Azure Zero-to-Hero
A five-tier mastery path — Foundation to Specialist — covering every Azure domain, every core certification, and real job, troubleshooting and architecting skills.
Start the courseA complete, job-oriented path through Microsoft Azure: fundamentals, identity, networking, compute, data, security, governance, enterprise landing zones, operations, automation, and resilience — built from production-grade lessons and capped with a real-world capstone.
What you’ll be able to do
- Navigate Azure confidently — subscriptions, regions, resource groups, portal, CLI and Cloud Shell
- Design identity and access with Microsoft Entra ID, RBAC, Conditional Access and PIM
- Build secure hub-and-spoke networks with firewalls, private endpoints and global traffic management
- Run compute and data services — App Service, Functions, Container Apps, SQL, Cosmos DB, PostgreSQL
- Govern an enterprise estate with the Cloud Adoption Framework, landing zones and Policy-as-Code
- Operate in production — monitoring, backup, DR, patching, cost engineering and resilience testing
- Be interview- and certification-ready, and able to deliver a real Azure landing zone end to end
Prerequisites
- Basic IT literacy (files, networks, a terminal) — no prior cloud experience required
- A free Azure account for the hands-on labs (free tier / trial credit is enough)
Who it’s for
Career-changers and developers new to the cloud, sysadmins moving to Azure, and engineers preparing for AZ-104/AZ-305 or real Azure delivery work.
Curriculum
Tier 1 · Foundation — Cloud & Azure Basics (AZ-900)
Begin at zero: what the cloud is, how Azure is organised, the global backbone, the tooling, and cloud economics.
- 1 Cloud Computing Fundamentals: IaaS, PaaS, SaaS & the Shared-Responsibility Model
- 2 What Is Azure? Accounts, Subscriptions, Regions & Resource Groups
- 3 Azure Global Infrastructure: Geographies, Regions, Availability Zones, Availability Sets, Fault & Update Domains
- 4 Working with Azure: Portal, CLI, PowerShell & Cloud Shell
- 5 Azure Cloud Economics: Pricing, TCO, SLAs, Service Lifecycle & Support
- 6 A Simple Serverless API on Azure for Beginners
Tier 1 · Foundation — Identity & Security Basics (AZ-900)
Who you are and how you sign in — the first thing every Azure workload depends on.
Tier 1 · Foundation — AI Fundamentals (AI-900)
Artificial intelligence from scratch: ML, the Azure AI services, generative AI, and Responsible AI.
Tier 1 · Foundation — Data Fundamentals (DP-900)
Data from scratch: core concepts, relational data, non-relational data and analytics on Azure.
Tier 2 · Intermediate — Identity & Access Administration (AZ-104)
Administer identity day to day: RBAC at scale, privileged access, and Conditional Access.
Tier 2 · Intermediate — Core Networking (AZ-104)
The networking an administrator runs every day: VNets, egress, secure access, and load balancing.
- 18 Azure Virtual Network Basics: Subnets, NSGs, and Peering
- 19 Deterministic Outbound with Azure NAT Gateway: Fixing SNAT Port Exhaustion
- 20 Azure Bastion Deep Dive: Native Client Tunneling, Shareable Links, and Just-in-Time Secure Access
- 21 Azure Load Balancing Deep Dive: Load Balancer, App Gateway, Front Door & Traffic Manager
Tier 2 · Intermediate — Compute (AZ-104)
Run and resize compute: virtual machines, availability, disks, and App Service.
- 22 Azure Virtual Machines Deep Dive: Every Creation & Post-Creation Setting
- 23 Azure VM Resilience: Availability Sets (Fault & Update Domains), Availability Zones & Scale Sets
- 24 Azure Managed Disks Deep Dive: Every Disk Type, Caching, Encryption & Performance
- 25 Azure App Service Deep Dive: Plans, Scaling, Slots, TLS, Custom Domains & Networking
Tier 2 · Intermediate — Storage (AZ-104)
Store data durably: storage accounts, blob lifecycle, and file shares.
Tier 2 · Intermediate — Monitoring & Management (AZ-104)
Keep the estate healthy: Azure Monitor, service health, and patch management.
