Back to: C#.NET Tutorials For Beginners and Professionals
Microsoft Azure Developer & Cloud Integration with AI Training Program
This course is designed for .NET developers who want to understand Microsoft Azure from the fundamentals and then build, deploy, secure, integrate, monitor, and operate real-world cloud applications.
The course follows a structured chapter-based learning approach. Participants begin with Cloud and Azure fundamentals, then progressively move into application hosting, serverless development, messaging, events, APIs, security, private networking, monitoring, containers, CI/CD, infrastructure automation, hybrid connectivity, migration, and Azure AI.
Contact Us
📱 Telegram Group: https://telegram.me/microsoftazuretraining
📞 Mobile / WhatsApp Number: +91 70218 01173
ℹ️ WhatsApp Group: https://chat.whatsapp.com/JpFqI2n5hWX9lQSqYWpEf0
📺 YouTube Channel: https://www.youtube.com/@DotNetTutorials
Course Details:
Duration: 4 Months
Fees: 12K INR
Registration Link: https://forms.gle/vxgePayr5jxBbZbTA
Prerequisites
This training program starts with the fundamentals of Cloud Computing and Microsoft Azure, so prior Azure or cloud experience is not required. However, participants should have:
- Basic knowledge of C# and .NET
- Basic understanding of ASP.NET Core / Web API development
- Basic knowledge of SQL and databases
- Familiarity with REST APIs, HTTP, and JSON is helpful
- Familiarity with Visual Studio or Visual Studio Code is helpful.
Who Can Enroll for This Training Program?
This training program is suitable for:
- .NET Developers who want to build and deploy cloud-native applications on Microsoft Azure
- Software Developers planning to move from on-premises development to cloud development
- Technical Leads and Solution Developers who want a practical understanding of Azure architecture and services
- DevOps-oriented Developers who want exposure to CI/CD, containers, AKS, monitoring, and Infrastructure as Code
- Developers interested in Azure AI integration with modern .NET applications
- Students and Freshers with good C#/.NET fundamentals who want to build a career in Microsoft Azure development
Detailed Course Syllabus
Chapter 1: Introduction to Cloud Computing
In this chapter, we will build the foundation needed for the rest of the course by understanding what cloud computing is, how it differs from traditional on-premises infrastructure, and why organizations adopt cloud platforms. We will also learn the major cloud models, service models, pricing ideas, shared responsibility, scalability, elasticity, availability, resilience, and other core concepts used throughout Azure.
Highlighted Topics
- What cloud computing is and why organizations use cloud platforms.
- Traditional on-premises infrastructure versus cloud computing.
- Business and technical reasons for moving applications to the cloud.
- Public cloud, private cloud, and hybrid cloud models.
- Infrastructure as a Service (IaaS), Platform as a Service (PaaS), Software as a Service (SaaS), and serverless computing.
- Scalability, elasticity, high availability, fault tolerance, resilience, and global reach.
- Capital expenditure (CapEx) versus operational expenditure (OpEx).
- Consumption-based pricing and the pay-for-what-you-use model.
- Shared responsibility model: what the cloud provider manages and what the customer manages.
- Simple examples of cloud-hosted web, API, database, storage, messaging, and background-processing workloads.
Chapter 2: Introduction to Microsoft Azure
In this chapter, we will understand what Microsoft Azure is and how developers use its services to build complete cloud applications. We will explore Azure’s major service categories, global infrastructure, regions, Availability Zones, region selection, Service Level Agreements, data-residency considerations, and the way multiple Azure services work together in a typical .NET solution.
Highlighted Topics
- What Microsoft Azure is and how developers use it to build and run applications.
- Major Azure service categories: Compute, Networking, Storage, Databases, Identity, Integration, Containers, Monitoring, DevOps, Data, and AI.
- Azure global infrastructure and the relationship between geographies, regions, and datacenters.
- Azure regions, region selection, latency, compliance, service availability, and data-residency basics.
- Availability Zones and why they improve resilience.
- Region-pair concepts and multi-region design awareness.
- Service Level Agreements (SLAs) at a beginner level.
- How real Azure solutions combine multiple services instead of relying on one service in isolation.
- Typical Azure application architecture for a .NET web/API workload.
- Overview of the learning path used throughout this course.
Chapter 3: Azure Accounts, Tenants, Subscriptions, and Resource Organization
In this chapter, we will learn how Azure resources are organized and governed through accounts, Microsoft Entra tenants, subscriptions, management groups, resource groups, and individual resources. We will also understand environment separation, naming conventions, tagging, and practical approaches for organizing Development, Test, UAT, and Production resources.
Highlighted Topics
- Microsoft account, work/school account, Azure account, and Microsoft Entra tenant basics.
- What an Azure subscription is and how it provides billing, quota, access, and deployment boundaries.
- Relationship between Microsoft Entra tenants and Azure subscriptions.
- Management groups and hierarchical governance across subscriptions.
- Resource groups and how they act as lifecycle containers for related resources.
- Azure resources and resource types.
- Separating development, test, UAT, and production environments.
- Subscription and resource-group organization for teams and projects.
- Naming conventions and consistent resource naming.
- Tags for ownership, environment, application, cost center, and operational metadata.
Chapter 4: Azure Portal, Cloud Shell, Azure CLI, PowerShell, Azure Developer CLI (azd), and Developer Tools
In this chapter, we will learn the main tools used by Azure developers to create, configure, inspect, and deploy resources. We will work with the Azure portal, Cloud Shell, Azure CLI, Azure PowerShell, Visual Studio, Visual Studio Code, Azure SDKs for .NET, DefaultAzureCredential, and Azure Developer CLI (azd), including the basic azd workflow for repeatable application provisioning and deployment.
Highlighted Topics
- Navigating the Azure portal and locating commonly used Azure services.
- Creating, viewing, configuring, and deleting Azure resources safely.
- Using Azure Cloud Shell for browser-based administration.
- Introduction to Azure CLI and common command patterns.
- Introduction to Azure PowerShell and common cmdlet patterns.
- Installing and authenticating Azure CLI locally.
- Using Visual Studio and Visual Studio Code with Azure development workloads.
- Introduction to Azure SDKs for .NET.
- Using DefaultAzureCredential during local development and after deployment.
- Finding authoritative service documentation in Microsoft Learn.
- Understand Azure Developer CLI (azd) as an application-centric developer tool for provisioning and deploying Azure applications.
- Learn the purpose of azd templates, environments, and environment-specific configuration.
- Learn the core azd workflow: azd init, azd auth login, azd up, azd provision, azd deploy, and azd down at a beginner level.
- Understand the difference between Azure CLI for general Azure resource administration and azd for repeatable application development and deployment workflows.
- Hands-on: create a resource group using the portal/Azure CLI, then initialize and inspect a simple Azure Developer CLI project.
Chapter 5: Azure Resource Manager, Resource Management, Cost Basics, and Azure Advisor
In this chapter, we will understand how Azure Resource Manager manages cloud resources through the control plane and how resource providers, resource IDs, dependencies, tags, and locks fit together. We will also introduce Azure pricing, budgets, cost analysis, Azure Advisor, Service Health, Resource Health, and the basic ideas that lead into infrastructure as code.
Highlighted Topics
- What Azure Resource Manager (ARM) is and how Azure resources are managed through the control plane.
- Control plane versus data plane.
- Resource providers and resource types.
- Azure resource IDs and how Azure uniquely identifies resources.
- Tags and resource locks.
- Resource dependencies and deployment ordering concepts.
- Basic Azure pricing concepts: service tiers, meters, usage, and billing.
- Budgets, cost alerts, cost analysis, and cost-allocation awareness.
- Common cost-optimization approaches such as right-sizing, autoscaling, and deleting unused resources.
- Azure Advisor recommendations for cost, reliability, performance, security, and operational excellence.
- Azure Service Health versus Resource Health.
- Introduction to infrastructure-as-code concepts before learning Bicep and Terraform later in the course.
Chapter 6: Microsoft Entra ID Fundamentals
In this chapter, we will learn the identity foundations required for securing Azure applications. We will understand Microsoft Entra ID, tenants, directories, users, groups, devices, administrative roles, enterprise applications, service principals, authentication versus authorization, Single Sign-On, workforce identities, and least-privilege identity practices.
Highlighted Topics
- What Microsoft Entra ID is and why identity is central to Azure security.
- Tenant, directory, users, groups, devices, and administrative roles.
- Cloud identities versus synchronized/hybrid identities at a conceptual level.
- Authentication versus authorization.
- Microsoft Entra roles versus Azure RBAC roles.
