**Azure architecture and networking | AZ-900 | Video 3 — Transcript & Summary | SozAI**
Source: https://sozai.app/transcript/azure-architecture-networking-az900-video3/

Learn Azure architecture, networking, compute, and management fundamentals in this AZ-900 session by Microsoft Learn.

## Key Takeaways

- Azure architecture is designed for high availability and disaster recovery using regions and availability zones.
- Subscriptions and resource groups are fundamental for organizing and managing Azure resources.
- Azure offers diverse compute and networking options to build scalable and secure cloud solutions.
- Azure Cloud Shell supports both PowerShell and Bash, with Copilot assisting in command generation.
- Free Azure accounts provide an accessible way for beginners and students to start learning and experimenting.

## What the video covers

- Introduction to Azure architecture and networking fundamentals as part of the AZ-900 Microsoft Azure Fundamentals series.
- Overview of Azure global infrastructure including regions, availability zones, and disaster recovery strategies.
- Explanation of Azure subscriptions and resource groups for organizing and managing cloud resources effectively.
- Detailed coverage of Azure compute options such as virtual machines, app services, and container-based solutions.
- Introduction to Azure networking essentials including virtual networks, subnets, network security groups, and connectivity options.
- Demonstration of Azure portal features including Cloud Shell usage with PowerShell and Bash, and leveraging Copilot for CLI commands.
- Discussion of Azure free accounts for beginners and students, including access to free services and credits.
- Insights into Azure DNS, ExpressRoute, and security features to ensure secure and reliable cloud solutions.
- Guidance on managing Azure resources, billing boundaries, and deployment templates for efficient cloud environment setup.
- Encouragement to explore Azure further through Microsoft Learn and practical demos.

## Chapters

1. 00:00 Introduction and session overview
2. 02:43 Importance of Azure architecture concepts
3. 05:05 Azure free accounts and student offers
4. 07:32 Using Azure Cloud Shell with PowerShell and Bash
5. 10:14 Transition to Azure architectural components
6. 13:23 Azure regions and disaster recovery
7. 16:03 Exploring Azure datacenters and global infrastructure
8. 18:25 Resource groups and subscription management
9. 26:21 Azure compute options and deployment templates
10. 31:03 Networking fundamentals and security

Answers

## Questions about this video

What is the purpose of Azure subscriptions and resource groups?

Azure subscriptions act as billing boundaries and provide access to Azure services, while resource groups help organize and manage related resources logically within those subscriptions.

How can beginners start using Azure for free?

Beginners can sign up for an Azure free account, which offers free access to popular services for 12 months, a credit for the first 30 days, and access to always-free products without being charged unless upgraded.

What tools does Azure provide for interacting with resources via command line?

Azure offers Cloud Shell, which supports both PowerShell and Bash environments, and includes a Copilot feature that helps generate CLI commands for managing Azure resources.

## Full Transcript — Download SRT & Markdown

00:01

Speaker A

[Music] Alexandra Zakharova: Hello, and thank you for joining me. Welcome to the second session of AZ-900 Microsoft Azure Fundamentals.

00:15

Speaker A

I hope you have had a chance to watch the previous video in this series and are ready to continue building your Azure knowledge.

00:24

Speaker A

I am Alexandra Zakharova, a Senior Technical Trainer specializing in Data and AI. And I am excited to guide you through this learning journey.

00:33

Speaker A

If you would like to connect, you can find me on LinkedIn via ak.ms/Alexandra. Before we dive in, here is a fun fact about me.

00:45

Speaker A

I have been dancing tango for over a decade. Tango is all about rhythm, quality, precision, and creativity, qualities that remind me of how cloud architecture works when everything is perfectly orchestrated.

00:59

Speaker A

The AZ-900 Certification is an excellent way to demonstrate your understanding of essential cloud concepts, Azure services and workloads, security and privacy in Azure, as well as pricing and support options.

01:15

Speaker A

It provides a strong foundation for anyone starting their journey with Microsoft Azure. The second session is divided into two parts delivered in separate videos.

01:28

Speaker A

In this first part, we will take a deep dive into Azure architectural components, the backbone of Microsoft’s global cloud infrastructure.

01:38

Speaker A

You will learn how Azure organizes resources across its worldwide network of regions and availability zones, ensuring high availability and disaster recovery.

01:51

Speaker A

We will also explore subscriptions and resource groups, which are key to managing and organizing resources effectively.

01:59

Speaker A

Next, we will move into compute and networking fundamentals. We will discover the different compute options Azure offers, including virtual machines, app services for hosting applications, and container-based solutions.

02:17

Speaker A

We will also look at networking essentials, such as virtual networks, subnets, and connectivity options that allow resources to communicate securely and effectively.

02:29

Speaker A

By the end of this session, you will have a clear understanding of how Azure structures its architecture and delivers compute and networking capabilities to support scalable, secure, and reliable solutions.

02:43

Speaker A

These concepts are critical for anyone planning to design or manage cloud-based environments. So let's get started.

02:52

Speaker A

In our second session, we are diving deep into the building blocks of Azure. We will start with Azure architectural components.

03:03

Speaker A

You will learn how regions and availability zones keep your apps resilient and how subscriptions and resource groups help you stay organized.

03:12

Speaker A

Then, we will move into compute and networking. We will explore different compute types, how to host applications, and how virtual networking connects everything securely.

03:25

Speaker A

Next, we will tackle storage, from services and redundancy options to file management and migration.

03:34

Speaker A

Finally, we will wrap up with identity, access, and security, covering directory services, authentication methods, and security models to protect your environment.

03:50

Speaker A

So we want to create and use Azure services. Here is the first step: you need an Azure subscription.

03:57

Speaker A

Think of it as your ticket to the cloud. When you set up your Azure account, you will automatically get a subscription.

04:04

Speaker A

From there, you can create more, maybe one for development, another for marketing, and one for sales.

