<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:dc="http://purl.org/dc/elements/1.1/">
  <channel>
    <title>DEV Community: Adams Adam</title>
    <description>The latest articles on DEV Community by Adams Adam (@adams_adam_02860737759bbb).</description>
    <link>https://dev.to/adams_adam_02860737759bbb</link>
    <image>
      <url>https://media2.dev.to/dynamic/image/width=90,height=90,fit=cover,gravity=auto,format=auto/https:%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Fuser%2Fprofile_image%2F3952629%2F6ac2be91-a8ba-4e88-9c01-dde191be25e9.jpg</url>
      <title>DEV Community: Adams Adam</title>
      <link>https://dev.to/adams_adam_02860737759bbb</link>
    </image>
    <atom:link rel="self" type="application/rss+xml" href="https://dev.to/feed/adams_adam_02860737759bbb"/>
    <language>en</language>
    <item>
      <title>Creating a Resource Group, and an Azure Blob Storage account, using the Azure Portal</title>
      <dc:creator>Adams Adam</dc:creator>
      <pubDate>Tue, 22 Sep 2026 12:21:17 +0000</pubDate>
      <link>https://dev.to/adams_adam_02860737759bbb/creating-a-resource-group-and-an-azure-blob-storage-account-using-the-azure-portal-2n8a</link>
      <guid>https://dev.to/adams_adam_02860737759bbb/creating-a-resource-group-and-an-azure-blob-storage-account-using-the-azure-portal-2n8a</guid>
      <description>&lt;h2&gt;
  
  
  Method 1: Creating Storage via the Azure Portal (Beginner-Friendly)
&lt;/h2&gt;

&lt;p&gt;This is the easiest way to provision the storage account visually.&lt;/p&gt;

&lt;h3&gt;
  
  
  Step 1: Navigate to Azure Portal
&lt;/h3&gt;

&lt;p&gt;Go to the &lt;a href="https://portal.azure.com/" rel="noopener noreferrer"&gt;Azure Portal&lt;/a&gt;.&lt;br&gt;
Log in with your credentials.&lt;br&gt;
&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fbhumjc2kr1484jp8xvvy.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fbhumjc2kr1484jp8xvvy.png" alt=" " width="446" height="480"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;h3&gt;
  
  
  Step 2: In the search bar at the top, type &lt;strong&gt;"Resource Group"&lt;/strong&gt; and select the Review + create.
&lt;/h3&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fri11afp6wpplhhgfxrx6.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fri11afp6wpplhhgfxrx6.png" alt=" " width="800" height="628"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;Click &lt;strong&gt;"+ Create"&lt;/strong&gt; (or "Create resource").&lt;br&gt;
&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fv6fdmze90x07e1vrev74.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fv6fdmze90x07e1vrev74.png" alt=" " width="800" height="640"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;ol&gt;
&lt;li&gt;In the search bar at the top, type &lt;strong&gt;"Storage accounts"&lt;/strong&gt; and select the service.&lt;/li&gt;
&lt;li&gt;Click &lt;strong&gt;"+ Create"&lt;/strong&gt; (or "Create resource").&lt;/li&gt;
&lt;/ol&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2F9wcn7xzkqhu3j4ngzvlo.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2F9wcn7xzkqhu3j4ngzvlo.png" alt=" " width="800" height="640"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;h3&gt;
  
  
  Step 3: Configure the Storage Account
&lt;/h3&gt;

&lt;p&gt;Fill out the details for your new storage account:&lt;br&gt;
&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fj6e4x2ad1q1upxqmet0b.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fj6e4x2ad1q1upxqmet0b.png" alt=" " width="800" height="640"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;ol&gt;
&lt;li&gt;
&lt;strong&gt;Subscription:&lt;/strong&gt; Select the Azure subscription where you want to 
deploy the resource.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Resource Group:&lt;/strong&gt; Select an existing Resource Group or create a new 
one for organization.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Storage Account Name:&lt;/strong&gt; Choose a globally unique name (must be 
lowercase letters and numbers).&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Region:&lt;/strong&gt; Select the Azure region closest to your users or 
applications.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Performance:&lt;/strong&gt; Choose the appropriate performance tier (LRS, GRS, 
ZRS). &lt;strong&gt;GRS (Geo-Redundant Storage)&lt;/strong&gt; is often recommended for high 
availability.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Redundancy:&lt;/strong&gt; Choose the replication level.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Location:&lt;/strong&gt; Confirm the region.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Account Tier:&lt;/strong&gt; Select the appropriate access tier (e.g., Hot, Cool, 
or Archive).&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Access Tier (Optional):&lt;/strong&gt; Configure access policies and security 
settings here.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Review + Create:&lt;/strong&gt; Review your settings and click &lt;strong&gt;"Create."&lt;/strong&gt;
&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2F80a4rdpqae302pxnk0qt.png" alt=" " width="800" height="640"&gt;
&lt;/li&gt;
&lt;/ol&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fbkyd62n0yc2er9vpi2aw.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fbkyd62n0yc2er9vpi2aw.png" alt=" " width="800" height="640"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;h3&gt;
  
