AZ-ADMIN-300: VM Fleet Management - Four Tools, One Scenario
The capstone. Deploy the same 3-tier IaaS fleet four ways — Az CLI, Az PowerShell, Bicep, ARM. Head-to-head. End with a challenge lab picking the right tool per phase of an incident-response drill.
View badge details
About This Course
The capstone. One realistic brief deploy a 3-tier IaaS application (web VMSS + app VMs + SQL VM + Application Gateway + Azure Backup) solved four ways. Same brief, four repos: Azure CLI, Azure PowerShell, Bicep, and ARM. Compare shape, error handling, day-2 ops, and defensibility. Finish with a VM Challenge capstone where you pick the right tool for each phase of an incident-response drill. By the end of this course you will have a defensible decision framework for which Azure IaC/CLI tool to reach for at each phase of a fleet's lifecycle.
Course Curriculum
7 Lessons
The scenario, the four repos, and the decision framework
Meet Nimbus Freight — a regional logistics carrier whose internal order-tracking app runs as a classic 3-tier IaaS stack (VMSS behind Application Gateway, App VMs in an availability zone, SQL VM protected by Azure Backup). Over the next six lessons you will deploy that same fleet four different ways using Azure CLI, Azure PowerShell, Bicep, and ARM templates in turn. This opening teaching lesson introduces the scenario, the tool-agnostic vocabulary you need for the head-to-head comparisons ahead (declarative vs imperative, dry-run vs commit, drift, idempotency), and a decision matrix for choosing the right tool per phase of a fleet's lifecycle. By the end of this lesson you will be able to describe the Nimbus Freight architecture end-to-end, explain what each of the four tools is optimized for, and defend a tool choice for a build / operate / audit / incident-response task.
Build 1 — Azure CLI: the whole fleet with bash - Lab Exercises
Note: This lab pre-provisions Azure resources at start — allow up to 10 minutes for the environment to become ready before beginning the exercises.
Build the Nimbus Freight 3-tier IaaS fleet end-to-end with Azure CLI in bash. Same fleet you saw in lesson 1: VNet + subnets + NSG, a Virtual Machine Scale Set behind Application Gateway v2 for the web tier, three zonal VMs for the app tier, a SQL VM for the data tier, and an Azure Backup Recovery Services vault protecting SQL. Deploy every resource by hand with az commands, then consolidate the whole flow into one reusable bash script. By the end of this lab you will be able to compose an Azure CLI build script that stands up a real 3-tier IaaS fleet from a blank resource group, verify each resource with az ... show, and defend where imperative bash earned its keep vs where you felt the ergonomic pain that Bicep would have taken away.
Rebuild 2 — Azure PowerShell — what's different, and what's better
A 30-minute teaching preview of the Nimbus Freight rebuild in Azure PowerShell. The web tier, the app tier, the SQL VM, the App Gateway, and the Azure Backup vault — all the same as Lesson 2, but rendered as Az PowerShell cmdlets instead of az CLI commands. This lesson prepares you to write the whole fleet in PowerShell in Lesson 4 by highlighting where the PowerShell shape wins over bash (pipeline objects that carry properties without re-querying, splatting for the twenty-flag App Gateway create, and per-cmdlet -WhatIf gating), and where it does not (verbosity, cmdlet-name discovery cost). By the end of this lesson you will be able to name the three ergonomic wins Az PowerShell brings over Azure CLI for a fleet-build script and defend at least one place where the CLI shape is still the correct reach.
Build 2 — Azure PowerShell: the whole fleet with Az PS - Lab Exercises
Note: This lab pre-provisions Azure resources at start — allow up to 10 minutes for the environment to become ready before beginning the exercises.
Rebuild the Nimbus Freight 3-tier IaaS fleet from scratch — same architecture as Lesson 2, this time in Azure PowerShell. Use pipeline objects for VNet + subnet + VMSS wiring, splatting for the twenty-parameter Application Gateway create, a foreach loop over 1..3 for the zonal App VMs, and Set-AzRecoveryServicesVaultContext to chain the backup vault + policy + protection calls. Save the flow as Deploy-NimbusFreight.ps1. By the end of this lab you will be able to compare line-of-code count, readability, and error-handling behavior between an Azure CLI bash script and an equivalent Azure PowerShell script for the same fleet, and defend which shape you would submit as the source-of-truth deliverable to a Windows-shop administration team.
Rebuild 3 & 4 — Bicep and ARM — the declarative story
A 30-minute teaching preview of the Nimbus Freight fleet rebuilt twice more — first in Bicep, then in ARM JSON. This lesson makes concrete what "declarative" buys you: order derived from resource references rather than encoded by the author, idempotent re-runs by default, and what-if as a first-class day-2 tool. It also names honestly where declarative pays a cost — the length of ARM JSON, the mental step-up from a bash script to a compiled resource graph, and the moments where imperative tools are still the correct reach. By the end of this lesson you will be able to compare Bicep and ARM as authoring surfaces and defend which of the four course tools is the correct pick for build, audit, operate, and incident-response tasks.
Builds 3 & 4 — Bicep and ARM — deploy the same fleet declaratively - Lab Exercises
Note: This lab pre-provisions Azure resources at start — allow up to 10 minutes for the environment to become ready before beginning the exercises.
Rebuild the Nimbus Freight 3-tier IaaS fleet a third and a fourth time — this time declaratively. Author a full Bicep implementation split into network.bicep + compute.bicep + data.bicep modules under main.bicep; deploy with az deployment group create; run az deployment group what-if to inspect the intended-vs-actual delta. Then deploy a provided ARM version of the same fleet to feel the JSON-verbosity trade-off firsthand. By the end of this lab you will be able to compose a multi-module Bicep template for a real 3-tier fleet, use what-if as a day-2 drift-audit tool, translate between Bicep and ARM with az bicep build / az bicep decompile, and write a defensible 200-word decision-framework verdict on which of the four course tools to reach for at each phase of a fleet's lifecycle.
Nimbus Freight incident-response drill - Lab Exercises
Note: This lab pre-provisions Azure resources at start — allow up to 12 minutes for the environment to become ready before beginning the exercises.
The capstone. You inherit a degraded Nimbus Freight fleet already deployed in production, with three failures baked in: three App VMs are unreachable, the Application Gateway backend pool is failing health probes, and Azure Backup has stopped taking snapshots on the SQL VM. Diagnose each failure using the right tool for the phase, remediate using the right tool for the phase, then codify at least one fix back into the appropriate IaC repo — and defend every tool choice in a 300-word decision log. Grading (AI-graded via the challenge tool): all three issues correctly diagnosed AND remediated (backend pool healthy, backup snapshotting, three VMs responding), your IaC repo carries a commit that codifies at least one fix, and your decision log names tool + reasoning per action. By the end of this lab you will have proven your defensible 4-tool decision framework under production-incident pressure.