Implement Windows Server IaaS VM networking
At a glance
-
Level
-
Skill
-
Subject
In this learning path, you’ll learn about Azure IaaS networking and identity. After completing the learning path, you’ll be able to implement IP addressing, manage DNS, and deploy and manage domain controllers in Azure.
Prerequisites
- Experience with managing Windows Server operating system and Windows Server workloads in on-premises scenarios, including AD DS, DNS, DFS, Hyper-V, and File and Storage Services.
- Experience with common Windows Server management tools (implied by the first prerequisite).
- Basic knowledge of core Microsoft compute, storage, networking, and virtualization technologies (implied by the first prerequisite).
- Basic knowledge of on-premises resiliency Windows Server-based compute and storage technologies (Failover Clustering, Storage Spaces).
- Basic experience with implementing and managing IaaS services in Microsoft Azure.
- Basic knowledge of Microsoft Entra ID.
- Basic understanding security-related technologies (firewalls, encryption, multi-factor authentication, SIEM/SOAR).
- Basic knowledge of PowerShell scripting.
- An understanding of the following concepts as related to Windows Server technologies:
- High Availability and Disaster Recovery
- Automation
- Monitoring
Get started with Azure
Choose the Azure account that's right for you. Pay as you go or try Azure free for up to 30 days. Sign up.
Achievement Code
Would you like to request an achievement code?
Modules in this learning path
This module covers how to implement IP addressing and routing for Windows Server IaaS virtual machines in Azure. You learn how to implement Azure virtual networks (VNets) with subnets and private IP address spaces, configure private and public IP addresses using dynamic and static allocation methods, manage network interfaces and assign IP configurations during VM creation, understand system routes and implement user-defined routes for custom traffic flow between subnets and networks, and implement IPv6 for Azure VNet to support dual-stack networking.
This module covers how to implement DNS for Windows Server IaaS virtual machines in Azure. You learn how to describe Azure DNS including its anycast network, RBAC integration, and current limitations such as the lack of DNSSEC support, configure Azure public DNS zones with delegation and record sets, implement Azure private DNS zones with VNet linking and autoregistration for VM host records, deploy Windows Server DNS in Azure IaaS VMs for AD DS-integrated scenarios, implement split-horizon DNS to serve different records for internal and external clients, and troubleshoot DNS issues in Azure environments.
This module covers how to implement network security for Windows Server IaaS virtual machines in Azure. You learn how to configure network security groups (NSGs) with inbound and outbound security rules, priority-based processing, and default rules, deploy and configure Azure Firewall for centralized network traffic filtering, configure Windows Defender Firewall with Advanced Security for host-level protection, choose the appropriate filtering solution from NSGs, Azure Firewall, and Windows Defender Firewall, and use Azure Network Watcher to capture network traffic and log network flows for diagnostics.