1.3 Tags, Naming, and Cost: The Operational Reality
This lesson is locked
Complete the previous required lesson to unlock this one.
- Chapter 1: The Blueprint
- 1.1 Demystifying Microsoft Azure
- 1.2 The Resource Hierarchy: Where Things Live
- 1.3 Tags, Naming, and Cost: The Operational Reality
- 1.4 Infrastructure as Code: ARM & Bicep
- 1.5 Azure Policy and Resource Locks: The Guardrails
- 1.6 LAB: OPERATION DEAD DEPLOY
- Chapter 2: Entra ID
- 2.1 Welcome to the Gate
- 2.2 Tenants vs Subscriptions: The Trust Relationship
- 2.3 Users, Groups, and Administrative Units
- 2.4 App Registrations and Service Principals
- 2.5 Conditional Access: If/Then Security
- 2.6 MFA Enforcement and Authentication Methods
- 2.7 LAB: THE STOLEN IDENTITY
- Chapter 3: RBAC and Privileged Access
- 3.1 RBAC Fundamentals: Roles, Scope, Inheritance
- 3.2 Built-in Roles vs Custom Roles
- 3.3 Least Privilege in Practice
- 3.4 Privileged Identity Management (PIM)
- 3.5 LAB: PRIVILEGE AUDIT
- Chapter 4: Compute Fundamentals
- 4.1 Virtual Machines: Sizes, Regions, Availability
- 4.2 App Service: PaaS Web Hosting
- 4.3 Functions and Logic Apps: Serverless Compute
- 4.4 Managed Identities: No More Credentials
- 4.5 Containers and AKS at a High Level
- 4.6 LAB: THE FRIDAY DEPLOY
- Chapter 5: Virtual Networking
- 5.1 Virtual Networks and Subnets
- 5.2 Network Security Groups and Application Security Groups
- 5.3 Routing and User Defined Routes
- 5.4 Azure Firewall and Load Balancers
- 5.5 VNet Peering and Private Endpoints
- 5.6 LAB: NETWORK LIKE AN OPERATIVE
- Chapter 6: Storage and Secrets
- 6.1 Azure Storage Accounts: Blob, File, Queue, Table
- 6.2 Access Keys, SAS Tokens, and Entra ID Auth
- 6.3 Storage Network Security
- 6.4 Azure SQL and Cosmos DB
- 6.5 Azure Key Vault: Secrets, Keys, Certificates
- 6.6 LAB: LOOTING BUCKETS
- Chapter 7: Monitoring and Logs
- 7.1 Azure Monitor and Log Analytics
- 7.2 KQL Basics
- 7.3 Diagnostic Settings: Where Logs Actually Come From
- 7.4 Alerts and Action Groups
- 7.5 LAB: FIND THE ANOMALY
- Chapter 8: Microsoft Sentinel
- 8.1 What is Sentinel? SIEM and SOAR Together
- 8.2 Data Connectors and Ingestion
- 8.3 Analytics Rules and Detections
- 8.4 Incidents and Investigations
- 8.5 Workbooks and Threat Hunting
- 8.6 LAB: THREAT HUNT
- Chapter 9: Defender for Cloud
- 9.1 Defender for Cloud Overview: CSPM and CWPP
- 9.2 Secure Score and Recommendations
- 9.3 Defender Plans (Servers, Storage, SQL, App Service)
- 9.4 Just-in-Time VM Access
- 9.5 LAB: SCORE THE TENANT
- Chapter 10: Capstone Investigation
- LAB: THE BREACH