AZ-ADMIN-130: ARM Templates - Fundamentals and Migration to Bicep
Read, maintain, and safely modernize ARM JSON templates. Master parameters, functions, copy loops, linked templates, arm-ttk testing, and the `bicep decompile` migration path.
View badge details
About This Course
The legacy-fluency IaC course. Enterprise Azure teams still ship hundreds of ARM JSON templates today you need to read, modify, and eventually modernize them. Learn how ARM JSON deployments actually work, master parameters, variables, functions, copy loops, conditions, linked and nested templates, deploymentScripts, and template specs. Test every template with arm-ttk. Then decompile a real 400-line template to Bicep and clean it up. By the end of this course you will be able to confidently maintain existing ARM investments and modernize them to Bicep when the timing is right.
Course Curriculum
8 Lessons
ARM JSON — what deploys where, and why we still care
Understand how Azure Resource Manager JSON templates are structured and how the deployment engine evaluates them end to end. You will learn the six template sections ($schema, contentVersion, parameters, variables, resources, outputs), how ARM parses parameters and variables before resources, how it resolves dependencies and parallelizes work, the difference between resource-group, subscription, management-group, and tenant deployment scopes, the core template functions administrators use every day, and the critical distinction between Incremental and Complete deployment modes. By the end of this lesson you will be able to read any ARM template, predict what it will deploy, and reason confidently about deployment mode risk before you press Enter.
Read + deploy a real ARM template — parameters, variables, outputs - Lab Exercises
Note: This lab pre-provisions Azure resources at start — allow up to 10 minutes for the environment to become ready before beginning the exercises.
Deploy your first real ARM JSON template end to end. You will read a provided storage-account template, deploy it with the Azure CLI, extract its hard-coded values into parameters, layer in a parameters file, add a variables block for tag composition, expose the primary blob endpoint through an output, and finally run arm-ttk against the result and fix every finding. By the end of this lab you will be able to confidently take any existing ARM JSON template, parameterize it correctly, and prove it clean with arm-ttk before deploying.
Copy loops, conditions, and dependencies in ARM JSON
Learn how ARM JSON scales a template from one resource to N — using the copy element on resources and inside properties, guarding a resource with a condition expression, and understanding when dependsOn is required vs when implicit references are enough. You will also learn how reference() differs from resourceId() and when to reach for each. By the end of this lesson you will be able to read any looped or conditional ARM template, predict how many resources it will actually deploy for a given set of parameters, and correctly wire dependencies between them.
Deploy N VMs with copy loops, a conditional public IP, and inter-resource deps - Lab Exercises
Note: This lab pre-provisions Azure resources at start — allow up to 10 minutes for the environment to become ready before beginning the exercises.
Take everything you learned about copy loops, conditions, and dependencies from the teaching lesson and apply it end to end. You will author an ARM template that deploys a parameter-driven number of virtual machines, uses property copy to make a single VNet with multiple subnets, gates a public IP behind a condition so only VM #0 gets one, uses reference() to expose the deployed subnet ID as an output, and passes arm-ttk cleanly. By the end of this lab you will be able to build fleet-shaped ARM templates that scale from one to many with a single parameter change.
Linked, nested, and specced templates
Move beyond a monolithic ARM template. You will learn the three ways ARM composes deployments across files and boundaries — linked templates that pull JSON from a URL, nested templates that inline a child template inside the parent, and template specs that publish a template as a first-class Azure resource you reference by ID. You will also see how deploymentScripts run az CLI or PowerShell mid-deploy for post-provision configuration. By the end of this lesson you will be able to decompose a large ARM template into reusable modules and choose the right composition mechanism for each scenario.
Compose a multi-file deployment with linked templates + a template spec + a deploymentScript - Lab Exercises
Note: This lab pre-provisions Azure resources at start — allow up to 10 minutes for the environment to become ready before beginning the exercises.
Break a monolithic 300-line ARM template into a maintainable multi-module composition. You will split it into a main template plus two linked modules, wire the modules via templateLink URIs, publish the VNet module as a versioned template spec that other workloads can reference by resource ID, and add a deploymentScript that runs az CLI to seed a blob container after the storage account provisions. By the end of this lab you will be able to design real enterprise-scale ARM deployments that share modules across teams via template specs and use deploymentScripts to close the gap between declarative and imperative operations.
Testing ARM with arm-ttk + Pester, and gating in CI
Learn how to catch ARM template issues before they hit production. You will learn what arm-ttk actually tests, how to interpret its output, how to wrap arm-ttk tests in Pester for CI-friendly pass/fail assertions, and how to gate a GitHub pull request on both arm-ttk and az deployment group what-if. By the end of this lesson you will be able to build a repeatable ARM template quality gate that stops broken templates from ever merging.
Test in CI + decompile a real ARM template to Bicep - Lab Exercises
Note: This lab pre-provisions Azure resources at start — allow up to 10 minutes for the environment to become ready before beginning the exercises.
Wire the ARM testing gate you designed in Lesson 7 and then use it to help decide the future of a real inherited template. You will author Pester tests that wrap arm-ttk into pass/fail assertions, wire those tests plus az deployment group validate and what-if into a GitHub Actions workflow that gates a pull request, then take a provided 400-line real-world ARM template (VMSS + Load Balancer + VNet + NSG), decompile it to Bicep with bicep decompile, inspect and clean up the decompilation artifacts, and write a keep-as-ARM vs migrate-to-Bicep vs leave-until-next-major verdict per section. By the end of this lab you will be able to build a real ARM quality gate AND make a defensible modernization call on any legacy template you inherit.