Resource Management - AZ-104¶
π Azure Resource Manager Documentation - Deployment and management service for Azure
Resource Groups¶
π Manage Resource Groups - Organize and manage Azure resources - Logical container for resources - All resources must be in a resource group - Cannot be nested - Resources can be in different regions - Free (no charge)
Lifecycle: - Deleting RG deletes all resources - Move resources between RGs - Lock RG to prevent deletion
Management Groups¶
π Management Groups Overview - Organize subscriptions at scale
- Organize subscriptions
- Hierarchy: Management groups > Subscriptions > Resource groups > Resources
- Apply policies and RBAC at any level
- Up to 6 levels deep
- Inheritance: Policies flow down
Azure Policy¶
π Azure Policy Overview - Enforce organizational standards and assess compliance
- Enforce standards and compliance
- JSON-based policy definitions
- Built-in and custom policies
- Initiatives: Group of policies
Effects:
π Azure Policy Effects - Understand policy enforcement options
- Deny: Block non-compliant resources
- Audit: Log non-compliance
- Append: Add properties
- Modify: Change properties
- DeployIfNotExists: Auto-remediate
Resource Locks¶
π Lock Resources to Prevent Changes - Protect critical resources from accidental changes
- Prevent accidental deletion/modification
- CanNotDelete: Can modify, can't delete
- ReadOnly: Can't modify or delete
- Applies to all child resources
- Override requires removing lock first
Tags¶
π Use Tags to Organize Resources - Apply metadata for organization and billing
- Metadata key-value pairs
- Max 50 tags per resource
- Not inherited by child resources
- Use for cost tracking, automation, organization
Azure Resource Manager (ARM)¶
π ARM Templates Documentation - Implement infrastructure as code with templates
- Deployment and management layer
- Consistent management interface
- Template-based deployments
- Declarative syntax (JSON)
ARM Templates: - Parameters: Input values - Variables: Reusable values - Resources: What to deploy - Outputs: Return values
Bicep¶
π Bicep Documentation - Modern declarative language for Azure resources
- Domain-specific language for ARM
- Simpler syntax than JSON
- Transpiles to ARM JSON
- Better IntelliSense and type safety
Moving Resources¶
π Move Resources to New Resource Group - Move resources between groups and subscriptions
- Within subscription: Same or different RG
- Across subscriptions: Different RG
- Validation before move
- Some resources can't be moved (AKS, App Service with cert)
Exam Tips¶
- Resource groups: Logical grouping, lifecycle management
- Management groups: Multi-subscription organization
- Policies: Enforce compliance
- Locks: Prevent accidents (CanNotDelete common)
- Tags: Cost allocation and organization
- ARM templates: Infrastructure as code
- Bicep: Easier ARM authoring