All right, that's all. Once that is done then you have the management section where you can define uh whether you want to assign manage
whether you want to login using Microsoft enter ID or no whether you want to auto shutdown your virtual machine so if you're using dev for dev test it's better to keep auto shutdown on so automatically VM will be shut down
at so and so point in time whenever you want 700 p.m. UTC or 700 p.m. a whatever. Okay. Then monitoring. So if you want to enable monitoring, you can have we have a dedicated chapter for monitoring. So
we are not doing any changes here. Then in advance if you want to run any script after the VM is getting deployed. So you can give that script here and Azure will execute your script once the VM is deployed. Okay. Then tags and review
create. If you want to have tags for your virtual machine like uh environment fraud, you can add the tag and then review create. Okay. Now, Kailash is asking what happens if we select enter ID login. It doesn't
yet. When you create enter ID, you're not creating domain. Okay. So, if you select Microsoft Enra ID, this will give you the option. When you select this, it
will allow you to use your enter ID credentials to log into this virtual machine. So this enter ID credentials. So anyone having the so-called uh role like virtual machine administrator login role or virtual machine user login role
uh from the arbback to this virtual machine they'll be able to login using their enter ID credentials. It's not joining domain. It's not creating joining domain. It's not creating domain. Okay. [snorts]
create uh and then create so it will start deploying the virtual machine. provided the subscription resource group the virtual machine name region uh image image will help you decide whether you
machine. Then you need to provide the size of your virtual machine 8 gig or two or 4 G whatever you want and then two or 4 G whatever you want and then username password uh inbound role that's
all rest even if you're not making any change and you click on review create it change and you click on review create it should it should work okay so rest are just non-mandatory things which Azure is automatically selecting
for you and then I click on create so it will start deploying the virtual machine it will take around 2 minutes to 3 minutes for the virtual machine to be deployed. Okay.
machine is deployed. Now in order to connect definition of cloud computing we just put the definition of cloud computing.
What is the definition of cloud computing? delivery of compute services over internet. Now my question is where is this virtual machine sitting? [snorts]
You have all the information in front of you. Where is this virtual machine deployed or sitting central India and where I am? I am in Malaysia or even if where I am? I am in Malaysia or even if I'm in India, I'm not sitting or I'm not
I'm in India, I'm not sitting or I'm not inside the Azure data center. Okay. So Central India is not Nagpur Hurry. Central India is uh Pune for Azour. Okay. For us is it's Nagpur but it's it's the data center is actually in
Pune. Okay. So I'm sitting in Malaysia. Now delivery of compute services over internet. So if I want to connect to this web server machine, what I need? I just need an access to internet. That's all. And the
IP address and the credential of this virtual machine. Okay. So let's connect. virtual machine. Okay. So let's connect. In order to take a remote access of this virtual machine, what I'll be doing, I'll be
right click. I'll do a right click on my start button of my laptop. So if you see, I'll do right click and then I go to run. And after run, I'll do MSTSC.
a shortcut to open the remote desktop connection wizard and here you need to provide the IP address the public IP address which is mentioned here in the uh on on the screen. You see the public IP address here. So I just copy this
public IP and I paste the public IP here and then I click on connect. So once I click on connect it asked me the credentials. So I provide the credentials.
the credentials that we provided at the first page when we were creating the virtual machine. Okay. Then click on yes and it will give me access. Now I'm inside my virtual machine. So whatever software or install
installation I'll be do doing that will be impacting my virtual machine not my laptop. Okay. I'm connected to the virtual machine. You can see the public IP of the virtual machine. similar to what you see here 20.219.24.129.
Okay. Okay. You can see [snorts] that here.
2025. So let's start with our uh let's continue our compute journey where if you remember uh when we were when we completed the yesterday's session uh we deployed a virtual machine and on that
virtual machine we hosted one single a very basic website okay so uh since the deployment of website was very quick so what I have done I've already created
what I have done I've already created the same virtual machine web server 01 which we had yesterday. So I'll be connecting to that web server 01 and then I'll be deploying the web server role and after that I'll be hosting the
website. Okay. So I'll copy the public IP. This is something we covered at the IP. This is something we covered at the last uh yesterday uh at the last half an hour. So I'll copy the public IP of my virtual machine. This is my virtual
public IP and I'll connect to this Windows virtual machine, what I have to do? I have to connect it using RDP and I need to make sure that port number 3389 is open which we discussed yesterday.