- Enterprise applications and service principals at a beginner level.
- Single Sign-On (SSO) concepts.
- Workforce identities versus external/customer identities.
- Identity-first security and least-privilege principles.
- Hands-on: explore users, groups, enterprise applications, and sign-in information in Microsoft Entra.
Chapter 7: Multi-Factor Authentication and Conditional Access
In this chapter, we will learn how Azure strengthens sign-in security beyond passwords. We will understand Multi-Factor Authentication, common authentication methods, security defaults, Conditional Access signals and controls, authentication strength, sign-in risk scenarios, and the developer considerations that arise when applications use Microsoft Entra authentication.
Highlighted Topics
- Password-based authentication and why passwords alone are not sufficient.
- Multi-Factor Authentication (MFA) concepts.
- Common authentication methods such as Microsoft Authenticator, passkeys, and security keys.
- Security defaults and their purpose.
- Conditional Access fundamentals.
- Conditional Access signals such as user, application, device, location, and risk.
- Grant, block, and authentication-strength concepts at a beginner level.
- Common sign-in risk scenarios.
- How MFA and Conditional Access protect Azure administrators and application users.
- Developer considerations when an application uses Microsoft Entra authentication.
Chapter 8: App Registrations, OAuth 2.0, OpenID Connect, and Application Authentication
In this chapter, we will learn how applications authenticate users and other applications using Microsoft Entra ID. We will understand App Registrations, service principals, application identifiers, redirect URIs, secrets and certificates, OAuth 2.0, OpenID Connect, access and ID tokens, delegated and application permissions, consent, and how ASP.NET Core APIs validate and authorize tokens.
Highlighted Topics
- What an App Registration is and when an application needs one.
- Application (client) ID, tenant ID, object ID, redirect URI, and application credentials.
- Client secrets versus certificates and why long-lived secrets should be minimized.
- OAuth 2.0 fundamentals.
- OpenID Connect fundamentals.
- Access tokens versus ID tokens.
- Scopes, delegated permissions, and user consent.
- Application permissions and application-only access.
- Service principals and enterprise applications.
- Protecting ASP.NET Core APIs with Microsoft Entra ID.
- Calling protected APIs from client or service applications.
Chapter 9: External Identities, B2B Collaboration, and Microsoft Entra External ID
In this chapter, we will learn how Azure applications work with users outside the organization’s workforce tenant. We will understand Microsoft Entra B2B collaboration, guest users, cross-tenant collaboration, guest lifecycle considerations, Microsoft Entra External ID, external tenants, customer sign-up and sign-in flows, and secure external-user onboarding and authorization.
Highlighted Topics
- Internal workforce users versus external users and customer identities.
- Microsoft Entra B2B collaboration concepts.
- Inviting guest users and controlling guest access.
- Guest-user lifecycle and access-review awareness.
- Cross-tenant access and collaboration concepts.
- Microsoft Entra External ID for customer-facing applications.
- External tenants and customer sign-up/sign-in flows.
- External identity providers and social identity concepts.
- Workforce tenant versus external tenant considerations.
- Designing secure external-user onboarding and authorization.
Chapter 10: Azure Role-Based Access Control (Azure RBAC)
In this chapter, we will learn how Azure Role-Based Access Control determines what authenticated identities are allowed to do. We will understand security principals, role definitions, scopes, role assignments, inheritance, built-in and custom roles, control-plane versus data-plane access, least privilege, and common RBAC mistakes developers should avoid.
Highlighted Topics
- Why authorization is required after identity has been established.
- Security principal, role definition, scope, and role assignment.
- Built-in roles and the principle of least privilege.
- Owner, Contributor, Reader, and service-specific data roles.
- RBAC scopes: management group, subscription, resource group, and resource.
- Inherited permissions and effective access.
- Control-plane permissions versus data-plane permissions.
- Assigning roles through the Azure portal and automation.
- Custom roles at a conceptual level.
- Common RBAC mistakes developers should avoid.
- Hands-on: give an application only the minimum role it needs to access an Azure resource.
Chapter 11: Managed Identities and Secretless Azure Authentication
In this chapter, we will learn how Azure-hosted applications can authenticate to other Azure services without storing usernames, passwords, or client secrets. We will understand system-assigned and user-assigned managed identities, DefaultAzureCredential, Azure RBAC integration, and practical secretless access patterns for Key Vault, Storage, Azure SQL, Service Bus, and other supported services.
Highlighted Topics
- Why deployed applications should avoid storing usernames, passwords, and client secrets.
- What a managed identity is and how it obtains Microsoft Entra tokens.
- System-assigned managed identities.
- User-assigned managed identities.
- Choosing between system-assigned and user-assigned identities.
- Using managed identity with Azure Key Vault.
- Using managed identity with Azure Storage.
- Using managed identity with Azure SQL.
- Using managed identity with Service Bus and other supported Azure services.
- DefaultAzureCredential and the local-development-to-Azure authentication experience.
- Combining managed identity with Azure RBAC for least-privilege access.
- Hands-on: authenticate from a .NET application to an Azure service without storing a password.
Chapter 12: Azure Key Vault
In this chapter, we will learn how Azure Key Vault protects application secrets, encryption keys, and certificates. We will cover RBAC-based access, managed identity integration, .NET access patterns, Key Vault references, secret rotation, certificate lifecycle, soft delete, purge protection, logging, firewalls, private endpoints, and secure configuration practices.
Highlighted Topics
- Purpose of Azure Key Vault.
- Secrets, keys, and certificates.
- Creating and configuring a Key Vault.
- Key Vault access using Azure RBAC.
- Reading secrets from .NET applications.
- Using managed identity with Key Vault.
- Key Vault references in Azure App Service and other supported hosting services.
- Secret rotation and certificate lifecycle concepts.
- Soft delete and purge protection.
- Logging and monitoring Key Vault access.
- Network security, firewalls, and private endpoints for Key Vault.
- Security practices for avoiding secrets in source code and configuration files.
Chapter 13: Azure App Configuration and Feature Management
In this chapter, we will learn how Azure App Configuration centralizes non-secret application settings across services and environments. We will understand key-values, labels, environment-specific configuration, dynamic refresh, feature flags, targeted and percentage-based rollout concepts, variants, snapshots, identity-based access, private networking, and the relationship between App Configuration and Key Vault.
Highlighted Topics
- Understand why cloud applications need centralized configuration instead of duplicating settings across applications and environments.
- Learn Azure App Configuration and the problems it solves for distributed .NET applications.
- Understand key-values, keys, values, content types, labels, and environment-specific configuration.
- Learn the difference between application configuration and secrets: use App Configuration for normal settings and Key Vault for sensitive values.
- Integrate Azure App Configuration with .NET and ASP.NET Core configuration providers.
- Understand configuration loading, selection, prefixes, labels, and application startup behavior.
- Learn dynamic configuration refresh so applications can receive updated settings without unnecessary redeployment.
- Understand feature flags and how feature management separates feature release from application deployment.
- Learn feature-management concepts such as conditions, targeting, percentage rollout, time windows, and variants at a practical level.
- Understand configuration snapshots/versioning concepts for controlled configuration rollouts and recovery.
- Use Microsoft Entra ID, Azure RBAC, managed identity, and DefaultAzureCredential for secure application access.
- Understand private networking, monitoring, availability, and troubleshooting considerations.
- Compare App Configuration, application settings/environment variables, and Key Vault and know when each should be used.
- Hands-on: connect an ASP.NET Core application to Azure App Configuration, load environment-specific settings, and control a feature with a feature flag.
Chapter 14: Azure Networking Fundamentals for Developers
In this chapter, we will build the networking foundation required to connect and secure Azure applications. We will learn IP addressing, ports, protocols, DNS, routing, firewalls, NAT, Virtual Networks, CIDR, subnets, Network Security Groups, route tables, NAT Gateway, VNet peering, and the difference between inbound and outbound connectivity for PaaS and VM workloads.
Highlighted Topics
- Why networking matters to application developers.
- IP addresses, ports, protocols, DNS, routing, firewall, and NAT fundamentals.
- Virtual Networks (VNets) and address spaces.
- CIDR notation at a beginner level.
- Subnets and network segmentation.
- Private IP addresses versus public IP addresses.
- Network Security Groups (NSGs), inbound/outbound rules, priorities, and service tags.
- Route tables and user-defined routes at a conceptual level.
- NAT Gateway for controlled outbound internet connectivity.
- Azure DNS and basic name-resolution concepts.
- VNet peering.
- Inbound versus outbound connectivity for PaaS and VM workloads.
