A free 52-chapter field guide

AI-Native Cloud on Microsoft Azure

From Zero to Production

This plain-English Microsoft Azure tutorial takes you from account signup and billing safety to secure global AI systems. You will learn every major cloud decision through portal walkthroughs, Azure CLI, PowerShell, Bicep, Terraform, diagrams, real screenshots, production checklists, and hands-on capstones.

Chapters
52
Learning parts
10
Capstones
3
Microsoft Foundry home page for building AI apps and agents on Azure
The book uses genuine Microsoft Azure and Microsoft Learn screens, with sources and capture dates recorded in the manuscript.

What will you learn?

You will learn Azure as one connected operating system: identity controls access, networks control paths, platforms run code, data services preserve truth, automation makes change repeatable, and governance keeps the whole system safe and affordable.

  • Signup, portal, Cloud Shell, tools, and cost safety
  • Entra ID, RBAC, private networks, storage, and Key Vault
  • VMs, App Service, Functions, containers, AKS, and APIs
  • SQL, Cosmos DB, messaging, analytics, and managed caching
  • Microsoft Foundry, Azure OpenAI, RAG, agents, and evaluation
  • Bicep, Terraform, CI/CD, GitOps, security, recovery, and FinOps
  • Landing zones, hybrid cloud, multi-tenant SaaS, and global systems
  • Beginner, governed-AI, and regulated-enterprise capstones

What is inside the complete Microsoft Azure book?

The sequence starts with safe foundations, then adds application, data, AI, automation, operations, enterprise, and advanced architecture skills. Every chapter is available as a direct link for study, search, and citation.

PART 01

Start Here

  1. 00About This Book: Your Azure Journey from Zero to Production
  2. 01Cloud Computing and Microsoft Azure from First Principles
  3. 02Create Your Microsoft Account and Azure Subscription Safely
  4. 03Tour the Azure Portal, Cloud Shell, Subscriptions, Tenants, and Regions
  5. 04Install Azure CLI, Azure PowerShell, VS Code, Git, Bicep, and Terraform
  6. 05Prevent Surprise Azure Bills with Budgets, Alerts, Tags, and Cleanup
PART 02

Azure Foundations

  1. 01Azure Resource Manager: Resource Groups, Providers, Tags, Locks, and IDs
  2. 02Microsoft Entra ID, Azure RBAC, Service Principals, and Managed Identities
  3. 03Azure Networking: VNets, Subnets, NSGs, Routes, DNS, NAT, Peering, and Private Endpoints
  4. 04Azure Storage: Blobs, Files, Queues, Tables, Redundancy, Security, and Lifecycle
  5. 05Azure Key Vault: Secrets, Keys, Certificates, Rotation, and Private Access
PART 03

Compute and Application Hosting

  1. 01Azure Virtual Machines, Disks, Images, Scale Sets, Bastion, and Updates
  2. 02Azure App Service: Web Apps, Configuration, Scaling, and Deployment Slots
  3. 03Azure Functions: Event-Driven Serverless Applications
  4. 04Azure Container Registry, Container Apps, and Container Jobs
  5. 05Azure Kubernetes Service from First Cluster to Production Baseline
  6. 06API Management, Front Door, Application Gateway, Load Balancer, and Traffic Manager
PART 04

Data and Integration

  1. 01Azure SQL, PostgreSQL, and MySQL: Choosing and Operating Relational Databases
  2. 02Azure Cosmos DB: Partitioning, Consistency, Indexing, Throughput, and Global Distribution
  3. 03Azure Messaging: Service Bus, Event Grid, Event Hubs, and Reliable Patterns
  4. 04Data Factory, Microsoft Fabric, Azure Databricks, and Data Lake Architecture
  5. 05Azure Managed Redis, Caching, Sessions, and Distributed State
PART 05

AI-Native Azure

  1. 01Microsoft Foundry and Azure OpenAI: Projects, Models, Deployments, Quotas, and Safety
  2. 02Prompt Engineering, Structured Outputs, Model Routing, and Token Economics
  3. 03Retrieval-Augmented Generation with Azure AI Search
  4. 04Azure AI Services: Document Intelligence, Speech, Vision, Language, and Content Processing
  5. 05Agentic Applications: Tools, Memory, Workflows, and Human Approval
  6. 06AI Evaluation, Tracing, Responsible AI, Safety, and Red Teaming
  7. 07Production AI Lab: Build the Northstar Governed RAG Assistant
PART 06

