AZ-DEV-100: Building Web Applications with Azure App Service
Take ASP.NET Core apps from a first-deploy to production on Azure App Service. Learn deployment slots, autoscale, VNet integration, managed identity, TLS, and Application Insights, then ship a multi-tier web app end-to-end.
View badge details
About This Course
Azure App Service is Microsoft's flagship PaaS for hosting web applications, APIs, and containers. This course takes .NET developers from a first-deploy through production hardening. You will learn how to choose the right plan tier for a workload, deploy from CLI and from GitHub Actions with OpenID Connect federation, use deployment slots for zero-downtime blue/green promotions, configure metric-driven autoscale, integrate with a virtual network and private endpoints for secured backend access, wire your app to Key Vault, App Configuration, Azure SQL, and Storage using managed identity, enforce modern TLS on both the default and custom hostnames, and instrument your app with Application Insights and OpenTelemetry so operational questions are answerable in KQL.By the end of this course you will be able to design, ship, and operate a multi-tier ASP.NET Core web app on Azure App Service in production with slot-based promotions, autoscale, managed-identity access to Storage and SQL, TLS enforcement, and full Application Insights instrumentation and know when to reach for App Service Environment, Application Gateway, or Front Door in front of it.
Course Curriculum
20 Lessons
AZ-DEV-100 M1L1 - App Service fundamentals — plans, tiers, and hosting models
Choose the right App Service Plan tier for a given workload, and decide when App Service is the right host at all. You will learn how the plan-vs-app model works, how the tier ladder trades cost for isolation and features, when Linux vs Windows hosting matters, when to reach for App Service Environment (Isolated) instead of multi-tenant Premium, and when a different Azure service (Container Apps, AKS) is a better fit. By the end of this lesson you will be able to defend a hosting-tier choice for any Anchorline Outdoors workload.
AZ-DEV-100 M1L2 - Provision an App Service Plan and deploy your first ASP.NET Core app - Lab Exercises
Note: This lab pre-provisions an empty resource group at start — allow up to 3 minutes for it to become ready before beginning the exercises.
Provision the Anchorline storefront's baseline yourself: a Standard S1 Linux App Service Plan and a .NET 10 Web App with the storefront's required site config (HTTPS-only, TLS 1.3, HTTP/2, FTPS disabled, Always On, /health probe, System-Assigned Managed Identity). Then deploy the ASP.NET Core 10 starter scaffold, verify it's live over HTTPS, and observe what changes when you scale the plan from S1 to Premium V3 and back. By the end you will have deployed a real running workload — and can defend every configuration choice you made.
AZ-DEV-100 M2L3 - Configuration, secrets, and centralized config for App Service
Master the ASP.NET Core configuration model on Azure App Service. You will learn how the IConfiguration precedence chain resolves values across appsettings.json, environment variables, command-line flags, user secrets, and cloud providers; how Key Vault references let you store secrets in Key Vault while your app reads them like ordinary app settings; and when Azure App Configuration + feature flags is worth the extra service versus raw app settings. By the end of this lesson you will be able to defend a configuration architecture for any Anchorline Outdoors workload and predict where each value comes from at runtime.
AZ-DEV-100 M2L4 - Wire Key Vault and App Configuration into an ASP.NET Core app - Lab Exercises
Note: This lab pre-provisions Azure resources at start — allow up to 12 minutes for the environment to become ready before beginning the exercises.
Wire the Anchorline Outdoors storefront to real secrets and centralized configuration. You will inspect the pre-provisioned Key Vault and App Configuration store, deploy the starter app so it reads the Stripe API key via a Key Vault reference (managed-identity-authenticated, no code path), toggle the Beta.FallDiscount feature flag in App Configuration and watch the app pick it up live via the sentinel-key refresh pattern, and add a new secret + cascade it through both surfaces. By the end you will have a defensible answer for where every Anchorline config value should live and how it flows from Azure to your process.
AZ-DEV-100 M3L5 - Deployment options for App Service — CLI, GitHub Actions with OIDC, and containers
Master the four deployment mechanisms Azure App Service exposes and pick the right one for a given workload. You will learn how the Azure CLI's zip-deploy works, how GitHub Actions with OIDC federated identity deploys on every push without publish-profile secrets, how the Deployment Center wizard bootstraps the same pipeline in the portal, and how container deploys from Azure Container Registry work through managed identity. By the end you will be able to defend a deployment architecture for any Anchorline workload and design a rollback strategy that actually works when the deploy goes bad at 3 AM.