  
  Step 4: Post-Creation Access and Setup
&lt;/h3&gt;

&lt;p&gt;Once the deployment is complete:&lt;/p&gt;

&lt;ol&gt;
&lt;li&gt;&lt;strong&gt;Navigate to your new Storage Account.&lt;/strong&gt;&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Create Blobs:&lt;/strong&gt; Navigate to the &lt;strong&gt;"Containers"&lt;/strong&gt; section. &lt;/li&gt;
&lt;/ol&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Flrew56l3i6eh8r40bbaq.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Flrew56l3i6eh8r40bbaq.png" alt=" " width="800" height="640"&gt;&lt;/a&gt;&lt;br&gt;
Here you can create your initial blob containers (folders) where you will &lt;br&gt;
store your files.&lt;/p&gt;

&lt;p&gt;Select Add container &lt;/p&gt;

&lt;ol&gt;
&lt;li&gt;Container name&lt;/li&gt;
&lt;li&gt;Select-Container (anonymous read access container and blobs)&lt;/li&gt;
&lt;li&gt;Create&lt;/li&gt;
&lt;/ol&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2F7r7sfxm1j1imrl8trekm.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2F7r7sfxm1j1imrl8trekm.png" alt=" " width="800" height="640"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;h3&gt;
  
  
  All Azure Services
&lt;/h3&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fmn5tym7uzi3et6hc4vxj.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fmn5tym7uzi3et6hc4vxj.png" alt=" " width="800" height="640"&gt;&lt;/a&gt;&lt;/p&gt;

</description>
      <category>azure</category>
      <category>beginners</category>
      <category>cloud</category>
      <category>tutorial</category>
    </item>
    <item>
      <title>What I Learned Building IAM and RBAC on Azure</title>
      <dc:creator>Adams Adam</dc:creator>
      <pubDate>Wed, 16 Sep 2026 16:02:10 +0000</pubDate>
      <link>https://dev.to/adams_adam_02860737759bbb/what-i-learned-building-iam-and-rbac-on-azure-256g</link>
      <guid>https://dev.to/adams_adam_02860737759bbb/what-i-learned-building-iam-and-rbac-on-azure-256g</guid>
      <description>&lt;p&gt;As part of my Azure learning journey, I recently worked on a hands-on lab focused on &lt;strong&gt;Identity and Access Management (IAM)&lt;/strong&gt; and &lt;strong&gt;Role-Based Access Control (RBAC)&lt;/strong&gt; in Microsoft Azure.&lt;/p&gt;

&lt;p&gt;Before this lab, IAM and RBAC sounded like concepts mainly used by cybersecurity and cloud professionals. After working with them practically, I understood that they are really about one simple question:&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Who should be allowed to do what, and where?&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fcisfe8hjiz4o7avor582.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fcisfe8hjiz4o7avor582.png" alt=" " width="800" height="388"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;h2&gt;
  
  
  IAM and RBAC in Plain English
&lt;/h2&gt;

&lt;p&gt;&lt;strong&gt;Identity and Access Management (IAM)&lt;/strong&gt; is the process of controlling who can access a company's systems, applications, data, and cloud resources.&lt;/p&gt;

&lt;p&gt;Think of an office building. Not everyone who enters the building should have access to every room. An employee may have access to their department, while the finance team may have access to financial records. The security team may have access to security systems.&lt;/p&gt;

&lt;p&gt;Cloud environments work in a similar way.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Role-Based Access Control (RBAC)&lt;/strong&gt; takes this a step further by assigning permissions based on a person's job or role.&lt;/p&gt;

&lt;p&gt;For example:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;A developer may need permission to deploy and manage applications.&lt;/li&gt;
&lt;li&gt;An accountant may only need access to financial information.&lt;/li&gt;
&lt;li&gt;An auditor may need to view resources but should not be able to modify them.&lt;/li&gt;
&lt;li&gt;A junior employee may only need limited access to specific resources.
&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fud41tkrtz7vt1pblg2kq.png" alt=" " width="800" height="571"&gt;
&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;The important principle is &lt;strong&gt;least privilege&lt;/strong&gt;: give users only the access they need to perform their responsibilities.&lt;/p&gt;

&lt;h2&gt;
  
  
  What Can Go Wrong Without Proper IAM and RBAC?
&lt;/h2&gt;

