This is an example of a simple banner

Training: Design and Implement Microsoft Azure Network Solutions (AZ-700)

Ref. AZ-700T00
Duration:
3
 days
Exam:
Optionnel
Level:
Intermediate

Design and Implement Microsoft Azure Network Solutions training (AZ-700)

Cloud network infrastructure represents a strategic pillar for businesses today. Indeed, mastering Microsoft Azure network solutions becomes essential to ensure performance and security. This AZ-700 training enables you to acquire the technical skills necessary to design and manage complex network architectures.

Complete Azure network expertise

This training directly prepares for the AZ-700 certification. It is structured around practical and progressive modules. This course covers the entire spectrum of Microsoft Azure network solutions. You will learn to deploy robust and scalable infrastructures. Moreover, you will master hybrid connectivity between your on-premise environments and the cloud. VPN connections, ExpressRoute, and Virtual WAN will hold no secrets for you. Additionally, you will develop skills in load balancing and advanced routing.

Participant Profiles

  • Network engineers and system administrators
  • Cloud solution architects
  • IT professionals in charge of infrastructures
  • Digital transformation consultants
  • Technicians looking to specialize in Azure

Objectives

  • Design and deploy Azure virtual networks
  • Implement secure hybrid connections
  • Configure Azure ExpressRoute for dedicated connectivity
  • Master HTTP(S) and non-HTTP(S) load balancing
  • Deploy advanced network security solutions
  • Configure private access to Azure services
  • Implement monitoring with Azure Monitor and Network Watcher

Prerequisites

  • Basic knowledge of computer networks (TCP/IP, DNS, routing)
  • Familiarity with virtualization and cloud computing concepts
  • General understanding of the Microsoft Azure ecosystem

Course Content

Module 1: Introduction to Azure virtual networks

  • Discover Azure virtual networks
  • Configure public IP services
  • Design name resolution for your virtual network
  • Enable connectivity between virtual networks with peering
  • Implement virtual network traffic routing
  • Configure Internet access with Azure Virtual NAT

Module 2: Design and implement a hybrid network

  • Design and implement an Azure VPN Gateway
  • Connect networks with site-to-site VPN connections
  • Connect devices to networks with point-to-site VPN connections
  • Connect remote resources using Azure Virtual WAN
  • Create a network virtual appliance in a virtual hub

Module 3: Design and implement Azure ExpressRoute

  • Explore Azure ExpressRoute
  • Design an ExpressRoute deployment
  • Configure peering for an ExpressRoute deployment
  • Design an ExpressRoute circuit for resilience
  • Connect geographically dispersed networks with ExpressRoute Global Reach
  • Improve data path performance between networks with ExpressRoute FastPath
  • Troubleshoot ExpressRoute connectivity issues

Module 4: Load balancing non-HTTP(S) traffic in Azure

  • Explore load balancing
  • Design and implement Azure Load Balancer using the Azure portal
  • Explore Azure Traffic Manager

Module 5: Load balancing HTTP(S) traffic in Azure

  • Design Azure Application Gateway
  • Configure Azure Application Gateway
  • Design and configure Azure Front Door

Module 6: Design and implement network security

  • Get network security recommendations with Microsoft Defender for Cloud
  • Deploy Azure DDoS Protection using the Azure portal
  • Deploy network security groups using the Azure portal
  • Design and implement Azure Firewall
  • Secure your networks with Azure Firewall Manager
  • Implement a web application firewall

Module 7: Design and implement private access to Azure services

  • Explain virtual network service endpoints
  • Define Private Link service and private endpoint
  • Integrate a private endpoint with DNS (Domain Name Service)

Module 8: Design and implement network monitoring

  • Monitor your networks using Azure Monitor
  • Monitor your networks using Azure Network Watcher

Documentation

  • Access to Microsoft Learn, Microsoft’s online learning platform, offering interactive resources and educational content to deepen your knowledge and develop your technical skills.

Lab / Exercises

  • This course provides you with exclusive access to the official Microsoft lab, enabling you to practice your skills in a professional environment.

Exam

  • This course prepares for the AZ-700 exam: Azure Network Engineer Associate

Complementary Courses

Eligible Funding

ITTA is a partner of a continuing education fund dedicated to temporary workers. This fund can subsidize your training, provided that you are subject to the “Service Provision” collective labor agreement (CCT) and meet certain conditions, including having worked at least 88 hours in the past 12 months.

Additional Information

The evolution of network architectures in the cloud computing era

Traditional network infrastructures are reaching their limits in the face of current requirements. Indeed, scalability, flexibility, and security are becoming business imperatives. Microsoft Azure offers a modern approach that radically transforms enterprise network management. This evolution concerns not only technology but also the professional skills required.

