Public Cloud
Private Cloud
Hybrid Cloud
pay as you go modelregions each of which are hundreds of miles apartregional pairseperate from the public cloudThe fact regions are physically seperated by hundreds of miles protects azure users from data loss and application outages caused by disasters in a particular region
availabilty zones to safe guard against a building outage in that regionexplicitly deploy zonal services into two or more zoneszone redundant when you deploy them.
Azure takes care of the zone redundancy as part of the service
Azure storage account where yoou select ZRS is an example
delete all resources within it
subscription ID
tenant root group. This is automatically created as part of the initial Azure AD deplymentyou don't pay for the VM but only the cpu and memory your container usesAzure subscription, Custom Management Group or Tenant Root group and Resource group
3 fault domains20 update domainsscale sets
in availability sets automatically. You get the benefit of fault and update domainsare compatible with availability zonesThere are three tiers available in app service:
Static webapps are webapps that are linked to a code repo and are updated when there is a commit to the repo
podsnode or a workernode or worker has to have the container runtime installed such as containerd or dockerkubernetes control planeglobal vNet peering to peer vNets across regionsbasic tier Azure load balancer you won’t be able to connect to those resources using the public IP. If this is a requirement you have to upgrade the load balancer to a standard tier
inbound and outbound
User defined routes to foce traffic from subnets to go through the azure firewallapplication rules. This means you can categorise rules by URL, FQDNTLS Inspectionlink it to multiple vNets.
This will protect the public IPs of resources on those vNetsmultiple subscriptions and networks
#### Azure DNSpublic endpoints and private zone contains entries for private endpointslink the zone to the vNet
subnet called the gateway subnettwo vnets together. Each subnet needs a VPN Gateway and they don’t have to be in the same Azure Region or subscription1.25 Gbps
circuitMicrosoft Enterprise Edge router (MSEE)Customer –> Service Provider –> MSEE (Router) –> Azure
Express Route Direct is when you remove the Service Provider. This allows you to connect to the physical port on the MSEE RouterblobAzure File Syncmin 30 daysmin 180 days. Access to the first byte is within 15 hours.rehydrate it to the hot or cool tiers
cannot change the redundancy option once the storage account has been createddoesn't protect against a region failureMake read access to data available in the event of regional unavailability. This changes the Replication to Read Access Geo-Zone Redundant Storagewithin a region are synchronus and Inter region is asynchronous
10 seperate storage accounts10 seperate storage accountsSkill 2.4 Describe Azure Identity, access and security —
authentication and authorisation
replica setAzure AD Connect allows you to connect your on-prem AD DS to Azure AD DS. It can also ensure the cloud and on-prem domains are in sync25,000 objects and 3000 authentications100,000 objects and 10,000 authenticationsfive resource forest trusts500,000 objects and 70,000 authentications10 forest trustsazure AD Connectper-User MFA within Azure AD Users
Azure AD B2Benterprise applications that can access
Azure AD Premiumassignments and access controls to configure acess to your resourcesaccess control policy is enforcedzero trustbilling zones. MS costs for egress traffic out of each zone might differ
azure reservationsreserved capacity pricing. Reserved capacity pricing is like a reservation for VMssubscription or management groupmanagement group can be used by any subscription within that management groupowner or User access administratorcompliance manager# list extensions
az extension list-available --output table
# Install externsions
az extensions install extension_name
az interactive
Azure Connected Machine Agentmanaged identity in Azure. You can manage the server with RBAC, Azure Policy, Tags, Protection with Azure Defender for cloudmultiple conditionsalert groupThere are several support plans such as:
* Basic
* Developer (cheapest paid-for support)
* Standard
* Professional Direct
* Premier
24/7 access to tech support by email and phone is only available with standard, Professional direct, premier plans
The stages are:
* Define strategy
* Plan
* Ready
* Adopt
* Govern
* Manage
* Govern Describe privacy and compliance resources * Three documents:
* MS privacy statement
* personal data MS processes
* how MS processes it
* For what purpose
* Online services Terms OST
* legal agreement between MS and customer
* Outlines obligations and security of customer data and personal data
* Data protection Addendum DPA
* Defines the data processing and security terms of online services
* compliance of laws
* security practises
* data transferred, retention and deletion ## Trust Centre * Three key components
* Security
* Privacy
* Compliance * breaks down MS services into those three elements and gives you details of how MS meet those three elements ## Azure soverign regions * Azure government is for US government or contractors * Azure China. This is operated by 21 vanet. not operated by MS. Same features as Azure global but not operated by China