&lt;p&gt;During the lab, I realized that access control is not just an administrative task. Poor access management can create serious security and operational problems.&lt;/p&gt;

&lt;h3&gt;
  
  
  1. A careless or disgruntled employee could delete production resources
&lt;/h3&gt;

&lt;p&gt;Imagine an employee has full administrative access to a company's Azure environment when their job only requires access to a specific application.&lt;/p&gt;

&lt;p&gt;If they accidentally delete a production database, virtual machine, or other critical resource, the company could experience downtime or data loss.&lt;/p&gt;

&lt;p&gt;RBAC can reduce this risk by ensuring that employees receive only the permissions required for their roles.&lt;/p&gt;

&lt;h3&gt;
  
  
  2. A leaked password could provide far more access than necessary
&lt;/h3&gt;

&lt;p&gt;Suppose an employee's Azure credentials are stolen through phishing or another attack.&lt;/p&gt;

&lt;p&gt;If that account has excessive privileges, the attacker could potentially access or modify resources far beyond what the employee actually needs.&lt;/p&gt;

&lt;p&gt;With properly configured RBAC, a compromised account can be restricted to a smaller set of permissions, reducing the potential impact.&lt;/p&gt;

&lt;h3&gt;
  
  
  3. An auditor could accidentally make changes
&lt;/h3&gt;

&lt;p&gt;An auditor may need to inspect resources, configurations, and activity logs without changing anything.&lt;/p&gt;

&lt;p&gt;Giving the auditor an administrative role creates unnecessary risk.&lt;/p&gt;

&lt;p&gt;A read-only role allows the auditor to perform their job while preventing accidental configuration changes.&lt;br&gt;
&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fn6q5sds4ip5wtf4lrg7o.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fn6q5sds4ip5wtf4lrg7o.png" alt=" " width="800" height="388"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;h2&gt;
  
  
  My Azure IAM and RBAC Lab
&lt;/h2&gt;

&lt;p&gt;In my lab, I worked with Azure access control and role assignments to understand how permissions can be assigned to identities and resources.&lt;/p&gt;

&lt;p&gt;The practical experience helped me understand that RBAC is not simply about giving someone access. It is about &lt;strong&gt;giving the correct level of access to the correct identity at the correct scope&lt;/strong&gt;.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Lab 1 – Azure IAM/RBAC configuration&lt;/strong&gt;&lt;br&gt;
&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2F7kqzm0oxwvvu5na52md7.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2F7kqzm0oxwvvu5na52md7.png" alt=" " width="800" height="600"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Lab 2 – Role assignment / access verification&lt;/strong&gt;&lt;br&gt;
&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fpse47xocp13k5z2u5ic5.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fpse47xocp13k5z2u5ic5.png" alt=" " width="799" height="553"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;One of the most important things I learned is that permissions can be managed at different scopes, such as a subscription, resource group, or individual resource. This makes it possible to provide access without automatically giving someone control over the entire environment.&lt;/p&gt;

&lt;h2&gt;
  
  
  Why IAM and RBAC Matter to a Company Like Flutterwave
&lt;/h2&gt;

&lt;p&gt;IAM and RBAC become especially important for companies that handle &lt;strong&gt;financial transactions, payment information, and customer data&lt;/strong&gt;.&lt;/p&gt;

&lt;p&gt;A company such as Flutterwave operates in an environment where cloud infrastructure and business systems can contain highly sensitive information and critical services.&lt;/p&gt;

&lt;p&gt;Consider what could happen if a privileged employee account were compromised.&lt;/p&gt;

&lt;p&gt;If that account had unnecessary administrative permissions, an attacker who obtained the credentials could potentially use those privileges to access or modify resources beyond what was required for the employee's job.&lt;/p&gt;

&lt;p&gt;This is why security teams use principles such as:&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2F7j64uondmb49hfr0et3b.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2F7j64uondmb49hfr0et3b.png" alt=" " width="800" height="350"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Least privilege*&lt;/li&gt;
&lt;li&gt;Role separation*&lt;/li&gt;
&lt;li&gt;Multi-factor authentication*&lt;/li&gt;
&lt;li&gt;Regular access reviews*&lt;/li&gt;
&lt;li&gt;Privileged access management*&lt;/li&gt;
&lt;li&gt;Monitoring and auditing of user activity*&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;IAM and RBAC do not eliminate every security threat, but they help reduce the &lt;strong&gt;blast radius&lt;/strong&gt; when something goes wrong.&lt;/p&gt;

&lt;h2&gt;
  
  
  Key Lessons From the Lab
&lt;/h2&gt;

&lt;p&gt;My biggest takeaways were:&lt;/p&gt;