04:11

Speaker A

It's all about keeping things organized. So how do you get Azure? Easy. Sign up on the Azure website, go through a Microsoft rep, or work with a cloud solution provider partner for a fully managed experience.

04:28

Speaker A

Now, what about the Azure free account? It's perfect for beginners because it gives you free access to popular services for 12 months, a credit to use in the first 30 days, and access to more than 25 products that are always free.

04:47

Speaker A

Signing up is simple. You will need a phone number, a Microsoft or GitHub account, and a credit card for identity verification.

04:55

Speaker A

Don't worry, you won't be charged unless you upgrade. Students, we have got something special for you, too: the Azure free student account.

05:05

Speaker A

It includes free access to certain services for 12 months, a credit to use during that time, and developer tools to help you build amazing projects.

05:16

Speaker A

The best part: no credit card required. Now let me show you how you can interact with Azure.

05:27

Speaker A

In this demo, we will see together how to explore interacting with Azure. If you want to follow this demo, you can also find the instructions on the Microsoft Learn website.

05:36

Speaker A

When you first connect to Microsoft Azure, you will find Azure services in the middle of your screen, as well as recent and favorite resources in the bottom part of your screen.

05:46

Speaker A

I highly recommend using the Search tab on the top if you want to discover some resources, services, or even documentation.

05:58

Speaker A

If, for example, here I type "virtual machine," I will see the services recommended here, but also marketplace resources and documentation that will redirect me to Microsoft Learn.

06:14

Speaker A

On the left side, you will find the most common Azure resources as well as your favorite resources that you can adjust according to your needs.

06:27

Speaker A

On the right side, next to my profile picture, you have Cloud Shell, Notifications, Settings, and Support buttons if you need to reach support, or you can also provide feedback to our team.

06:42

Speaker A

Let's start with Settings. It's here you can select your subscription. You will find the full subscriptions list in this part.

06:50

Speaker A

And, if you want to switch between subscriptions, you can. You will also see the Appearance part.

06:56

Speaker A

If you want to set up the view of your Azure interface or the theme, for example, if you want to switch to dark, you can do it here, as well as decide how your left side menu behaves.

07:12

Speaker A

You can switch the language as well, and you can change your contact information in the same Settings part.

07:20

Speaker A

We do have here Cloud Shell. Let's say you prefer to use cloud to interact with your Azure environment instead of a visual interface.

07:32

Speaker A

In this case, you can launch Cloud Shell directly in Azure and select if you want to use PowerShell or Bash.

07:42

Speaker A

So, by default here, I have my PowerShell that did authentication for me, and I can write some commands here, for example, get a location to see all locations available in Azure.

07:57

Speaker A

So those are different regions that I can use. We will discuss them later in the module related to storage.

08:07

Speaker A

Also, I can ask to provide the same formatted as a table. And so I add to my command "ft," and it will provide me the same list of regions available in Azure in a different format, like you can see here.

08:23

Speaker A

And, if you are more familiar with CLI, so Bash, you can also change to CLI interface inside of our Cloud Shell.

08:35

Speaker A

And, technically, even write the same command, but in a different language. Like here, I can ask for az account list locations to review the list of the regions available.

08:49

Speaker A

And, if I want, I can format it as a table as well in a Bash environment.

08:56

Speaker A

To do it, I will just add to the same command "az account list locations --output table," so it means organize as a table, and basically, I achieve to do here.

09:09

Speaker A

I will see the same result as I did in PowerShell. For sure, if you are more familiar with graphical interface, it's more comfortable, you can use it.

09:17

Speaker A

If you want to try some Cloud Shell here, but you don't know all these commands, I highly recommend using the "Copilot" button on the top as it proposes you some CLI language formulas and capabilities.

09:37

Speaker A

For example, if I don't know how to use it, I can ask how to create a virtual machine with a specific size, and it will suggest my command, and I can just copy/paste it directly from Copilot to my Cloud Shell.

09:51

Speaker A

Or, also, I could ask any other question about Azure insight to learn more about it.

09:57

Speaker A

So, so far, we saw that we can leverage the Search part of our portal, use the most common services, set up our account, and also leverage Copilot to communicate better with Azure and to know more about this portal.

10:14

Speaker A

I hope you enjoyed. Let's come back to our presentation. Let's continue with the next lesson centered around the fundamental components of the architecture.

10:26

Speaker A

This happens to be my favorite lesson.

10:42

Speaker A

A region is a geographical area that contains at least one data center or multiple data centers located nearby and interconnected with low latency networking.

10:53

Speaker A

The Azure platform automatically allocates and manages resources within each region and shrink proper load balancing.

11:03

Speaker A

When deploying a resource in Azure, you often need to select a region where it should be deployed.

11:10

Speaker A

Certain services or virtual machines type may only be available in specific regions. Additionally, there are global Azure services that don't require choosing a specific region, such as Microsoft Entra ID, Azure Traffic Manager and Azure DNS.

11:30

Speaker A

Microsoft Azure currently comprises more than 60 regions worldwide available in 140 countries. The second term related to our regions is "availability zones." Availability zones are physically separated data centers within a single Azure region.

11:51

Speaker A

Each availability zone consists of one or more data centers equipped with independent power, cooling and networking systems.

12:03

Speaker A

As a result, an availability zone acts as an isolation boundary. If one zone experiences an outage, the other continue functioning.

12:15

Speaker A

Availability zones are connected through private high-speed fiber optic networks. To ensure resilience, each region supporting availability zone has at least three separate availability zones.

12:31

Speaker A

However, some services may have limited support for availability zones. For example, some may only support availability zones for certain tiers, regions or SKUs.

12:46

Speaker A

Another crucial point to note is the most Azure regions are paired with another region within the same geographical area with a separation of at least 482 kilometers, or 300 miles, between them.

