AI Instructor Live Labs Included

AZ-ADMIN-100: Azure CLI Essentials for IaaS Administrators

Master the Azure CLI as a scripting-first admin toolkit — JMESPath, subscription/RG defaults, VM/VNet/Storage/RBAC lifecycle, tagging at scale. For admins moving from portal to reliable scripts.

Intermediate
11h 25m
10 Lessons
AZ-ADMIN-100
AZ-ADMIN-100 — Azure CLI Essentials for IaaS Administrators Badge

View badge details

About This Course

Move from portal clicks to a scripted Azure workflow with the Azure CLI. Master JMESPath output filtering, subscription/RG defaults, config profiles, and the deploy commands administrators reach for every day VM lifecycle, disks and snapshots, virtual networks and NSGs, storage accounts, RBAC assignments, and tagging at scale. By the end of this course you will be able to script the day-to-day work of an Azure IaaS administrator with the CLI, produce output that is machine-parseable for downstream tooling, and gate scripts on --only-show-errors and --query patterns that production admins actually use.

Course Curriculum

10 Lessons
01
AI Lesson
AI Lesson

How the Azure CLI works, and how administrators use it well

30m

Learn how the Azure CLI actually talks to Azure Resource Manager and how experienced administrators drive it — install channels and upgrade paths, sign-in with az login including managed-identity mode, subscription and default-group configuration, and the query pipeline (--query with JMESPath plus --output) that turns raw JSON into pipeline-ready text. Also covers config profiles, --only-show-errors for CI, and the difference between --verbose and --debug. By the end of this lesson you will be able to explain how the CLI transports your commands, choose the right output format for every situation, and use JMESPath filters to reduce raw ARM JSON to exactly the fields your downstream tooling needs.

02
Lab Exercise
Lab Exercise

Your first admin CLI workflow — set defaults, query resources, extract IDs for pipelines - Lab Exercises

1h 15m 5 Exercises

Note: This lab pre-provisions Azure resources at start — allow up to 10 minutes for the environment to become ready before beginning the exercises.

Turn Azure CLI defaults, --query, and --output into a fluent daily workflow. Practice on two pre-provisioned VMs, one virtual network, and one network security group. Set your subscription and default resource group, project a table view of every VM in the resource group with JMESPath, extract a clean list of resource IDs, and pipe them into a shell loop that runs az vm show per item. Wrap the whole thing in a saved CLI config profile you can switch between. By the end of this lab you will be able to script a repeatable read-only inventory sweep of any resource group using CLI defaults, filters, and standard bash tooling — the same shape you will reuse for cost reviews, tag audits, and change reporting.

03
AI Lesson
AI Lesson

Provisioning and managing Azure VMs and disks with the CLI

30m

Understand the mental model of az vm create end-to-end — how the CLI composes a public IP, network interface, NSG, subnet, image, and managed disk into a running virtual machine in a single command, and where each of those pieces can be swapped for one you built earlier. Covers image selection with az vm image list, image aliases like Ubuntu2404 and Win2022Datacenter, size discovery with az vm list-sizes, the four managed-disk SKUs (Standard_LRS, Premium_LRS, Premium_ZRS, UltraSSD), snapshot lifecycle, and az vm run-command invoke for post-provision customization. By the end of this lesson you will be able to reason about VM provisioning as a composition of independent resources, choose the right disk SKU for a workload, and drive OS-level actions on a running VM without ever opening SSH or RDP.

04
Lab Exercise
Lab Exercise

Deploy VMs, snapshot the OS disk, restore into a clone - Lab Exercises

1h 30m 11 Exercises

Note: This lab pre-provisions Azure resources at start — allow up to 10 minutes for the environment to become ready before beginning the exercises.

Walk the everyday VM-lifecycle path from the CLI. Deploy a Linux VM with SSH key auth and a Premium_LRS data disk, install and verify a web workload without opening a terminal on the VM, then take an OS-disk snapshot and rehydrate it into a second machine to prove the clone-and-recover pattern. Finish with a resize (deallocate, resize SKU, restart) and a clean tear-down. By the end of this lab you will be able to script a full create, customize, snapshot, restore, resize, and delete cycle for a Linux VM in Azure without ever leaving the terminal — the underlying workflow behind almost every disaster-recovery runbook in a production administrator's kit.

05
AI Lesson
AI Lesson

Azure virtual networks, NSGs, public IPs, and DNS from the CLI

30m

Learn the CLI shape of Azure networking — how az network vnet and az network vnet subnet compose an address space, how NSG rules evaluate in priority order with allow/deny/direction/source/destination semantics, how service tags express Azure-owned CIDRs so you never have to hard-code them, the Basic vs Standard public-IP SKU difference including zone redundancy, and how Azure Private DNS zones plus vnet-links replace legacy DNS forwarders for private-endpoint scenarios. By the end of this lesson you will be able to describe an NSG rule evaluation in your head, pick the right public-IP SKU for a workload, and reason about hub-spoke networking as a small number of composable CLI verbs.

06
Lab Exercise
Lab Exercise

Build a hub-spoke topology with NSGs, service tags, and peering - Lab Exercises

2h 15m 11 Exercises

Note: This lab pre-provisions Azure resources at start — allow up to 10 minutes for the environment to become ready before beginning the exercises.