&lt;ol&gt;
&lt;li&gt;&lt;strong&gt;Access should be based on job responsibilities.&lt;/strong&gt;&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Users should receive the minimum permissions they need.&lt;/strong&gt;&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Administrative access should be carefully controlled.&lt;/strong&gt;&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Read-only access is useful for users who need visibility but should not make changes.&lt;/strong&gt;&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Regularly reviewing permissions is just as important as assigning them.&lt;/strong&gt;&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Good IAM and RBAC can limit the damage caused by compromised accounts.&lt;/strong&gt;&lt;/li&gt;
&lt;/ol&gt;

&lt;h2&gt;
  
  
  Conclusion
&lt;/h2&gt;

&lt;p&gt;Building IAM and RBAC in Azure helped me move from understanding these concepts theoretically to seeing how they work in a real cloud environment.&lt;/p&gt;

&lt;p&gt;The biggest lesson for me is simple:&lt;/p&gt;

&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;Don't give everyone a master key when they only need access to one room.&lt;/strong&gt;&lt;/p&gt;
&lt;/blockquote&gt;

&lt;p&gt;Good identity and access management helps organizations protect their infrastructure, reduce accidental changes, limit the impact of compromised accounts, and maintain better control over their cloud environment.&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fwwtjzs1sxc0eutpbbbn0.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fwwtjzs1sxc0eutpbbbn0.png" alt=" " width="800" height="597"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;For companies handling payments and customer information, access control is not just a technical configuration. It is an important part of protecting the business and the people who trust it.&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fljr8brbvrxmdvgxlj7dr.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fljr8brbvrxmdvgxlj7dr.png" alt=" " width="800" height="395"&gt;&lt;/a&gt;&lt;/p&gt;

</description>
      <category>azure</category>
      <category>cloud</category>
      <category>learning</category>
      <category>security</category>
    </item>
    <item>
      <title>Understanding Azure Hierarchy and Microsoft Entra ID: My First Hands-On Azure Lab</title>
      <dc:creator>Adams Adam</dc:creator>
      <pubDate>Thu, 10 Sep 2026 17:52:34 +0000</pubDate>
      <link>https://dev.to/adams_adam_02860737759bbb/understanding-azure-hierarchy-and-microsoft-entra-id-my-first-hands-on-azure-lab-5156</link>
      <guid>https://dev.to/adams_adam_02860737759bbb/understanding-azure-hierarchy-and-microsoft-entra-id-my-first-hands-on-azure-lab-5156</guid>
      <description>&lt;p&gt;It's important to understand the structure and terms that are specific to Azure resources. The following image shows an example of the four levels of scope that are provided by Azure: &lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fniqjaoonbc30axcp51cj.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fniqjaoonbc30axcp51cj.png" alt=" " width="385" height="245"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;Cloud computing is not only about creating virtual machines and deploying applications. Before working with Azure resources, it is important to understand how Azure organizes resources and how identities are managed.&lt;/p&gt;

&lt;p&gt;As part of my Azure learning journey, I completed a hands-on lab covering:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Azure Subscription&lt;/li&gt;
&lt;li&gt;Resource Groups&lt;/li&gt;
&lt;li&gt;Microsoft Entra ID&lt;/li&gt;
&lt;li&gt;Microsoft Entra users&lt;/li&gt;
&lt;li&gt;Azure hierarchy&lt;/li&gt;
&lt;li&gt;User sign-in and access&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;This practical exercise helped me understand how identity and resource management work together in Microsoft Azure.&lt;/p&gt;

&lt;h2&gt;
  
  
  What is Azure Hierarchy?
&lt;/h2&gt;

&lt;p&gt;Azure uses a hierarchical structure to organize and manage cloud resources.&lt;/p&gt;

&lt;p&gt;A simplified view is:&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Management Group → Subscription → Resource Group → Resource&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Ftia6ssqo8ei7ld4ynxf2.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Ftia6ssqo8ei7ld4ynxf2.png" alt=" " width="500" height="267"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;At the top level, management groups can be used to organize multiple Azure subscriptions.&lt;/p&gt;

&lt;p&gt;A subscription provides a boundary for billing and resource management.&lt;/p&gt;

&lt;p&gt;A Resource Group is a logical container for related Azure resources.&lt;/p&gt;

&lt;p&gt;Resources are the actual services deployed in Azure, such as:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Virtual Machines&lt;/li&gt;
&lt;li&gt;Storage Accounts&lt;/li&gt;
&lt;li&gt;Virtual Networks&lt;/li&gt;
&lt;li&gt;Databases&lt;/li&gt;
&lt;li&gt;App Services&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;Understanding this hierarchy is important because permissions, policies and management operations can be applied at different levels.&lt;/p&gt;

&lt;h2&gt;
  
  
  What is a Microsoft Entra ID?
&lt;/h2&gt;