13:05

Speaker A

The strategy enables the replication of resources across geographical zones, minimizing the risk of disruption caused by natural disasters, extensive outage, power failures or network issues affecting an entire region.

13:23

Speaker A

For instance, if one region from a pair is impacted by a natural disaster, services will automatically switch over to the other region in this pairing.

13:36

Speaker A

Some examples of Asia region pairs include West US and East US as well as Southeast Asia and East Asia among others as mentioned on this slide.

13:49

Speaker A

Since region pairs are directly connected and adequately distant from each other, they can be utilized to ensure redundant and reliable services and data.

14:02

Speaker A

Besides the regular regions, Azure also offer sovereign independent regions for governmental organization. In other words, sovereign and independent regions are Azure regions dedicated to government entities isolated from the main Azure environment.

14:22

Speaker A

Azure government regions in the United States are physically and logically isolated from Azure networks for US government agencies and their partners.

14:34

Speaker A

These data centers are operated by US citizens and undergo additional compliance checks. Azure government utilizes the same underlying technology as Azure, sometimes referred to as the commercial or public Azure version.

14:53

Speaker A

This includes the core components of Infrastructure as a Service, Platform as a Service and Software as a Service.

15:02

Speaker A

Both Azure and Azure Government provides comprehensive security management capabilities and uphold Microsoft data protection commitments.

15:15

Speaker A

Azure China represent a distant sovereign region constituting an isolated Azure environment within China's borders.

15:23

Speaker A

This exclusive Azure sovereign region in China is established through special collaboration between Microsoft and 21Vianet.

15:34

Speaker A

Unlike other Azure region, Microsoft doesn't directly oversee the operation of data centers here. Instead, 21Vianet autonomously manages this region.

15:48

Speaker A

Now let's proceed with a demo to explore our architectural landscape with the context of our global reach.

15:57

Speaker A

In this demo, we will explore Azure global infrastructure. It's available in public access to everyone.

16:03

Speaker A

We have the following website, datacenters.microsoft.com. So, if you want to explore the globe on your own, it's totally possible.

16:15

Speaker A

When you connect to this website, you will have a 3D model view. You can also switch to the View Map of view information about regions as a table or use this global 3D view that I really like.

16:28

Speaker A

Each time when you click on the region, you will find information about its location, year when it was opened, different compliance information, regional one, industry one as well as a global one.

16:43

Speaker A

And you can review this information that potentially can help you to select the right region.

16:50

Speaker A

If you look in a different part of the planet here, there are also some regions that are coming soon, they have different icons and we can review what will be created soon, as well as we have sustainability projects created

17:06

Speaker A

by Microsoft with information about location and the type of sustainability projects that they are using.

17:15

Speaker A

If you want, you can use the legend with the powerful filters here to see exact information that you are searching for, or you have also specific region filters by compliance solutions, disaster recovery options, sustainability features as well as availability zones present that we will discuss

17:39

Speaker A

in a different session. So I could select specific compliance features that I am interested in or certificate and review the regions that hold it.

17:52

Speaker A

Also, next to it, on the right side, we have a Take a Tour possibility so we can discover together how data centers looks like from inside.

18:03

Speaker A

A very interesting experience. So, here, we have again a 3D model. This time it's not a globe, but a data center.

18:10

Speaker A

And, inside of the navigation menu, you will find different information about sustainability and security of Microsoft data center.

18:19

Speaker A

We can even enter inside of this data center and to review how a typical lobby of the data center will look like.

18:30

Speaker A

You have a possibility to explore again everything in 3D model, navigate them and to go to the different part of the data center to also check its security feature.

18:45

Speaker A

I hope you will do it on your own. There are much more to discover.

18:49

Speaker A

But the most important here is for sure our globe map in which one we can discover different regions and networking opportunity provided by Microsoft.

19:02

Speaker A

I hope you enjoy it. Let's come back to our presentation. A resource is a basic standard building block, meaning any component in Azure.

19:11

Speaker A

Everything you create, provision, deploy, et cetera, is a resource. Virtual machines, virtual networks, databases, cognitive services and et cetera, all of them are resources in Azure.

19:27

Speaker A

We will talk about each of those things in more details on the next slides of this session.

19:34

Speaker A

For now, I won't explain each one in detail, but I will come back to that later when we discuss their meanings.

19:44

Speaker A

Resource groups are simply resources grouped together, as the name suggests. When creating a resource, you need to place it in a resource group.

19:54

Speaker A

While a resource group can contain multiple resources, each resource can only reside in one resource group at a time.

20:04

Speaker A

Some resources can be moved between resource groups, but, when moved, they will no longer be associated with the original group.

20:12

Speaker A

Additionally, resource groups cannot be nested, meaning you can't place Resource Group B within Resource Group A, and we can't create a hierarchy between them.

20:27

Speaker A

Resource groups offer a convenient way to group resources because actions applied to resource group apply to all resources within it.

20:38

Speaker A

Deleting a resource group will remove all resources within it. By granting or denying access to resource group, you are effectively granting or denying access to all resources within that group.

20:53

Speaker A

When preparing resources, it's recommended to carefully plan the resource group structure that best suits your needs.

21:02

Speaker A

For example, if you are setting up a temporary development environment, grouping all resources allows you to undo the setup of all related resources simultaneously by deleting the resource group.

21:18

Speaker A

If you need to set up three different ways to access the compute resources you are creating, it's a good idea to organize the resources by each access method and then manage access at the level of the grouped resources.

21:34

Speaker A

Now let's examine the management structure that contains all resource groups. To do that, we will proceed to subscriptions.

21:47

Speaker A

Subscriptions are the unit of management, billing and scaling in Azure. Similar to how resource groups are a way of logically organizing resources, an account can have multiple subscriptions, but it only requires one.

22:05

Speaker A

In an account with multiple subscriptions, you can use subscriptions to configure different billing models and apply various access management policies.

