Skip to content

Section 06 / Final chapter

Troubleshooting

Azure Administrator

11 topic guides with diagnostic sections. Use this chapter after the core material, or when an implementation behaves differently from the expected result. Each link opens the relevant section in its original reference.

Before changing anything

  1. Record the affected user, device or resource, the exact error, and when it started.
  2. Compare the current state with the prerequisites and expected result in the topic reference.
  3. Collect the relevant logs, check the scope, and test one change at a time.
  4. Verify the result and document the change. Review rollback and impact before changing production.

01Identities & Governance

Azure RBAC: Built-in Roles & Custom Role Definitions

Apply least-privilege Azure RBAC assignments, select an appropriate scope, create a narrow custom role, and verify effective access.

Azure Governance: Management Groups, Azure Policy & Resource Locks

Establish enterprise cloud governance across multi-subscription environments using Management Group hierarchies, Azure Policy compliance definitions with auto-remediation, and Resource Locks.

02Storage Management

Storage Accounts: Blob Access Tiers & Lifecycle

Deploy and optimize Azure Storage accounts, configure Hot/Cool/Cold/Archive tiers, automated lifecycle management rules, and immutable blob storage.

Azure Files, Azure File Sync & Storage Private Endpoints

Deploy serverless SMB 3.0 / NFS Azure file shares, synchronize on-premises file servers using Azure File Sync with Cloud Tiering, and secure access via Storage Private Endpoints and SAS tokens.

03Compute & Virtual Machines

Virtual Machines: Availability Zones & Azure Bastion

Deploy highly available Azure Virtual Machines across Availability Zones, configure Availability Sets (Fault/Update Domains), and enforce secure browser-based RDP/SSH via Azure Bastion.

Azure VM Scale Sets (VMSS) & Azure App Services

Configure elastic compute with Virtual Machine Scale Sets (VMSS) autoscale rules, upgrade policies (Automatic, Rolling, Manual), and deploy high-availability web applications using Azure App Service plans and deployment slots.

04Virtual Networking

Virtual Networks: Subnets & VNet Peering

Architect Azure Virtual Networks, design non-overlapping IP address spaces, configure VNet Peering, Gateway Transit, and User Defined Routes (UDR).

Network Security Groups (NSG) & Application Security Groups (ASG)

Design stateful packet filtering rules, priority evaluations, default security rules, and Application Security Group (ASG) workload isolation in Azure.

Azure Load Balancer, Application Gateway & Private DNS

Design Layer 4 and Layer 7 traffic distribution, health monitoring, Application Gateway subnet capacity, and private DNS resolution in Azure.

05Monitoring & Backup

Azure Monitor: Log Analytics & KQL Queries

Collect diagnostics, query telemetry with Kusto Query Language (KQL), configure alert rules, and build Azure Monitor workbooks for enterprise observability.

Azure Backup, Recovery Services Vault & Disaster Recovery

Implement enterprise data protection and business continuity using Azure Backup, Recovery Services Vaults, VM snapshot policies, Cross-Region Restore (CRR), Soft Delete, and Azure Site Recovery (ASR).