Tijekom treninga IT profesionalci će usvojiti vještine i znanja za upravljanje Azure preplatama, osiguranje identiteta, administriranje infrastrukture, konfiguriranje virtualnog umrežavanja, povezivanje Azurea i loklanih (eng. on-premises) resursa i upravljanje mrežnim prometom.
IT profesionalci također će naučiti kako implementirati rješenja za pohranu podataka, kreirati i skalirati virtualne strojeve, implementirati web aplikacije i kontejnere, izraditi sigurnosne kopije i dijeliti podatke te nadgledati svoja rješenja.
Što ćete naučiti
- Upravljajti Azure pretplatama i resursima.
- Implementirati i upravljati Azure prostorom za pohranu.
- Implementirati i upravljati Azure virtualnim strojevima.
- Konfigurirati i upravljati Azure virtualnim mrežama.
- Upravljati identitetima.
- Postaviti Azure Resource Manager ARM predloške.
Kome je namijenjeno
Azure administratorima čiji je zadatak implementiranje, upravljanje i nadgledanje identiteta, prostora za pohranu i virtualnih mreža u cloud okolini. Azure administratorima čija je zadaća osigurati, mjeriti, pratiti i prilagoditi resurse prema potrebi.
Preduvjeti
- Razumijevanje lokalnih (eng. on-premises) tehnologija virtualizacije kao što su VM, virtualno umrežavanje i virtualni hard diskovi.
- Razumijevanje mrežnih tehnologija, komponenti, servisa i protokola kao što su TCP/IP, Domain Name System (DNS), virtual private networks (VPNs), vatrozid i tehnologija enkripcije.
- Razumijevanje Active Directory koncepata što uključuje korisnike, grupe i kontrole pristupa ovisno o ulozi.
- Razumijevanje otpornosti i oporavka od katastrofe, uključujući operacije sigurnosnog kopiranja i vraćanja podataka.
- Microsoft Azure Fundamentals: Describe cloud concepts
- Azure Fundamentals: Describe Azure architecture and services
- Azure Fundamentals: Describe Azure management and governance
- AZ-104: Prerequisites for Azure administrators
Nastavni plan
-
Pregledaj
- Module 1: Configure Azure Active Directory
Learn how to configure Azure Active Directory, including features like Azure AD join and self-service password reset.
After completing this module, students will be able to:
- Define Azure AD concepts, including identities, accounts, and tenants
- Describe Azure AD features to support different configurations
- Understand differences between Azure AD and Active Directory Domain Services (AD DS)
- Choose between supported editions of Azure AD
- Implement the Azure AD join feature
- Use the Azure AD self-service password reset feature
- Configure users accounts and user account properties
- Create new user accounts
- Import bulk user accounts with a template
- Configure group accounts and assignment types
- Determine the correct region to locate Azure services
- Review features and use cases for Azure subscriptions
- Obtain an Azure subscription
- Understand billing and features for different Azure subscriptions
- Use Microsoft Cost Management for cost analysis
- Discover when to use Azure resource tagging
- Identify ways to reduce costs
- Create management groups to target policies and spending budgets
- Implement Azure Policy with policy and initiative definitions
- Scope Azure policies and determine compliance
- Identify features and use cases for role-based access control
- List and create role definitions
- Create role assignments
- Identify differences between Azure RBAC and Azure Active Directory roles
- Manage access to subscriptions with RBAC
- Review built-in Azure RBAC roles
- Manage resources with the Azure portal
- Manage resources with Azure Cloud Shell
- Manage resources with Azure PowerShell
- Manage resources with Azure CLI
- Identify the features and usage cases for Azure Resource Manager
- Describe each Azure Resource Manager component and its usage
- Organize your Azure resources with resource groups
- Apply Azure Resource Manager locks
- Move Azure resources between groups, subscriptions, and regions
- Remove resources and resource groups
- Apply and track resource limits
- List the advantages of Azure templates
- Identify the Azure template schema components
- Specify Azure template parameters
- Locate and use Azure Quickstart Templates
- Describe Azure Virtual Network features and components
- Identify features and usage cases for subnets and subnetting
- Identify usage cases for private and public IP addresses
- Create and determine which resources require public IP addresses
- Create and determine which resources require private IP addresses
- Create virtual networks
- Determine when to use network security groups
- Implement network security group rules
- Evaluate network security group effective rules
- Examine advantages of application security groups
- Determine when to use Azure Firewall
- Implement Azure Firewall including firewall rules
- Identify features and usage cases for domains, custom domains, and private zones
- Verify custom domain names by using DNS records
- Implement DNS zones, DNS delegation, and DNS record sets
- Identify usage cases and product features of Azure Virtual Network peering
- Configure your network to implement Azure VPN Gateway for transit connectivity
