CLI Basics
az login
az account list --output table
az account set --subscription "Production"
az group create --name app-rg --location westeurope
az resource list --resource-group app-rg -o table
az group delete --name app-rg --yes # deletes everything in it
Resource Hierarchy
| Level | Role |
|---|---|
| Management Group | Policy across subscriptions |
| Subscription | Billing + quota boundary |
| Resource Group | Lifecycle container |
| Resource | Single service instance |
Entra ID & RBAC
az role assignment create --assignee user@contoso.com \
--role "Contributor" \
--scope /subscriptions/<sub>/resourceGroups/app-rg
az role assignment list --resource-group app-rg -o table
| Role | Grants |
|---|---|
| Owner | Full + can grant access |
| Contributor | Manage resources, no role assign |
| Reader | View only |
Assign role to principal at a scope. Use the narrowest scope.
Compute
az vm create -g app-rg -n web-1 --image Ubuntu2404 \
--size Standard_B2s --admin-username azureuser --generate-ssh-keys
az vm open-port -g app-rg -n web-1 --port 443
az vm list -g app-rg -o table
az vm start|stop|deallocate -g app-rg -n web-1
az webapp up --name my-app -g app-rg --runtime "NODE:20-lts" --sku B1
az functionapp create ... # serverless FaaS
VMs = IaaS · App Service = PaaS · Functions = FaaS · AKS = managed K8s.
Storage
az storage account create -n acct2026 -g app-rg \
--sku Standard_LRS --kind StorageV2 --min-tls-version TLS1_2
az storage container create -n assets --account-name acct2026 --auth-mode login
az storage blob upload --account-name acct2026 -c assets \
-n logo.png -f ./logo.png --auth-mode login
| Redundancy | Copies |
|---|---|
| LRS | 3x in one data center |
| ZRS | Across Availability Zones |
| GRS | Replicated to paired region |
Blob tiers: Hot · Cool · Cold · Archive.
Networking
az network vnet create -g app-rg -n app-vnet \
--address-prefix 10.0.0.0/16 --subnet-name web --subnet-prefix 10.0.1.0/24
az network nsg create -g app-rg -n web-nsg
az network nsg rule create -g app-rg --nsg-name web-nsg -n AllowHTTPS \
--priority 100 --protocol Tcp --destination-port-ranges 443 \
--access Allow --direction Inbound
VNet = network · NSG = firewall rules · Load Balancer (L4) · App Gateway (L7 + WAF).
Azure ↔ AWS
| Azure | AWS |
|---|---|
| Virtual Machines | EC2 |
| Blob Storage | S3 |
| App Service | Elastic Beanstalk |
| Azure Functions | Lambda |
| Cosmos DB | DynamoDB |
| Entra ID | IAM |
| AKS | EKS |