&lt;p&gt;Microsoft Entra ID is Microsoft's cloud-based identity and access management service.&lt;/p&gt;

&lt;p&gt;It allows organizations to manage identities such as:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Users&lt;/li&gt;
&lt;li&gt;Groups&lt;/li&gt;
&lt;li&gt;Applications&lt;/li&gt;
&lt;li&gt;Devices&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;It also provides authentication and authorization capabilities.&lt;/p&gt;

&lt;p&gt;In simple terms:&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Microsoft Entra ID answers the question: "Who are you and what are you allowed to access?"&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;Azure resources then use permissions and roles to determine what an authenticated user can do.&lt;/p&gt;

&lt;h2&gt;
  
  
  My Practical Azure Lab
&lt;/h2&gt;

&lt;p&gt;For this exercise, I performed four major tasks.&lt;/p&gt;

&lt;h3&gt;
  
  
  1. Azure Subscription
&lt;/h3&gt;

&lt;p&gt;The first step was to create/access an Azure subscription.&lt;/p&gt;

&lt;p&gt;The subscription provides the management and billing boundary for the Azure resources I create.&lt;/p&gt;

&lt;h3&gt;
  
  
  Azure Subscription
&lt;/h3&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fzqsz6e9fl5dac4yonodh.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fzqsz6e9fl5dac4yonodh.png" alt=" " width="799" height="406"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Figure 1: Azure Subscription&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;I learned that every Azure resource is associated with a subscription.&lt;/p&gt;




&lt;h2&gt;
  
  
  2. Creating a Resource Group
&lt;/h2&gt;

&lt;p&gt;The next step was creating a Resource Group.&lt;/p&gt;

&lt;p&gt;I created a Resource Group called:&lt;/p&gt;

&lt;p&gt;&lt;code&gt;rg-4cloud_test-environment&lt;/code&gt;&lt;/p&gt;

&lt;p&gt;A Resource Group provides a logical container for related Azure resources.&lt;/p&gt;

&lt;p&gt;For example, if I were building a web application, I could place the application's virtual machine, storage account and networking resources within the same Resource Group.&lt;/p&gt;

&lt;h3&gt;
  
  
  Resource Group
&lt;/h3&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2F37cqjs8h8xmy4gy9g9ca.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2F37cqjs8h8xmy4gy9g9ca.png" alt=" " width="800" height="381"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fdxhg2p3052mfbsmnzvzk.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fdxhg2p3052mfbsmnzvzk.png" alt=" " width="799" height="380"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fwx54r4y3t7dacmtjn6vm.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fwx54r4y3t7dacmtjn6vm.png" alt=" " width="800" height="337"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Figure 2: Resource Group created successfully&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;One important lesson I learned is that Resource Groups make it easier to organize and manage related resources.&lt;/p&gt;

&lt;h2&gt;
  
  
  3. Creating a Microsoft Entra ID User
&lt;/h2&gt;

&lt;p&gt;The next stage was creating a new user in Microsoft Entra ID.&lt;/p&gt;

&lt;p&gt;I navigated to:&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Microsoft Entra ID → Users → New user&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;I created a test user for the lab.&lt;/p&gt;

&lt;h3&gt;
  
  
  Microsoft Entra Test User
&lt;/h3&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fy5e0b3z2a2bu1tbv8wcx.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fy5e0b3z2a2bu1tbv8wcx.png" alt=" " width="800" height="386"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Figure 3: Microsoft Entra ID user created&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;This demonstrated how Azure identities can be centrally managed using Microsoft Entra ID.&lt;/p&gt;

&lt;h2&gt;
  
  
  4. Testing the New User
&lt;/h2&gt;

&lt;p&gt;After creating the user, I opened a private/incognito browser window.&lt;/p&gt;

&lt;p&gt;I then navigated to the Azure Portal and attempted to sign in using the new Microsoft Entra account.&lt;/p&gt;

&lt;p&gt;New User Sign-in&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fkd3ewbkx3wlh3l79z100.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fkd3ewbkx3wlh3l79z100.png" alt=" " width="799" height="324"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fqawww2q86m7d22s2y4df.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fqawww2q86m7d22s2y4df.png" alt=" " width="799" height="347"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fxvk40v6n6w76ye98fp0t.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fxvk40v6n6w76ye98fp0t.png" alt=" " width="799" height="356"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2F61i3tk2i4w48fnu9t38n.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2F61i3tk2i4w48fnu9t38n.png" alt=" " width="799" height="362"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fj8imsxyidtygxnoua7ff.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fj8imsxyidtygxnoua7ff.png" alt=" " width="800" height="355"&gt;&lt;/a&gt;&lt;br&gt;
&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fhe85mdys182o0ay74zxi.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fhe85mdys182o0ay74zxi.png" alt=" " width="800" height="348"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fb2isrdbypaxwafw4oryr.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fb2isrdbypaxwafw4oryr.png" alt=" " width="800" height="395"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Figure 4: Signing in with the newly created Microsoft Entra user&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;This was an important part of the exercise because creating an identity is different from actually granting that identity access to Azure resources.&lt;/p&gt;

