Enterprise Azure Terraform Lab Phase 2C Part 4: Monitoring, KQL Queries, and Cleanup
Completing the SC-300 identity governance lab with Microsoft Entra diagnostic settings, Log Analytics integration, KQL query examples, and cleanup of temporary governance objects.
Enterprise Azure Terraform Lab Phase 2C Part 3: Identity Governance Lifecycle with Access Packages, Terms of Use, Access Reviews, and PIM
Building an SC-300 identity governance lifecycle using Microsoft Entra Entitlement Management, access packages, Terms of Use, Access Reviews, and Privileged Identity Management.
Enterprise Azure Terraform Lab Phase 2C Part 2: Identity Risk and External Access Boundary
Reviewing Microsoft Entra ID Protection, risky users, risky sign-ins, B2B guest access, external collaboration settings, and cross-tenant access controls for an SC-300 identity governance lab.
Enterprise Azure Terraform Lab Phase 2C Part 1: Scoped Administration and Authentication Baseline
Building the Microsoft Entra ID governance baseline for an SC-300 lab with administrative units, scoped role assignments, custom security attribute review, device identity review, scoped passkey/FIDO2 authentication, SSPR, password protection, and Conditional Access session controls.
SC-300 Phase 2 Part B: Converting My Microsoft Entra ID Lab into Terraform
A brownfield Terraform adoption walkthrough for an existing Microsoft Entra ID and Azure App Service identity lab, covering imported Entra groups, App Registration, Enterprise Application, App Roles, Azure RBAC, Managed Identity, Key Vault access, Terraform drift, import errors, and safe IaC migration.
Enterprise Azure Terraform Lab Phase 2B: Authorization and Secure Resource Access
Extending the SC-300 Azure identity lab with app roles, role-aware dashboard evidence, Azure RBAC, Conditional Access, Managed Identity, Key Vault RBAC, and Key Vault references.
Enterprise Azure Terraform Lab Phase 2A: Identity Access Foundation
Building the Microsoft Entra ID identity foundation for an Azure App Service lab with security groups, app registration, API permissions, Enterprise Application assignment, and App Service Authentication.
Enterprise Azure Terraform Lab Phase 1.5 Part 2 : Private Endpoint and Defender for Cloud Demo
Demonstrating optional production-style Azure security controls with Key Vault Private Endpoint, Private DNS integration, CLI validation, and a short Microsoft Defender for Cloud paid-plan demo.
Enterprise Azure Terraform Lab Phase 1.5 Part 1 : Security Baseline Hardening
Hardening a low-cost Azure Terraform lab with secure Storage Account settings, App Service security controls, Managed Identity, Key Vault, diagnostic settings, and Azure Policy as Code.
Enterprise Azure Terraform Lab Phase 1 Part 6 : RBAC, Scripts, Troubleshooting, and Cleanup
Finishing the AZ-104 Terraform lab with group-based Azure RBAC, local deployment scripts, troubleshooting notes, screenshot evidence, and clean destroy discipline.
Enterprise Azure Terraform Lab Phase 1 Part 5 : Scaling, Deployment Slots, Diagnostics, and Budget Alerts
Documenting Azure App Service scaling, deployment slot strategy, diagnostic settings, and Resource Group budget alerts in a cost-controlled AZ-104 Terraform lab.
Enterprise Azure Terraform Lab Phase 1 Part 4 : App Service and React Deployment
Deploying a React Vite dashboard to Azure App Service while keeping Terraform responsible for the platform and zip deploy responsible for the application artifact.
Enterprise Azure Terraform Lab Phase 1 Part 3 : Network, Storage, and Monitoring Baseline
Designing a low-cost Azure network security and monitoring baseline with VNet segmentation, NSG rules, secure Storage Account settings, and Log Analytics.
Enterprise Azure Terraform Lab Phase 1 Part 2: Terraform Variables and Locals Explained
A note-style explanation of Terraform basics, input variables, locals, naming patterns, and why generic-input-variables.tf and locals.tf matter in an Azure infrastructure lab.
Enterprise Azure Terraform Lab Phase 1 Part 1: Foundation and Remote State
Building the foundation of an AZ-104 style Azure Terraform lab with remote state, lifecycle boundaries, naming, tags, and cost-aware design.
Project 1 - Part 5 - Cloudflare Security and Edge Protection
Configuring practical Cloudflare security settings for the site, including SSL/TLS mode, HTTPS enforcement, bot protection, country rules, and API rate limiting.
Project 1 - Part 4 - DNS Setup with Azure Static Web Apps and Cloudflare
Connecting Azure Static Web Apps to a custom domain through Cloudflare DNS, validating the custom domain in Azure, and moving the live hostname behind Cloudflare proxying.
Project 1 - Part 3 - Azure Budget Setup and Cost Control
Creating a small Azure budget for the resource group, configuring alert thresholds, and adding a basic cost-control layer to the project.
Project 1 - Part 2 - Custom Domain, HTTPS, and Cloudflare Integration
Connecting Azure Static Web Apps to a custom domain, enabling HTTPS, and adding Cloudflare for DNS, routing, and basic edge security.
Project 1 - Part 1 - Feature Branch, Pull Request, and Azure Static Web Apps CI/CD
Creating a feature branch, opening a Pull Request, and validating deployment through Azure Static Web Apps GitHub Actions.
Building This Website with Azure Static Web Apps, AZ-104 Knowledge, and DevOps
Building and deploying a portfolio website using Azure Static Web Apps, GitHub, Cloudflare, and a practical DevOps workflow.