Advanced Enterprise Architecture Design and Management in Microsoft Azure (AZURE2)
Microsoft, Azure
This course builds on Azure Fundamentals and focuses on designing and operating enterprise-grade architectures in Azure. It covers the Cloud Adoption Framework, practical Landing Zones, advanced networking patterns and security and governance for hybrid and multi‑cloud environments, including subscription design and management groups.
Hands-on labs and workshops emphasize automation, detection and reliability: Bicep and Terraform modules, Microsoft Sentinel (KQL) detections and playbooks, operational reliability with SLO/SLI and runbooks, plus FinOps cost optimization and reference templates for DR/BCP.
Location, current course term
The course:
Hide detail
-
Cloud Adoption Framework & Landing Zones
-
Overview of CAF phases (Strategy, Plan, Ready, Adopt, Govern, Manage)
-
Landing Zone concepts: management groups, subscription design, policy baseline
-
Tools: Azure Landing Zone Accelerator, Terraform modules
-
Advanced Networking
-
Hub‑Spoke, Virtual WAN, ExpressRoute vs. VPN, Azure Firewall, DDoS Protection
-
Private Link vs. Service Endpoints, Private DNS Zones
-
Application Gateway, Front Door, Traffic Manager — global distribution and WAF
-
Security & Compliance
-
Microsoft Defender for Cloud — recommendations, hardening, workload protection
-
Microsoft Sentinel — data connectors, KQL detections, playbooks (Logic Apps)
-
PIM, Conditional Access, Identity Protection
-
Encryption: disk encryption, Key Vault + Managed HSM, CMK scenarios
-
Compliance & audit (Azure Policy, regulatory compliance dashboard)
-
IaC & Automation
-
Bicep vs. Terraform — modules, repo structure, CI/CD pipelines (GitHub Actions/Azure DevOps)
-
Policy-as-Code — testing and deployment in pipelines (OPA/Checkov/Tfsec)
-
Automation Accounts, Functions, Logic Apps for operational tasks
-
Observability, SLO/SLI & Operations
-
Deep dive into Azure Monitor, advanced Log Analytics KQL queries
-
Application Insights distributed tracing
-
Incident response runbooks, alert routing (Teams/Slack/PagerDuty)
-
Cost Management advanced: Savings Plans/Reserved Instances, rightsizing, budgets & showback
-
DR/BCP & Resilience Patterns
-
Geo‑redundant storage, cross‑region failover, Azure Site Recovery
-
Chaos engineering in Azure (Chaos Studio)
-
Runbooks and DR testing
-
Hands‑on / Architecture Workshops
-
Workshop 1: design Landing Zone and policy baseline (practical)
-
Workshop 2: Sentinel detection rule and automated playbook response
-
(Optional) Terraform/Bicep lab: VNet/Hub‑Spoke module and pipeline
-
Assumed knowledge:
-
Basic knowledge of DevOps tools such as Git, CI/CD, Docker/K8s, and Terraform.
-
Recommended previous course:
-
Azure – Platform Fundamentals in Practice (AZURE1)
-
Schedule:
-
2 days (9:00 AM - 5:00 PM )
-
Course price:
-
672.00 € ( 813.12 € incl. 21% VAT)
-
Language:
-