22:18

Speaker A

Azure subscriptions can be used to define boundaries for Azure products, services and resources. Subscription boundaries comes in two types: billing boundaries and access management boundaries.

22:38

Speaker A

The billing boundaries of a subscription determines how charges for using Azure in the account are applied.

22:46

Speaker A

You can create multiple subscriptions for different billing requirements. Azure generates separate billing reports and invoices for each subscription to help you organize and manage expenses.

23:00

Speaker A

Additionally, Azure applies access management policies at the subscription level. You can create individual subscriptions that align with your organization structure.

23:13

Speaker A

For example, this means a company's specific departments could have separate Azure subscription policies. This billing model allows you to control access to resources used by users with their respective subscriptions.

23:30

Speaker A

So, when thinking about subscriptions, remember that they serve as billing boundaries and regulate access.

23:41

Speaker A

The last architectural element I want to discuss with you is management groups. As you already understand, resources are grouped into resource groups and resource groups are further organized into subscriptions.

23:58

Speaker A

If you are just starting with Azure, this hierarchy might seem sufficient for organizing things.

24:05

Speaker A

However, imagine you are working with multiple application, several development teams in different geographical regions.

24:13

Speaker A

With many subscriptions, an effective approach is needed to manage access, policies and compliance. Azure management groups offer high-level coverage over subscriptions, your group subscriptions into containers called management groups and apply government's condition to them.

24:37

Speaker A

All subscriptions within a management group automatically inherits the condition applied to the management group, similar to how resource groups inherit settings from subscriptions.

24:48

Speaker A

And resources inherit settings from resource groups. Management groups provide enterprise-level management at large scales regardless of subscription types.

25:01

Speaker A

Resource groups can be nested within management groups. Important facts about management groups. One directory can support up to an incredible 10,000 management groups, Alpha.

25:16

Speaker A

A crucial fact is the management group tree can support up to six levels of depths.

25:24

Speaker A

This limitation doesn't include the root level or the subscription level. Within the tree, each management group and subscription can have only one parent element.

25:36

Speaker A

To better understand the structure, let's see how we can create a resource on the portal.

25:43

Speaker A

In this demo, we will see how to create an Azure resource. This demo scenario is also available on Microsoft Learn if you want to follow it with me and create your own resource.

25:54

Speaker A

Just for example, I will show it on virtual machine, but you can use any other resource for creation.

26:00

Speaker A

You see that resources appear in different part. You have "Search" button in the center of your screen as well as in the left panel.

26:07

Speaker A

When you open it, you have an option here that's called Create. It will be the same for any other resources.

26:13

Speaker A

And, when you first create a resource, you need to select the subscription, the resource group in which one you want to locate this resource, the virtual machine name or the name of any other resource.

26:27

Speaker A

And, after you set up your subscription, this is your billing boundary and resource group that you use for organizing logically your projects.

26:37

Speaker A

You will have an option to select the region as well. It's better to locate your resource closest to your customers so I highly recommend to select a region that is close to your users.

26:51

Speaker A

As soon as we selected the region, we also can review our estimated monthly cost of our virtual machine.

26:58

Speaker A

We also have some availability options, zone options and availability zones that we will discuss later when we will walk through virtual machine setup.

27:08

Speaker A

We can select image size of our resource. And, to connect to it later, we will also provide the username and the password.

27:18

Speaker A

So, for example, if I use virtual desktop later, I will need to use this information to connect to it.

27:27

Speaker A

So I provided a username, password and I confirm it. I can also set up inbound ports on my virtual machine and also bring my own license if I have already want to save some costs.

27:42

Speaker A

You can select the disk attached to this VM, networking options, management if you want to activate some extra security feature like Microsoft Defender, monitoring options if you want to send some alarms related to it, add some advanced feature like extension, I will show you

28:04

Speaker A

in another demo how we can do it also through the PowerShell, and tax for billing purpose.

28:11

Speaker A

Let's say if I want to filter after that my resources by specific division name, I will use a tag like "IT" here.

28:22

Speaker A

And, after we set up all of it, we can review our resource information here after the validation passed, review the final price for our resource.

28:36

Speaker A

And, if everything looks correct, we can hit "Create" button. This takes usually ups to a few minutes to create a resource.

28:48

Speaker A

It depends on the complexity of the resource. You see that it has started the deployment.

28:54

Speaker A

There is also a template that will be attached to this deployment. And it will not only create a VM, but also will provision all related resources.

29:05

Speaker A

So, first, you see it has network interface that was attached to this virtual machine that was created.

29:15

Speaker A

And, as soon as this resource is deployed, there will be a bunch of other resources like public IP address, network security group and also it's continue to create the rest.

29:29

Speaker A

What I really like about any resource creation, so if I need to redeploy this resource, I can use a template provided to me.

29:39

Speaker A

And it means that it simplify any resource creation in the future. Now (inaudible) is most of it are done.

29:47

Speaker A

There are five related resources that are created together. And the "Redeploy" button is just on the top if I want to redeploy it here.

29:59

Speaker A

Or, if I want to save it as a template, I can download this template as well.

30:04

Speaker A

We will speak about them in our Session 3. And I think you are mostly complete.

30:11

Speaker A

Let's refresh to just to here if you want to check if it's done or not.

30:20

Speaker A

Usually, it takes around a few minutes as we deploy multiple resources. And now it's done.

30:28

Speaker A

Deployment succeed. Let's go to resource. This is where it's created our virtual machine. And, if I want, I can also open the resource group that we created on this tab.

30:40

Speaker A

And we do find six resources in total that are associated to this resource group including our VM, IP addresses, network options, disk and virtual network itself.

30:55

Speaker A

Multiple topics that we will discuss a bit later in our training. So we did discover how we can create multiple resources.

31:03

Speaker A

The most important, first, you need to select the resource that you want to deploy.

