An engineer at a growing startup opens RDP directly to the internet on a production VM "just to finish a quick fix," and within days automated scanners have found the open port and are attempting brute-force logins. This pillar covers the networking primitives that determine whether an Azure environment is secure and performant, or quietly exposed - virtual networks, security groups, load balancing, and the hybrid connectivity options that link Azure back to an on-premises datacenter.
What This Pillar Covers
- Designing Virtual Networks and Subnets with CIDR ranges that won't need to be rebuilt later
- Securing VMs and subnets with Network Security Group inbound and outbound rules
- Accessing VMs securely through Azure Bastion instead of exposing RDP or SSH to the internet
- Choosing between Azure Load Balancer (Layer 4) and Application Gateway (Layer 7) correctly
- Choosing between Traffic Manager and Azure Front Door for multi-region traffic distribution
- Choosing between VPN Gateway and ExpressRoute for connecting to an on-premises network
- Caching static content globally with Azure CDN to reduce latency and origin load
Who This Is For
Cloud administrators, network engineers, and DevOps engineers responsible for designing secure network architectures, routing application traffic correctly, and connecting Azure environments to on-premises infrastructure.
Why This Matters in Production
At a food delivery platform like Swiggy, a single misconfigured Network Security Group rule during peak dinner-hour traffic can silently block legitimate customer requests for minutes before anyone notices. Choosing Azure Load Balancer when the actual requirement was path-based HTTP routing means rebuilding the entire traffic layer later - understanding the real distinction between Layer 4 and Layer 7 routing from the start avoids that rework entirely.
Prerequisites
- Completion of Azure Fundamentals and Governance, or equivalent familiarity with Resource Groups and RBAC
- Understanding of core networking concepts - IP addressing, CIDR notation, DNS, and TCP/IP
- Basic familiarity with firewall concepts is helpful for the NSG topics