Tier 2 · Intermediate — Backup & Recovery (AZ-104)
Protect data: Azure Backup and immutable, multi-user-authorised recovery.
Tier 2 · Intermediate — Governance & Cost (AZ-104)
Organise and control spend: resource organisation, Policy-as-Code, FinOps and reservations.
- 34 Azure Landing Zone: Resource Organization — Management Groups, Subscription Strategy, Naming & Resource Group Structure
- 35 Azure Policy as Code: A Git-Driven Governance Pipeline
- 36 FinOps on Azure: From Cost Visibility to Engineered Savings
- 37 Azure Commitment Strategy: Reservations, Savings Plans, and Hybrid Benefit Optimization
Tier 3 · Advanced — Developing Solutions (AZ-204)
Build cloud-native apps: Functions, Durable, Container Apps, zero-downtime deploys, Cosmos and Redis.
- 38 Azure Functions Flex Consumption: VNet Integration, Concurrency, and Cold-Start Tuning
- 39 Durable Functions in Production: Orchestrations, Fan-out/Fan-in, and Entity State
- 40 Azure Container Apps Deep Dive: Dapr, KEDA Scaling, Revisions, and Split Traffic
- 41 Hardening Azure App Service: VNet Integration, Private Endpoints, and Zero-Downtime Slots
- 42 Cosmos DB for NoSQL: Partition Key Design, RU Optimization, and Hot Partition Repair
- 43 Azure Cache for Redis Enterprise: Clustering, Active Geo-Replication, and Resilient Failover Patterns
Tier 3 · Advanced — Messaging & Integration (AZ-204)
Decouple and integrate systems: Service Bus, Event Grid, API Management and Logic Apps.
- 44 Azure Service Bus at Scale: Sessions, Deduplication, and Dead-Letter Handling
- 45 Event-Driven Architectures with Azure Event Grid: MQTT, Routing, and Reliable Delivery
- 46 API Management Self-Hosted Gateway: Hybrid APIs and Advanced Policy Engineering
- 47 Azure Logic Apps Standard: Stateful Workflows, VNet Integration, and B2B/EDI Integration Accounts
Tier 3 · Advanced — Hybrid Identity, Federation & SSO
Connect on-premises identity to the cloud: hybrid identity, ADFS migration, sync and SCIM provisioning.
- 48 Azure Enterprise Architecture: Hybrid Identity & SSO
- 49 Migrating from Entra Connect Sync to Entra Cloud Sync: A Step-by-Step Cutover Guide
- 50 Migrating from AD FS to Entra ID Authentication: Staged Cutover with PHS, Staged Rollout, and Claims-Rule Mapping
- 51 Building a SCIM 2.0 Provisioning Endpoint and Integrating It with Entra ID Automatic Provisioning
Tier 3 · Advanced — Networking Engineering (AZ-700)
Design enterprise networks: deep VNet, firewall, private DNS/endpoints, App Gateway, Front Door, vWAN and BGP.
- 52 Azure Virtual Networks Deep Dive: Every Setting from Subnets to Peering
- 53 Routing All Egress Through Azure Firewall: UDRs, Forced Tunneling, and Policy
- 54 Hybrid DNS at Scale: Azure DNS Private Resolver with Conditional Forwarding
- 55 Private Endpoints and Private DNS at Scale: A Hub-and-Spoke Resolution Architecture
- 56 Application Gateway v2 and WAF: L7 Routing, TLS Termination, and Tuning That Holds
- 57 Global Traffic Management: Azure Front Door and Traffic Manager for Multi-Region Failover
- 58 Scaling Connectivity with Azure Virtual WAN: A Global Network Build
- 59 BGP Route Control in Hybrid Cloud: Communities, AS-Path, and Local-Pref Without Black Holes
- 60 DNSSEC End to End: Signing Public Zones and Enforcing Validation on Hybrid Resolvers
Tier 3 · Advanced — Security Engineering (AZ-500)
Engineer defence in depth: Zero Trust, Key Vault & encryption, Defender for Cloud/XDR, and Sentinel.
