Cloud & Architecture
Amazon AWS SAA-C03: Decoupling Workloads with SQS
Amazon SQS decouples producers from consumers by giving them a durable queue between request creation and processing. The producer does not need the worker to be available at the same moment; the worker can process at its own pace, scale horizontally, retry transient failures, and survive temporary downstream outages. This simple buffer can remove synchronous dependencies from web requests, batch pipelines, image processing, integration work, and other distributed systems. Current AWS documentation distinguishes Standard and FIFO queues. Standard queues provide very high, nearly unlimited API throughput, at-least-once delivery, and best-effort…
Amazon AWS SAA-C03: Control Tower for Growing Environments
AWS Control Tower provides a managed way to establish and govern a multi-account AWS environment on top of AWS Organizations. It creates or integrates landing-zone components, applies controls, supports governed organizational units, and provides account provisioning workflows through Account Factory. The value is consistency: new accounts can inherit organization structure, central logging, security roles, control baselines, and identity integration without every platform team rebuilding those foundations manually. AWS Control Tower has changed materially in recent versions. Landing zone version 4.0, released in late 2025, introduced a more flexible Controls-Only experience,…
Amazon AWS SAA-C03: AWS Organizations Design Patterns
AWS Organizations is the foundation for governing a multi-account AWS environment. It provides the organization root, organizational units, member accounts, consolidated billing, delegated administration, and policy types such as service control policies. The architecture challenge is not creating the organization. It is designing an OU and account model that can support security, workload autonomy, cost ownership, compliance, and service delegation without turning the management account into the place where every cloud task must be performed. AWS’s current Organizations guidance recommends keeping workloads out of the management account, restricting access to…
Microsoft AZ-104: Windows Server Hybrid Management
Windows Server hybrid management increasingly uses Azure Arc to project on-premises and multicloud Windows Server machines into the Azure control plane. Once a server is Arc-enabled, organizations can use Azure RBAC, tags, Policy, monitoring, extensions, Update Manager, Defender capabilities, and other Azure services against a consistent resource identity. The architecture does not replace Active Directory, Configuration Manager, Windows Admin Center, or workload-specific management automatically; it gives platform teams a cloud management plane that can unify selected operations across locations. Microsoft’s current Azure Arc documentation supports deploying and updating VM extensions…
Microsoft AZ-104: Virtual WAN Design Choices
Azure Virtual WAN is a Microsoft-managed networking service for connecting branches, virtual networks, remote users, ExpressRoute circuits, and network virtual appliances through managed virtual hubs. It can simplify global transit compared with building and operating large custom hub-and-spoke route tables, but the managed control plane introduces its own design choices around hub placement, Standard versus Basic tier, routing tables, routing intent, secured hubs, inter-hub traffic, branch connectivity, and migration from existing networks. Microsoft’s current Virtual WAN guidance describes routing intent as a declarative way to send private and internet traffic…
Microsoft AZ-104: VPN Gateway Design on Azure
Azure VPN Gateway provides encrypted connectivity for site-to-site, point-to-site, and VNet-to-VNet scenarios. A production design is not complete when one IPsec tunnel connects. The architecture needs an appropriate gateway SKU, zone strategy, active-active or active-standby mode, BGP where dynamic routing adds value, redundant on-premises VPN devices, connection and route limits, authentication choices, and a tested failure path. Microsoft’s current VPN Gateway guidance recommends AZ-capable gateway SKUs for new deployments and documents active-active designs where both Azure gateway instances use separate public IPs. For maximum site-to-site reliability, Microsoft shows dual-redundancy active-active…
Microsoft AZ-104: Subscription Design for Azure Estates
Azure subscriptions are more than billing containers. They are policy, RBAC, quota, deployment, lifecycle, and operational boundaries. Microsoft’s current landing-zone guidance treats subscriptions as foundational scale units and recommends “subscription democratization”: platform teams provide governed subscriptions to workload teams, and workload teams operate inside those guardrails. A scalable estate therefore needs subscription patterns that are easy to vend, place in management groups, budget, secure, and retire. Subscription design should start with workload and operating-model boundaries rather than arbitrary resource counts. Environment separation, regulatory boundaries, product ownership, regional architecture, quotas, delegated…
Microsoft AZ-104: Resource Locks and Operational Safety
