Az 104t00a Enu Powerpoint 02
Az 104t00a Enu Powerpoint 02
Az 104t00a Enu Powerpoint 02
Azure Subscriptions
Getting a Subscription
Resource Tags
Cost Savings
Review
© Copyright Microsoft Corporation. All rights reserved.
Regions
Subscription Usage
Includes a $200 credit for the first 30 days, free limited access for
Free
12 months
Create a budget
Review recommendations
Azure Policy
Policy Definitions
Azure Policy
Create Initiative Definitions
Overview
Scope the Initiative Definition
Determine Compliance
Review
© Copyright Microsoft Corporation. All rights reserved.
Management Groups
Usage Cases
A service to create, assign, and Allowed resource types – Specify the resource types that
manage policies your organization can deploy
Advantages: Require tag and its value – Enforces a required tag and
its value
Enforcement and compliance
Apply policies at scale Azure Backup should be enabled for Virtual Machines –
Audit if Azure Backup service is enabled for all Virtual
Remediation machines
Requires planning
Assign a policy
Role Definition
Role Assignment
Review
© Copyright Microsoft Corporation. All rights reserved.
Role-Based Access Control
Role information can be accessed in the Azure Role information can be accessed in Azure portal,
portal, Azure CLI, Azure PowerShell, Azure Microsoft 365 admin portal, Microsoft Graph,
Resource Manager templates, REST API Azure Active Directory PowerShell for Graph
User Access Manages user access to This applies to managing access, rather
Administrator Azure resources than to managing resources
Lab scenario
To improve management of Azure resources in Contoso, you have been tasked with implementing
the following functionality:
• Tagging resource groups that include only infrastructure resources
• Ensuring that only properly tagged infrastructure resources can be added to infrastructure
resource groups
• Remediating any non-compliant resources
Objectives
Task 1: Task 2: Task 3:
Create and assign tags via Enforce tagging via an Apply tagging via an
the Azure portal Azure Policy Azure Policy
Task 1
Name: Role
Value: Infra Task 2
Azure policy
Cloud Shell Storage Require a tag and its value on resources
Resource Group
Task 3
Azure policy
Inherit a tag from the resource group if
New Storage Account missing