AZ-DEV-100 M3L6 - Set up GitHub Actions with OIDC and deploy on every push - Lab Exercises
Note: This lab pre-provisions Azure resources at start — allow up to 12 minutes for the environment to become ready before beginning the exercises.
Ship the Anchorline Outdoors storefront from GitHub with OIDC federated identity — zero publish-profile secrets in the repo. You will inspect the pre-provisioned user-assigned managed identity (which holds Website Contributor on the Web App), sign in to Azure and GitHub, create a fresh GitHub repo of your own, push the starter to it, configure a federated credential on the UAMI that trusts your fork's main branch, watch your first push deploy the app, then introduce a bad commit and roll back via a workflow re-run on the prior tag. By the end you will have muscle memory for the entire OIDC deploy pipeline pattern.
AZ-DEV-100 M4L7 - Deployment slots and blue/green promotions
Master App Service deployment slots — the pivot that turns a production deploy from a risky one-way flip into a rehearsed swap you can reverse in 30 seconds. You will learn slot basics + swap semantics, warm-up patterns (applicationInitialization, WEBSITE_SWAP_WARMUP_PING_PATH), sticky settings for slot-specific config, auto-swap for continuous deployment, and traffic-percentage testing for canary rollouts. By the end you will be able to design a blue/green promotion for any Anchorline workload and defend the trade-offs against alternative rollback strategies.
AZ-DEV-100 M4L8 - Ship a blue/green promotion with deployment slots - Lab Exercises
Note: This lab pre-provisions Azure resources at start — allow up to 10 minutes for the environment to become ready before beginning the exercises.
Add a staging slot to the Anchorline storefront and use it to ship a change safely. You will inspect the pre-provisioned Web App + staging slot, deploy the starter to the staging slot, warm it up + smoke-test its /version endpoint, swap it to production with a single command, then introduce a deliberately broken change and reverse-swap in 30 seconds to recover. Same App Service Plan compute; dramatically different risk profile.
AZ-DEV-100 M5L9 - Scaling and performance patterns for App Service
Master App Service scaling — manual scale up/out, autoscale rules driven by metrics, and the trade-offs between different scale triggers. You will learn the difference between scaling up (bigger VMs) and scaling out (more instances), how autoscale rules evaluate metrics with statistical aggregation, how to build metric-based rules on CPU and memory, and how to build rules that respond to external metrics like Service Bus queue depth. By the end you will be able to design an autoscale strategy for any App Service workload and defend the choices against cost and reliability constraints.
AZ-DEV-100 M5L10 - Configure autoscale driven by CPU and Service Bus queue depth - Lab Exercises
Note: This lab pre-provisions Azure resources at start — allow up to 12 minutes for the environment to become ready before beginning the exercises.
Watch autoscale react to real load on the Anchorline storefront. You will inspect the pre-provisioned PremiumV3 plan + autoscale settings + Service Bus queue, deploy the starter, load-test with hey to drive CpuPercentage above 70% and watch instance count climb from 2 to 4, run the producer script to push 500 messages into the queue and watch the ActiveMessageCount rule fire, then let both metrics settle and observe scale-in.
AZ-DEV-100 M6L11 - Networking and security for App Service — VNet integration, private endpoints, and access restrictions
Wire App Service into a virtual network for secure backend access, protect inbound traffic with private endpoints, and lock down what can reach the app. You will learn regional VNet integration (outbound path with subnet delegation), private endpoints (inbound path with private DNS zones), and access restrictions (IP allow/deny + service tag rules). By the end you will be able to design App Service networking for a compliance-driven workload and defend the choices against alternative isolation patterns like ASE.
AZ-DEV-100 M6L12 - Integrate App Service with a VNet and reach Azure SQL over a private endpoint - Lab Exercises
Note: This lab pre-provisions Azure resources at start — allow up to 15 minutes for the environment to become ready before beginning the exercises.
Wire the Anchorline storefront to a private-endpoint SQL database. You will inspect the pre-provisioned VNet + private endpoint + private DNS zone, seed a Products table via sqlcmd from the container, deploy the starter and confirm /products returns rows over the private path, verify /dns shows a private IP for the SQL hostname, then add an access restriction that blocks direct hits on the app's public hostname.