Azure resource locks protect management-plane resources from accidental deletion or modification even when a user otherwise has sufficient RBAC permission. Azure supports two primary lock levels: CanNotDelete, which blocks deletion while still allowing authorized updates, and ReadOnly, which blocks updates and deletion. Because locks override user permissions at the management plane and inherit from parent scopes, they are powerful safety controls—but they can also break legitimate operations if applied without understanding the resource lifecycle. Microsoft’s current guidance is explicit that locks are not an authorization substitute. Azure RBAC grants permissions;…
Microsoft AZ-104: Management Groups That Scale
Azure management groups are the governance hierarchy above subscriptions. They let platform teams apply Azure Policy, role assignments, and compliance conditions to groups of subscriptions instead of repeating configuration one subscription at a time. That makes the hierarchy a control-plane architecture decision: the shape of the tree determines what inherits, who can administer which scope, how new subscriptions are placed, and how easy it is to explain why a workload receives a particular policy. Microsoft’s current Cloud Adoption Framework recommends a relatively simple management-group hierarchy aligned to the Azure landing…
Microsoft AZ-104: Hybrid Identity for Azure Admins
Hybrid identity connects on-premises Active Directory with Microsoft Entra ID so users, groups, devices, applications, and authentication can span datacenter and cloud environments. For Azure administrators, the architecture is no longer simply “install Entra Connect.” Microsoft now positions Microsoft Entra Cloud Sync as the strategic direction for most directory-synchronization scenarios, while Connect Sync remains necessary for capabilities that Cloud Sync does not yet support. Authentication choice—password hash synchronization, pass-through authentication, or federation—is a separate decision from object synchronization. Microsoft’s current 2026 guidance explicitly recommends evaluating Cloud Sync for eligible organizations…
Microsoft AZ-104: Front Door or Application Gateway?
Azure Front Door and Azure Application Gateway are both Layer 7 services for HTTP and HTTPS, but their scope is fundamentally different. Front Door is a global edge service that accepts traffic at Microsoft’s distributed points of presence, can route across regions, provide CDN acceleration, perform global health-based failover, and apply WAF at the edge. Application Gateway is a regional service deployed with virtual-network integration for regional HTTP routing, TLS termination, backend pools, private addresses, and optional WAF. Microsoft’s current internet-ingress guidance recommends Front Door for most multi-region HTTP/S applications…
Microsoft AZ-104: FSLogix for Azure Virtual Desktop
FSLogix is the profile-virtualization layer Microsoft recommends for Azure Virtual Desktop. It places a user’s Windows profile inside a VHD or VHDX container stored on supported remote storage and attaches that container at sign-in. The user receives a normal Windows profile experience while pooled or replaceable session hosts remain largely stateless. The technology solves a simple architectural problem—separate user state from host lifecycle—but production reliability depends heavily on storage, identity, security, container settings, and support procedures. Microsoft’s current guidance recommends Azure Files or Azure NetApp Files for FSLogix Profile Containers…
Microsoft AZ-104: ExpressRoute Resiliency Patterns
ExpressRoute is built with redundant connectivity inside Microsoft’s network, but one circuit at one peering location does not protect the entire hybrid path from every failure. Enterprise resiliency depends on circuit design, provider diversity, peering-location diversity, on-premises edge devices, cross-connects, BGP sessions, virtual network gateways, regional topology, and fallback paths. The business outcome is private connectivity that continues through maintenance, device failure, provider failure, and—where required—peering-site or regional failure. Microsoft’s current ExpressRoute guidance describes Standard, High, and Maximum resiliency options. Current Well-Architected guidance recommends Maximum resiliency for critical workloads: multiple…
Microsoft AZ-104: Designing Recovery with Azure Backup
Azure Backup design starts with recovery requirements, not with creating a vault. The workload team needs to define what must be recoverable, how much data loss is acceptable, how quickly restores must complete, which failures the backup protects against, who can authorize destructive changes, and how recovery continues if the primary region or administrator account is compromised. Azure Backup then becomes one part of a broader recovery architecture alongside application-native replication, snapshots, Site Recovery, and business runbooks. Microsoft’s current Azure Backup guidance emphasizes vault redundancy, soft delete, immutable vaults, multi-user…
Microsoft AZ-104: Designing Azure Firewall Egress
Azure Firewall egress design controls which workloads can reach external destinations, how that traffic is inspected, which source addresses outside systems see, and how operators prove that a flow was permitted. A strong design combines routing, Firewall Policy, network and application rules, DNS, FQDN handling, source NAT, private endpoints, logging, and workload identity or application controls where network information alone is insufficient. Microsoft’s current Azure Firewall guidance distinguishes network rules from application rules and supports FQDN filtering in different ways. Application rules can filter HTTP/S and MSSQL traffic by requested…