Short, honest write-ups of the ideas that come up in interviews and on the job. Each one teaches the concept properly, cites the Microsoft documentation, and points back to the class that drills it until it sticks.
Nine notes folded into one: how a definition is built, the eleven effects and the order they run in, why remediation needs a managed identity, exemptions versus exclusions, and the five guardrails to assign first — allowed locations, tags, no public IPs, diagnostic settings, and a custom definition — with verified built-in names and CLI.
A shared vault per environment is easy to run — and puts every team's secrets one over-broad role apart. Blast radius, throttling, RBAC boundaries, and the recommended default.
The portal keeps sign-in logs only briefly. Export them to Log Analytics, storage, and a SIEM — then query, alert, and keep the history an investigation needs. With the KQL you'll actually use.
An isolated US-government cloud for agencies and contractors — FedRAMP High, DoD Impact Levels, separate endpoints. Commercial vs Government, and what differs for engineers.
Someone with legitimate delete rights fat-fingers the wrong resource group and the production database goes with it. Resource locks make that specific disaster impossible — even for people who are allowed to delete.
One subscription is easy to govern. Fifty is a nightmare if you configure each by hand. Management groups are the layer above subscriptions where you set a rule once and let inheritance push it to all of them.
Three roles cover most of what you do — and the difference between two of them is the most common access mistake in the cloud. Contributor builds everything and grants nothing; that gap is the whole point.
The prepared runway: what a landing zone is, the eight design areas, the six CAF phases around it, and the Corp vs Online fork — which splits workloads by connectivity intent, not importance. Includes the honest case for small shops not building the full tree.