Build a working hub-spoke Azure network from the CLI. Create a hub virtual network and a spoke, attach a network security group to the spoke workload subnet that allows the AzureLoadBalancer service tag and denies Internet inbound, peer the two networks in both directions with forwarded-traffic enabled, and deploy one VM per network to validate reachability by running ping through the CLI's remote-command channel. Then break peering, prove the failure mode, and re-peer with gateway transit enabled. By the end of this lab you will be able to describe every hub-spoke reachability property from first principles and reproduce a production-shaped topology in the CLI in under twenty minutes.

07
AI Lesson
AI Lesson

Storage accounts, RBAC assignments, and Managed Identities from the CLI

30m

Learn the CLI shape of Azure Storage plus the identity primitives that make storage safely usable — SKU choices (LRS, GRS, RA-GRS, ZRS), access tiers (Hot, Cool, Cold, Archive), the storage-account firewall model (VNet rules plus IP rules plus service endpoints plus private endpoints), the role-assignment syntax on az role assignment create --assignee with users, service principals, and managed identities, the distinction between system-assigned and user-assigned managed identities, and the difference between SAS-key blob access and --auth-mode login. By the end of this lesson you will be able to explain when to use a managed identity over a service principal, why --auth-mode login is the safer default for admin blob operations, and how storage RBAC roles map to actual data-plane permissions.

08
Lab Exercise
Lab Exercise

Storage with private access plus AzCopy plus managed-identity authenticated access - Lab Exercises

2h 10m 6 Exercises

Note: This lab pre-provisions Azure resources at start — allow up to 10 minutes for the environment to become ready before beginning the exercises.

Stand up a locked-down storage account, upload data with your Entra identity instead of a shared key, then prove that a VM with an attached managed identity can pull the same data with zero secrets in the workload. Along the way you will open a VNet rule for a spoke workload subnet, assign a data-plane role at container scope, and batch-tag every storage account in the resource group in a single command. By the end of this lab you will be able to build a passwordless VM-to-storage access path and describe every hop in the authorization chain, from the token the CLI acquires to the RBAC assignment that lets a blob download succeed.

09
AI Lesson
AI Lesson

Robust CLI scripts — error handling, idempotence, and cross-subscription operations

30m

Move from ad-hoc CLI commands to scripts that survive real production conditions — partial failures, existing resources, changing subscription context, and running unattended in continuous integration. Covers set -euo pipefail plus --only-show-errors, the difference between a non-zero exit and an empty stdout, the idempotent create-or-update patterns admins actually use, the cross-subscription script structure (per-command --subscription vs process-wide az account set), and the modern GitHub Actions plus azure/login@v2 OIDC federated-credential flow that removes long-lived client secrets from your automation. By the end of this lesson you will be able to write a bash script that will run twice against the same subscription and make changes only on the first run.

10
Lab Exercise
Lab Exercise

Ship a robust admin script — bash toolkit, GitHub Actions workflow, and OIDC-authenticated cross-sub run - Lab Exercises

1h 45m 5 Exercises

Note: This lab pre-provisions Azure resources at start — allow up to 10 minutes for the environment to become ready before beginning the exercises.

Ship a real automation artifact. Refactor a naive "create VM if it doesn't exist, otherwise update tag" bash script into one that runs cleanly with set -euo pipefail and honors a --dry-run flag backed by az deployment group what-if, wire it into a GitHub Actions workflow that authenticates through an OIDC federated credential (no long-lived client secret), and prove idempotence by running the pipeline twice with the second run reporting zero changes. By the end of this lab you will be able to structure any CLI-based admin script for CI, configure an app registration with an OIDC federated credential against a GitHub repo, and reason about the token flow from the runner to Entra ID and on to Azure Resource Manager.

This course includes:

  • 24/7 AI Instructor Support
  • Live Lab Environments
  • 5 Hands-on Lessons
  • Completion Badge
AZ-ADMIN-100 — Azure CLI Essentials for IaaS Administrators Badge

Earn Your Badge

Complete all lessons to unlock the AZ-ADMIN-100 — Azure CLI Essentials for IaaS Administrators achievement badge.

Skill Level Intermediate
Total Duration 11h 25m
AZ-ADMIN-100 — Azure CLI Essentials for IaaS Administrators Badge
Achievement Badge

AZ-ADMIN-100 — Azure CLI Essentials for IaaS Administrators

Awarded to administrators who can drive day-to-day Azure IaaS operations from the Azure CLI — JMESPath filtering, VM/VNet/Storage/RBAC lifecycle, and idempotent scripting patterns.

Course AZ-ADMIN-100: Azure CLI Essentials for IaaS Administrators
Criteria Complete all 10 lessons of Azure CLI Essentials for IaaS Administrators, including 5 hands-on labs covering CLI defaults + queries, VM/disk lifecycle, hub-spoke networking, storage + MI-authenticated access, and robust scripting with OIDC.

Skills You'll Earn

Azure CLI JMESPath Azure VM lifecycle Azure Networking (VNet, NSG, Peering) Azure Storage + RBAC Managed Identities Idempotent scripting GitHub Actions OIDC

Complete all lessons in this course to earn this badge