AZ-DEV-120: Azure Blob Storage for .NET Developers
.NET 10 + Azure.Storage.Blobs v12 end-to-end — blob types, auth, tiers, events, ADLS Gen2, capstone DMS.
About This Course
Deep dive into Azure Blob Storage from a .NET developer perspective. Blob types, authentication models (SAS, Entra ID, MI), access tiers and lifecycle management, static websites, ADLS Gen2, blob events and change feed, and a capstone document management system that ties every capability together.
Course Curriculum
20 Lessons
Storage fundamentals - account types, redundancy, and performance
Learn how Azure Storage is architected at the account level — general-purpose v2 vs BlockBlobStorage premium, redundancy tiers (LRS/ZRS/GRS/RA-GRS/GZRS/RA-GZRS), Standard vs Premium performance, replication SLA, and the cost model. You will be able to pick the right account shape for any workload.
Provision a GP v2 RA-GZRS storage account and probe the primary and secondary endpoints - Lab Exercises
Note: This lab pre-provisions an empty resource group at start — allow up to 3 minutes for it to become ready before beginning the exercises.
Create Anchorline's first Blob Storage account (GP v2, RA-GZRS, Hot) yourself using the Azure CLI. Grant your lab user Storage Blob Data Contributor at container scope, upload a file to prove auth works, then read the file back from the -secondary read endpoint to confirm RA-GZRS is live. Finish by modelling the four line items in a storage bill and identifying the biggest cost lever.
Blob types - block, append, and page blobs
Learn the three blob types Azure supports — block (default), append (logs), page (VHDs) — and when each is the right choice. You will be able to reason about staging blocks, block IDs, max sizes, and design a workload's blob-type choice.
Compare single-connection vs parallel block-blob upload of a large file - Lab Exercises
Note: This lab pre-provisions Azure resources at start — allow up to 10 minutes for the environment to become ready before beginning the exercises.
Generate a large local file, upload it once with default single-connection settings and once with 8 parallel × 8 MiB blocks, and measure the throughput delta. Then switch to an append blob and observe how concurrent appends behave with multiple writer processes.
Authentication and access - account keys, SAS, and Entra ID RBAC
Learn the four ways to authenticate to Blob Storage — account keys (avoid), SAS tokens (service, account, user-delegation), Entra ID with data-plane RBAC, and stored access policies. You will be able to choose the right auth model per caller and generate user-delegation SAS for browser-direct uploads.
Wire an MI-backed API that mints user-delegation SAS for browser direct upload - Lab Exercises
Note: This lab pre-provisions Azure resources at start — allow up to 10 minutes for the environment to become ready before beginning the exercises.
Deploy the Anchorline SAS-issuer API. Verify the Web App's identity has Storage Blob Data Contributor + Storage Blob Delegator, POST to /api/upload/prepare to receive a user-delegation SAS URL, PUT a file directly to that URL, then break the Storage Blob Delegator role assignment and observe the failure signature.
Blob operations with the .NET SDK - metadata, tags, leases, and batch
Learn the BlobServiceClient → BlobContainerClient → BlobClient hierarchy and the operations that matter for real apps — metadata, blob index tags, leases, copy, batch. You will be able to design a searchable blob store using tags without maintaining a separate index.
Build a searchable blob-based document store with metadata and tags - Lab Exercises
Note: This lab pre-provisions Azure resources at start — allow up to 10 minutes for the environment to become ready before beginning the exercises.
Grant yourself the required roles, upload a document with metadata + tags, seed 100 synthetic docs, then query by tag (year = '2026' AND documentType = 'invoice') to verify server-side index behavior. Confirm metadata is NOT queryable.
Access tiers and lifecycle management
Learn how to move data through Hot / Cool / Cold / Archive tiers automatically via lifecycle management policies, or let Azure pick per-blob tiers automatically with Smart auto-tiering. You will be able to design a policy that reduces cost by 60-80% for a mixed workload while keeping data reachable when the business needs it.
Author a cascade lifecycle policy and observe tier transitions - Lab Exercises
Note: This lab pre-provisions Azure resources at start — allow up to 10 minutes for the environment to become ready before beginning the exercises.