31:08

Speaker A

And, each time on any resource, you will have this "+" for creation of the resource and multiple step to complete.

31:15

Speaker A

And you will select normally each type subscription resource group and the region for the most of the resources.

31:24

Speaker A

I hope you enjoy it. Let's come back to our slides. So let's now explore different types of Azure computing and networking.

31:35

Speaker A

In this section of this session, we will get to know Azure's computing services. We will explore different choices for computing like virtual machines, app services, containers and virtual desktops, which are displayed on the screen.

31:52

Speaker A

We will look at each of these resources separately in this session. So let's begin with virtual machines which we saw in our previous demonstration.

32:04

Speaker A

With Azure Virtual Machines, you can create and use virtual machines in the cloud. They provide Infrastructure as a Service, IaaS, in the form of virtualized servers.

32:17

Speaker A

And you can use them in various ways. Just like on a physical computer, you can configure any software running on a virtual machine.

32:28

Speaker A

Azure Virtual Machines are an ideal choice if you need full control over the operating system, the ability to run custom software and the integration of customizable deployment configuration.

32:43

Speaker A

Azure Virtual Machines offer flexible virtualization capabilities without the need to purchase and maintain the physical hardware on which they run.

32:54

Speaker A

However, within the IaaS offering, you still need to handle the setup, updates and maintenance of the software running on the virtual machine.

33:06

Speaker A

Virtual machines also have various capabilities that I briefly mentioned during our virtual machine creation, such as scale sets and availability sets.

33:18

Speaker A

In our next demo, let's see how to create a virtual machine differently by using CloudShell.

33:25

Speaker A

Also, if you would like, you can follow this exercise. It's available on Microsoft Learn platform.

33:31

Speaker A

So let's get started. In this demo, we will see how we can create a virtual machine and install the web server package by using CloudShell.

33:42

Speaker A

In the past, we did see the same steps, but using graphic interface of Azure.

33:49

Speaker A

This time, I want to show you how you can save your time by using CloudShell for it.

33:54

Speaker A

So, first, I will create a resource group that I name Intro Azure Resource Group.

34:00

Speaker A

I am using exactly the same naming and scenario that you can find on Microsoft Learn if you want to try it on your own.

34:07

Speaker A

So here is a second command from Microsoft Learn that is very useful where we select the creation of the VM, we select resource group, name of the VM, size, public IP address, image, username and location.

34:24

Speaker A

And it will deploy our VM in less than one minute. And it's a good way to illustrate that both ways to dand interface and CloudShell are very powerful ways of creating your resources.

34:38

Speaker A

The difference with PowerShell is that you need to know CLI or PowerShell to do it and it will be much, much faster here and very easy going.

34:54

Speaker A

So you see that my command was accepted. After we created a VM, we will also install the Web Server Package on it.

35:05

Speaker A

Now it's running. Succeed. And, as soon as succeed, you do see here the ID of operation, location when VM is created, private IP address of it, public IP address and the resource group to which one it was added.

35:23

Speaker A

Now to illustrate how I can add some extension. I will add another command here that you can also try, az vm extension set, and I specify resource group, the name of the VM, the custom script and I also say to Azure

35:46

Speaker A

where this custom script is located. For demo purpose, as I really want that you also make all of the steps, I am using again exact scenario from Microsoft Learn so you can also review this file that we added for you on the GitHub.

36:03

Speaker A

And, here, you have exactly what we are installing on the top of our VM as an extension.

36:14

Speaker A

Again, it's much, much faster in the CloudShell than via virtual visual Azure interface. And, as soon as it's running and it's done, here, we have Status Succeed, resource group, when it was published, the file location, the type of the file extension and the name of it.

36:38

Speaker A

And we can verify that everything was deployed correctly. We can find this virtual machine that we created.

36:47

Speaker A

And, if you want, we can also open the resource groups that we created via our CloudShell where we will find virtual machine disk, network security group, public IP addresses, interface and virtual network attached to it.

37:05

Speaker A

On our virtual machine, if we want to modify some settings, we can reuse again CloudShell for it or Azure interface and Azure Portal.

37:18

Speaker A

And, in this availability and scale part, we could potentially change our size of the VM after its deployment.

37:28

Speaker A

And those scaling opportunity and availability opportunity we will also see just in a while on our slide deck.

37:37

Speaker A

But, as we already discussed, the slides of our VM, you can also review it here.

37:43

Speaker A

And there are six columns related. And, if you would like to add some extra features like availability zones that I will explain in a while or scale sets that we will review very soon, you can also add it on your virtual machine setup

38:00

Speaker A

in the left side menu. And, here, it's what I wanted to show you about VM creation.

38:10

Speaker A

Let's come back to our presentation. Virtual machine scale sets enable you to form sets of identical virtual machines while incorporating load balancing and management capabilities.

38:24

Speaker A

Why might you opt for virtual machine scale sets? Primary, they offer redundancy and enhanced performance.

38:32

Speaker A

Applications often require distribution across multiple instances for reliability. As your application communicates through load balancer, it distributes requests to various application instances.

38:46

Speaker A

During maintenance or updates of one instance, the load balancer shifts customer requests to available instances, ensuring continuous service.

38:56

Speaker A

For handling increased customer demand, you might need to scale up the number of application instances running your software.

39:05

Speaker A

Azure Virtual Machine scale sets provide this essential management capability. They seamlessly manage application spanning numerous virtual machines, automatically adjusting resource allocation and evenly distributing traffic.

39:22

Speaker A

The advantages are apparent. Firstly, they are effortless created and managed, even from multiple virtual machines.

39:32

Speaker A

Secondly, they offer heightened availability and application resilience. Thirdly, they enable your application to adapt as resource needs fluctuate.

39:46

Speaker A

Lastly, they are equipped to handle substantial scales, with some sets accommodating up to 1,000 virtual machine instances.