&lt;p&gt;Azure uses role-based access control to determine what users can do with Azure resources.&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fizxxg4p5s0s54cyc5jlr.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fizxxg4p5s0s54cyc5jlr.png" alt=" " width="800" height="660"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;h2&gt;
  
  
  Azure Hierarchy in Practice
&lt;/h2&gt;

&lt;p&gt;The practical exercise helped me connect the concepts together.&lt;/p&gt;

&lt;p&gt;The structure can be visualized as:&lt;/p&gt;

&lt;p&gt;Microsoft Entra Tenant&lt;br&gt;
        |&lt;br&gt;
  Azure Subscription&lt;br&gt;
        |&lt;br&gt;
   Resource Group&lt;br&gt;
        |&lt;br&gt;
   Azure Resources&lt;/p&gt;

&lt;p&gt;The Microsoft Entra tenant manages identities, while the Azure subscription provides the resource management boundary.&lt;/p&gt;

&lt;p&gt;The Resource Group then organizes related Azure resources.&lt;/p&gt;

&lt;h2&gt;
  
  
  What I Learned
&lt;/h2&gt;

&lt;p&gt;This exercise gave me a better understanding of several important Azure concepts.&lt;/p&gt;

&lt;h3&gt;
  
  
  1. Azure is structured
&lt;/h3&gt;

&lt;p&gt;Azure resources are not simply created randomly. They are organized into management scopes.&lt;/p&gt;

&lt;h3&gt;
  
  
  2. Identity is important
&lt;/h3&gt;

&lt;p&gt;Before users can securely access cloud resources, their identities need to be managed and authenticated.&lt;/p&gt;

&lt;h3&gt;
  
  
  3. Microsoft Entra ID manages identity
&lt;/h3&gt;

&lt;p&gt;Microsoft Entra ID provides the identity layer for users, groups and applications.&lt;/p&gt;

&lt;h3&gt;
  
  
  4. Resource Groups improve organization
&lt;/h3&gt;

&lt;p&gt;Resource Groups make it easier to manage related resources as a logical unit.&lt;/p&gt;

&lt;h3&gt;
  
  
  5. Authentication and authorization are different
&lt;/h3&gt;

&lt;p&gt;Authentication verifies who the user is.&lt;/p&gt;

&lt;p&gt;Authorization determines what the user is allowed to do.&lt;/p&gt;

&lt;p&gt;This distinction is very important in cloud security.&lt;/p&gt;

&lt;h2&gt;
  
  
  Final Thoughts
&lt;/h2&gt;

&lt;p&gt;This lab was a valuable step in my Microsoft Azure learning journey.&lt;/p&gt;

&lt;p&gt;Before this exercise, concepts such as subscriptions, resource groups, tenants and Microsoft Entra ID could easily seem like separate topics.&lt;/p&gt;

&lt;p&gt;The practical exercise helped me understand how they connect.&lt;/p&gt;

&lt;p&gt;My simplified mental model is:&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Microsoft Entra ID → Identity&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Subscription → Resource management boundary&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Resource Group → Resource organization&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Resources → Actual Azure services&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;I am continuing to build my practical knowledge of Azure, cloud computing and DevOps by combining theory with hands-on labs.&lt;/p&gt;

&lt;p&gt;The next step is to continue working with Azure resources, role-based access control, networking, virtual machines and eventually automation and DevOps pipelines.&lt;br&gt;
&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fv8lln4oavcvgs9kzzv1j.jpeg" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fv8lln4oavcvgs9kzzv1j.jpeg" alt=" " width="627" height="605"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;h1&gt;
  
  
  Azure #MicrosoftAzure #MicrosoftEntra #CloudComputing #DevOps #CloudEngineering #AzureAdministrator #LearningInPublic #TechCareer
&lt;/h1&gt;

</description>
      <category>azure</category>
      <category>cloud</category>
      <category>learning</category>
      <category>tutorial</category>
    </item>
    <item>
      <title>My First Steps into Cloud Computing: Understanding Azure, IaaS, PaaS and SaaS</title>
      <dc:creator>Adams Adam</dc:creator>
      <pubDate>Tue, 08 Sep 2026 14:00:47 +0000</pubDate>
      <link>https://dev.to/adams_adam_02860737759bbb/my-first-steps-into-cloud-computing-understanding-azure-iaas-paas-and-saas-1ln5</link>
      <guid>https://dev.to/adams_adam_02860737759bbb/my-first-steps-into-cloud-computing-understanding-azure-iaas-paas-and-saas-1ln5</guid>
      <description>&lt;p&gt;Cloud computing is one of the technologies changing how modern applications are built, deployed and managed.&lt;/p&gt;