- Hands-on: create a VNet, subnet, and NSG and trace an application’s network path.
Chapter 15: Private Link, Private Endpoints, and Private DNS
In this chapter, we will learn how to keep supported Azure PaaS services privately reachable through Azure Private Link and private endpoints. We will understand private DNS, name resolution, service endpoints, VNet integration, firewall restrictions, private access patterns, and how to troubleshoot DNS, routing, and authorization problems in network-isolated applications.
Highlighted Topics
- Public endpoints versus private endpoints.
- Azure Private Link and how private endpoints work.
- Creating private endpoints for supported PaaS services.
- Private DNS zones and required DNS records.
- Name resolution when a service has both public and private endpoints.
- Service endpoints versus private endpoints and when each approach fits.
- Securing Azure Storage, Azure SQL, Key Vault, APIM, and other supported services privately.
- VNet integration versus private endpoints: outbound versus inbound private connectivity.
- Firewall and network-restriction concepts.
- Troubleshooting DNS, routing, and authorization issues with private endpoints.
- Design patterns for network-isolated PaaS applications.
Chapter 16: Connecting Azure to On-Premises and Hybrid Systems
In this chapter, we will learn how Azure applications communicate securely with systems that remain on-premises or in other private environments. We will cover Site-to-Site and Point-to-Site VPN concepts, ExpressRoute, routing and DNS considerations, App Service Hybrid Connections, Azure Relay, API Management self-hosted gateway, Logic Apps connectivity, Data Factory Self-hosted Integration Runtime, and messaging-based hybrid integration.
Highlighted Topics
- Common hybrid application and integration scenarios.
- Network-level versus application-level hybrid integration.
- Site-to-Site VPN concepts.
- Point-to-Site VPN concepts.
- Azure ExpressRoute concepts.
- DNS, routing, firewall, latency, bandwidth, and availability considerations.
- App Service Hybrid Connections for supported outbound scenarios.
- Azure Relay concepts for securely reaching services without directly exposing inbound endpoints.
- API Management self-hosted gateway concepts for APIs running outside Azure.
- Logic Apps connectivity to on-premises systems where supported.
- Azure Data Factory Self-hosted Integration Runtime for private/on-premises data sources.
- Using Service Bus to decouple Azure applications from intermittently available on-premises systems.
- Designing and monitoring secure end-to-end hybrid communication.
Chapter 17: Azure Virtual Machines for Developers
In this chapter, we will learn when Azure Virtual Machines are appropriate and what responsibilities come with using them. We will understand VM images, sizes, compute and memory choices, disks, networking, secure administration, availability options, VM Scale Sets, diagnostics, patching, backup, monitoring, and how VMs compare with App Service, Functions, Container Apps, and AKS.
Highlighted Topics
- What an Azure Virtual Machine is and when a VM is appropriate.
- When to choose a VM instead of a managed PaaS service.
- VM images, operating systems, VM sizes, CPU, and memory.
- OS disks, data disks, and temporary storage.
- VM networking, public/private access, and NSGs.
- Secure administration and identity considerations.
- Availability Zones, availability concepts, and VM Scale Sets.
- VM extensions, boot diagnostics, patching, and backup awareness.
- Hosting applications on VMs.
- Monitoring and cost considerations.
- Comparing VMs with App Service, Functions, Container Apps, and AKS.
- Hands-on: deploy a small VM, review connectivity and monitoring, then remove the lab resources.
Chapter 18: Azure Storage Accounts and Core Storage Services
In this chapter, we will learn the foundation of Azure Storage and how one storage account can provide several data services. We will understand redundancy options, Blob, Files, Queue, and Table storage, Data Lake Storage Gen2, service endpoints, Microsoft Entra and RBAC-based access, SAS, account keys, firewalls, private endpoints, encryption, Storage Explorer, and storage-service selection.
Highlighted Topics
- What an Azure Storage account is.
- Storage account naming, region selection, performance, and secure endpoints.
- Storage redundancy: locally redundant, zone-redundant, geo-redundant, and geo-zone-redundant concepts.
- Overview of Blob, Files, Queue, and Table storage.
- Azure Data Lake Storage Gen2 concepts for analytics-oriented storage.
- Storage endpoints and service URLs.
- Authentication using Microsoft Entra ID and Azure RBAC as the preferred application pattern.
- Account keys, Shared Access Signatures (SAS), and user-delegation SAS.
- Storage firewalls, network restrictions, and private endpoints.
- Encryption at rest and basic data-protection concepts.
- Using Azure Storage Explorer.
- Choosing the correct storage service for a business requirement.
Chapter 19: Azure Blob Storage
In this chapter, we will learn how Azure Blob Storage handles application files and other object data. We will work with containers, blobs, metadata, content types, access tiers, the .NET Blob SDK, Microsoft Entra and RBAC authorization, Shared Access Signatures, lifecycle policies, versioning, soft delete, Event Grid integration, private endpoints, and secure file upload/download scenarios.
Highlighted Topics
- Blob Storage concepts and common application scenarios.
- Containers, blobs, virtual directories, metadata, and content types.
- Block blobs and large-object upload concepts.
- Hot, cool, cold, and archive access-tier concepts.
- Uploading, downloading, listing, and deleting blobs.
- Using the Azure Blob Storage SDK for .NET.
- Secure access with Microsoft Entra ID, Azure RBAC, and managed identity.
- Shared Access Signatures and user-delegation SAS.
- Lifecycle-management policies.
- Blob versioning, soft delete, and recovery concepts.
- Storage events and integration with Event Grid.
- Private endpoints for Blob Storage.
- Hands-on: implement secure file upload/download from an ASP.NET Core application.
Chapter 20: Azure Queue Storage, Table Storage, and Azure Files
In this chapter, we will learn when to use Azure Queue Storage, Table Storage, and Azure Files. We will cover queue-based asynchronous processing, visibility and poison-message concepts, simple NoSQL key/attribute storage, partition and row keys, managed file shares, .NET access, security and network controls, and how these services compare with alternatives such as Service Bus.
Highlighted Topics
- Azure Queue Storage fundamentals.
- Queue-based asynchronous processing.
- Queue messages, visibility timeout, dequeue behavior, and poison-message awareness.
- Azure Queue Storage versus Azure Service Bus.
- Azure Table Storage fundamentals.
- Partition key and row key concepts.
- Basic NoSQL/key-attribute access patterns.
- Azure Files and managed file shares.
- SMB file-share concepts and application scenarios.
- Accessing Queue, Table, and Files services from .NET.
- Identity, RBAC, SAS, and network-security considerations.
- Choosing the correct service for simple queues, key-value data, or shared files.
Chapter 21: Azure SQL for Application Developers
In this chapter, we will learn how .NET applications use managed relational databases in Azure. We will understand Azure SQL Database, Azure SQL Managed Instance, logical servers, compute and storage choices, network access, Microsoft Entra authentication, managed identity, private endpoints, backups and restore, geo-replication, query performance, EF Core, retries, and database schema changes in CI/CD.
Highlighted Topics
- Relational database fundamentals and Azure SQL service options.
- Azure SQL Database and Azure SQL Managed Instance at a conceptual level.
- When a managed Azure SQL service is preferable to SQL Server on a VM.
- Logical servers, databases, compute tiers, storage, and service configuration.
- Connecting from SQL tools and .NET applications.
- Firewall rules and network access.
- Microsoft Entra authentication for Azure SQL.
- Managed identity connectivity from Azure-hosted applications.
- Private endpoints for Azure SQL.
- Automated backups, point-in-time restore, geo-replication, and failover concepts.
- Indexes, query performance, connection pooling, transient failures, and retry logic.
- Using EF Core with Azure SQL.
- Database schema migration considerations in CI/CD.
- Hands-on: connect an ASP.NET Core application to Azure SQL without embedding production credentials.
Chapter 22: Azure Cosmos DB for NoSQL
In this chapter, we will learn when a document-oriented NoSQL database is a better fit than a relational database and how Azure Cosmos DB for NoSQL is structured. We will understand accounts, databases, containers, items, partition keys, Request Units, throughput modes, consistency, indexing, the .NET SDK, querying, pagination, ETags, TTL, change feed, identity-based access, private networking, monitoring, and cost considerations.
Highlighted Topics
- Understand NoSQL databases and when a document-oriented cloud database is preferable to a relational database.
- Learn Azure Cosmos DB for NoSQL and common application scenarios such as globally distributed applications, user/profile data, catalogs, events, and AI-related application data.
- Understand the Azure Cosmos DB resource hierarchy: account, database, container, and item.