All right. So if I scroll down here, you see port number 3389 is open. So I can copy the public IP and then connect to this virtual machine. So I copy the this virtual machine. So I copy the public IP. I I press Windows R on my
laptop and I type MSTSC which is the shortcut to Microsoft uh sorry to RDP to RDC connection to remote desktop connection. So once I type MSTSC and press enter it will open this run uh this dialogue box this wizard where I
can paste the public IP of my machine and then I can click on connect. So once I click on connect it ask me for the credential. These are the credential which we provided when we created the virtual machine. All right. So I'll go
virtual machine. All right. So I'll go with the credential that I used credentials are okay then I can u click on yes and it should
uh connect me to the virtual machine that is deployed on uh in central India that is deployed on uh in central India on Azure platform.
any service? This is nothing but a server, right? So we deployed a Windows server operating system. If you see this, if you see the operating system here, this is nothing but the Windows server 2025 data center. So it's a
server operating system. The operating system that you have in your laptop which is for commercial use is is a client operating system. You might be having Windows 10 or Windows 11. So that is a client operating system. What is
client? Server provides some kind of service and client accesses those those So if you want to host your application or you want to host your website then you need a server operating system. You can't do that with client operating
system. All right. So that's why here we have selected Windows Server 2025 which would give us the capability to deploy whatever service we want. As of now we are focusing on deploying a website. Okay. So in order to deploy a website I
need to deploy web server role. In Microsoft Windows you have web server role known as IIS. If you're working with Linux Linux has different flavors with Linux Linux has different flavors like you can install Nix. Ninx is
another web server. So you can use that. So let's say instead of Windows operating system you deploy uh Ubuntu. Ubuntu is a distribution in Linux. So Ubuntu is a distribution in Linux. So for that I need to deploy ngx on top of
Linux operating system or you can make use of HTTP also known as Apache. We can use Apache as well. So Apache is another web server that you can deploy on top of have deployed Windows server operating system. So we will touch the uh we will
install the IIS role. All right. Now in order to install the ISO role I have to connect to my virtual machine which I have connected remotely. Right. So once I connect to that virtual machine there in every windows uh virtual machine in
every windows machine not virtual in every windows machine you have something known as server manager. Now there are different ways to deploy the role or different ways to deploy the role or service on windows uh machine like you
have graphical way you have powershell way you have cmd way. So there are different different ways available. Now since we have uh 40 50% of freshers here so I'll be sticking to GUI way since that would be easy to understand okay
instead of doing it via PowerShell and all [snorts] all [snorts] by default in Windows machine or Windows server operating system you should see this server manager which should open
automatically even if you don't uh open it it should uh open its wizard automatically if it's if if you see let's Say for in your case if server manager is not popping up what you can do you can you can go to the start
button in the in virtual machine and here also you can see server manager. So if the server manager windows or or dialog box is not opening you can click here and it should open right this is the first page that I should see
whenever I connect to my virtual Windows virtual machine. Now I have to wait. You see this blue line which is uh collecting some inventory. So I need to wait. It won't let me do anything until this is gone. Okay. So what it does,
it's preparing your server, collecting inventory data like what is the IP all those stuff it's collecting. So this is Windows specific. I need to wait until this is gone. So if I click on add roles and feature it won't let me do
okay. So it's letting me do that means it has already collect collected the data. You see now that blue line which was which was traveling is gone. Okay. It's gone. That means now I can work with my server.
Okay. So what I did on the homepage on the dashboard itself I clicked on add rules and features and from here you can select whatever service you you want to provide you want your server to provide like if I click on next next here you
have the tab known as server role okay what this server role is if you let's say we discuss about active directory domain service right so if you want to uh have this server behave as an identity server you can install active
directory domain service. If you want this server to behave as a DNS server, you can install the DNS server. Right? Now, what we are interested here, we are interested in the web server role. So, if you see here W under W, you have web
server IIS. So, this is the role which you use uh to host the websites or web applications. Okay. So, I selected web server and then I do nothing. I just click next, next, next, install. That's all.
So now it will start installing the server role for me. All right. Which installing web server. Once the role is installed, I'll simply copy paste my application files and this
uh this machine, this web server or this uh Windows machine should host my website and I should be able to access that website. That's where we stopped yesterday. Okay. So I'm continuing from there since this was very quick
there since this was very quick yesterday. That's why I'm repeating. So I'll have to wait until the installation is done. Okay. I see Ram is asking today's topic. Uh I think I already covered today's topic is is the
same. We are continuing our compute journey. So we only saw one compute as of now virtual machine we still have other compute services to to see. Okay. Once that is done we will start with our networking topic. So these are the two
plan topic in the agenda for today. All right. [snorts] So I'll have to wait until this is done. Once the installation is complete, I just have to copy the files. That's all. Where I'll be copying the
file. Since this is Windows machine, I have a file system here. Uh where I can navigate to C uh inet and here you have dubdubdub. So this is the folder where your application lives. All right. So I
select dubdubdubdub the are these are the default files. So if I don't change anything a default website would be loaded to wait until the installation is done and then only copy.
