What Is Microsoft Azure?
Azure is Microsoft's public cloud platform, offering IaaS, PaaS, and SaaS services across data centers in more than 60 regions worldwide. It integrates tightly with Microsoft 365, Windows Server, SQL Server, and Microsoft Entra ID (formerly Azure Active Directory), which makes it the default cloud for many enterprises already invested in Microsoft tooling.
You interact with Azure through the Azure portal (web UI), the az Azure CLI, Azure PowerShell, or infrastructure-as-code tools such as Bicep and Terraform.
The Resource Hierarchy
Azure organizes everything into a four-level hierarchy. Understanding it is the single most important concept for a beginner, because billing, policy, and access control all flow down through it.
| Level | Purpose |
|---|---|
| Management Group | Governs many subscriptions; apply policy org-wide |
| Subscription | Billing + quota boundary |
| Resource Group | Logical container for related resources with a shared lifecycle |
| Resource | An individual service instance (VM, storage account, DB) |
A resource group holds resources that share a lifecycle — you typically deploy, update, and delete them together. Every resource lives in exactly one resource group and one region.
# Sign in and pick a subscription
az login
az account set --subscription "Production"
# Create a resource group in West Europe
az group create --name app-rg --location westeurope
# List everything inside it
az resource list --resource-group app-rg --output table
Group by lifecycle, not by type
Put resources that live and die together in one resource group (e.g. all of "app-staging"). Deleting the group deletes everything in it, which makes teardown of a whole environment a single command.
Microsoft Entra ID and RBAC
Microsoft Entra ID is Azure's identity provider: it holds users, groups, and service principals (app identities). Authorization is handled by Azure RBAC (role-based access control), where you assign a role (a set of permissions) to a principal at a scope (management group, subscription, resource group, or single resource).
| Built-in role | Grants |
|---|---|
| Owner | Full access, including granting access to others |
| Contributor | Create/manage resources, but not assign roles |
| Reader | View only |
| User Access Administrator | Manage access to resources |
# Grant a user Contributor on one resource group (least privilege scope)
az role assignment create \
--assignee jane@contoso.com \
--role "Contributor" \
--scope /subscriptions/<sub-id>/resourceGroups/app-rg
Core Compute Services
- Virtual Machines — IaaS VMs (Linux or Windows), full OS control.
- Virtual Machine Scale Sets — identical VMs that autoscale behind a load balancer.
- App Service — PaaS web app/API hosting with built-in scaling and deployment slots.
- Azure Functions — serverless, event-driven functions (FaaS).
- Azure Kubernetes Service (AKS) — managed Kubernetes.
- Container Apps — serverless containers built on Kubernetes and Dapr.
# Create a small Linux VM with SSH keys generated automatically
az vm create \
--resource-group app-rg \
--name web-1 \
--image Ubuntu2404 \
--size Standard_B2s \
--admin-username azureuser \
--generate-ssh-keys
# Open port 443
az vm open-port --resource-group app-rg --name web-1 --port 443
# Deploy a PaaS web app instead (no VM to manage)
az webapp up --name my-web-app --resource-group app-rg \
--runtime "NODE:20-lts" --sku B1
Storage and Databases
The Storage Account is the umbrella resource for Azure Storage; inside it you get Blob (object storage, like S3), File (SMB/NFS shares), Queue, and Table storage. Blobs come in access tiers: Hot, Cool, Cold, and Archive.
For databases, Azure SQL Database is managed SQL Server, Azure Database for PostgreSQL / MySQL covers open-source engines, and Azure Cosmos DB is a globally distributed multi-model NoSQL database.
# Create a storage account and a blob container
az storage account create --name mystorageacct2026 \
--resource-group app-rg --location westeurope \
--sku Standard_LRS --kind StorageV2 --min-tls-version TLS1_2
az storage container create --name assets \
--account-name mystorageacct2026 --auth-mode login
# Upload a file
az storage blob upload --account-name mystorageacct2026 \
--container-name assets --name logo.png --file ./logo.png --auth-mode login
Redundancy suffixes
LRS keeps 3 copies in one data center, ZRS spreads them across Availability Zones, and GRS replicates to a paired region hundreds of miles away for disaster recovery. Pick based on how much you can afford to lose.
Networking
A Virtual Network (VNet) is Azure's isolated network, divided into subnets. Traffic is filtered by Network Security Groups (NSGs) — the rough equivalent of AWS security groups + NACLs combined. Load balancing is provided by the Azure Load Balancer (L4) and Application Gateway (L7, with WAF).
az network vnet create --resource-group app-rg --name app-vnet \
--address-prefix 10.0.0.0/16 \
--subnet-name web --subnet-prefix 10.0.1.0/24
az network nsg create --resource-group app-rg --name web-nsg
az network nsg rule create --resource-group app-rg --nsg-name web-nsg \
--name AllowHTTPS --priority 100 --protocol Tcp \
--destination-port-ranges 443 --access Allow --direction Inbound
Azure vs AWS Service Names
| Category | Azure | AWS | GCP |
|---|---|---|---|
| VMs | Virtual Machines | EC2 | Compute Engine |
| Object storage | Blob Storage | S3 | Cloud Storage |
| PaaS web hosting | App Service | Elastic Beanstalk | App Engine |
| Serverless functions | Azure Functions | Lambda | Cloud Run functions |
| NoSQL | Cosmos DB | DynamoDB | Firestore |
| Identity | Entra ID | IAM | Cloud IAM |
Practice Exercises
- Draw the four levels of the Azure resource hierarchy from top to bottom and state which level is the billing boundary.
- Grant a colleague the ability to create and manage resources in one resource group but not to hand out access to others. Which built-in role do you assign, and at what scope?
- You need a public website with no servers to patch. Would you choose a Virtual Machine or App Service, and why?
- Explain the difference between the
LRS,ZRS, andGRSstorage redundancy options. - Write the
azcommands to create a VNet with one subnet and an NSG rule that allows inbound HTTPS. - Match these Azure services to their AWS equivalents: Blob Storage, Cosmos DB, Azure Functions, and Entra ID.