AI Instructor Live Labs Included

AZ-ADMIN-120: Bicep Fundamentals for Azure Infrastructure

Move from portal clicks to codified Azure infrastructure with Bicep — modules, deployment scopes, what-if previews, deployment stacks, and CI linting for administrators who need reliable, reviewable deploys.

Intermediate
11h 0m
10 Lessons
AZ-ADMIN-120
AZ-ADMIN-120 — Bicep Fundamentals for Azure Infrastructure Badge

View badge details

About This Course

Master Microsoft's declarative language for provisioning Azure infrastructure. Move beyond portal clicks to reliable, reviewable, repeatable deployments with Bicep the modern IaC language that succeeded ARM JSON. Across 10 lessons pairing focused teaching with hands-on labs, you'll learn how a Bicep file becomes a deployment, how to compose reusable modules across resource groups and subscriptions, how to preview infrastructure changes safely with what-if and deployment stacks, and how to gate a template on a linter in CI. Every lab uses the in-browser VS Code container with the Bicep extension pre-installed. By the end of this course you will be able to design, deploy, and safely evolve production-grade Azure infrastructure using Bicep modules, deployment scopes, what-if previews, deployment stacks, and CI-based linting.

Course Curriculum

10 Lessons
01
AI Lesson
AI Lesson

What is Bicep, and how a deployment works

35m

Bicep is Microsoft's declarative DSL for provisioning Azure resources — the modern successor to ARM JSON. In this ~35-minute AI-guided lesson you'll learn what Bicep is, why it exists, and exactly what happens between saving a .bicep file and seeing resources appear in your subscription. You'll walk through the transpile-and-submit pipeline (Bicep source becomes ARM JSON becomes an Azure Resource Manager deployment), map the four deployment scopes (resource group, subscription, management group, tenant) to the resources that legally live at each, and pick the correct deploy command from Azure CLI or Azure PowerShell for the scope you want. You'll also see the VS Code Bicep extension surface — IntelliSense, quick-fix, the Bicep Visualizer, the Deployment Pane — and the decompile flow for migrating existing ARM JSON into Bicep. By the end of this lesson you will be able to explain how Bicep relates to ARM JSON, trace a .bicep file through the transpile pipeline into deployed Azure resources, identify which scope a given resource type deploys at, and choose the correct CLI or PowerShell command to deploy a template at each scope.

02
Lab Exercise
Lab Exercise

Your first Bicep deployment - Lab Exercises

1h 15m 5 Exercises

Take your first Bicep file from an empty editor to a real Azure Storage account you deployed yourself. Start by verifying the VS Code container's Bicep tooling, author a minimal main.bicep that declares a StorageV2 account with TLS 1.2 and no public blob access, and deploy it to a pre-created resource group with az deployment group create. From there, refactor the account name into a parameter with length constraints and a description, add an output that surfaces the primary blob endpoint you can retrieve after deployment, and finish by previewing a SKU change from Standard_LRS to Standard_GRS through az deployment group what-if — learning to read the Modify change type before you ever apply it. By the end, you'll have hands-on experience with the four Bicep verbs you'll use daily: author, deploy, output, and preview.

03
AI Lesson
AI Lesson

Parameters, variables, outputs, and modules

35m

Make your Bicep files reusable across environments. In this ~35-minute AI-led lesson you will use parameters with decorators (@allowed, @minLength, @secure) to gate inputs; use variables to compute derived values without cluttering the caller; use outputs to hand values to the pipeline or a downstream module; and compose parent-child module trees drawn from local paths, the Azure Verified Modules public registry, and a private ACR-hosted module registry. You will also see how modules can target a different scope than the parent, so a subscription-level parent can deploy a resource-group-scoped storage account.

04
Lab Exercise
Lab Exercise

Build a modular Bicep project — VNet module for hub + spoke - Lab Exercises

2h 15m 5 Exercises

Move past the copy-paste VNet pattern that ate the last landing-zone project. In 90 minutes you will refactor a single inline VNet Bicep file into a reusable module, call it twice to stand up a hub-and-spoke topology (GatewaySubnet + AzureBastionSubnet on the hub; workload + database subnets on the spoke), wire a bidirectional peering, and surface subnet resource IDs as outputs the way downstream Bicep modules expect them. You will use az deployment group what-if between each refactor to prove the change is a no-op — the modularization pattern every landing-zone reference architecture from Microsoft ships with. By the end you will have a five-file Bicep project you can lift into the next spoke workload without opening the address-space spreadsheet.

05
AI Lesson
AI Lesson

Loops, conditions, dependencies, and deployment scopes

35m

Bicep gives you three lever sets that lift a template from one-off script into production-grade infrastructure code: loops that deploy N resources from one declaration, the if expression that skips a resource on demand, and the targetScope keyword that lets a single file target a resource group, a subscription, a management group, or the whole tenant. In this ~35-minute lesson we walk through for iteration and filtered loops, if-based conditional deployment, implicit vs explicit dependencies (and why the compiler almost always figures it out for you), the existing keyword for read-only references to resources this file doesn't own, and the mechanics of the four deployment scopes plus the exact CLI command each one takes. By the end you will read and write Bicep that scales, filters, references, and deploys across the entire Azure control plane.