The steps are important to understand what we did. We first deploy the uh the virtual machine and while deploying the virtual machine we selected that we want Windows OS. You can select Linux if your pref if your preference is Linux. After
installing the Windows OS what we did we added the role the web server role known as IIS. And after the IIS is installed we are copying our files. So this is the the the steps these are the steps that we
are taking. All right. Virtual machine created virtual machine. Uh while creating virtual machine we selected Windows operating system. Windows server operating system. On top of it we deployed IIS. On top of it we will be
copying our files. Once the IS installation is done. already installed. So instead [snorts] of waiting let's just okay it's done. If
you see installation succeeded says it says installation succeeded on web server 01. So once that is done you can close it right without changing anything. If I hit the IP address the public IP address of the server uh it
should load the default website. Okay I just hit the public IP address. This is the default website. So if I navigate or go back to the server, you should see this is what is being loaded.
So if you open this with paint or something, if you open this with paint, this is what is being loaded. So if I replace this with my own website, I should be able to uh see my own website. Okay. So
I made some changes. Click on save and then minimize the virtual machine and refresh the the page. So you see the changes are reflected instantly right. So now if I copy my simple uh app. So if I go to downloads and copy
website. So I copy all this file go to the same location where the default website is located. Remember the location the path is cetpdw. Okay. So I delete this thing the default one and I copy I paste all the files
that I have for my website. Okay. Now if I minimize the virtual machine and uh refresh the browser now it should load my website. All right. So it's it's it's that simple. But uh if you want to learn more
on how it's it's it's not this much on on web server. There's a lot that you can do with web server. Okay. Now since we just want to understand how compute works so we are doing this. All right. Now you can just [snorts] go to the
public IP of this machine and you should be able to see the same website. Okay. which step you want me to repeat what what what we did is we installed or we
&gt;&gt; [snorts] &gt;&gt; We selected Windows OS and then we installed IIS. This is clear. Okay. So the address where you make changes is within the virtual machine
changes is within the virtual machine Cetp. This is C drive. C drive inet. So this is the folder where you have your website. Okay.
we install in this server. Uh this is not something at easy 305 level. You can not something at easy 305 level. You can install as many as you want. Uh depends on the configuration that you have selected. Okay. So I have selected uh
four uh 8 GB virtual 8 GB memory. Okay. So if my web app is is is lightweight web app, lightweight traffic, light traffic is coming in, I can install as many as my server can support. Okay, there's no proper limit. You can install
whatever you want. If you want more, you just change the size here and you install hundreds of web app. It should work. Okay. work. Okay. All right.
Okay. So pankage this is not uh something uh we should cover in uh uh something uh we should cover in uh uh a305 okay it's IIS related. So if you want to learn more on server thing then I would recommend you to go for a 800 or
a 8001 okay so these are the courses where you cover where we cover the uh server related thing but if you want to do that that you need to do from the IIS uh management console. So if I search for IIS here
another website. All right. So here if you see I have one site this is the add additional website but this has nothing to do with a 305. So I'm not covering this here. Can give it a name. You can give physical path where your
application is wherever you want to store. Mostly you'll be storing it in pub. You add additional site here with the name whatever name you want to give my site or something you select that you add your files there and and it and you
should run it. Okay. So this is how you do it but this is has this has nothing to do with a305. If you want to learn more on this uh I If you want to learn more on this uh I would encourage you to go for IIS
course or server level course. Okay. But remember one thing uh on port 80 my default website is running. So I cannot use the same port for a second website. So that's the catch there. So you need to do some routing here. And instead of
to do some routing here. And instead of uh reaching out to server over port 80, you need to use the naming the host name uh base host name routing here instead of port numbers. All right. So here whatever host name I'll be giving that
host name this server will be listening for port number 80. for port number 80. All right. So let's not complicate it.
demonstration how you can uh host a web app or a website on on Windows server. app or a website on on Windows server. All right.