39:59

Speaker A

Lastly, let's talk about virtual machine availability sets. These are used to make sure that if something goes wrong with the network or power, all our virtual machines won't be affected.

40:13

Speaker A

Availability sets work by grouping virtual machines in two ways: update domains and fault domains.

40:23

Speaker A

Update domains are groups of virtual machines that can be restarted together when updates are needed.

40:32

Speaker A

This way, only a few groups are updated at a time, so some virtual machines are always running.

40:40

Speaker A

Fault domains group virtual machines based on shared power and network connections. By default, availability set split virtual machines into three fault domains.

40:55

Speaker A

So, even if power or network fails in one domain, others stay safe. This method is cost effective, too.

41:04

Speaker A

You pay only for the virtual machines you use. Another type of virtual machine is Azure Virtual Desktop.

41:11

Speaker A

Azure Virtual Desktop is a virtualization service for desktop systems and applications that operate in the cloud.

41:20

Speaker A

It allows us to use a cloud-hosted version of Windows from any location. Azure Virtual Desktop works on various devices and operating systems, and it's compatible with applications that can access remote desktops or most modern web browsers.

41:39

Speaker A

Azure Virtual Desktop provides centralized management of user desktop security. You can enable multifactor authentication to secure user login.

41:51

Speaker A

Additionally, you can protect data accesses with detailed role-based access control. When using Azure Virtual Desktop, data and applications are isolated from local hardware.

42:05

Speaker A

In fact, the desktop and application run in the cloud, reducing the risk of sensitive data remaining on personal devices.

42:16

Speaker A

Moreover, user sessions are isolated in a single or multi-sessions environments. When it comes to virtual machines, they are a smart choice for cost savings as they eliminate the need for physical hardware investments.

42:35

Speaker A

However, they do have a limitation. Each virtual machine can only run a single operating system.

42:44

Speaker A

Containers, on the other hand, offer an excellent solution when you require multiple instances of an application to operate on a single host computer.

42:56

Speaker A

The Azure Container Instances service offers the swiftest and easiest method to run containers within Azure, all without the complexities of managing virtual machines or utilizing additional services.

43:13

Speaker A

This service falls under the Platform as a Service, or PaaS, model. With Azure Container Instances, you can deploy your containers and the service will take care of launching them.

43:29

Speaker A

The second key element on this slide introduces Azure Container Apps, a fully managed environment tailored for running microservices and containerized application on a serverless platform.

43:47

Speaker A

This platform enables the execution of application code packed into any container and it remains openminded about the runtime or programming model you choose.

44:01

Speaker A

With Container Apps, you harness the benefits of running containers while shedding the burdens of managing complex cloud infrastructure and container orchestrators.

44:15

Speaker A

Lastly, the Azure Kubernetes Services, AKS, stands out as the quickest road to initiate the development and deployment of purely cloud-native applications.

44:29

Speaker A

Offering built-in pipelines that take you from code to the cloud and comprehensive security feature, Azure Kubernetes Service streamlines the deployment of a managed Kubernetes cluster within Azure, alleviating the operational responsibilities and shifting them to Azure.

44:51

Speaker A

This service manages vital tasks including house monitoring and maintenance. Quite a bit of new information, isn't it?

45:03

Speaker A

Let's do a quick recap and compare the compute options. In the case of virtual machine, we have a cloud server supporting Windows or Linux.

45:13

Speaker A

A virtual desktop provides capabilities for Windows cloud desktop. Containers, on the other hand, offer an environment for running microservices.

45:25

Speaker A

As for their usage purpose, virtual machines are typically used when migrating to the cloud, virtual desktops for connecting user to desktop applications and containers for scalability.

45:40

Speaker A

Each service has its interesting advantages. Virtual machines include a full operating system package. Virtual desktop can support multiple users simultaneously, while containers can reside on one operating system of the virtual machine server.

46:01

Speaker A

If you need to deploy an application in Azure, you can first consider virtual machines or containers.

46:07

Speaker A

Both virtual machines and containers offer excellent solutions for deployment. Virtual machines provide maximum control over the hosting environment and precise configuration.

46:20

Speaker A

They can also be the most familiar way to deploy if you are just starting with cloud.

46:27

Speaker A

Containers, with their isolation capabilities and individual management of different aspect of the deployment, can also be a reliable and efficient option.

46:40

Speaker A

It enables automatic deployment from GitHub, Azure DevOps or any Git repository to support continuous deployment.

46:48

Speaker A

Great. We have covered containers and virtual machines. Azure functions are event-driven serverless complete resources that don't require the management of virtual machines or containers.

47:01

Speaker A

When building an application using virtual machine or containers, these resources must be running for the application to work.

47:10

Speaker A

With Azure Function, an event triggers the function, reducing the time to prepare resources when there are no events.

47:19

Speaker A

Azure functions are suitable when you care only about the code for the service, not the underlying platform or infrastructure.

47:29

Speaker A

They are used when simple and fast action which completes in a few seconds or even less needs to be performed in response to an event, such as a rest request, timer or message from another Azure service.

47:46

Speaker A

Azure functions automatically scale on demand, making them ideal for cases where requirements change. The Azure Function Service executes code when triggered and automatically deallocates resources after the function's execution.

48:06

Speaker A

Azure App Service is your go-to solution for hosting applications in the cloud. It takes care of the heavy lifting like availability and infrastructure so you can focus on building and improving your app.

48:23

Speaker A

App Service runs on an HTTP-based model and it's perfect for hosting web apps, RESTful APIs and mobile backends.

48:34

Speaker A

It supports multiple languages including.Net,.Net Core, Java, Ruby, Node, GC, PHP and Python, and works seamlessly on both Windows and Linux environment.

48:51

Speaker A

What makes it powerful? Built-in features like security, load balancing, automatic scaling and automated management.

