Azure Fundamentals For Cloud
Azure Fundamentals For Cloud
Module 7
| About this course
• This course provides foundational level knowledge on cloud concepts; core Azure
services; security, privacy, compliance, and trust; and Azure pricing and support.
• The audience for this course is just beginning to learn about cloud computing and how
Microsoft Azure provides that service.
• There are no prerequisites for the course, but students with an IT background will find
the concepts easier to understand.
•Module 01 – Cloud concepts
Cloud Concepts
| Module 01 - Outline
▪ Cloud Models
• Public, Private, and Hybrid cloud
• Choosing the best for you
▪ Cloud Benefits and Considerations
• Benefits of the cloud
• Cloud considerations
▪ Cloud Services
• IaaS, PaaS, and SaaS
• Sharing responsibility
| What is cloud computing?
Cloud Computing is the delivery of computing services over the internet, enabling faster
innovation, flexible resources, and economies of scale.
| Economies of scale
• The concept of economies of scale is the ability to reduce costs and gain efficiency when
operating at a larger scale in comparison to operating at a smaller scale.
• Cloud providers are very large businesses and are able to leverage the benefits of
economies of scale, and then pass those benefits on to their customers.
| CapEx vs OpEx
In previous years, startup companies needed to acquire a physical premises and
infrastructure to start their business and begin trading. Large amounts of money were
need to get a new business up and running, or to grow an existing company. They would
have to buy new datacenters or new servers to allow them build out new services, which
they could then deliver to their customers. That is no longer the case.
A public cloud is owned by the cloud services provider (also known as a hosting provider).
It provides resources and services to multiple organizations and users, who connect to
the cloud service via a secure network connection, typically over the internet
● Ownership.
● Hardware.
● Users.
● Connectivity.
● Public access.
● Skills.
| Types of cloud models
Hybrid Cloud
A hybrid cloud combines both public and private clouds, allowing you to run your
applications in the most appropriate location.
Hybrid cloud models have the following characteristics:
● Resource location.
● Cost and efficiency.
● Control.
● Skills.
| Cloud model comparison
Azure Logic Apps is a cloud service that helps you automate and
orchestrate tasks, business processes, and workflows when you
need to integrate apps, data, systems, and services.
| Module 01 Review
Core Services
| Module 02 - Outline
Availability Zone 3
| Azure Resources
Azure resources are components like storage, virtual machines, and networks that are
available to build cloud solutions.
| Resource groups
Resource groups
A resource group is a container to manage (web + DB, VM, Storage) in one group
and aggregate resources in a single unit.
• Resources can exist in only one resource
group.
• Resources can exist in different regions.
• Resources can be moved to different
resource groups.
• Applications can utilize multiple resource
groups.
Web and Virtual
DB machine Storage
resource resource resource
group group group
| Azure Resource Manager
Disk storage provides disks for virtual machines, applications, and other
services to access and use.
Azure Files sets up a highly available network file shares that can be accessed
by using the standard Server Message Block (SMB) protocol.
| Azure storage access tiers
Core Solutions
| Module 03 – Outline
Azure Advisor analyzes deployed Azure resources and makes recommendations based on best
practices to optimize Azure deployments.
• Reliability
• Security
• Performance
• Cost
• Operational Excellence
| Azure Monitor
• Application Insights
• Log Analytics
• Smart Alerts
• Automation Actions
• Customized Dashboards
| Azure Service Health
Evaluate the impact of Azure service issues with personalized guidance and support,
notifications, and issue resolution updates.
| Azure Service Health 2
Azure Service Health provides a personalized view of the health of Azure services and the
regions being used.
• Azure Resource Manager (ARM) templates are JavaScript Object Notation (JSON) files that
can be used to create and deploy Azure infrastructure without having to write programing
commands.
• Declarative syntax
• Repeatable results
• Orchestration
• Modular files
• Built-in validation
• Exportable code
| Module 03 Review
Security
| Module 04 - Outline
Azure Security Center is a monitoring service that provides threat protection across both
Azure and on-premises datacenters.
• Provides security
recommendations
• Detect and block
malware
• Analyze and identify
potential attacks
• Just-in-time access
control for ports
| Azure Security Center - capabilities
Policy Compliance
Threat Protection
Azure Dedicated Host provides physical servers that host one or more Azure virtual machines that
is dedicated to a single organization’s workload.
Benefits
• Hardware isolation at the server level
• Control over maintenance event timing
• Aligned with Azure Hybrid Use Benefits
| Defense in depth
Compute
Application
Data
| Shared Security
• Set inbound and outbound rules to filter by source and destination IP address, port,
and protocol.