So next compute service that we have is Azure batch solution or Azure batch service. Now Azure batch service is not something uh similar to what we just saw. It's not a virtual machine where you can host your application. It's a
totally different compute service where you can run large scale batch processing. What is the meaning of batch processing? When you want to process multiple files parallelly. Okay, many files parallelly at once. So if you have
that kind of requirement then Azure batch uh Azure batch solution is the batch uh Azure batch solution is the service for you which you can use to run multiple processes or multiple files. You want to process lot of files at once
parallelly. So if you want to process that kind of thing, you need large compute, heavy compute. So Azure batch solution is for you. Okay. Now what is the uh advantage of using Azure batch service? As I just mentioned batch
processing. If you have anything where you require HPC, HPC stands for high performance compute. You want to do distributed computing. Okay. I want to uh process certain files for uh in two virtual machines and certain files in
three virtual machines. So I can do that kind of uh thing. It also helps you to do the orchestration. uh you can optimize cost by uh you can optimize cost by by uh combining different sizes of
obviously you can integrate it with any other Azio service. Now where where in real world it's it it's being used. Okay. So I give a very simple example of uh YouTube. Okay. So what is YouTube?
please share the today and all past topic. Sorry. Sorry. What you mean M? I don't understand what you're trying to ask. So I'm trying to explain batch solution. So please focus here. All right. So I'm
explaining batch solution here. What is batch solution? Batch solution is a service in Azio. It's again a compute service in Azio which helps you to uh do a batch processing. So let's take an example of YouTube. What is a YouTube
service guys? YouTube is a service where you can stream videos, right? You can stream videos. So what what I can do? I can stream videos. It's a video service, a video streaming service. Apart from video streaming service, what you can do
channel, right? You can create your YouTube channel and you can upload videos. Anyone here who is a YouTuber or I'm I'm I'm damn sure that 50% of people might have tried YouTube and they might have
their own channel there and they might be uploading videos as well. So anyone here who knows how YouTube works. So what you do you create a channel and then you upload your videos. Now tell me are you the only person in the world who
has the channel and who is uploading the video how many videos are being uploaded on on YouTube at this point in time 7:26 p.m.
YouTube at this point in time 7:26 p.m. day. What do you think? How many videos day. What do you think? How many videos are being uploaded? Come on, quick. Just take a guess. How many videos in 1 second? How many videos are getting
uploaded to YouTube? Million billions of videos, right? There's no count. Millions of videos are being uploaded. Now, when you upload a video to YouTube, what YouTube does? YouTube processes
what YouTube does? YouTube processes your video. Right? If I go to YouTube, I your video. Right? If I go to YouTube, I upload my video. If I have a channel,
video, you have different options to play like you you can play that in 1K, play like you you can play that in 1K, 2K, 3 uh 4K, right? So 1080 pixels. So there are different different uh once anyone is uploading the video, YouTube
it's available in different different resolutions, right? It's not loading. I don't know why but let's come come back to the topic. So when someone is uploading at at any point in time thousands or millions of people are
uploading videos. So millions of videos are getting uploaded to YouTube. Now tell me when YouTube is processing YouTube has certain kind of application YouTube has certain kind of application which is processing this video.
being uploaded and YouTube needs some service which can process this millions of videos parallelly at the same time. Now imagine you are uploading the video and your video is in queue. After the million videos only your video will be
it will take for that video to be available on your channel. Right? So I need some kind of service as a YouTube I need some kind of service which can process this this millions of
videos parallelly and quickly. So Azure batch solution is the service which can batch solution is the service which can helps you to achieve this kind of thing. So if you have any application where you require batch processing then Azure
batch solution is the service for you. Another example, you have your marketing team in in your uh company. What does marketing team do? They come up with videos. Has anyone here work with editing or anything? So when you edit a
editing a video, what do we do? We cut our uh I mean we we record a raw footage first. Once you record a raw footage, you then take that footage, put it in
any of the editing tool and then you cut the unwanted footage. So when you when you cut unwanted footage, that means you are uh you just
like final after the final cut. Right? So when we are finally there I mean we have cut all the unwanted footage and now we have uh
added all the all the clips of footage that we need. So that means this is my final cut. After the final cut what do we do? We export our video. Export is nothing but this is my final video export it in in a full video kind of
video what that what does that editing tool do? Have you heard the term render? So the what this editing to tool is doing it's rendering your video that means it's making your full video
whatever final cut you have come up with it's making that into a single video since you have cut your raw footage and you have change entire changed your entire video and when you click on export it it starts rendering your video
that means it's exporting that video to a full video like maybe you have used MP4 or whatever format you have used now imagine imagine your company is
your company is creating or editing thousands of video uh in one day. So at that point in time I'll I I'll require the HPC the high performance compute to render my video since this rendering takes a lot of