Network Engineers must now master two complementary worlds. On one hand, networking fundamentals remain essential to understand flows and protocols. On the other, cloud services introduce new paradigms such as software-defined networking. This duality represents both a challenge and a career opportunity. Professionals capable of navigating between these two worlds are particularly sought after.

The challenges of hybrid connectivity in enterprise

Few organizations migrate entirely to the cloud overnight. Reality imposes a prolonged coexistence between existing infrastructures and new cloud resources. This transition generates complex issues of connectivity, latency, and security. Site-to-site VPN solutions offer an accessible first approach to establish these technological bridges.

However, bandwidth and reliability needs evolve rapidly. ExpressRoute meets these requirements by providing dedicated private connections to Azure. This technology bypasses the public Internet to guarantee predictable and consistent performance. Financial, healthcare, or government organizations favor this approach for their sensitive data. The higher initial cost is justified by risk reduction and improved user experience.

Azure Virtual WAN represents a major evolution for multi-site enterprises. This solution centralizes connectivity management on a global scale. It drastically simplifies architectures that previously required complex configurations. Network administrators save valuable time on daily operations. Moreover, native integration with other Azure services facilitates overall orchestration.

Advanced strategies for application traffic distribution

The performance of modern applications directly depends on intelligent traffic distribution. A simple load balancer is no longer sufficient to meet user expectations. Azure offers a complete range of tools adapted to different business contexts. Understanding the nuances between these solutions allows for significant architecture optimization.

Azure Load Balancer excels in TCP and UDP traffic distribution. It offers exceptional availability with a 99.99% SLA for redundant configurations. This solution is perfectly suited to classic n-tier applications requiring simple distribution. Its rapid deployment and attractive pricing make it a popular choice.

For sophisticated web applications, Application Gateway brings layer 7 functionalities. URL-based routing allows intelligent direction of requests to different backends. Web Application Firewall integration protects against common OWASP attacks. This security-performance combination meets the needs of critical applications. SSL certificates can be managed centrally to simplify administration.

Azure Front Door adds a global dimension to your distribution strategy. This integrated CDN solution accelerates content delivery on a planetary scale. Users are automatically routed to the nearest point of presence. This optimization significantly reduces perceived latencies. International companies find an immediate competitive advantage.

Network security as the foundation of digital trust

Cyberattacks are continuously becoming more sophisticated and particularly target network infrastructures. A multilayer defensive approach becomes essential to effectively protect digital assets. Microsoft Azure integrates security mechanisms at every infrastructure level. This “security by design” philosophy facilitates the implementation of best practices.

Network Security Groups constitute the first line of granular defense. They function as distributed firewalls associated with network interfaces or subnets. This approach allows fine control of inbound and outbound flows. Creating effective rules requires a thorough understanding of application needs. Overly permissive configurations unnecessarily expose infrastructure to risks.

Azure Firewall centralizes protection at the entire organization level. This managed solution scales automatically according to needs without manual intervention. Application rules allow FQDN traffic filtering with TLS inspection. Integration with Threat Intelligence automatically blocks known malicious IP addresses. This automation reduces operational burden while strengthening security posture.

DDoS protection deserves particular attention in the current context. Denial-of-service attacks can instantly paralyze critical services. Azure DDoS Protection Standard offers adaptive mitigation against these volumetric threats. The service analyzes traffic patterns in real-time to distinguish legitimate activity from attacks. This rapid response capability minimizes the impact on service availability.

The crucial importance of proactive monitoring

An invisible network remains an uncontrollable and potentially vulnerable network. Complete observability is a prerequisite for maintaining high service levels. Azure Monitor and Network Watcher provide the necessary tools for this continuous visibility. These platforms collect terabytes of telemetry data daily.

Defining relevant alerts represents a subtle art requiring experience and judgment. Too many alerts generate fatigue and dangerous blind spots. Conversely, overly tolerant thresholds delay the detection of real incidents. Progressive adjustment based on history allows for refining this configuration. Mature teams implement automated runbooks for recurring scenarios.

FAQ

What is the difference between VPN Gateway and ExpressRoute?

VPN Gateway uses the public Internet with encryption to connect your sites. ExpressRoute establishes a dedicated private connection without going through the Internet. ExpressRoute offers superior performance but costs more. The choice depends on your latency, security, and budget constraints.

How to choose between Azure Load Balancer and Application Gateway?

Azure Load Balancer operates at the transport level for all TCP/UDP traffic. Application Gateway operates at the application level specifically for HTTP/HTTPS. If you need URL-based routing or SSL offloading, choose Application Gateway. For simple network load distribution, Load Balancer is sufficient.

Can multiple load balancing solutions be combined?

