A team at Razorpay spins up a virtual machine, assigns everyone Owner access "to keep things simple," and six months later nobody can explain who created which resource or why the monthly bill tripled. This pillar covers the foundational structure every other Azure skill depends on - the Portal and CLI, the resource hierarchy, access control, and the governance tools that turn a chaotic subscription into a well-managed one.
What This Pillar Covers
- Navigating the Azure Portal, CLI, PowerShell, and Cloud Shell for daily administration
- Understanding the Management Group, Subscription, Resource Group, and Resource hierarchy
- Configuring Role-Based Access Control (RBAC) with the correct principal, role, and scope
- Enforcing compliance automatically with Azure Policy and Initiatives
- Setting up Azure Cost Management budgets and alerts before overspending happens
- Deploying resources declaratively with ARM templates instead of manual clicks
- Using Azure Advisor and Secure Score to catch misconfigurations proactively
Who This Is For
Cloud administrators, DevOps engineers, and IT professionals responsible for organizing Azure subscriptions, controlling who can access what, and keeping cloud spend predictable across growing engineering teams.
Why This Matters in Production
At a fast-growing fintech like Zerodha, a single overly broad RBAC assignment can let a contractor delete production infrastructure by accident. Without Azure Policy enforcing tagging and region restrictions, cost allocation becomes guesswork and compliance audits become weeks-long manual investigations. Getting governance right from day one is far cheaper than untangling it after fifty engineers have already created a thousand ungoverned resources.
Prerequisites
- Basic familiarity with command-line tools (Bash or PowerShell)
- General understanding of cloud computing concepts (IaaS, PaaS, SaaS)
- An Azure Free Tier account for hands-on practice