time. So if that's my requirement I can rely So if that's my requirement I can rely on Azure batch solution service. Okay. U so these are the two examples from the real world that I can came up with. All
right. I don't have any demonstration for Azure batch solution since I don't have any application which can do this kind of stuff. Okay. But Azure batch solution how it works behind the scenes. You create Azure batch pool and whenever
there is a there is a task which is coming in the compute will be will be anything. You're doing this kind of stuff where you are processing videos. you are rendering videos or you're working with 3D modeling. So in 3D
performance compute kind of thing. That's why you might see that any editor That's why you might see that any editor mostly uh any editor who who is working on editing and all they they use the Apple uh Mac Mac studio or or Mac Pro
Apple uh Mac Mac studio or or Mac Pro right why? Because th those PCs those Mac PCs are built for this kind of work. So similarly if I want to process now now Mac is like built for one single kind of thing like I'm I'm I'm an editor
and I'm processing or rendering or creating or developing a video and I want to edit that. So I'm working on one video at a time or mostly two video in in a day. So I'm doing that. So for that kind of work Mac is okay. But if you
want to do in batches that means multiple or many videos at at at uh in a single day or in a single minute and that point in time you'll require something which can handle the batch processing. So Azure batch solution is
that solution is that service where you can uh which you can use to do this kind All right, clear. Any questions on batch processing
or or sorry a batch solution? [snorts] uh scientific research where you need like like for example weather weather
prediction models where you need to work on large amount of data from previous days and then you need to come up with a uh with with a prediction what what can be today's weather tomorrow's weather. So that's where Azure bath solution uh
perfectly fits. Okay. [snorts] I don't have any demonstration mir okay since you need an application which can which can do the batch processing and you need to send data in batches so that you can see that in live I don't have
that what I can show is just creation of batch solution which will not make any sense okay I don't have any any demonstration for that all right
Azure app service as your app solution. This is another compute service. Okay. It's not like ETL run. Okay. Batch processing. Yeah, you can use it for ETL as well. So if you're doing any uh extract, transform, load kind of thing,
you can use batch solution for that. So it's similar to that. All right. But main job of this is is to mostly where I have seen bath solution is implemented have seen bath solution is implemented is uh in in in in the in in the
is uh in in in in the in in the marketing uh team. So I've seen my friend working in a company uh and they have implemented this as your batch solution for their marketing team. Okay. But it's similar to ETL
right where you will be taking data that data will be triggered and that data will uh triggered your compute your compute will process that data and then that you can integrate it with any other service to load that data somewhere.
service to load that data somewhere. All right. next compute service that we have in Azure is Azure app service. Now, Azure
app service is also a service where you can host your application. All right. So, if you want to host your web app, uh you can make use of app service. Uh the infrastructure for this is managed totally. So, fully managed
infrastructure. Uh you have the option to scale it out or scale it in depending available. You can integrate it with DevOps. uh it gives you the option to
compliance. By default, your data will be secured. Okay. Then you can integrate Azure app service with with other Azure services since this is an Azure service. integrate it with Azure other Azure services and it has support for
containers as well. So main main thing that you need to understand for Azure app services this is mainly used for hosting web apps or website. Okay. Or
APIs if you're creating if you're working with APIs. So you can host these working with APIs. So you can host these three things. Now question may arise for freshers that here also I can host web app. In virtual machine also I can host
web app. So what is the difference between these two? The difference between these two is virtual machine is infrastructure as a service. Okay. Where you have the full control over operating system. So I can
as as you saw that I logged into the virtual machine and then I can make any change instead of web server. If I want to make this as a DNS server, I can do that. I have that flexibility or that option or that capability to make this
as a DNS server. Okay, I can make it as a DHC DHCP server as well. So I have Whatever I want to install, I can do that. So that uh instead of just keeping this as a web server, I can install all these roles as
server, I can install all these roles as well. So that uh benefit we get when we in when we use Azure virtual machine. Whereas when you're using Azure app service you do not have control over the operating system. If you remember from
operating system. If you remember from from the uh basics from the first uh session we discussed infrastructure as a service and platform as a service. What as a service and platform as a service? In infrastructure as a service, you have
In infrastructure as a service, you have full control over the operating system. So when I use infrastructure as a service model, I am deploying a virtual machine. I'm selecting an operating system and I have full control over that
operating system. When I'm selecting platform as a service, I can select which operating system I want whether Windows or Linux. But I don't have That means when I say I don't have
control I'm I cannot log to that virtual machine when I'm using platform as a service model. So what uh what pass can help you to do is host your web app website or uh web app
website or API but you won't be able to log the v operating system that you have selected whether it's Windows or Linux. Okay. Now when you don't have control over the operating system, what advantage you have?