- Learn JSON document storage and the schemaless/flexible-schema data model.
- Understand partition keys and why partition-key design is one of the most important scalability decisions.
- Learn logical partitions, physical partitions, data distribution, and avoiding hot partitions at a beginner-friendly level.
- Understand Request Units (RUs), throughput, provisioned throughput, autoscale, serverless concepts, and how workload patterns affect cost.
- Learn consistency levels and the trade-off between consistency, latency, and availability.
- Understand indexing and how index policy affects query behavior and write cost.
- Use the Azure Cosmos DB SDK for .NET to create, read, update, delete, and query items.
- Learn parameterized queries, pagination, continuation tokens, and efficient query practices.
- Understand optimistic concurrency using ETags and conditional updates.
- Learn Time to Live (TTL), transactional batch concepts, and change feed at an introductory level.
- Use Microsoft Entra ID, Azure RBAC, managed identity, and DefaultAzureCredential instead of embedding account credentials where supported.
- Understand network restrictions, private endpoints, encryption, backup/recovery, and high-availability considerations.
- Monitor requests, RU consumption, throttling, latency, failures, storage, and cost.
- Compare Azure Cosmos DB with Azure SQL and Azure Table Storage so students can choose the correct data store.
- Hands-on: build a small .NET application that stores and queries documents in Azure Cosmos DB for NoSQL using identity-based authentication.
- Compare Azure SQL and Azure Cosmos DB at a high level before choosing a relational or NoSQL data model.
Chapter 23: Azure App Service Fundamentals
In this chapter, we will learn how Azure App Service hosts web applications and REST APIs without requiring developers to manage the underlying servers. We will understand App Service Plans, Windows and Linux hosting, deployment, configuration, custom domains, TLS, scaling, Microsoft Entra integration, managed identity, Key Vault, VNet integration, and private inbound access.
Highlighted Topics
- What Azure App Service is and when to use it.
- Web Apps and REST API hosting.
- App Service Plans and the relationship between plans and apps.
- Choosing compute size and plan characteristics.
- Windows versus Linux hosting.
- Deploying ASP.NET Core applications and APIs.
- Application settings, environment variables, and connection strings.
- Environment-specific configuration.
- Custom domains and TLS certificates.
- HTTPS-only configuration.
- Scaling up versus scaling out.
- App Service authentication/authorization overview with Microsoft Entra ID.
- Managed identity and Key Vault integration.
- VNet integration for outbound private access and private endpoints for inbound private access.
Chapter 24: App Service Diagnostics, Kudu/SCM, and WebJobs
In this chapter, we will learn how to diagnose and support applications running on Azure App Service. We will use Kudu/SCM for deployment troubleshooting, console and file-system access, process and environment inspection, application and deployment logs, and common runtime investigations. We will also learn when WebJobs fit background-processing scenarios and how they compare with Azure Functions.
Highlighted Topics
- What the App Service SCM/Kudu site is.
- Using Kudu for deployment diagnostics and troubleshooting.
- File-system inspection and console access.
- Viewing environment information and running processes.
- App Service application logs and diagnostic output.
- Deployment logs and common deployment-failure investigation.
- What WebJobs are and when they fit an App Service solution.
- Continuous versus triggered WebJobs.
- Typical background-processing scenarios.
- WebJobs versus Azure Functions.
- Using configuration, identity, and Azure services from background jobs.
- Troubleshooting application startup, configuration, dependency, and runtime failures.
Chapter 25: App Service Deployment Slots and Blue-Green Deployment
In this chapter, we will learn how App Service deployment slots support safer releases and blue-green deployment practices. We will understand staging and production slots, slot-specific configuration, warm-up, swap behavior, validation, rollback, traffic considerations, CI/CD integration, and a practical staging-to-production release workflow.
Highlighted Topics
- What deployment slots are.
- Production, staging, and additional slot concepts.
- Slot-specific versus swappable configuration.
- Deploying and testing an application in a staging slot.
- Warm-up and readiness before production release.
- Slot swap behavior.
- Blue-green deployment using deployment slots.
- Low-downtime deployment concepts.
- Rollback strategies after a bad release.
- Traffic-routing and validation considerations.
- Combining deployment slots with Azure DevOps pipelines.
- Hands-on: deploy to staging, validate, swap to production, and perform a rollback exercise.
Chapter 26: Azure Functions Fundamentals
In this chapter, we will learn the fundamentals of serverless application development with Azure Functions. We will understand Function Apps, individual functions, triggers, bindings, local development, .NET implementation, HTTP, Timer, Blob, and Queue triggers, deployment, debugging, and basic monitoring with Application Insights and Azure Monitor.
Highlighted Topics
- What serverless computing means.
- What Azure Functions is and when it is a good fit.
- Function App versus individual function.
- Triggers and bindings.
- Creating Azure Functions using .NET.
- HTTP-triggered functions for lightweight APIs and webhooks.
- Timer-triggered functions for scheduled jobs.
- Blob-triggered functions for storage-event processing.
- Queue-triggered functions for asynchronous work.
- Local development, debugging, and configuration.
- Deploying Function Apps to Azure.
- Using Application Insights and Azure Monitor for basic diagnostics.
Chapter 27: Azure Functions Hosting, Triggers, Bindings, and Scaling
In this chapter, we will learn how Azure Functions hosting and trigger choices affect scalability, performance, networking, and cost. We will compare Flex Consumption, Premium, Dedicated/App Service, and Container Apps hosting, and then explore concurrency, cold starts, bindings, additional Azure triggers, dependency injection, retries, poison-message handling, timeouts, idempotency, and reliable event-driven design.
Highlighted Topics
- How Azure Functions hosting choices affect scale, networking, performance, and cost.
- Flex Consumption as the recommended serverless hosting plan for new serverless Function Apps.
- Premium plan for advanced scale, networking, and warm-instance requirements.
- Dedicated/App Service plan hosting when functions share dedicated compute.
- Azure Container Apps hosting for appropriate container-based Function workloads.
- Scaling, concurrency, cold starts, always-ready instances, and workload characteristics.
- Input and output bindings and when explicit SDK code is preferable.
- Storage, Service Bus, Event Grid, and Event Hubs triggers.
- Dependency injection and configuration in .NET Functions.
- Retries, poison messages, timeouts, and idempotency.
- Reliable event-driven Function design.
- Hands-on: build a Function that accepts a request, writes a message, and processes it asynchronously.
Chapter 28: Securing Azure Function Apps
In this chapter, we will learn how to secure Azure Function Apps in production. We will cover authorization levels, Microsoft Entra authentication, managed identity, Key Vault, identity-based access to dependent services, CORS, access restrictions, VNet integration, private endpoints, least-privilege RBAC, logging, auditing, and a production security checklist for serverless workloads.
Highlighted Topics
- Authentication and authorization for HTTP-triggered functions.
- Function authorization levels and when they are appropriate.
- Microsoft Entra authentication for Function Apps.
- Managed identities.
- Key Vault integration and secure configuration management.
- Accessing Storage, Service Bus, SQL, and other services using identity instead of application secrets.
- CORS and browser-access considerations.
- Network access restrictions.
- VNet integration for outbound access to private resources.
- Private endpoints for private inbound access.
- Least-privilege RBAC for Function Apps.
- Logging, auditing, and security monitoring.
- Production security checklist for serverless applications.
Chapter 29: Durable Functions and Long-Running Workflows
In this chapter, we will learn how Durable Functions adds stateful orchestration to serverless applications. We will understand orchestrator, activity, and client functions, orchestration state and history, chaining, fan-out/fan-in, asynchronous HTTP, human approval, monitor patterns, durable timers, external events, deterministic code, retries, compensation, idempotency, and when Durable Functions differs from Logic Apps.
Highlighted Topics
- Why ordinary stateless functions are not ideal for every long-running workflow.
- Durable Functions concepts and stateful orchestration.
- Orchestrator functions.
- Activity functions.
- Client functions and orchestration instance management.
- Durable state and orchestration history.
- Function-chaining pattern.
- Fan-out/fan-in pattern.
- Asynchronous HTTP API and status-polling pattern.
- Human interaction and approval workflows.
- Monitor/polling patterns.
- Durable timers and external events.
- Deterministic orchestrator-code requirements.
- Retries, compensation, idempotency, and failure handling.
- Durable Functions versus Logic Apps.
- Hands-on: implement an order-processing or approval orchestration.
Chapter 30: Azure Logic Apps
In this chapter, we will learn how Azure Logic Apps automates workflows and integrates Azure, SaaS, API, database, and messaging services. We will understand Consumption and Standard workflows, triggers, actions, connectors, conditions, loops, expressions, retries, scopes, run-after handling, managed identity, Key Vault, private networking, diagnostics, resubmission, and when Logic Apps differs from Azure Functions.