06
Lab Exercise
Lab Exercise

Deploy N VMs with a copy loop, RBAC at RG scope, and a policy at sub scope - Lab Exercises

1h 30m 5 Exercises

Refactor a hard-wired single-VM Bicep file into a copy loop that deploys N Ubuntu VMs, add a conditional public IP for only the first VM, grant Reader at resource-group scope with an RBAC role assignment, then move to a subscription-scope Bicep file that assigns the built-in "Not allowed resource types" policy — and confirm the guardrail actually blocks a rogue public IP. You leave with hands-on fluency in the three most-used features that separate a copy-paste ARM/Bicep author from an infrastructure engineer: loops, conditions, and multi-scope deployments.

07
AI Lesson
AI Lesson

Existing resources, references, and private connectivity

35m

Not every resource your Bicep file touches is one it should create. Existing storage accounts, Key Vaults, and virtual networks already exist — you just need to reference them without redeploying. This lesson teaches the existing keyword for read-only references (including cross-resource-group scoping), the getSecret() and listKeys() pattern for pulling secrets from Key Vault at deploy-time with the @secure() parameter contract, and the private-endpoint + private-DNS-zone pattern that lets a client's mystorage.blob.core.windows.net request resolve to a private IP inside your VNet. You'll learn to distinguish private endpoints from private links and service endpoints — three terms that get conflated but do different things. By the end you'll be able to compose Bicep files that consume shared infrastructure safely, wire secrets in without exposing them, and stand up private connectivity without opening the storage account to the public internet.

08
Lab Exercise
Lab Exercise

Reference an existing Key Vault + deploy Storage with private endpoint + private DNS - Lab Exercises

1h 30m 4 Exercises

Note: This lab pre-provisions Azure resources at start — allow up to 10 minutes for the environment to become ready before beginning the exercises.

In this hands-on lab you use the Bicep existing keyword to reference a Key Vault the platform team pre-created for you, pull an admin password out of it with getSecret() and feed it — as a @secure() parameter — into a small Linux VM. You then land a Standard_LRS Storage account behind a Private Endpoint on the pre-created spoke-vnet, disable public network access on the storage account, and finish by deploying privatelink.blob.core.windows.net, linking it to the spoke, and attaching a privateDnsZoneGroups child on the PE so the NIC IP auto-registers as an A record.

By the end you can reason about the two existing-keyword scopes (Microsoft.KeyVault/vaults vs Microsoft.Network/virtualNetworks), the getSecret() compile-time contract, and the DNS-name-matching rule that makes Private Link auto-resolution actually work.

09
AI Lesson
AI Lesson

what-if, deploymentStacks, and CI

35m

You have a Bicep file that works. Now you need to ship it — safely, repeatably, and without the 3 a.m. call because a production storage account vanished. This lesson teaches you the three tools that make that possible: what-if to preview what a deploy will actually change; deployment stacks to treat a set of resources as a unit that resists accidental deletion; and CI gates (bicep build, bicep lint, PSRule.Rules.Azure, Pester) that stop bad templates before they reach Azure. You'll leave able to preview a deploy end-to-end, protect a stack with deny-settings, and gate a merge on a linter — the mechanics of Bicep at production altitude.

10
Lab Exercise
Lab Exercise

Deploy a stack with deny-settings + wire PSRule and bicep build into GitHub Actions - Lab Exercises

1h 35m 5 Exercises

Two production incidents pushed Cascade Renewable Energy's platform team to the same fix: an on-call engineer accidentally az group delete-d a shared spoke VNet in dev with no lock in place, and a merged PR added a public-blob-access Storage Account that nothing in CI caught. In 90 minutes you convert the deployed hub-and-spoke workload into a deployment stack that enforces denyDelete on every managed resource, preview the next change with az stack-whatif group create (the current supported shape — the older known-issues page is stale), run PSRule.Rules.Azure locally against the Bicep workload, and author the GitHub Actions gate (bicep build, bicep lint --diagnostics-format sarif, and microsoft/ps-rule@v2.9.0) that will block a PR that regresses the workload's security posture. By the end you have both halves of the change-safety story wired: production drift blocked at the resource-manager plane, and bad templates blocked at the PR plane before they merge.

This course includes:

  • 24/7 AI Instructor Support
  • Live Lab Environments
  • 5 Hands-on Lessons
  • Completion Badge
AZ-ADMIN-120 — Bicep Fundamentals for Azure Infrastructure Badge

Earn Your Badge

Complete all lessons to unlock the AZ-ADMIN-120 — Bicep Fundamentals for Azure Infrastructure achievement badge.

Skill Level Intermediate
Total Duration 11h 0m
AZ-ADMIN-120 — Bicep Fundamentals for Azure Infrastructure Badge
Achievement Badge

AZ-ADMIN-120 — Bicep Fundamentals for Azure Infrastructure

Awarded on completion of Bicep Fundamentals for Azure Infrastructure. Recognizes the earner's ability to design, deploy, and safely evolve Azure infrastructure using Bicep modules, deployment scopes, what-if previews, deployment stacks, and CI-based linting.

Course AZ-ADMIN-120: Bicep Fundamentals for Azure Infrastructure
Criteria Complete all 10 lessons of Bicep Fundamentals for Azure Infrastructure, including the 5 hands-on labs that deploy real Azure resources with Bicep.

Skills You'll Earn

Bicep Azure Resource Manager Infrastructure as Code Bicep modules Deployment scopes what-if previews Deployment stacks PSRule.Rules.Azure Azure networking Azure RBAC

Complete all lessons in this course to earn this badge