Session
Building a Secure Azure Landing Zone from the Ground Up with Bicep
In this workshop, you'll build a secure Azure environment from an empty subscription, one piece at a time, and learn how private endpoints, DNS zones, subnets, NSGs, and RBAC work together along the way.
Throughout the day, you'll write the Bicep for a complete landing zone, covering networking, private connectivity, identity, and a WAF-protected front end, and deploy the landing zone resources with GitHub Actions.
You'll learn how to:
- Design a VNet with dedicated subnets for private endpoints, App Gateway, and VNet-integrated apps
- Deploy private endpoints and link the private DNS zones that make them resolve
- Put App Gateway with a Web App Firewall (WAF) in front of an App Service that has public access disabled
- Replace keys and connection strings with managed identities and scoped RBAC
- Restrict a Function App to Event Grid traffic with access restrictions
- Connect Azure AI Search to Azure OpenAI through a shared private link
- Structure Bicep into reusable modules and deploy it through GitHub Actions with OIDC
- Verify that the deployed resources are private and correctly configured
Prerequisites:
- A laptop with VS Code (with the Bicep extension), the Azure CLI, PowerShell 7, and Git installed
- A GitHub account
- An Azure subscription where you have Owner rights, or Contributor plus User Access Administrator, so you can create resources and assign roles
- Azure OpenAI quota for a chat model and an embedding model in the region you'll deploy to
- Familiarity with the Azure portal. Bicep or ARM experience helps but isn't required.
Brian Gorman
Microsoft Azure MVP, Speaker, Author, Trainer, and .Net Developer
Waterloo, Iowa, United States
Links
Please note that Sessionize is not responsible for the accuracy or validity of the data provided by speakers. If you suspect this profile to be fake or spam, please let us know.
Jump to top