- 61 Azure Zero-Trust & the Multi-Layer Security Model
- 62 Eliminating Secrets: Key Vault and Workload Identity Federation End to End
- 63 Eliminating Secrets in Azure: Key Vault, Managed Identity, and Automated Rotation
- 64 Encryption at Rest in Azure: Customer-Managed Keys, HSM, and Double Encryption
- 65 Azure Managed HSM and Secure Key Release: Attestation-Gated Keys for Confidential Workloads
- 66 Operationalizing Microsoft Defender for Cloud: CSPM, Secure Score, and Workload Protection
- 67 Cloud Workload Protection in Practice: Defender for Servers, Containers, and Databases
- 68 Defender for Cloud Attack Path Analysis: Custom Recommendations and Governance Rules
- 69 Standing Up Microsoft Sentinel: Data Connectors, Analytics Rules, and SOAR Playbooks
- 70 Sentinel Detection-as-Code: Content Hub, Repositories, and CI/CD Pipelines
- 71 Deploying Microsoft Defender for Endpoint: Onboarding, ASR Rules, and EDR in Block Mode
- 72 Detecting Identity Attacks with Defender for Identity: Sensors, Honeytokens, and ISPM
- 73 Defender XDR Advanced Hunting: Custom Detection Rules and Automatic Attack Disruption
Tier 3 · Advanced — Data Engineering Core
Run data at scale: Azure SQL, PostgreSQL, Cosmos multi-region, Data Factory/Synapse/Fabric and the data lake.
- 74 Azure SQL Database Advanced Patterns: Hyperscale, Elastic Pools, Ledger, and Always Encrypted with Secure Enclaves
- 75 Azure SQL Managed Instance HA: Failover Groups, the Link Feature, and Business Continuity
- 76 Azure Database for PostgreSQL Flexible Server: Zone-Redundant HA, Read Replicas, PgBouncer, and In-Place Upgrades
- 77 Cosmos DB Multi-Region Writes: Consistency Levels and Conflict Resolution
- 78 Azure Data Integration & Analytics: Data Factory, Synapse & Microsoft Fabric
- 79 Azure Enterprise Architecture: Enterprise Data Lake & Analytics
Tier 3 · Advanced — Compute at Scale & Specialized Compute
Scale and specialise compute: VM Scale Sets, AKS microservices, and dedicated/spot/confidential/HPC compute.
Tier 3 · Advanced — Observability & APM
See inside production: data-collection rules, distributed tracing, and managed Prometheus/Grafana.
Tier 4 · Expert — Architecture & Design Mastery (AZ-305)
Think like an architect: the Well-Architected Framework, CAF, architecture styles, the design-pattern catalogue, and mission-critical design.
- 86 The Azure Well-Architected Framework, In Depth: 5 Pillars as a Tradeoff System
- 87 Cloud Adoption Framework & Azure Landing Zones, In Depth
- 88 Choosing an Architecture: Styles & the Ten Design Principles
- 89 The 43 Azure Cloud Design Patterns: A Complete, Practical Catalogue
- 90 Mission-Critical (AlwaysOn) Architecture on Azure: The Apex Design
Tier 4 · Expert — Enterprise Landing Zones
Build the enterprise platform: CAF landing zones across identity, network, security, governance and platform automation.
- 91 Designing an Azure Landing Zone with the Cloud Adoption Framework
- 92 Azure Landing Zone: Identity & Access Management — Entra ID Design, the RBAC Model, PIM, Conditional Access, Hybrid Identity, and the Identity Subscription
- 93 Azure Landing Zone: Network Topology & Connectivity — Hub-Spoke vs Virtual WAN, the Connectivity Subscription, Hybrid Links, Segmentation, DNS, Inspection & Private Link
- 94 Azure Landing Zone: Security — Defender for Cloud, Sentinel, Encryption & Key Management, the Security Baseline Policy Set, and Secure Score
- 95 Azure Landing Zone: Governance — Azure Policy Initiatives, Cost Guardrails, Compliance Frameworks & Tag Enforcement
- 96 Azure Landing Zone: Platform Automation & DevOps — IaC with Bicep & Terraform, the ALZ Accelerator, Subscription Vending, Platform CI/CD & GitOps
- 97 Subscription Vending at Scale: Automating Landing Zone Onboarding
- 98 Azure Cloud Adoption Framework: Secure — Methodology, Zero Trust, MCRA/MCSB, and Securing Access, Operations, Assets & Innovation
Tier 4 · Expert — Resilience & Disaster Recovery
Design for failure: zone/region failover, multi-region active-active, and chaos engineering.