Highlighted Topics
- What Azure Logic Apps is and where workflow automation fits.
- Consumption and Standard Logic Apps at a conceptual level.
- Workflow triggers and actions.
- Built-in and managed connectors.
- HTTP and REST API integration.
- Schedule, Service Bus, Event Grid, Storage, database, and SaaS integration scenarios.
- Conditions, loops, variables, expressions, and workflow state.
- Run-after configuration, scopes, retries, timeouts, and error handling.
- Compensation concepts for business workflows.
- Managed identity and Key Vault integration.
- Private networking and hybrid/on-premises connectivity concepts.
- Run history, diagnostics, resubmission, and troubleshooting.
- Logic Apps versus Azure Functions.
- Hands-on: build a workflow that receives an event, calls an API, persists data, and sends a notification.
Chapter 31: Azure Service Bus – Queues, Topics, and Pub/Sub
In this chapter, we will learn how Azure Service Bus provides reliable asynchronous messaging for enterprise applications. We will understand queues, topics, subscriptions, Pub/Sub, message settlement, locks, TTL, dead-letter queues, duplicate detection, scheduling, sessions, transactions, identity-based access, the .NET SDK, monitoring, and the differences between Service Bus and Queue Storage.
Highlighted Topics
- Why enterprise messaging is needed.
- Synchronous versus asynchronous communication.
- Service Bus namespaces.
- Queues and point-to-point messaging.
- Topics, subscriptions, and publish/subscribe messaging.
- Subscription filters.
- Message properties and application metadata.
- Peek-lock processing and message settlement: complete, abandon, defer, and dead-letter.
- Delivery count, lock duration, and message TTL.
- Dead-letter queues, poison messages, replay, and reprocessing.
- Duplicate detection, scheduled messages, sessions, and ordering considerations.
- Transactions and batching at a conceptual level.
- Authentication using Microsoft Entra ID, Azure RBAC, and managed identity.
- Using the current Azure Service Bus SDK from .NET.
- Monitoring active, dead-lettered, and processed messages.
- Service Bus versus Queue Storage.
- Hands-on: build queue-based and topic-based .NET messaging examples.
Chapter 32: Azure Event Grid and Event-Driven Architecture
In this chapter, we will learn how Azure Event Grid enables loosely coupled event-driven applications. We will understand events, publishers, event sources, topics, subscriptions, handlers, filtering, push delivery, retry and dead-letter behavior, CloudEvents, secure delivery, integrations with Storage, Functions, Logic Apps and Service Bus, and when Event Grid differs from Service Bus and Event Hubs.
Highlighted Topics
- Events versus messages versus commands.
- Event-driven architecture and loose coupling.
- Event Grid publishers, event sources, topics, subscriptions, handlers, and delivery.
- System topics and custom topics.
- Push-based event delivery.
- Subject filtering and advanced filtering concepts.
- Retry behavior and delivery attempts.
- Dead-lettering and idempotent event handlers.
- CloudEvents and Event Grid event-schema concepts.
- Integration with Blob Storage, Functions, Logic Apps, webhooks, and Service Bus.
- Identity and secure event delivery where supported.
- Event Grid versus Service Bus versus Event Hubs.
- Hands-on: react to a Blob Storage event with an Azure Function or Logic App.
Chapter 33: Azure Event Hubs and High-Throughput Event Streaming
In this chapter, we will learn how Azure Event Hubs ingests and distributes high-volume event streams such as telemetry, logs, and clickstreams. We will understand namespaces, event hubs, partitions, producers, consumers, consumer groups, checkpoints, capacity planning, Capture, Azure Functions integration, authentication, monitoring, and how Event Hubs differs from Service Bus and Event Grid.
Highlighted Topics
- What event streaming is and when it is required.
- Telemetry, application events, logs, and clickstream scenarios.
- Event Hubs namespaces and event hubs.
- Partitions and partition keys.
- Producers and consumers.
- Consumer groups and independent stream readers.
- Checkpoints and resuming processing.
- Throughput/capacity and partition-planning concepts.
- Event Hubs Capture at a conceptual level.
- Integration with Azure Functions and analytics/stream-processing services.
- Authentication using Microsoft Entra ID and managed identity.
- Monitoring throughput, errors, incoming/outgoing events, and consumer processing.
- Event Hubs versus Service Bus versus Event Grid.
- Hands-on: publish telemetry from a .NET application and consume it with a separate processor.
Chapter 34: Azure Integration Services Architecture
In this chapter, we will bring the major Azure integration services together and learn how to choose the right service for each communication problem. We will compare synchronous communication, messaging, events, streaming, workflow orchestration, Functions, Durable Functions, Logic Apps, Service Bus, Event Grid, Event Hubs, API Management, and Storage as building blocks for loosely coupled enterprise solutions.
Highlighted Topics
- What application and enterprise integration mean.
- Synchronous versus asynchronous communication.
- Messaging versus events versus event streaming.
- Azure Functions for custom event-driven compute.
- Durable Functions for stateful code-based orchestration.
- Logic Apps for workflow and connector-driven integration.
- Service Bus for reliable enterprise messaging and Pub/Sub.
- Event Grid for event notification and reactive architectures.
- Event Hubs for high-volume streaming and telemetry ingestion.
- API Management for API exposure, protection, transformation, and governance.
- Storage services as integration building blocks.
- Designing loosely coupled, resilient systems.
- Choosing the correct integration service based on business requirements.
- Combining multiple services in an order-processing or enterprise-integration architecture.
Chapter 35: RESTful API Development for Azure
In this chapter, we will learn how to design RESTful APIs that integrate cleanly with Azure services. We will cover resources, routes, HTTP methods and status codes, request and response design, JSON, DTOs, validation, error handling, pagination, filtering, sorting, PATCH, idempotency, OAuth/OpenID Connect/JWT security, throttling, caching, retries, correlation IDs, distributed tracing, and ASP.NET Core Web API integration.
Highlighted Topics
- What an API is and why APIs are central to cloud integration.
- REST fundamentals and resource-oriented design.
- Resources, endpoints, routes, and URI design.
- HTTP methods and expected semantics.
- HTTP status codes.
- Headers, query strings, and request/response bodies.
- JSON serialization and content types.
- DTOs, validation, and consistent error responses.
- Pagination, filtering, sorting, and searching.
- Partial updates and PATCH concepts.
- Idempotency and retry-safe API operations.
- OAuth 2.0, OpenID Connect, JWT access tokens, scopes, and roles for API security.
- Rate limiting, throttling, quotas, caching, timeouts, retries, and circuit-breaker concepts.
- Correlation IDs and distributed tracing.
- Building ASP.NET Core Web APIs for Azure and integrating them with Azure services.
Chapter 36: Azure API Management (APIM) and API Gateway Concepts
In this chapter, we will learn how Azure API Management acts as an API gateway and governance layer in front of backend APIs. We will understand APIM services, APIs, operations, products, subscriptions, OpenAPI import, policy sections, JWT validation, transformations, rate limits, quotas, caching, CORS, Microsoft Entra integration, managed identity, private networking, self-hosted gateway, diagnostics, CI/CD, and infrastructure as code.
Highlighted Topics
- What the API Gateway pattern is and why APIs use a gateway.
- What Azure API Management is and where it fits in an architecture.
- APIM service instance, gateway, management plane, APIs, operations, products, subscriptions, and groups.
- Importing APIs from OpenAPI definitions.
- Inbound, backend, outbound, and on-error policy sections.
- Policies for JWT validation, authentication, header manipulation, URL rewriting, and transformation.
- Rate limiting, quotas, and caching.
- CORS configuration at the gateway.
- Microsoft Entra ID integration and securing backend APIs.
- Managed identity for APIM-to-backend authentication where appropriate.
- Developer experience/portal concepts.
- APIM networking, private endpoints, virtual-network scenarios, and private backends.
- Self-hosted gateway concepts for hybrid/distributed API scenarios.
- Diagnostics, metrics, tracing, and Application Insights integration.
- APIM CI/CD and infrastructure-as-code concepts.
- Hands-on: publish an API and apply authentication and throttling policies.
Chapter 37: API Versioning, Lifecycle, and Governance
In this chapter, we will learn how to evolve APIs without unnecessarily breaking existing consumers. We will cover API versioning strategies, backward compatibility, APIM versions and revisions, lifecycle stages, naming standards, documentation, security policies, throttling, observability, deprecation, retirement planning, and governance across multiple environments and teams.
