Module 01: Identity & Governance

Master identity management, access control, and governance in Azure
🟡 Beginner to Advanced ⏱ 765 Minutes (12.75 Hours) 📘 AZ-104 · Module 01 · 8 Labs
Why This Matters

Identity and governance are the foundation of secure, compliant Azure deployments. This comprehensive module covers everything from managing users and groups (Entra ID) to enterprise-scale governance, security hardening, cost control, and compliance. Master the patterns used by Fortune 500 companies managing thousands of resources across multiple departments.

Module Overview

Module 01 teaches you how to control access to Azure resources through identity and governance. You'll learn about Microsoft Entra ID (formerly Azure AD) for managing users and groups, RBAC for granting permissions, and Management Groups with Azure Policy for governance at scale.

These are the critical skills for administering Azure securely and ensuring compliance across your organization.

Concepts

01 - Entra ID Overview

Learn Microsoft's cloud identity service — how to create users, groups, administrative units, and manage identities at scale.

Read Concept →

02 - RBAC Fundamentals

Master Role-Based Access Control — the system for granting permissions to Azure resources based on roles.

Read Concept →

03 - Management Groups & Azure Policy

Understand how to organize subscriptions, enforce policies, and govern Azure at scale across your organization.

Read Concept →

04 - Access Control Scenarios

Explore real-world patterns for implementing secure access control in complex organizational structures.

Read Concept →

05 - Identity Best Practices

Learn industry best practices for identity management, security, and governance in Azure environments.

Read Concept →

Hands-On Labs (8 Complete Labs)

Apply your knowledge with practical labs that cover everything from identity management to enterprise-scale governance, security hardening, and compliance.

Beginner Tier (125 min)

Lab 01 - Entra Users & Groups

Create users, organize them into groups, and set up administrative units for delegated management. (50 min)

Start Lab →

Lab 02 - RBAC & Azure Policy

Assign RBAC roles, create custom roles, and enforce Azure Policies across subscriptions. (45 min)

Start Lab →

Lab 03 - Management Groups

Create management group hierarchies and organize subscriptions for centralized governance. (30 min)

Start Lab →

Intermediate Tier (310 min)

Lab 04 - Environment Segregation

Segregate Dev/Staging/Prod with different access levels and policies to protect production. (120 min) ⭐⭐⭐⭐⭐

Start Lab →

Lab 05 - Cost Management

Implement tagging, budgets, and policies to control cloud costs by department. (90 min) ⭐⭐⭐⭐

Start Lab →

Lab 06 - Department Delegation

Create multi-department isolation with autonomous management and central IT oversight. (100 min) ⭐⭐⭐⭐

Start Lab →

Advanced Tier (330 min)

Lab 07 - Identity Security Hardening

Implement all 8 best practices: least privilege, access reviews, MFA, monitoring, approvals, offboarding, and more. (250+ min) ⭐⭐⭐⭐⭐

Start Lab →

Lab 08 - Compliance & Audit

Set up activity logging, immutable audit trails, and compliance policies for SOC 2 readiness. (80 min) ⭐⭐⭐

Start Lab →

Recommended Learning Path

  1. Start here: Read Entra ID Overview to understand identity management
  2. Then: Read RBAC Fundamentals to understand access control
  3. Next: Read Management Groups & Policy to understand governance
  4. Explore: Read Access Control Scenarios for real-world patterns
  5. Master: Read Identity Best Practices
  6. Practice Beginner: Complete Lab 01, Lab 02, and Lab 03 for foundational skills
  7. Enterprise Patterns: Complete Lab 04 (environment segregation), Lab 05 (cost management), and Lab 06 (department delegation)
  8. Advanced Security: Complete Lab 07 to learn all 8 identity best practices and security hardening
  9. Compliance Ready: Complete Lab 08 to prepare for SOC 2 audits and implement compliance infrastructure