Absolutely, Microsoft even recommends this approach for certain complex scenarios. For example, Front Door can route to regional Application Gateways. These then distribute to internal Load Balancers. This multilayer architecture optimizes performance and resilience simultaneously.

Is Azure Private Link compatible with all Azure services?

Private Link supports the majority of popular PaaS services such as Storage, SQL Database, Key Vault. The list is regularly enriched with new service versions. Consult the official documentation to verify specific compatibility. Some services offer service endpoints as an alternative.

Prix de l'inscription
CHF 2'350.-
Inclus dans ce cours
  • Training provided by a certified trainer
  • 180 days of access to Official Microsoft Labs
  • Official documentation in digital format
  • Official Microsoft achievement badge
Mois actuel

lun08Déc(Déc 8)09:00mer10(Déc 10)17:00VirtuelVirtual Etiquettes de sessionAZ-700T00

lun08Déc(Déc 8)09:00mer10(Déc 10)17:00Genève, Route des Jeunes 35, 1227 Genève Etiquettes de sessionAZ-700T00

lun05Jan(Jan 5)09:00mer07(Jan 7)17:00VirtuelVirtual Etiquettes de sessionAZ-700T00

lun05Jan(Jan 5)09:00mer07(Jan 7)17:00Genève, Route des Jeunes 35, 1227 Genève Etiquettes de sessionAZ-700T00

lun02Fév(Fév 2)09:00mer04(Fév 4)17:00VirtuelVirtual Etiquettes de sessionAZ-700T00

lun02Fév(Fév 2)09:00mer04(Fév 4)17:00Lausanne, Av. Mon-Repos 24, 1005 Lausanne Etiquettes de sessionAZ-700T00

lun09Mar(Mar 9)09:00mer11(Mar 11)17:00VirtuelVirtual Etiquettes de sessionAZ-700T00

lun09Mar(Mar 9)09:00mer11(Mar 11)17:00Genève, Route des Jeunes 35, 1227 Genève Etiquettes de sessionAZ-700T00

lun13Avr(Avr 13)09:00mer15(Avr 15)17:00VirtuelVirtual Etiquettes de sessionAZ-700T00

lun13Avr(Avr 13)09:00mer15(Avr 15)17:00Lausanne, Av. Mon-Repos 24, 1005 Lausanne Etiquettes de sessionAZ-700T00

lun18Mai(Mai 18)09:00mer20(Mai 20)17:00VirtuelVirtual Etiquettes de sessionAZ-700T00

lun18Mai(Mai 18)09:00mer20(Mai 20)17:00Genève, Route des Jeunes 35, 1227 Genève Etiquettes de sessionAZ-700T00

lun22Juin(Juin 22)09:00mer24(Juin 24)17:00VirtuelVirtual Etiquettes de sessionAZ-700T00

lun22Juin(Juin 22)09:00mer24(Juin 24)17:00Lausanne, Av. Mon-Repos 24, 1005 Lausanne Etiquettes de sessionAZ-700T00

lun27juil(juil 27)09:00mer29(juil 29)17:00VirtuelVirtual Etiquettes de sessionAZ-700T00

lun27juil(juil 27)09:00mer29(juil 29)17:00Genève, Route des Jeunes 35, 1227 Genève Etiquettes de sessionAZ-700T00

lun31Aoû(Aoû 31)09:00mer02Sep(Sep 2)17:00VirtuelVirtual Etiquettes de sessionAZ-700T00

lun31Aoû(Aoû 31)09:00mer02Sep(Sep 2)17:00Lausanne, Av. Mon-Repos 24, 1005 Lausanne Etiquettes de sessionAZ-700T00

lun05Oct(Oct 5)09:00mer07(Oct 7)17:00VirtuelVirtual Etiquettes de sessionAZ-700T00

lun05Oct(Oct 5)09:00mer07(Oct 7)17:00Genève, Route des Jeunes 35, 1227 Genève Etiquettes de sessionAZ-700T00

lun09Nov(Nov 9)09:00mer11(Nov 11)17:00VirtuelVirtual Etiquettes de sessionAZ-700T00

lun09Nov(Nov 9)09:00mer11(Nov 11)17:00Lausanne, Av. Mon-Repos 24, 1005 Lausanne Etiquettes de sessionAZ-700T00

Contact

ITTA
Route des jeunes 35
1227 Carouge, Suisse

Opening hours

Monday to Friday
8:30 AM to 6:00 PM
Tel. 058 307 73 00

Contact-us

ITTA
Route des jeunes 35
1227 Carouge, Suisse

Make a request

Contact

ITTA
Route des jeunes 35
1227 Carouge, Suisse

Opening hours

Monday to Friday, from 8:30 am to 06:00 pm.

Contact us

Your request