Case study · Cloud administration
Azure administration lab: CLI provisioning, cost controls and private storage with RBAC
A pay-as-you-go DevTest subscription used to practise Azure administration beyond tenant-level troubleshooting, with cost governance and least-privilege access configured before anything that could incur a bill.
At a glance
Key facts
- Subscription
- Pay-as-you-go DevTest
- Tooling
- Azure CLI
- Cost control
- Monthly budget with an Action Group
- Storage
- Private blob storage, public access disabled
- Access
- Storage Blob Data Contributor via RBAC
- Azure
- Azure CLI
- RBAC
- Blob Storage
- Cost Management
Context
At work, Azure and Entra ID administration happens inside an established enterprise tenant with its own subscriptions, policies and change process. That is valuable experience, but it does not cover setting up a subscription from nothing.
This lab exists to work through subscription-level administration from scratch: creating resources, controlling spend and granting access the way a production environment should, using the CLI rather than the portal so that each step is explicit and repeatable.
What was built
- Resource groups and resources created and managed through Azure CLI.
- A monthly budget with an Action Group for cost notifications, configured before any chargeable resource.
- A private blob storage account with public access disabled.
- The Storage Blob Data Contributor role assigned through RBAC to the identity that needed to work with the data.
Validation
Access was tested rather than assumed. Blob upload and listing operations were run as the authenticated identity against the private storage and confirmed to succeed with the RBAC assignment in place.
Why this order
Cost governance and access control were configured first because they are cheaper to get right up front than to retrofit. A budget alert that exists before the first resource catches mistakes early, and a least-privilege role assigned before any data is present means nothing was ever reachable more broadly than intended.
How this connects to day-to-day work
The lab is the counterpart to the Entra ID and Intune administration I do at Lockton. Identity, RBAC and Conditional Access concepts carry across directly; the lab adds the subscription, resource and cost layers that a service-delivery role does not normally touch.
Scope
What this does not claim
- No virtual machines, virtual networks or other compute have been deployed in this lab yet, and this page does not claim them.
- AZ-104 study is ongoing, with the exam planned for early 2027.
More