Highlighted Topics
- Why APIs evolve and why consumers need stability.
- Backward compatibility and avoiding breaking changes.
- URL, query-string, and header versioning concepts.
- APIM versions versus revisions.
- API lifecycle stages from design through retirement.
- API naming, standards, documentation, and ownership.
- Authentication, authorization, and security-policy standards.
- Rate limits, quotas, and abuse protection.
- API observability and audit requirements.
- Deprecation communication and consumer migration planning.
- Governance across many teams and APIs.
- Design review checklist for enterprise APIs.
Chapter 38: Azure Front Door, Application Gateway v2, Standard Load Balancer, and Traffic Manager
In this chapter, we will learn how Azure distributes and routes application traffic at regional and global scale. We will compare Layer 4 and Layer 7 traffic handling, Standard Load Balancer, Application Gateway v2, Web Application Firewall, Azure Front Door Standard/Premium, Traffic Manager, health probes, failover, routing, acceleration, and common architectures that combine these services with APIM.
Highlighted Topics
- Why applications need traffic distribution, failover, acceleration, and global routing.
- Layer 4 versus Layer 7 load balancing.
- Azure Standard Load Balancer for TCP/UDP workloads.
- Public versus internal Standard Load Balancers.
- Backend pools, health probes, load-balancing rules, and outbound connectivity.
- Azure Application Gateway v2 for regional HTTP/HTTPS application delivery.
- Listeners, backend pools, routing rules, TLS termination, autoscaling, and Web Application Firewall (WAF).
- Azure Front Door Standard/Premium for global HTTP/HTTPS entry, edge acceleration, routing, caching/CDN capabilities, WAF, and multi-region applications.
- Front Door origin groups, health probes, routing, custom domains, TLS, and health-based failover.
- Azure Traffic Manager for DNS-based global traffic routing.
- Traffic Manager priority, weighted, performance, and geographic routing concepts.
- Global versus regional traffic-management decisions.
- Front Door versus Application Gateway versus Standard Load Balancer versus Traffic Manager.
- Common architectures such as Front Door + APIM and Front Door + Application Gateway.
- Hands-on architecture exercise: choose the correct traffic service for multiple application scenarios.
Chapter 39: Azure Managed Redis and Application Caching
In this chapter, we will learn how distributed caching improves application performance and reduces repeated database work. We will understand Azure Managed Redis, cache-aside, key design, serialization, expiration, eviction, invalidation, session and reference-data scenarios, high availability, clustering, private connectivity, monitoring, .NET client usage, and resilient cache behavior.
Highlighted Topics
- What Redis is and why applications use distributed caching.
- Azure Managed Redis for modern Azure caching workloads.
- Distributed cache versus in-process cache.
- Cache-aside pattern.
- Key design, serialization, expiration, and TTL.
- Eviction and memory-management concepts.
- Caching database query results and reference data.
- Session and temporary-data scenarios.
- Cache invalidation and stale-data risks.
- High availability, clustering, sizing, and scaling concepts.
- Secure connectivity, authentication, TLS, and network restrictions where supported.
- Monitoring memory, connections, operations, latency, and cache-hit behavior.
- Using Redis from .NET with resilient connection handling.
- Hands-on: add cache-aside behavior to an API and measure the reduction in backend calls.
Chapter 40: Azure Monitor, Log Analytics, and KQL Fundamentals
In this chapter, we will learn the core Azure observability platform and how to query operational data. We will understand metrics, logs, traces, events, alerts, Azure Monitor, Activity Log, diagnostic settings, Log Analytics workspaces, Azure Monitor Agent, Data Collection Rules, and Kusto Query Language for filtering, projecting, summarizing, ordering, correlating, and visualizing telemetry.
Highlighted Topics
- Why cloud applications need observability.
- Metrics, logs, traces, events, and alerts.
- Azure Monitor overview.
- Platform metrics and resource metrics.
- Azure Activity Log.
- Diagnostic settings and routing resource logs to destinations.
- Log Analytics workspaces.
- Centralizing logs from multiple Azure resources.
- Kusto Query Language (KQL) fundamentals.
- Using where, project, summarize, count, order, extend, time filters, and simple joins.
- Azure Monitor Agent and Data Collection Rules for supported machine/VM monitoring scenarios.
- Workbooks and dashboards at a conceptual level.
- Building a basic monitoring strategy for applications and infrastructure.
Chapter 41: Application Insights, OpenTelemetry, and Performance Monitoring
In this chapter, we will learn how to monitor application performance and trace requests across distributed .NET services. We will work with Application Insights, OpenTelemetry, requests, dependencies, exceptions, traces, availability telemetry, connection-string configuration, automatic and custom instrumentation, structured logging, correlation, distributed tracing, Application Map, Live Metrics, and performance troubleshooting.
Highlighted Topics
- Application Insights as application performance monitoring (APM) within Azure Monitor.
- Workspace-based Application Insights.
- Requests, dependencies, exceptions, traces, and availability telemetry.
- Connection-string-based Application Insights configuration.
- Instrumenting ASP.NET Core applications.
- OpenTelemetry concepts and vendor-neutral instrumentation.
- Distributed tracing and cross-service correlation.
- Application Map and distributed transaction views.
- Custom events, custom metrics, and structured logging.
- Live metrics and near-real-time troubleshooting.
- Finding slow requests, failed dependencies, database latency, saturation, and throttling.
- Synthetic availability testing concepts.
- Performance baselines and regression detection.
- Hands-on: generate a failure and a slow dependency, then investigate the telemetry.
Chapter 42: Azure Monitor Alerts, Action Groups, and Operational Monitoring
In this chapter, we will learn how to turn Azure monitoring data into actionable operational alerts. We will understand metric alerts, log-search alerts, conditions, thresholds, evaluation frequency, action groups, notification and automation channels, alert severity, noise reduction, dashboards, workbooks, availability monitoring, and practical operational monitoring baselines.
Highlighted Topics
- Why proactive monitoring is required.
- Metric alerts.
- Log search alerts.
- Alert rules, conditions, thresholds, and evaluation frequency.
- Action groups and notification/action channels.
- Email, SMS, webhook, and automation concepts where appropriate.
- Severity and incident-priority concepts.
- Monitoring availability and performance thresholds.
- Reducing alert noise and avoiding duplicate/non-actionable alerts.
- Dashboards and workbooks for operational visibility.
- Resource Health and Service Health in operational monitoring.
- Using Azure Advisor recommendations as part of ongoing operational review.
- Building a practical monitoring and alerting baseline for development, test, and production.
Chapter 43: Container Fundamentals and Azure Container Registry (ACR)
In this chapter, we will learn container fundamentals before deploying containers to Azure. We will understand images, containers, registries, layers, tags, ports, environment variables, volumes, Dockerfiles, ASP.NET Core container images, Azure Container Registry repositories, authentication, RBAC, managed identity, image versioning, security awareness, private networking, and CI/CD build-and-push workflows.
Highlighted Topics
- What containers are and why developers use them.
- Containers versus virtual machines.
- Container images, containers, registries, layers, tags, ports, environment variables, and volumes.
- Dockerfile fundamentals.
- Building an ASP.NET Core container image.
- Container-image versioning and immutable deployment practices.
- What Azure Container Registry is.
- Repositories and image tags.
- Pushing and pulling images.
- ACR authentication, Azure RBAC, managed identity, and pull/push permissions.
- Container supply-chain and image-security awareness.
- ACR integration with Azure Container Apps and AKS.
- Private networking and restricted registry access concepts.
- Hands-on: build a .NET image, push it to ACR, and validate versioned tags.
Chapter 44: Azure Container Apps
In this chapter, we will learn how Azure Container Apps runs containerized applications without requiring direct Kubernetes management. We will understand environments, apps, revisions, replicas, ingress, secrets, managed identity, autoscaling, scale-to-zero, jobs, traffic splitting, blue-green and canary-style deployment, networking, observability, and when Container Apps fits better than App Service, Functions, or AKS.
Highlighted Topics
- What Azure Container Apps is and when to choose it.
- Container Apps environments.
- Container apps, replicas, revisions, and revision modes.
- External and internal ingress.
- Environment variables and secrets.
- Managed identity and Key Vault integration patterns.
- HTTP-driven and event-driven autoscaling concepts.
- Revision traffic splitting for safe rollout, blue-green, and canary-style deployment.
- Container Apps jobs for finite/background workloads.
- Service-to-service communication inside an environment.
- Networking and virtual-network integration concepts.