&lt;p&gt;As part of my cloud computing learning journey, I recently explored the fundamentals of cloud computing, including deployment models, service models, Azure regions, availability zones, redundancy and the Azure Portal.&lt;/p&gt;

&lt;p&gt;Here are some of the key concepts I learned.&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2F41jrd9mwzj1c4gwfzq9u.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2F41jrd9mwzj1c4gwfzq9u.png" alt=" " width="800" height="409"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;In simple terms, cloud computing means renting of powerful computing resources over the internet instead of owning and maintaining all the physical infrastructure yourself.&lt;/p&gt;

&lt;p&gt;We interact with cloud services every day, sometimes without realizing it.&lt;/p&gt;

&lt;p&gt;Examples include:&lt;br&gt;
1.Gmail&lt;br&gt;
2.WhatsApp&lt;br&gt;
3.Netflix&lt;br&gt;
4.Microsoft 365&lt;br&gt;
5.Online portals and services&lt;/p&gt;

&lt;p&gt;Instead of a company purchasing and maintaining every server required for its applications, it can consume computing resources from a cloud provider.&lt;/p&gt;

&lt;p&gt;Traditional IT vs Cloud Computing&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fvube8u36d3a3fdwz4kmz.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fvube8u36d3a3fdwz4kmz.png" alt=" " width="800" height="409"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;The traditional approach requires organizations to purchase physical servers, provide server rooms, cooling, electricity, backup power and security, while also maintaining the infrastructure.&lt;/p&gt;

&lt;p&gt;Cloud computing changes this model.&lt;/p&gt;

&lt;p&gt;Instead of purchasing everything upfront, organizations can rent computing resources and scale them according to their requirements.&lt;/p&gt;

&lt;p&gt;This can provide:&lt;/p&gt;

&lt;ol&gt;
&lt;li&gt;Faster deployment&lt;/li&gt;
&lt;li&gt;Better scalability&lt;/li&gt;
&lt;li&gt;Reduced upfront infrastructure costs&lt;/li&gt;
&lt;li&gt;Greater flexibility&lt;/li&gt;
&lt;li&gt;Easier access to computing resources&lt;/li&gt;
&lt;/ol&gt;

&lt;p&gt;Understanding IaaS, PaaS and SaaS&lt;/p&gt;

&lt;p&gt;One of the most useful concepts I learned was the difference between the three major cloud service models.&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Ftgaoaht20rfpkus0kgek.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Ftgaoaht20rfpkus0kgek.png" alt=" " width="800" height="450"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;IaaS — Infrastructure as a Service&lt;br&gt;
With IaaS, the cloud provider gives you infrastructure such as virtual machines, storage and networking.&lt;/p&gt;

&lt;p&gt;You have greater control, but you are also responsible for managing more of the environment.&lt;/p&gt;

&lt;p&gt;Examples include Azure Virtual Machines and AWS EC2.&lt;/p&gt;

&lt;p&gt;PaaS — Platform as a Service&lt;br&gt;
PaaS provides a platform where developers can build and deploy applications without having to manage all the underlying infrastructure.&lt;/p&gt;

&lt;p&gt;The cloud provider handles much of the infrastructure management while developers focus primarily on their applications.&lt;/p&gt;

&lt;p&gt;An example is Azure App Service.&lt;/p&gt;

&lt;p&gt;SaaS — Software as a Service&lt;br&gt;
SaaS provides a complete software application that users can access without managing the underlying infrastructure.&lt;/p&gt;

&lt;p&gt;Examples include Gmail, Microsoft 365 and Zoom.&lt;/p&gt;

&lt;p&gt;A simple way I remember the difference is:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;IaaS → Infrastructure&lt;/li&gt;
&lt;li&gt;PaaS → Platform&lt;/li&gt;
&lt;li&gt;SaaS → Software&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;Cloud Deployment Models&lt;/p&gt;

&lt;p&gt;I also learned about three major deployment models.&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fh2x4ikytqamdivc95juj.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fh2x4ikytqamdivc95juj.png" alt=" " width="800" height="450"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;Public Cloud&lt;br&gt;
Infrastructure is provided by a cloud provider and shared among multiple customers.&lt;/p&gt;

&lt;p&gt;Examples include Microsoft Azure, Amazon Web Services and Google Cloud.&lt;/p&gt;

&lt;p&gt;Private Cloud&lt;br&gt;
Infrastructure is dedicated to a single organization.&lt;br&gt;
This can provide greater control and customization but may require more investment and management.&lt;/p&gt;