49:00

Speaker A

Plus, it offers DevOps capabilities with continuous deployment from Azure DevOps, GitHub, Docker Hub and more.

49:12

Speaker A

Azure virtual networks and subnets facilitates seamless communication among Azure resources including virtual machines, web applications and databases.

49:24

Speaker A

This architecture also fosters connectivity with users across the internet and local client computers. These virtual networks can be visualized as extensions of your on-premises network interconnecting various Azure resources.

49:42

Speaker A

Moreover, in the context of networking within Azure, network peering is a significant feature. Network peering enables the linking of different virtual networks, creating a private connection for communication between them.

50:00

Speaker A

This connection is similar to a local network extension across virtual spaces. By establishing network peering, you can seamlessly share resources, such as virtual machines or databases, across distinct virtual networks, ensuring efficient and secure communication.

50:22

Speaker A

Within Azure Virtual Network, two types of endpoint play crucial role in data exchange, public and private.

50:33

Speaker A

Public endpoints possess public IP addresses accessible from anywhere globally. Private endpoints, however, are confined within the virtual network and are assigned private IP addresses using the virtual network's IP address space.

50:53

Speaker A

When configuring an Azure virtual network, a private IP address range is defined utilizing either public or private IP address ranges.

51:05

Speaker A

This IP address range remains confined using the virtual network and lacks internet routing capabilities.

51:14

Speaker A

Further division of this IP address range into subnet allow a specific portion of the range to be allocated to (inaudible) subnets.

51:25

Speaker A

For enhanced security and control, Azure virtual networks incorporate network security groups. These groups act as containers for numerous security rules governing inbound and outbound traffic by evaluating factors such as source and destination IP address, ports and protocols.

51:50

Speaker A

These rules dictate whether to permit or deny traffic. This fine-grained control ensures that traffic flows as intended, both steering the network overload security posture.

52:06

Speaker A

As we delve into the specifics of Azure's network capabilities, let's also explore the practical implementation of network security group with the Azure Portal.

52:20

Speaker A

In this demo, you will see how we can configure network access and stop our network security groups.

52:26

Speaker A

You can find also the scenario on Microsoft Learn website if you want to follow.

52:30

Speaker A

So, to do it, let's first select our resource group that we created in our previous demos.

52:37

Speaker A

And we will find here our virtual machine as well as network security group that was created together with our VM.

52:47

Speaker A

Inside, we have some inbound and outbound security rules. Those are six rules that were created by default.

52:54

Speaker A

If we look a bit on the right side, we will see that each rule has its source destination and action saying if traffic is going from any location to the internet, for example, we allow this traffic; if it's going from virtual network to virtual network,

53:09

Speaker A

allow; if it's from Azure load balancer to any network, allow; and if it's for virtual network to virtual network, again, allow.

53:17

Speaker A

So those are six rules are by default, we can't delete them. They are pre-created automatically in our network security group.

53:27

Speaker A

But we could add some rules to those six NSG rules. To do so, we have, on the left side, Settings.

53:37

Speaker A

You have settings for inbound security rule as well for outbound. And, when you add here any security rule, you have a opportunity to decide to which service you would like to add.

53:48

Speaker A

When I select "HTTPS Service," it will add by default related protocol. I can set up myself the priority and the name of this rule.

54:00

Speaker A

I provide to this rule Priority 300. You see that it's Port 443 for HTTPS.

54:10

Speaker A

And I can also add RDP service and protocol here and provide a different priority, like 290, for example.

54:20

Speaker A

I call it "RDP Security Rules." So, in this case, the rule that it has number 290 is more important that the Rule 300.

54:31

Speaker A

Lower than a number, the more it's important. And, also, I have some sign here saying that "be careful, Alexandra, you just opened this VM to the internet by opening Remote Desktop Protocol." So it's very important it's notify me

54:46

Speaker A

for security reason saying that there is a public connection to this VM right now.

54:51

Speaker A

This way, I could also add some outbound security rules and, after that, attach this network security group to network interface or to a subnet.

55:01

Speaker A

And what do we like about it? You can create one network security group and attach it to multiple VNets and subnets.

55:12

Speaker A

So, here, I will add another subnet to this network security group. So now I'm using this network security group to two different subnets.

55:23

Speaker A

And now, as we open our RDP protocol, it means that we can connect to Remote Desktop Protocol on this VM, I will download RDP file.

55:37

Speaker A

It will ask me if I am okay to connect to my remote desktop. I will need to add some credentials here like login and password information that I used to set up this VM at the beginning.

55:56

Speaker A

So I will select a different authentication method because, by default, it's try to use my face and, this time, I will just add the login and password information to connect to my remote desktop, thanks to this energy rule that we added.

56:13

Speaker A

And I will say "Okay," I am aware that I am connecting via the public access.

56:18

Speaker A

And, as soon done, it's popped up to my second screen. I just will bring it here.

56:23

Speaker A

For you, what we see, we see that we did launch a Remote Desktop Protocol, a remote desktop that I can use.

56:31

Speaker A

I can find the IP address of it and use it as a virtual desktop.

56:37

Speaker A

So it's magic happened. Now you know that by configuring NSGS you can connect to different ports and use inbound and outbound rules to secure your VM and communication with it.

56:56

Speaker A

Thank you. Let's come back to our presentation. Imagine living in a glass house where everyone can see what you are doing.

57:05

Speaker A

Not a great feeling, right? Well, using the internet without a secure VPN is a bit like that.

57:11

Speaker A

So what is a VPN? A VPN, or virtual private network, is like a secret tunnel on the internet.

57:19

Speaker A

It keeps your online information private and safe. It's like putting special tinted glass on your glass house.

57:29

Speaker A

You can see out, but no one can see in. When you are using a VPN, your data travels through the secure passage to special VPN servers.

57:40

Speaker A

No one, not even your internet service provider or government, can snoop on your data.