Tier 4 · Expert — DevOps, IaC & Automation (AZ-400)
Ship safely and repeatably: Bicep, Azure Verified Modules, Azure DevOps pipelines, and blue-green releases.
- 102 Shipping Azure Workloads with Bicep: Deployment Stacks, what-if, and a CI Pipeline
- 103 Operating a Bicep Private Module Registry and Templating at Scale
- 104 Building a Platform Layer with Azure Verified Modules and Terraform
- 105 Designing Multi-Stage Azure DevOps YAML Pipelines with Environments, Approvals, and Deployment Gates
- 106 Azure DevOps Scale Set Agents: Ephemeral Pools, Autoscaling, and Pipeline Hardening
- 107 Zero-Downtime Blue-Green Deployments on Azure: App Service Slots, Front Door, and Pipeline Automation
- 108 Building a FinOps Practice on Azure: From Tagging to Showback Automation
Tier 4 · Expert — FinOps & Cost Strategy
Optimise spend as a discipline: the cost-optimisation pillar and its tradeoffs.
Tier 5 · Specialist — AI Engineering (AI-102)
Engineer production AI: enterprise Azure OpenAI, AI Search/RAG, private endpoints, and agent orchestration.
- 111 An Enterprise Landing Zone for Azure OpenAI: Networking, Quotas, and Gateways
- 112 Azure AI Search for RAG: Vector Indexing, Hybrid Search, Semantic Ranking, and Indexer Pipelines
- 113 Enterprise RAG Platform on Azure OpenAI with Private Endpoints
- 114 AI Agent Orchestration with Tool-Calling and Guardrails
- 115 AI-102: Building Production AI — RAG, Copilots, Vision & Document Intelligence
Tier 5 · Specialist — Data Engineering (DP-203)
Engineer the data platform: lakehouse governance, streaming at scale, and end-to-end pipelines.
Tier 5 · Specialist — Hybrid, Arc & Migration
Extend Azure everywhere: Arc-enabled servers and Kubernetes, VMware migration, and the CAF migrate methodology.
- 119 Azure Arc-Enabled Servers: Onboarding at Scale, Machine Configuration Guest Policy, and Extended Security Updates
- 120 Azure Arc-Enabled Kubernetes: GitOps, Policy, and Fleet Governance for Hybrid Clusters
- 121 VMware to Azure VMware Solution Migration and Hybrid Operations
- 122 Azure Cloud Adoption Framework: Migrate — Assess/Deploy/Release, Azure Migrate Dependency Analysis, Waves & the Migration Factory, Replication & Cutover, Testing & Rollback
Tier 5 · Specialist — End-User Computing (AZ-140)
Deliver desktops & apps at scale: AVD and Windows 365 with FSLogix, MSIX and identity integration.
Tier 5 · Specialist — IoT & Digital Twins
Connect the physical world: IoT Hub, Device Provisioning, IoT Edge and Azure Digital Twins.
Tier 5 · Specialist — Compliance, Sovereignty & Regulated Cloud
Run regulated estates: Compliance Manager, regulatory frameworks, sovereign clouds and data residency.
Tier 5 · Specialist — Cybersecurity Architecture (SC-100)
Architect security strategy: confidential computing and end-to-end Zero-Trust reference designs.
Track · Troubleshooting (Easy → Complex)
Diagnose anything: a method and per-domain playbooks, the diagnostics toolkit, then complex multi-service incident RCA.
Track · Architecting (Easy → Complex)
Turn requirements into designs: a six-rung ladder from a simple web app to mission-critical, plus real proposal walkthroughs. Builds on Tier 4.
Track · Certification Center
Pass the exams: the master exam-prep kit with objective checklists, practice questions and cheat sheets.
Track · Job-Ready — Projects, Capstone & Interview
Get hired: a hands-on capstone landing zone, a portfolio-projects ladder, and full interview preparation.