Infrastructure and Delivery

  1. 01Azure Bicep and ARM from Zero: Repeatable Infrastructure
  2. 02Terraform on Azure: Providers, Modules, Remote State, Plans, Imports, and Drift
  3. 03GitHub Actions and Azure DevOps CI/CD for Azure
  4. 04GitOps, Progressive Delivery, Feature Flags, and Rollback
  5. 05Azure Developer CLI and Repeatable Developer Environments
PART 07

Security Governance and Operations

  1. 01Azure Governance: Management Groups, Policy, Initiatives, and Landing Zones
  2. 02Microsoft Defender for Cloud, Microsoft Sentinel, and Cloud Incident Response
  3. 03Azure Monitor, Log Analytics, Application Insights, Alerts, Dashboards, and SLOs
  4. 04Azure Backup, Site Recovery, Multi-Region Design, RTO, and RPO
  5. 05Azure FinOps: Cost Allocation, Budgets, Reservations, Savings Plans, and Right-Sizing
  6. 06Azure Well-Architected Framework and Production Readiness Review
PART 08

Enterprise and Hybrid

  1. 01Enterprise Azure Networking: Hub-Spoke and Azure Virtual WAN
  2. 02ExpressRoute, VPN Gateway, Azure Arc, and Hybrid Cloud Management
  3. 03Private DNS, Private Link, Azure Firewall, DDoS Protection, and Zero Trust Networking
  4. 04Enterprise Lab: Implement an Azure Landing Zone
PART 09

Advanced Architecture

  1. 01Multi-Tenant SaaS on Azure: Isolation, Identity, Data, Scale, and Deployment Stamps
  2. 02Event-Driven Microservices and Distributed-System Reliability on Azure
  3. 03Global Azure Architecture: Active-Active, Data Consistency, Traffic, and Disaster Tolerance
  4. 04Azure Platform Engineering: Golden Paths, Internal Developer Platforms, and Policy as Code
PART 10

Capstones and Reference

  1. 01Beginner Capstone: Deploy a Secure Azure Web Application
  2. 02AI Capstone: Deploy a Governed RAG Assistant on Azure
  3. 03Enterprise Capstone: Design a Regulated Azure Landing Zone and AI Workload
  4. 04Azure Service Decision Map, Command Reference, Certification Path, Glossary, and Next Steps

How should you use the portal, CLI, and infrastructure as code?

Use the portal to discover and inspect, Cloud Shell for a ready terminal, CLI or PowerShell for repeatable operations, and Bicep or Terraform for reviewed environments. The chapters explain when an option is appropriate instead of pretending every Azure action has five interchangeable interfaces.

Continue the AI-native path

Pair this cloud book with the existing Digital FTEs: Engineering curriculum and AI-Native Sales. For enterprise implementation, explore AI Native Consulting and Forward Deployed Engineering.

Frequently asked questions

Is this Microsoft Azure tutorial suitable for a complete beginner?
Yes. The book begins with cloud vocabulary, Microsoft account and Azure subscription signup, portal navigation, tool installation, and billing safety before it creates application resources. Experienced readers can jump directly to the service, architecture, or capstone they need.
Does the book teach the Azure portal and automation?
Yes. Technical chapters show the current portal path and Azure CLI, Azure PowerShell, Bicep, or Terraform options whenever those interfaces genuinely apply. The book says when an interactive identity, consent, or commercial step cannot be replaced by infrastructure as code.
Can the Azure labs create charges?
Some labs can create billable resources. Every hands-on section identifies cost risks and cleanup. Readers should create budgets, use the smallest suitable learning tiers, confirm the active subscription, delete isolated lab resource groups, and check Cost Management afterward.
Does the book cover Azure AI Foundry and Azure OpenAI?
Yes. The current product name is Microsoft Foundry, formerly Azure AI Foundry. The AI-native section covers model deployment, Azure OpenAI, RAG with Azure AI Search, document and speech services, agents, tool safety, evaluation, tracing, red teaming, and production operations.
How advanced does the Azure book become?
It progresses through CI/CD, GitOps, governance, Defender, Sentinel, observability, disaster recovery, FinOps, landing zones, hybrid networking, multi-tenant SaaS, global active-active design, platform engineering, and three production-shaped capstones.

Start safely, then build for production

Begin with the account, identity, and cost chapters. If your organization needs a secure landing zone or AI platform, discuss the architecture before creating expensive shared infrastructure.