Catalog / CLD-900
CLD-900Best sellerAzure Expert Bootcamp
Enterprise-scale Azure architecture: landing zones, identity, hybrid networking, governance, and migration strategy - taught at review depth.
About this program
This is not certification cramming. Over eight weeks the program works through the architecture decisions that define enterprise Azure estates: landing-zone design aligned to the Cloud Adoption Framework, identity boundaries with Microsoft Entra ID, hybrid networking, governance at scale, and migration strategy. Every topic is treated the way an architecture review board would treat it: options, trade-offs, and defensible decisions.
Who this is for
- Cloud engineers moving into Azure architecture ownership
- Architects standardizing an enterprise Azure estate
- Consultants and delivery leads who design for regulated environments
What you will be able to do
- Design enterprise-scale landing zones with clear subscription and management-group strategy
- Architect identity, access, and privileged-access patterns with Microsoft Entra ID
- Design hybrid networks spanning hub-spoke, Virtual WAN, ExpressRoute, and private connectivity
- Stand up governance with Azure Policy, cost guardrails, and Azure Arc for hybrid coverage
Program modules
Delivered over 8 weeks of live tutor-led sessions, applied work, and structured review.
Enterprise-scale foundations
- Cloud Adoption Framework and landing-zone architecture
- Management groups, subscription strategy, and environment separation
- Resource organization, naming, and tagging that scales
- Platform versus application landing zones
Identity and access architecture
- Microsoft Entra ID tenant design and identity boundaries
- Privileged Identity Management and just-in-time access
- Workload identities, managed identities, and service principals
- Cross-tenant collaboration and B2B patterns
Hybrid networking
- Hub-spoke and Virtual WAN topologies compared
- ExpressRoute, VPN, and connectivity resilience design
- Private endpoints, Private Link, and DNS architecture
- Network security: firewalls, NSGs, and segmentation strategy
Governance and policy at scale
- Azure Policy: initiatives, exemptions, and enforcement strategy
- Cost management guardrails and budget controls
- Azure Arc for governing hybrid and multicloud resources
- Compliance mapping for regulated environments
Compute and data platform selection
- IaaS, App Service, containers, and serverless: a selection framework
- AKS as an enterprise platform: when and how
- Data platform options: Azure SQL, PostgreSQL, Cosmos DB
- Integration patterns: messaging, events, and APIs
Migration strategy
- Assessment with Azure Migrate and estate classification
- Wave planning and dependency management
- Cutover design, rollback, and validation
- Post-migration optimization and operating handover
Resilience, continuity, and observability
- Region and zone architecture for availability targets
- Backup and disaster-recovery design with Azure services
- Azure Monitor, Log Analytics, and alerting architecture
- Testing resilience: game days and failover rehearsal
Architecture review capstone
- Assembling a full estate design from program artifacts
- Writing the architecture summary for a review board
- Live architecture review with structured critique
- Personal roadmap: applying the design in your environment
Hands-on components
- Dedicated Azure lab subscription for landing-zone and networking builds
- Policy-as-code and governance exercises against a live estate
- Capstone estate design defended in a live architecture review
Ready to apply?
Apply any time. Admissions reviews your fit, confirms the next available cohort, and issues an invoice. Your seat is confirmed on payment.