When I don't have control over operating system, I am not responsible for the patching of the Windows OS. So if I'm using infrastructure as a solution and I'm deploying everything in VM, I am responsible for the patching. So if I go
to the settings and Windows update, I need to make sure whenever a new update is available, I need to make sure that I have installed it. like these two updates are already there in my virtual machine. So I should be the one it's not
responsibility since I had deployed the virtual machine. So this should be installed by me as a as a user as a consumer. Okay. Whereas in path service responsibility. So underlying virtual machine will be
patched by Microsoft. All right. So that's the advantage that that you get. Now the question may arise which one to use? If you are a developer the best option for you is app service.
If you want more control on the infrastructure and you are infrastructure admin and you want more control then infrastructure as a service is the option for you. That's the best uh bet for you. All right. like you just
within the same virtual machine you need to install some other softwares and some other uh uh roles like DNS, DHCP whatever you need for your infrastructure. So you can install that that option you will not
get in app service. All right now whenever you want if let's say uh in interview you get a question explains the difference between p and I so you just remember this table. So with IAS infrastructure as a service you have
IAS infrastructure as a service you have more responsibility you as the as the uh consumer you have more responsibility when you're using IAS model when you're using pass model you have less responsibility
less responsibility okay so just remember this box what this let's say you want to deploy an application what option you have uh
I'll I'll draw one more box for onrem okay on premises that means your own data center so what options you have when you want to host an application when there is there was no cloud the
only option that we had was on-prem right so what you used to do when when you were when when we were using on-rem you had to had your own server physical server right on top of that server you'll have to deploy the operating
operating system or Linux operating system whichever. On top of that you need to deploy a runtime. What is a runtime? Runtime is a runtime. What is a runtime? Runtime is a is a is a framework which is used to uh
run your application in simple terms. Okay. So your developer might be writing Okay. So your developer might be writing application inn net or java or python whatever or or node. So there are different different runtimes available
right. So if my developer is writing uh the application inn net I need to have net framework installed net runtime installed. Okay if my developer is writing application in java I need to have java installed similarly python or
node whatever so this also I have to install net if my application is written in net and on top of that I'll be having actual files of my application. So when you're using on-prem you're responsible for everything from bringing physical
server installing operating system on top of it installing net framework on top of it and then bringing your files that means copying or adding your files responsibility when you go for on-prem now when cloud introduced cloud was
introduced in different uh models like infrastructure as service pass as a service so behind the scenes we still have the physical server and infrastructure service we still have the physical server. What is this physical
whose responsibility? Uh when you're using cloud physical server is the responsibility of the cloud provider. If you're using cloud the physical server is the responsibility of cloud provider. All right. Now you have the option you
have the flexibility to choose whether you want to use Windows OS or Linux OS. OS. So if you're using infrastructure as a service, Windows OS is my responsibility. That means the license which which is required for Windows
The monthly patching that I'll be doing is my responsibility. The runtime that Let's say I go forn net or java whatever. Okay. So, net installation of
net is also my responsibility. Then again files obviously the application go for infrastructure as service out of the four boxes the three boxes are your responsibility. The operating system, the framework and the files.
Okay. Then if you move to p platform as a service, the physical server the the state setup will be same. The physical server is still there. Now it's it machine or what. Right? And then operating system is still there. You
just have to tell the provider that I want to use Windows or Linux. The framework is still there. What your responsibility as a when you're using p model is only the files. So you just focus on development that's
So you just focus on development that's all the last box the I mean from the top the first box only the files is your responsibility rest three are the responsibilities of the provider so when you use on-prem
everything is your responsibility from scratch when you're using cloud uh or infrastructure as a service the physical server becomes the provider's the operating system is your respons responsibility. The framework that you
The files that you want to install on top of uh uh files are nothing but the want to install or deploy on top of that Windows operating system or Linux operating system is your responsibility. In p you are only responsible for
development. The infrastructure, the entire infrastructure, the platform is the provider's responsibility. Okay. So that's the difference between virtual machine and app service. App service is a path service. So what we
are responsible for is the the files that we need that we need to uh deploy. You create an Azure app service and then just push your files into that app
All right. Pankage is saying please explain runtime. Runtime is the framework punkage. Okay. So runtime is the framework as I mentioned here net java python node. So in order to install or
host any application your developer will be writing an application in certain language right in simple term it's a language which your developer is using uh to to write your application he can be use he might be using python he might
be use he might be using python he might be using net car might be using java host that application I need to have that framework installed that runtime installed on my machine and if I install
that runtime runtime is like a run time which helps your application to run. All right. Clear. Okay. So what we did when we installed the virtual machine we provided we we
informed the server the service provider the cloud that we need Windows operating system and then on top of it whatever we had to do we did like we installed IIS then we copied our files. Right now next month when there's patching I will be
physical infra is still uh cloud provider's responsibilities. So now now let's see uh demon let let me demonstrate how you can use Azure app service to host the same application that we are hosting on a machine on on a
virtual machine the same application which is hosted here. Now I'll host the same application on an app service. All right. So in order to create an app service, you need to search for app service in the s search bar. So I'll
search for app service here. All right. I click on app service. This is the first one app service. So I'll click on the app service and then I app.