AZ-DEV-100 M7L13 - Use managed identities to access Azure Storage, Key Vault, Azure SQL, and Cosmos DB from App Service
Learn how App Service managed identities let your code call Azure Storage, Key Vault, Azure SQL, and Cosmos DB without any secrets in the connection string. You will be able to choose between system-assigned and user-assigned managed identities, wire the right RBAC role for each service, and read the token issuance path end to end.
AZ-DEV-100 M7L14 - Wire an App Service to Storage, Key Vault, Azure SQL, and Cosmos DB with a managed identity - Lab Exercises
Note: This lab pre-provisions Azure resources at start — allow up to 15 minutes for the environment to become ready before beginning the exercises.
Wire the Anchorline storefront to four Azure services using a single system-assigned managed identity. You will inspect the identity's role assignments across Storage, Key Vault, SQL (Entra admin), and Cosmos DB; deploy the app; verify each endpoint reads its target service without any connection string in code; then break one role assignment and observe the exact 401/403 signature so you can recognize it in production.
AZ-DEV-100 M8L15 - Enforce TLS 1.3, add HSTS, and understand custom domain + managed certificate binding on App Service
Learn how App Service terminates TLS, why TLS 1.3 is now the safe minimum, how HSTS + HTTP/3 layer on top, and — because Anchorline is going public soon — the exact steps to bind a custom domain (shop.anchorline.com) with an App Service Managed Certificate. You'll be able to configure TLS + HSTS + HTTP/3 in ARM, walk the asuid + CNAME verification handshake end-to-end, and choose between managed certificate, App Service Certificate, and BYO KV cert.
AZ-DEV-100 M8L16 - Harden App Service TLS - enforce TLS 1.3, add HSTS, enable HTTP/3 - Lab Exercises
Note: This lab pre-provisions Azure resources at start — allow up to 10 minutes for the environment to become ready before beginning the exercises.
Harden the Anchorline storefront's TLS posture on its default *.azurewebsites.net hostname. You will inspect the intentionally-weak baseline (TLS 1.2, no HSTS, no HTTP/3), raise minTlsVersion to 1.3 and verify with openssl, disable FTPS, add UseHsts() middleware to Program.cs and confirm the header is emitted, and turn on HTTP/3 with az CLI + verify with curl --http3.
AZ-DEV-100 M9L17 - Diagnose App Service with Application Insights, Log Analytics, and OpenTelemetry
Learn how App Service, Application Insights, and Log Analytics fit together — from the auto-instrumentation site extension through OpenTelemetry SDK-in-code to Kusto queries that let you pinpoint a slow endpoint at 3am. You'll be able to instrument a .NET app end-to-end, write the KQL that answers common diagnostic questions, and configure alerts + autoscale on the metrics that matter.
AZ-DEV-100 M9L18 - Instrument an App Service with App Insights + OpenTelemetry, query logs with KQL, and configure a latency alert - Lab Exercises
Note: This lab pre-provisions Azure resources at start — allow up to 12 minutes for the environment to become ready before beginning the exercises.
Instrument the Anchorline storefront with Application Insights auto-instrumentation, then layer code-based OpenTelemetry for custom metrics and traces. Run a load generator, then use KQL against the Log Analytics workspace to find slow endpoints, correlate exceptions with request IDs, and calculate P95 latency. Finally, wire a metric alert on P95 latency with an Action Group that would page an on-call engineer.
AZ-DEV-100 M10L19 - Production readiness for App Service - SLOs, cost, runbooks, and the launch checklist
Learn how to ship the Anchorline storefront with confidence: the 20-item production readiness checklist, SLO/SLI/error budgets that turn "healthy" into a measurable number, cost engineering (SKU sizing + reserved instances), and the runbook + incident response cycle that keeps the site up after launch. You'll be able to evaluate a workload against production standards, compute SLOs from App Insights data, size an App Service Plan against expected load, and structure an incident response.
AZ-DEV-100 M10L20 - Anchorline capstone - deploy, harden, load-test, and diagnose an end-to-end production App Service - Lab Exercises
Note: This lab pre-provisions Azure resources at start — allow up to 15 minutes for the environment to become ready before beginning the exercises.
Ship the Anchorline storefront end-to-end. You will inspect the pre-provisioned production stack (P1V3 plan + slot + KV + MI + App Insights + autoscale), deploy the app to staging + slot-swap to production, wire the KV-referenced launch tag through the code, then run a load test large enough to trigger both autoscale and a P95 latency alert — using the runbook + KQL from the diagnostics module to identify the bottleneck and mitigate.