- Extend peering by using a hub and spoke network with user-defined routes and service chaining
- Identify features and usage cases for Azure VPN Gateway
- Implement high availability scenarios
- Configure site-to-site VPN connections by using a VPN gateway
- Identify features and usage cases for Azure ExpressRoute
- Coexist site-to-site and Azure ExpressRoute networks
- Identify features and usage cases for Azure Virtual WAN
- Implement system routes and user-defined routes
- Configure a custom route
- Implement service endpoints
- Identify features and usage cases for Azure Private Link and endpoint services
- Identify features and usage cases for Azure Load Balancer
- Implement public and internal Azure load balancers
- Compare features of load balancer SKUs and configuration differences
- Configure back-end pools, load-balancing rules, session persistence, and health probes
- Identify features and usage cases for Azure Application Gateway
- Implement an Azure application gateway, including selecting a routing method
- Configure gateway components, such as listeners, health probes, and routing rules
- Identify features and usage cases for Azure storage accounts
- Select between different types of Azure Storage and storage accounts
- Select a storage replication strategy
- Configure network access to storage accounts
- Secure storage endpoints
- Identify features and usage cases for Azure Blob Storage
- Configure Blob Storage and Blob access tiers
- Configure Blob lifecycle management rules
- Configure Blob object replication
- Upload and price Blob Storage
- Configure a shared access signature (SAS), including the uniform resource identifier (URI) and SAS parameters
- Configure Azure Storage encryption
- Implement customer-managed keys
- Recommend opportunities to improve Azure Storage security
- Identify storage for file shares and blob data
- Configure Azure Files shares and file share snapshots
- Identify features and usage cases of Azure File Sync
- Identify Azure File Sync components and configuration steps
- Configure and use Azure Storage Explorer
- Configure the Azure Import/Export service
- Use the WAImportExport tool with the Azure Import/Export service
- Configure and use AZCopy
- Create a virtual machine planning checklist
- Determine virtual machine locations and pricing models
- Determine the correct virtual machine size
- Configure virtual machine storage
- Implement availability sets and availability zones
- Implement update and fault domains
- Implement Azure Virtual Machine Scale Sets
- Autoscale virtual machines
- Identify features and usage cases for virtual machine extensions
- Identify features and usage cases for Custom Script Extensions
- Identify features and usage cases for Desired State Configuration
- Identify features and usage cases for Azure App Service
- Select an appropriate Azure App Service plan pricing tier
- Scale an Azure App Service plan
- Scale out an Azure App Service plan
- Identify features and usage cases for Azure App Service
- Create an app with Azure App Service
- Configure deployment settings, specifically deployment slots
- Secure your Azure App Service app
- Configure custom domain names
- Back up and restore your Azure App Service app
- Configure Azure Application Insights
- Identify when to use containers versus virtual machines
- Identify the features and usage cases of Azure Container Instances
- Implement Azure container groups
- Identify Azure Kubernetes Service (AKS) components including pods, clusters, and nodes
- Configure network connections for AKS
- Configure storage options for AKS
- Implement security options for AKS
- Scale AKS including adding Azure Container Instances
- Identify features and usage cases for Azure Backup
- Configure Azure Recovery Services vault backup options
- Configure the Microsoft Azure Recovery Services (MARS) agent for Azure Backup
- Implement on-premises file and folder backups
- Identify features and usage cases for different Azure backup methods
- Configure virtual machine snapshots and backup options
- Implement virtual machine backup and restore, including soft delete
- Perform site-to-site recovery by using Azure Site Recovery
- Compare the Azure Backup agent to the Microsoft Azure Backup Server
- Identify the features and usage cases for Azure Monitor
- Configure and interpret metrics and logs
- Identify the Azure Monitor components and data types
- Configure the Azure Monitor activity log
- Identify Azure Monitor alerts, including alert types and alert states
- Configure Azure Monitor alerts
- Create alert rules and action groups
- Identify the features and usage cases for Log Analytics
- Create a Log Analytics workspace
- Structure a Log Analytics query and review results
- Identify the features and usage cases for Azure Network Watcher
- Configure diagnostic capabilities like IP flow verify, next hop, and network topology
Za što vas priprema?
Certifikacijski ispit: Exam AZ-104: Microsoft Azure Administrator Certifikat: Microsoft Certified: Azure Administrator Associate