All right. Now as usual whichever resource you are deploying on Azure where Azure will be charging and a resource group where this where the resources for this service will be deployed. So I select AZ305 RG01 where
my resources will be deployed. Then the instance name instance name is the web app name okay so what web app name you want. Let's go with simply learn. This should be globally unique. Okay. So if I go for simply learn, you
see uh this name is not available. That means someone has already deployed a web app with this name. All right. So what I do, I just add some random number uh on on on front of it. All right. And this is the runtime stack that I was saying
whether you want to use net, you want to use Java, you want to use Python. All you need to install when you want to host an app. But when you're using a pass service, you just need to tell the provider that I want this runtime Python
and they will install Python. I want this runtime node and they will install node. So they are making sure that your platform is ready. You just need to bring your code. That's all. So if I
select net 10, net 10 will be installed on top of Windows operating system. So what I'm telling the provider is install Windows operating system. on top of that install.net. All right. And then the region where
your uh where you want to deploy the app service. So I I'll be mostly I'll be using central India for all of my servers. Sorry all of my services. So I'm using central India here. Okay. And then there is a plan. Plan is the skew
on um on the basis of which Azure will decide uh how much to charge. So there are different plans available. So there are different different plans available. You
can select whatever you want. So if I click on explore pricing plan, these are the different plans available. So it decides how much RAM you'll be getting, how much CPUs you'll be getting, right? You can go for premium plan which will
give you one virtual CPU and four uh GB requirement, you can choose whatever you want. All right. uh for some
plans the the prices are also the estimated prices are also mentioned. All right. Now since this is just for demo purpose so I'll go for standard or uh basic since that that that will cost me less. So we have standard plan as well.
less. So we have standard plan as well. Standard S1 now consider this plan as just the amount of RAM you'll be getting amount of uh CPUs you'll be getting. All right. and how much it will charge you how much Azure will charge you for that
particular uh RAM it's not like that once you choose and it will it will stay like this if you in future if you want to change the plan you can change it let's say I'm not satisfied with
standard the performance of standard S1 so if I want to go for premium I can go okay I can switch any point in time that's the that is the the benefit that you get in cloud so you see the benefit Benefit number three, the feature number
three, scalability. So right now when I'm deploying the service, I'm selecting a different plan and in future if I need a different plan, I can do that. Okay. All right. So I I'm selecting standard S1 for low cost as of now. All right.
And this is the name of plan. So this is the name. You can uh give whatever name you want. So this is the default name or uh a random name that name that Azure is name, you can you can give. So this is my simply learn uh app service plan 01.
Okay. You can give whatever name you want. All right. Now once that is defined that's all. If you don't want to touch any other uh uh tab that's fine.
You just click on review create and your app service will be created. But you can associate or create database here. If you want you can uh so you can have your uh CI/CD pipeline as I mentioned here key features DevOps integration. So if
you have a CI/CD pipeline you can integrate uh with C CI/CD pipeline as well. If you want to integrate it with network you can do that. All right. If you want to have uh a different service which will be monitoring uh this web app
you can uh enable that. I'm not enabling it. We have a dedicated chapter for monitoring. So I'll keep it for that. All right, that's all. You can associate it with database, you can associate it with CI/CD pipeline here, right? If you
have a network and you want to integrate your app service with network, you can do that from here. If you want to enable monitoring, you can enable it from here. anything. Just I'm going with the default setting. I just uh in the
monitoring section I just u change the radio button to no that's all and then I can click on review create and I click on create all right so it will start deploying my app service
I want to select standard or maybe basic.
standard now and uh it's it's now going to the deployment page. In 5 minutes your app service will be up and ready. All right. So I can browse my app service from here. As a end user if you want to go to YouTube how do you go? You
type dubdubdubdub.youtube.com on your browser. Right? So this is where this is the address where YouTube lives. Similarly for your app you have an address uh where your application is is living. Here you can see the domain. So
this is the address where your application is living. Simply learn 5689.eites.net. So here we have our app running. Okay. In sometime you should see your app. Now what we have done we have just made sure
that platform is ready. We still haven't pushed our code. We have not added our code. What did we do when we when we uh worked with virtual machine? We deployed the virtual machine right on top of it. We deployed the in uh IIS
role and then we copied our file. So, so far in app service what we have done, we have done this part. We still have not copied our files. So, we need to copy that. All right. We need to copy that.