• Add multiple rules, as needed, within subscription limits.
• Azure applies default, baseline security rules to new NSGs.
• Override default rules with new, higher priority rules.
| Azure Firewall
A stateful, managed Firewall as a Service (FaaS) that grants/denies server access based on
originating IP address, in order to protect network resources.
• Applies inbound and outbound traffic filtering rules
• Built-in high availability
• Unrestricted cloud scalability
• Uses Azure Monitor logging
DDoS attacks overwhelm and exhaust network resources, making apps slow
or unresponsive.
• Sanitizes unwanted network traffic before it impacts service availability.
• Basic service tier is automatically enabled in Azure.
• Standard service tier adds mitigation capabilities that are tuned to protect Azure Virtual Network
resources.
| Module 4 Review
Identity, governance,
privacy, and
compliance
| Module 05 - Outline
Provides additional security for your identities by requiring two or more elements for full
authentication.
Azure
subscription
User Apps User groups
Resource group
Resource group
| Resource locks
• Protect your Azure resources from accidental deletion or modification.
• Manage locks at subscription, resource group, or individual resource levels within Azure
Portal.
owner: joe
department: marketing cost-center: marketing
environment: production
| Azure Policy
Azure Policy helps to enforce organizational standards and to assess compliance at-scale. Provides
governance and resource consistency with regulatory compliance, security, cost, and management.
Azure Blueprints makes it possible for development teams to rapidly build and stand up new
environments. Development teams can quickly build trust through organizational compliance
with a set of built-in components (such as networking) in order to speed up development and
delivery.
• Role Assignments
• Policy Assignments
• Azure Resource Manager Templates
• Resource Groups
| Cloud Adoption Framework
• The One Microsoft approach to cloud adoption in Azure.
• Best practices from Microsoft employees, partners, and customers.
• Tools, guidance, and narratives for strategies and outcomes.
| Security, Privacy, and Compliance
CJIS HIPAA
Criminal Justice Information Services Health Insurance Portability and Accountability Act
NIST
EU Model Clauses
National Institute of Standards and Technology
| Microsoft privacy statement
The Microsoft privacy statement provides openness and honesty about how Microsoft handles the
user data collected from its products and services.
Online Services Terms: The licensing terms define the terms and conditions for the
products and Online Services you purchase through Microsoft Volume Licensing
programs.
Data Protection Addendum: The DPA sets forth the obligations, with respect to the
processing and security of Customer Data and Personal Data, in connection with the
Online Services.
| Trust Center
Learn about security, privacy, compliance, policies, features, and practices across Microsoft’s cloud
products.
Meets the security and compliance needs of US federal agencies, state and local governments, and
their solution providers.
Azure Government:
• Separate instance of Azure.
• Physically isolated from non-US government deployments.
• Accessible only to screened, authorized personnel.
Examples of compliant standards : FedRAMP, NIST 800.171 (DIB), ITAR, IRS 1075, DoD L2, L4 &
L5, and CJIS.
| Azure Sovereign Regions (Azure China)
Microsoft is China’s first foreign public cloud service provider, in compliance with government
regulations.
Azure pricing
and lifecycle
| Module 06 - Outline
The Pricing Calculator is a tool that helps you estimate the cost of Azure products. The options that
you can configure in the Pricing Calculator vary between products, but basic configuration options
include:
• Region
• Tier
• Billing options
• Support options
• Programs and offers
• Azure dev/test pricing
| Total Cost of Ownership Calculator
Perform Perform cost analyses. Use the Azure Pricing and TCO calculators.
Use Use spending limits. Use via free trial customers and some credit-based Azure subscriptions.
Choose Choose low-cost locations and regions. If possible, use low-cost locations.
Keep Keep up-to-date with the latest Azure customer and subscription offers.
Apply Apply tags to identify cost owners. Identify usage owners with tags.
| SLAs for Azure products and services
Downtime
• Performance targets are expressed as SLA
per month
uptime and connectivity guarantees.
99% 7h 18m 17s
• Performance-targets range from 99% to
99.999%. 99.5% 3h 39m 8s
• If a service fails to meet the guarantees, a 99.9% 43m 49s
percentage of the monthly service fees can
be credited. 99.95% 21m 54s
99.99% 4m 22s
99.999% 26s
| Actions that affect SLAs
Many factors can raise or lower your SLA. Design decisions based on business goals will
drive your SLA goals.
| Azure Preview Program
• With Azure previews, users can test beta and other
pre-release features, products, services, software,
and regions to provide feedback.