Azure RBAC: Built-in Roles & Custom Role Definitions
Apply least-privilege Azure RBAC assignments, select an appropriate scope, create a narrow custom role, and verify effective access.
Section 06 / Final chapter
Azure Administrator
11 topic guides with diagnostic sections. Use this chapter after the core material, or when an implementation behaves differently from the expected result. Each link opens the relevant section in its original reference.
Apply least-privilege Azure RBAC assignments, select an appropriate scope, create a narrow custom role, and verify effective access.
Establish enterprise cloud governance across multi-subscription environments using Management Group hierarchies, Azure Policy compliance definitions with auto-remediation, and Resource Locks.
Deploy and optimize Azure Storage accounts, configure Hot/Cool/Cold/Archive tiers, automated lifecycle management rules, and immutable blob storage.
Deploy serverless SMB 3.0 / NFS Azure file shares, synchronize on-premises file servers using Azure File Sync with Cloud Tiering, and secure access via Storage Private Endpoints and SAS tokens.
Deploy highly available Azure Virtual Machines across Availability Zones, configure Availability Sets (Fault/Update Domains), and enforce secure browser-based RDP/SSH via Azure Bastion.
Configure elastic compute with Virtual Machine Scale Sets (VMSS) autoscale rules, upgrade policies (Automatic, Rolling, Manual), and deploy high-availability web applications using Azure App Service plans and deployment slots.
Architect Azure Virtual Networks, design non-overlapping IP address spaces, configure VNet Peering, Gateway Transit, and User Defined Routes (UDR).
Design stateful packet filtering rules, priority evaluations, default security rules, and Application Security Group (ASG) workload isolation in Azure.
Design Layer 4 and Layer 7 traffic distribution, health monitoring, Application Gateway subnet capacity, and private DNS resolution in Azure.
Collect diagnostics, query telemetry with Kusto Query Language (KQL), configure alert rules, and build Azure Monitor workbooks for enterprise observability.
Implement enterprise data protection and business continuity using Azure Backup, Recovery Services Vaults, VM snapshot policies, Cross-Region Restore (CRR), Soft Delete, and Azure Site Recovery (ASR).