Seed a set of documents, manually tier a few to prove the SetAccessTier API works, then attach a cascade lifecycle policy (Cool at 30 days → Cold at 90 → Archive at 180 → Delete at 2555). Finally simulate a rehydration.
Static websites and Azure Front Door integration
Learn how to host a static web application on Blob Storage's $web container, layer Azure Front Door (Standard or Premium) in front, and configure cache-control headers to maximize CDN hit ratio while keeping HTML fresh. Custom-domain binding is taught deeply for production readiness. Covers the retirement of Azure CDN Standard from Microsoft (classic) and Azure Front Door (classic), and how to choose between Front Door Standard and Premium (WAF managed rule sets, bot manager, Private Link origins).
Host a static SPA in the $web container with per-file cache-control - Lab Exercises
Note: This lab pre-provisions Azure resources at start — allow up to 10 minutes for the environment to become ready before beginning the exercises.
Enable static website hosting on the storage account, deploy the Anchorline SPA to $web with per-file cache-control headers (immutable for hashed assets, no-cache for HTML), and confirm the strategy by inspecting HTTP headers with curl. Then simulate an asset update by uploading a new hashed filename and observing browser-side cache behavior.
Blob events and change feed
Learn Event Grid system topics for Storage, event schemas (CloudEvents 1.0), the change feed as an ordered log of blob-modifying operations, versioning, and soft delete. You will be able to build event-driven blob architectures without polling and replay history via the change feed reader SDK.
Read the change feed to replay blob operations and recover from an accidental overwrite - Lab Exercises
Note: This lab pre-provisions Azure resources at start — allow up to 10 minutes for the environment to become ready before beginning the exercises.
The pre-provisioned storage account has change feed, versioning, and soft delete enabled. Generate change traffic (upload, overwrite, tier, delete a few blobs), wait for the change feed to batch, then read the changes with the .NET ChangeFeedClient. Finally, overwrite a blob and recover the previous version.
ADLS Gen2 - hierarchical namespace, POSIX ACLs, and the DataLakeServiceClient
Learn how ADLS Gen2's hierarchical namespace changes the mental model — real directories, atomic renames, POSIX-style ACLs on directories and files. You will be able to design a per-tenant folder structure with role-based access using the DataLakeServiceClient SDK.
Scaffold a hierarchical tenant tree in ADLS Gen2 and apply POSIX ACLs - Lab Exercises
Note: This lab pre-provisions Azure resources at start — allow up to 10 minutes for the environment to become ready before beginning the exercises.
Grant yourself Blob Data Owner. Scaffold a per-tenant folder tree using the DataLakeServiceClient. Inspect and modify POSIX ACLs on a directory. Perform an atomic directory rename and confirm it's fast even with data underneath.
Copy, migration, and immutability policies
Learn how to migrate blobs between accounts (AzCopy, az storage copy, server-side copy), object replication policies for cross-region redundancy on premium accounts, and immutability policies (WORM) for compliance retention. You will be able to lock blobs against modification and recover point-in-time from a bad delete.
Protect blobs with soft-delete, versioning, and legal hold - Lab Exercises
Note: This lab pre-provisions Azure resources at start — allow up to 10 minutes for the environment to become ready before beginning the exercises.
Seed 10 audit blobs, prove soft-delete + versioning recovers a deleted or overwritten blob, then layer a legal hold on top and observe the compound protection. Immutability policies are covered conceptually only — locking one strands the storage account for the entire retention window, so we teach the concept via the agent's narrative rather than by running the CLI.
Document management system architecture and production readiness
Ties every course concept together — designing a multi-tenant document management system with SAS uploads, blob tags for search, lifecycle for cost, immutability for compliance, and MI auth for the app. The paired capstone hands-on builds it.
Ship the Anchorline document management system end-to-end - Capstone Lab Exercises
Note: This lab pre-provisions Azure resources at start — allow up to 12 minutes for the environment to become ready before beginning the exercises.
Deploy the Anchorline DMS. Upload docs for two tenants using the SAS-direct pattern, register metadata + tags via the API, search across tags, then verify tenant isolation by attempting to search across tenants.