- Logging, metrics, Application Insights/OpenTelemetry integration, and troubleshooting.
- Container Apps versus App Service versus Functions versus AKS.
- Hands-on: deploy an ASP.NET Core container from ACR, configure ingress, identity, scaling, and a new revision.
Chapter 45: Azure Kubernetes Service (AKS)
In this chapter, we will learn the Kubernetes fundamentals required to work with Azure Kubernetes Service. We will understand clusters, nodes, pods, Deployments, Services, namespaces, ConfigMaps, Secrets, YAML, ACR integration, Microsoft Entra and RBAC concepts, workload identity, networking, ingress, autoscaling, probes, rolling updates, monitoring, and why AKS has greater operational complexity than other managed compute options.
Highlighted Topics
- Why Kubernetes exists and when its additional flexibility is justified.
- Kubernetes cluster, control plane, node, and node-pool concepts.
- Pods, Deployments, ReplicaSets, Services, and Namespaces.
- ConfigMaps and Secrets.
- Declarative YAML and desired state.
- What Azure Kubernetes Service is.
- System and user node pools.
- Deploying containerized .NET applications.
- ClusterIP, LoadBalancer, and ingress concepts.
- Integrating AKS with Azure Container Registry.
- Microsoft Entra integration, Azure RBAC/Kubernetes authorization, and workload identity concepts.
- Networking, service discovery, DNS, and ingress routing.
- Horizontal pod autoscaling and cluster/node autoscaling.
- Health probes, rolling updates, rollback, and high availability.
- Azure Monitor and container insights for AKS.
- AKS versus Azure Container Apps.
- Hands-on: deploy a small multi-service application and troubleshoot pods, services, logs, and rollout status.
Chapter 46: Azure DevOps CI/CD for Azure Applications
In this chapter, we will learn how Azure DevOps automates the build, test, and release lifecycle for Azure applications. We will cover Repos, Pipelines, Artifacts, Boards, Environments, Git workflows, YAML pipelines, agents, variables, templates, automated testing, artifact publishing, deployments to App Service, Functions, Container Apps and AKS, safe release strategies, approvals, workload identity federation, and azd integration.
Highlighted Topics
- DevOps culture and the purpose of continuous integration and continuous delivery/deployment.
- Azure DevOps overview: Repos, Pipelines, Artifacts, Boards, and Environments.
- Git branches, pull requests, code reviews, and branch policies.
- YAML pipelines.
- Triggers, stages, jobs, steps, variables, templates, artifacts, and conditions.
- Microsoft-hosted versus self-hosted agents.
- Restore, build, unit test, code-quality, and packaging stages for .NET applications.
- Publishing and consuming build artifacts.
- Deploying ASP.NET Core applications to App Service.
- Deploying Azure Functions.
- Building container images and pushing them to ACR.
- Deploying containers to Container Apps or AKS.
- Environment-based deployments and configuration.
- Approvals, environment checks, and protected production releases.
- Safe deployment patterns: App Service slot swaps, Container Apps revision traffic splitting, AKS rolling deployment, and rollback.
- Pipeline identities, service connections, workload identity federation, and secret-minimization practices.
- Hands-on: build a pipeline that tests and deploys a .NET application to a non-production Azure environment.
- Understand how Azure Developer CLI (azd) can complement CI/CD by standardizing application provisioning and deployment workflows.
Chapter 47: Infrastructure as Code with Bicep and Terraform
In this chapter, we will learn how infrastructure as code makes Azure environments repeatable, reviewable, and version-controlled. We will focus on Bicep for Azure-native provisioning, including parameters, variables, resources, modules, outputs, conditions, loops, dependencies, environment parameter files, reusable patterns, Azure Verified Modules awareness, and CI/CD integration, while also introducing Terraform concepts, providers, variables, state, and drift.
Highlighted Topics
- Why infrastructure should be defined and versioned as code.
- Declarative versus imperative provisioning.
- Azure Resource Manager deployment concepts.
- Bicep as the primary Azure-native infrastructure-as-code language.
- Bicep parameters, variables, resources, modules, outputs, conditions, loops, and dependencies.
- Environment parameter files.
- Reusable Bicep modules and Azure Verified Modules awareness.
- Deploying Bicep from Azure CLI and Azure DevOps pipelines.
- Terraform concepts and when organizations choose Terraform for Azure.
- Terraform providers, resources, variables, outputs, and state at a beginner level.
- Environment-specific configuration and reusable infrastructure patterns.
- Managing secrets and sensitive configuration in automated deployments.
- Infrastructure validation and deployment sequencing.
- Repeatable creation of development, test, and production environments.
Chapter 48: Azure Policy and Cloud Governance
In this chapter, we will learn how Azure Policy and related governance controls enforce organizational standards across cloud environments. We will understand policy definitions, assignments, scope, inheritance, initiatives, compliance, remediation, common policy effects, approved regions and resource types, security requirements, naming and tagging governance, resource locks, RBAC boundaries, infrastructure-as-code integration, and governance baselines.
Highlighted Topics
- Why governance is required in cloud environments.
- Azure Policy fundamentals.
- Policy definitions and policy assignments.
- Scope and inheritance.
- Policy initiatives.
- Compliance state and remediation concepts.
- Audit, deny, modify, and deploy-if-not-exists effects at a beginner level.
- Enforcing approved regions, tags, resource types, SKUs, and security configuration.
- Naming and tagging governance.
- Resource locks.
- Azure RBAC versus Azure Policy versus resource locks.
- Governance across management groups, subscriptions, resource groups, and environments.
- Using policy with infrastructure as code and CI/CD.
- Creating a lightweight governance baseline for development, test, and production.
Chapter 49: Azure Data Factory and Data Integration
In this chapter, we will learn how Azure Data Factory orchestrates data movement and transformation workflows. We will understand ETL and ELT, factories, pipelines, activities, datasets, linked services, parameters, triggers, integration runtimes, Copy Activity, Self-hosted Integration Runtime, control-flow activities, incremental loading, Mapping Data Flows, identity and Key Vault integration, private networking, monitoring, Git integration, and CI/CD.
Highlighted Topics
- Data integration, ETL, ELT, batch movement, transformation, and orchestration concepts.
- What Azure Data Factory is and where it fits.
- Data Factory versus Logic Apps and Azure Functions.
- Factories, pipelines, activities, datasets, linked services, parameters, triggers, and integration runtimes.
- Copy Activity for moving data between supported sources and destinations.
- Azure Integration Runtime and Self-hosted Integration Runtime.
- Connecting to on-premises/private data sources.
- Parameters, variables, expressions, and dynamic content.
- Control-flow activities such as ForEach, If Condition, Switch, Until, Wait, and Execute Pipeline.
- Dependencies, failure paths, retries, and reusable pipeline design.
- Schedule, tumbling-window, and supported event-based triggering concepts.
- Incremental-load and watermark patterns.
- Mapping Data Flow concepts at an introductory level.
- Managed identity and Key Vault integration for secure linked services.
- Managed virtual network/private connectivity concepts where required.
- Pipeline and activity monitoring, alerts, reruns, and troubleshooting.
- Git integration and CI/CD for Data Factory artifacts.
- Hands-on: build a parameterized pipeline that copies data and handles failure paths.
Chapter 50: Azure Migration and Application Modernization
In this chapter, we will learn how organizations assess, migrate, and modernize workloads for Azure. We will understand migration strategies, discovery, inventory, dependency mapping, Azure Migrate, server and database migration considerations, common Azure SQL targets, web modernization to App Service, containerization, modernization of background jobs, data movement, security, cutover, rollback, validation, and post-migration optimization.
Highlighted Topics
- Why organizations migrate workloads to Azure.
- Migration versus modernization.
- Common strategies: rehost, replatform, refactor/re-architect, repurchase, retain, and retire.
- Discovery, inventory, dependency mapping, readiness assessment, and migration-wave planning.
- Azure Migrate concepts for discovery, assessment, sizing, and planning.
- Server-migration concepts.
- Database-migration considerations.
- Azure SQL Database and Azure SQL Managed Instance as common SQL migration targets.
- Azure Database Migration Service awareness for supported scenarios.
- Modernizing web applications to App Service.
- Containerizing applications for Container Apps or AKS.
- Moving suitable background jobs to WebJobs, Azure Functions, or Container Apps jobs.
- Moving file/object data with fit-for-purpose tools such as AzCopy, Storage Explorer, and Data Factory.
- Security, networking, downtime, and data-consistency considerations.
- Migration testing, pilot migration, cutover, DNS changes, rollback, and validation.
- Post-migration right-sizing, cost optimization, performance tuning, and monitoring.