57:48

Speaker A

The VPN also mask your real device's address and uses its own address instead. This provides a shield from internet use, even on public Wi-Fi networks.

58:04

Speaker A

A VPN works somewhat like building a secret road inside another road. It's useful for linking private networks over the big public internet.

58:15

Speaker A

Any data sent on this secret road is locked up with encryption, a protective layer that keeps your information secure.

58:25

Speaker A

Every network can only have one special entry point for this secret road, but this entry point can connect to various places, like other networks or your computers located in different spots.

58:40

Speaker A

In Azure, there exists dedicated VPN gateways. These gateways ensure that data can move securely between Azure networks and your own computers, even when they are far apart.

58:56

Speaker A

These gateways also enable different Azure networks to communicate securely with one another. In essence, a VPN is your personal concealed pathway on the internet ensuring your online activities remain private and secure, much like the walls of a glass house fitted with tinted windows.

59:22

Speaker A

ExpressRoute is an Azure service that allows you to create a private connection between Microsoft data centers and your on-premises infrastructure.

59:32

Speaker A

ExpressRoute connections do not go through the public internet, providing enhanced security, reliability and no latency performance compared to regular internet connections.

59:45

Speaker A

This means that ExpressRoute connections offer greater security, reliability and speed with reduced unpredictable latencies compared to standard internet connections.

59:59

Speaker A

In some cases, using ExpressRoute for data transfer between on-premises devices and Azure can significantly reduce costs.

60:09

Speaker A

ExpressRoute enables connections to Microsoft cloud services, such as Microsoft Azure and Microsoft 365, and connects offices, data centers or other locations to the Microsoft Cloud.

60:26

Speaker A

Each location has its own ExpressRoute service. You can enable ExpressRoute Global Reach to facilitate data exchange between on-premises sites by connecting them through your ExpressRoute circuits.

60:43

Speaker A

For example, if you have an office in Asia and a data center in Europe both connected to Microsoft network through ExpressRoute, you can use ExpressRoute Global Reach to connect this to locations so they can exchange data without going through the public internet.

61:04

Speaker A

In summary, the main difference between a VPN gateway and ExpressRoute lies in the nature of the connection and the level of performance and security they offer.

61:15

Speaker A

A VPN gateway uses the public internet to create secure connection, while ExpressRoute provides a dedicated private connection with higher performance and security features.

61:27

Speaker A

The choice between these options depends on your specific networking requirements, data sensitivity and performance needs.

61:37

Speaker A

Moving forward from discussing the difference between VPN gateways and ExpressRoute, let's now explore the capabilities of Azure DNS.

61:48

Speaker A

DNS, or Domain Name System, can be described as a phone book. It's translating human-readable names to computer-friendly addresses.

61:59

Speaker A

Azure DNS, or Azure Domain Name System, is the hosting service for DNS domains that provides name resolution by using Microsoft Azure infrastructure.

62:12

Speaker A

Azure DNS operates as a cloud-based solution offering the ability to host and manage DNS domains, also known as DNS zones.

62:24

Speaker A

These zones serve as collection of DNS records that handle the translation of human-visible domain names into machine-friendly IP addresses.

62:36

Speaker A

By entrusting your domains to Azure's infrastructure, you gain this convenience of overseeing your DNS records using familiar Azure tools, APIs and credentials.

62:49

Speaker A

The payment structure mirrors other Azure services where you are billed based on your usage.

62:55

Speaker A

Azure DNS seamlessly integrates with your Azure resources facilitating automated updates to DNS records based on changes within Azure, such as deployments or modification to resources.

63:11

Speaker A

When you relocate a web application to a different location, the associated Azure DNS record is automatically adjusted to reflect the change.

63:23

Speaker A

In Azure DNS, a global network of Azure DNS servers host DNS domains. This architecture ensures both resilience and high availability.

63:36

Speaker A

To optimize query processing speed and availability for your domain, the network is designed so that each DNS request is directed to the nearest available DNS server.

63:49

Speaker A

In summary, Azure DNS provides a dynamic platform for hosting and managing DNS domains. It leverages the convenience of Azure's ecosystem, the efficiency of automation and the assurance of high availability contributing to a smoother and more reliable online experience for your users.

64:15

Speaker A

And that brings us to the end of the first part of our second session in the AZ-900 Microsoft Azure Fundamentals course.

64:25

Speaker A

In this segment, we explored the core architectural components of Azure including regions and availability zones, subscriptions and resource groups.

64:37

Speaker A

We also examined compute and networking concepts covering compute types, application hosting options and the fundamentals of virtual networking, these topics from the foundation of how Azure organizes resources and delivers services across its global infrastructure.

65:00

Speaker A

A strong understanding of this concept is essential for anyone designing, deploying and managing solutions in the cloud.

65:08

Speaker A

In the next part of this session, we will dive into storage and identity management.

65:14

Speaker A

We will learn about Azure storage services, redundancy option, strategies for migrating files and key concepts around identity, access and security that help your solution secure and compliant.

65:29

Speaker A

Thank you for joining me for this part. When you are ready, let's continue with the second part and keep building your Azure knowledge.

65:38

Speaker A

And, remember, your learning journey doesn't stop here. Explore other videos in this course or discover your next favorite topic on Microsoft Learn at ak.ms/learn.

65:55

Speaker A

Thank you for being with me and happy learning. Hope to see you soon. Bye everyone.

Topics: Azure AZ-900 Microsoft Azure Fundamentals Cloud Architecture Azure Networking Virtual Machines Resource Groups Cloud Shell Azure Subscriptions Azure Free Account


---
This is the markdown twin of https://sozai.app/transcript/azure-architecture-networking-az900-video3/ — the same content, without the markup.
Published by SozAI (https://sozai.app). Reuse and quotation are allowed with attribution and a link back.
Machine-readable index: https://sozai.app/llms.txt · data API: https://sozai.app/api/
