AZ-ADMIN-110: Azure PowerShell for IaaS Administrators
Short-form Az PowerShell for IaaS admins — pipeline composition, splatting, Az.Tools.Predictor, and PSScriptAnalyzer linting. Companion to AZ-040 (course 444). VM/VNet/Storage/RBAC scenarios.
View badge details
About This Course
A short-form complement to AZ-040. Skip the PowerShell language basics dive straight into managing Azure IaaS with the Az module. Learn the pipeline idioms that let you compose one Get-AzVM output into three downstream cmdlets, master splatting for readable multi-parameter Azure calls, and use Az.Tools.Predictor to accelerate interactive admin work. By the end of this course you will be able to write clean, pipeline-first admin scripts for Azure VMs, networking, storage, and role assignments, and lint them with PSScriptAnalyzer before shipping.
Course Curriculum
4 Lessons
Az PowerShell for admins - pipelines, splatting, and the predictor
Learn to compose Azure PowerShell like an experienced administrator. You'll explore the Az module structure, sign in with the right identity for interactive, managed-identity, and service-principal contexts, and switch cleanly between subscriptions. You'll then chain cmdlets through pipelines instead of loops, tidy multi-parameter calls with splatting, enable Az.Tools.Predictor for machine-learning-driven IntelliSense, and lint scripts with PSScriptAnalyzer. By the end of this lesson you will be able to compose Az PowerShell admin scripts that use pipeline idioms, splatting, and predictor-assisted authoring to run repeatable operations against Azure resources.
VM and disk lifecycle in Az PowerShell - with predictor and PSScriptAnalyzer gates - Lab Exercises
Note: This lab pre-provisions Azure resources at start — allow up to 10 minutes for the environment to become ready before beginning the exercises.
Aurora Ridge Analytics is standing up a compute host for its nightly batch job. As the on-call IaaS administrator, you'll drive the whole VM lifecycle from Az PowerShell — no portal clicks — and end the session with a peer-reviewable script that passes the team's PSScriptAnalyzer gate.
You'll practice the everyday IaaS-admin muscle: sign in with device code, verify PSReadLine + Az.Tools.Predictor are giving you Predictive IntelliSense in ListView, deploy a Windows VM using splatted New-AzVM parameters, walk the VM's storage profile to introspect its OS disk and (empty) data-disk collection, resize the VM with Update-AzVM, snapshot the OS disk and stamp a new managed disk from that snapshot, and finally save the whole session as Manage-AzVMs.ps1 and drive it through Invoke-ScriptAnalyzer — remediating the classic PSAvoidUsingCmdletAliases, PSAvoidUsingWriteHost, and PSUseDeclaredVarsMoreThanAssignments findings until the analyzer returns clean.
By the end of this lab you will be able to provision, introspect, resize, and snapshot an Azure VM entirely from Az PowerShell using splatted parameter hashtables, and produce a lint-clean .ps1 script that would pass a code review on Aurora Ridge's platform team.
Networking, storage, and RBAC via Az PowerShell - pipeline chains that admins reuse
Chain Az PowerShell cmdlets the way seasoned admins actually chain them. In this ~30 minute lesson you'll build the reusable VM-to-NIC-to-private-IP one-liner, compose Network Security Group rules with New-AzNetworkSecurityRuleConfig and persist them with Set-AzNetworkSecurityGroup, lock a storage account to a spoke VNet using -NetworkRuleSet, and grant a data-team managed identity least-privilege blob access with Get-AzADServicePrincipal piped into New-AzRoleAssignment. Every state-changing example lands with the -WhatIf habit so you preview blast radius before you commit. By the end of this lesson you will be able to compose Az pipeline chains that filter, resolve, and act on Azure networking, storage, and RBAC resources with predictable results.
Hub-spoke networking, storage with private endpoint, RBAC, and batch admin operations - Lab Exercises
Note: This lab pre-provisions Azure resources at start — allow up to 10 minutes for the environment to become ready before beginning the exercises.
Aurora Ridge Analytics is standing up a new "data-science-team" workload. Their platform team asked you to compose the network + storage + RBAC posture with the Azure Az PowerShell module — pipeline-first, no imperative loops, no portal clicks — and then run a batch admin sweep across the estate so tags, sizes, and inventory reports match reality.
In this lab you will:
- Compose a hub-and-spoke virtual network topology by piping subnet configurations into
New-AzVirtualNetworkin one shot per VNet. - Build a Network Security Group from multiple rule objects and associate it to the spoke workload subnet.
- Peer the hub and spoke bidirectionally, using
-AllowForwardedTrafficand-AllowGatewayTransitdeliberately. - Deploy a storage account whose
NetworkRuleSetlocks data-plane access to a single spoke subnet and confirm the default-deny outside that subnet. - Assign
Storage Blob Data Readeron the storage account to a user-assigned Managed Identity that the environment pre-creates for you. - Adopt
-WhatIfas a pre-commit habit for state-changing cmdlets. - Batch-tag every storage resource in one pipeline using
Update-AzTag -Operation Merge. - Right-size a set of VMs by piping
Get-AzVM | Where-Object | Update-AzVM. - Combine
Get-AzVM,Get-AzNetworkInterface, andGet-AzStorageAccountinto a singleConvertTo-Html -Fragmentinventory report. - Package the whole session as a reusable
.psm1module withExport-ModuleMember.
By the end of this lab you will be able to compose Azure IaaS network + storage + RBAC posture with pipeline-first Az PowerShell, and package repeatable admin workflows as a portable module you can hand to teammates.