- Hands-on architecture exercise: assess a simple three-tier application and propose a target Azure architecture.
Chapter 51: Azure Communication Services (ACS)
In this chapter, we will learn how Azure Communication Services adds communication capabilities to business applications. We will understand communication resources and identities, SDK and REST integration, SMS, email, chat, voice and video concepts, Call Automation, authentication and least privilege, events and monitoring, and integrations with Functions, Logic Apps, Service Bus, Event Grid, APIs, and application monitoring.
Highlighted Topics
- What Azure Communication Services is and where it fits in application development.
- Communication resources and identity concepts.
- SDK and REST API integration approaches.
- SMS concepts, sender/number considerations, delivery status, and regional/compliance awareness.
- Email communication capabilities and application scenarios.
- Chat concepts for in-application messaging.
- Voice and video calling at a high level.
- Call Automation concepts for programmable calling workflows.
- Authentication, credential protection, least privilege, and managed-identity considerations where supported.
- Events and monitoring for communication workflows.
- Integration with Functions, Logic Apps, Service Bus, Event Grid, APIs, and application monitoring.
- Hands-on design exercise: create a communication flow for an order, appointment, or support scenario.
Chapter 52: Microsoft Foundry and Azure AI for Application Developers
In this chapter, we will learn how Azure developers can add generative AI and agent capabilities using Microsoft Foundry. We will understand AI and LLM fundamentals, prompts, tokens, grounding, structured output, hallucinations, responsible AI, model discovery and deployment, .NET integration, tool calling, embeddings, vector search, RAG, Azure AI Search, AI agents, identity and security, prompt-injection risks, observability, cost, and integration with other Azure application services.
Highlighted Topics
- AI, machine learning, generative AI, large language models, embeddings, and AI agents using beginner-friendly examples.
- When deterministic application code is more appropriate than generative AI.
- Prompts, tokens, context windows, inference, grounding, temperature, structured output, and hallucinations.
- Responsible AI, safety, privacy, security, evaluation, and human oversight.
- Microsoft Foundry as the current Azure platform for building AI applications and agents.
- Foundry resources/projects, model catalog/discovery, model deployment, endpoints, and developer workflow.
- Calling models from .NET using supported SDK/API approaches.
- Prompt design, system instructions, structured outputs, and tool/function calling.
- Embeddings and vector-search concepts.
- Retrieval-Augmented Generation (RAG).
- Azure AI Search as a common retrieval component for enterprise knowledge scenarios.
- AI agents: instructions, model, tools, knowledge, memory/state concepts, and actions.
- Using Azure Functions or APIs as tools that an agent can call.
- Microsoft Entra ID, RBAC, managed identity where supported, Key Vault, networking, and data-protection considerations.
- Prompt injection, sensitive-data leakage, and over-permissioned tool risks.
- AI observability: latency, failures, token usage, costs, traces, evaluations, and safety signals.
- Integrating Foundry with App Service, Container Apps, Functions, APIM, Storage, Search, and Azure Monitor.
- Hands-on: build a small AI-enabled .NET application with grounding and monitoring.
Microsoft Certifications You Can Prepare For
This training program covers many of the concepts, Azure services, development practices, and hands-on skills required for current Microsoft Azure certifications. After completing the course, participants can use the knowledge gained here as a strong foundation and continue with exam-specific preparation
1: Microsoft Certified: Azure Fundamentals – AZ-900
- Level: Fundamentals
- Recommended for students, freshers, developers, and professionals beginning their Microsoft Azure journey.
- Covers cloud computing concepts, Azure architecture, compute, networking, storage, security, governance, management, pricing, and monitoring.
- This training program covers these areas extensively during the foundational Azure chapters.
- A good certification to complete before moving toward intermediate Azure certifications.
- Current Status: Active.
- Microsoft currently does not list AZ-900 among certifications scheduled for retirement.
2: Microsoft Certified: Azure AI Fundamentals – AI-901
- Level: Fundamentals
- Recommended for developers and professionals who want to understand Artificial Intelligence and AI solutions on Microsoft Azure.
- Covers AI concepts, responsible AI, machine learning concepts, and implementing AI solutions using Microsoft Foundry.
- Particularly useful for participants interested in the Azure AI and AI-enabled application development portions of this training program.
- Can be taken as an AI foundation certification before progressing toward more advanced AI developer certifications.
- Current Status: Active.
- AI-901 is the current replacement for the retired AI-900 exam.
- Microsoft currently shows no retirement date for AI-901.
3: Microsoft Certified: Azure AI Cloud Developer Associate – AI-200
- Level: Intermediate / Associate
- This is one of the most relevant certifications for developers completing this training program.
- Designed for developers who build and implement cloud and AI-enabled solutions on Microsoft Azure.
- Covers Azure application development, Azure SDKs, data services, messaging and eventing, monitoring, troubleshooting, security, deployment, and other backend cloud-development responsibilities.
- Your syllabus includes many directly related areas such as App Service, Azure Functions, Storage, Azure SQL, Cosmos DB, Service Bus, Event Grid, Event Hubs, monitoring, APIs, containers, security, and cloud integration.
- Particularly suitable for .NET developers moving toward modern Azure cloud-development roles.
- Current Status: Active.
- AI-200 replaced the retired AZ-204: Azure Developer Associate certification.
4: Microsoft Certified: Azure AI Apps and Agents Developer Associate – AI-103
- Level: Intermediate / Associate
- Recommended for participants who want to move deeper into AI application development, Generative AI, AI agents, and Microsoft Foundry.
- Covers planning and managing Azure AI solutions, generative AI, agentic solutions, computer vision, text analysis, and information extraction.
- This training program provides useful Azure and AI foundations for this certification.
- However, participants targeting AI-103 should perform additional AI-specific and Python-based exam preparation, because Microsoft currently expects experience developing AI applications using Python.
- Current Status: Active.
- AI-103 replaced the retired AI-102: Azure AI Engineer Associate certification.
5: Microsoft Certified: Cloud and AI Security Engineer Associate – SC-500
- Level: Intermediate / Associate
- Suitable for participants who want to specialize further in Azure cloud security and AI workload security.
- Covers Microsoft Entra ID, identity and access management, Key Vault, storage security, database security, networking security, compute security, governance, security posture, and AI security.
- Your training program provides a useful foundation through Microsoft Entra ID, MFA, Conditional Access, RBAC, Managed Identities, Key Vault, private networking, Storage, databases, containers, and monitoring.
- Additional security-specific preparation would still be required before taking the SC-500 exam.
- Current Status: Active.
- SC-500 replaced the retired AZ-500: Azure Security Engineer Associate certification.
Important Microsoft Certification Retirement Updates
Microsoft has significantly updated its Azure certification portfolio in 2026, particularly to include more Cloud + AI skills.
AI-900 – Microsoft Certified: Azure AI Fundamentals
- Retired: June 30, 2026
- Replaced by: AI-901 – Microsoft Certified: Azure AI Fundamentals
- Students starting now should prepare for AI-901, not AI-900.
AI-102 – Microsoft Certified: Azure AI Engineer Associate
- Retired: June 30, 2026
- Replaced by: AI-103 – Microsoft Certified: Azure AI Apps and Agents Developer Associate
- The newer certification places greater emphasis on Microsoft Foundry, generative AI, and agentic AI solutions.
AZ-204 – Microsoft Certified: Azure Developer Associate
- Retired: July 31, 2026
- Replaced by: AI-200 – Microsoft Certified: Azure AI Cloud Developer Associate
- This is especially important for your course because AZ-204 was previously the primary certification for Azure application developers.
- Students beginning certification preparation now should focus on AI-200 rather than AZ-204.
AZ-500 – Microsoft Certified: Azure Security Engineer Associate
- Retired: August 31, 2026
- Replaced by: SC-500 – Microsoft Certified: Cloud and AI Security Engineer Associate
- Students interested in Azure security should therefore prepare for SC-500, not AZ-500.
Join Our Learning Community
- 🌐 Website: www.dotnettutorials.net
- ✉️ Email: info@dotnettutorials.net
- 📞 WhatsApp/Call: +91 70218 01173
- 💬 WhatsApp Group: Click here to join
- 📢 Telegram Group: Click here to join
- 📺 YouTube Channel: Click here to join
Enroll Today!
Take the first step towards becoming a Microsoft Azure expert. With our comprehensive training, hands-on projects, interactive sessions, and expert guidance, you’ll gain the skills needed to excel in cloud computing.
Don’t miss this opportunity! Enroll now and embark on a journey to advance your career in the cloud industry.