So you see when I browse that that endpoint that URL it says my web app is running but waiting for the content. So I still haven't published my content yet. Now for web app there are different different ways to publish the content.
One one way is to use the DevOps way of of publishing the content. Another way is to use the CLI to publish the content. So there are different different ways to publish the content but for our use case uh it's a simple
website which which we are using. So what we can do we can use the graphical way app service editor. I can open the editor. So it gives me the access uh
access to the file system where I can simply upload my files. Remember what we did with virtual machine. We deployed the IIS and then we copied our files. So we have to do the same thing with with the app service as well. So I need to
copy that file. So in order to copy what what Azure has done, Azure has given you the access to the file system. So under the development tools you have app service editor and from here you can open the editor and uh you can copy and
paste your files here. Okay. So let we have to wait until this is So let we have to wait until this is fully loaded. It takes s some time and in any point in time if you want to change the plan the app service plan you
have the option here under app service plan you have scale up scale out. Okay. So when you want to scale up you can change from basic to share to basic 2 to basic 3 to premium. So if you feel that the traffic which is coming to my
the traffic which is coming to my application uh is not served properly or served very slow. So that could be because you only have 1.75 GB of RAM. So it might take lot of time for processing a particular request. So
if you feel that at any point in time you can change your your plan. Now remember if you go for premium plan the cost will increase okay depending on which plan you are choosing and the amount of memory you're getting your
amount of memory you're getting your your cost may increase all right so now as you can see it's loaded and this is where did we copied our file under dubdubdub root right in virtual machine if I go to the virtual machine
we copied all of our file to dubdubdub root right similarly here also you have the dub dubdubdub root folder from where you can to where you can copy your file.
So what I can do I can delete this one the the default one and then I can right click and I can upload my simp my simple app files. So if I go to download and app files. So if I go to download and search for simple app
it. So this copy will be uploaded the files will be uploaded here right the index.html html this is the file which will be loaded. Now if I refresh my my endpoint, I should see the similar uh application here.
Okay, same website which is being loaded from virtual machine. Now it's being from virtual machine. Now it's being loaded from the uh app service as well. Clear you can also try to browse this and you
should see the same website being loaded. What is the advantage of using getting the SSL certificate free of cost. I mean the cost it's included in HTTPS uh which I need to buy separately if I'm
my virtual machine traffic is not secured. In order to secure that I need to buy a SSL certificate and obviously I need to buy a domain name as well since I'm directly hitting that at the IP address. Right? That thing is that is is
benefit when you're using path service. you already have HTTPS plus you have a domain name. You don't you're not hitting the website on on a particular IP address. You're getting a domain name separately
separately free of cost. Okay. All right. So for deploying the code it's very simple. You can go and you can place your since my website is quite basic so I can do that from the app
service editor. But if you want to deploy an entire code uh in that case you can make use of a web app command from from from where you can deploy the code. So a easy web app deploy or easy web app uh deploy is
the is the command that you can use. So this is the command that can be used in order to deploy entire source code. Okay. So your source code can be in in Okay. So your source code can be in in jar file or in in zip file and you can
deploy your source code. The example is also given over here right. If you want to deploy a war file uh this is the this is the command. If you want to deploy a zip file this is the command right. So there are different different uh ways to
deploy the code. If you want to use uh the command line way then this is these are this this is the command that you have. Okay. Apart from command line, you can also deploy using uh something known as Visual Studio Code. So from
known as Visual Studio Code. So from here also you can deploy the the the the source code. Apart from Visual Studio Code, there is another software from another IDE from Microsoft which is Visual Studio. From there also you can
ways to deploy the source code. Since our application is quite simple uh it's just a website. So I deployed using the graphical way which will be easier for graphical way which will be easier for freshers to understand. All right.
Um in future we have advanced topic as well. So once we are done with database well. So once we are done with database once we are done with uh the app service architecture. In the app service architecture we are going to deploy a a
fully looking app uh application. Okay. Uh so that's that's where you will understand how to deploy an entire source code or entire application &gt;&gt; Now we have come to the end of our session on a 305 designing Microsoft
Azure infrastructure solutions. Thanks for watching and keep practicing because cloud architecture is not just about knowing services and do not forget to subscribe simply learn for more such valuable courses.