&lt;p&gt;Hybrid Cloud&lt;br&gt;
Hybrid cloud combines public and private cloud environments.&lt;/p&gt;

&lt;p&gt;For example, an organization could keep sensitive information in a private environment while using public cloud services for other workloads.&lt;/p&gt;

&lt;p&gt;What Are Cloud Regions?&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2F85lc0n3h9e3q6as6j5cv.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2F85lc0n3h9e3q6as6j5cv.png" alt=" " width="800" height="450"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;Cloud providers operate data centers in different geographical locations known as regions.&lt;/p&gt;

&lt;p&gt;Choosing an appropriate region can be important for:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Performance&lt;/li&gt;
&lt;li&gt;Compliance&lt;/li&gt;
&lt;li&gt;Disaster recovery&lt;/li&gt;
&lt;li&gt;Availability&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;For applications serving Nigerian users, geographical proximity is one consideration when selecting infrastructure.&lt;/p&gt;

&lt;p&gt;Availability Zones and Redundancy&lt;/p&gt;

&lt;p&gt;Another important concept is availability zones.&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fhkxkx1301n7rp2orngb4.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fhkxkx1301n7rp2orngb4.png" alt=" " width="800" height="450"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;Within a region, cloud providers can have multiple physically separate locations with independent infrastructure.&lt;/p&gt;

&lt;p&gt;If one location experiences a failure, workloads can potentially continue running from another location, depending on how the application has been designed.&lt;/p&gt;

&lt;p&gt;Redundancy is another important principle.&lt;br&gt;
Instead of relying on a single copy of important data or infrastructure, organizations can maintain multiple copies or resources so that one failure does not necessarily bring the entire system down.&lt;/p&gt;

&lt;p&gt;My Azure Portal Experience&lt;/p&gt;

&lt;p&gt;I also explored the Microsoft Azure Portal.&lt;/p&gt;

&lt;p&gt;The Azure Portal is the web-based interface where users can interact with Azure services and manage cloud resources.&lt;/p&gt;

&lt;p&gt;Some of the areas I explored include:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Virtual Machines&lt;/li&gt;
&lt;li&gt;Resource Groups&lt;/li&gt;
&lt;li&gt;Subscriptions&lt;/li&gt;
&lt;li&gt;Azure services&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;One concept that stood out to me was the Resource Group.&lt;/p&gt;

&lt;p&gt;A Resource Group can be thought of as a logical container for resources belonging to a particular project or solution.&lt;/p&gt;

&lt;p&gt;Applying Cloud Computing to a Lagos Fintech&lt;/p&gt;

&lt;p&gt;Imagine a small fintech company in Lagos preparing to launch a mobile banking application.&lt;/p&gt;

&lt;p&gt;I would recommend using cloud computing rather than purchasing physical servers at the beginning.&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fz2hfkm0r0qhh4kpbwdxa.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fz2hfkm0r0qhh4kpbwdxa.png" alt=" " width="800" height="409"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;ol&gt;
&lt;li&gt;Scalability&lt;/li&gt;
&lt;/ol&gt;

&lt;p&gt;The application may start with a small number of users but could potentially grow rapidly.&lt;/p&gt;

&lt;p&gt;Cloud resources can be scaled as demand changes.&lt;/p&gt;

&lt;ol&gt;
&lt;li&gt;Cost Efficiency&lt;/li&gt;
&lt;/ol&gt;

&lt;p&gt;The fintech would avoid a large initial investment in physical servers, server rooms, cooling systems and other infrastructure.&lt;/p&gt;

&lt;ol&gt;
&lt;li&gt;Availability&lt;/li&gt;
&lt;/ol&gt;

&lt;p&gt;The application can be designed using redundant infrastructure to reduce the impact of individual failures.&lt;/p&gt;

&lt;ol&gt;
&lt;li&gt;Faster Time to Market&lt;/li&gt;
&lt;/ol&gt;

&lt;p&gt;Developers can provision cloud resources quickly and focus on building and improving the application instead of waiting for physical infrastructure to be purchased and installed.&lt;/p&gt;

&lt;p&gt;Final Thoughts&lt;/p&gt;

&lt;p&gt;My biggest takeaway is that cloud computing is more than simply "storing files online."&lt;/p&gt;

&lt;p&gt;It is an approach to consuming computing infrastructure, platforms and software as services.&lt;/p&gt;

&lt;p&gt;Understanding the difference between IaaS, PaaS and SaaS, together with concepts such as regions, availability zones, scalability and redundancy, provides a strong foundation for anyone beginning a career in cloud computing.&lt;/p&gt;

&lt;p&gt;This is just the beginning of my cloud journey, and I am looking forward to building more practical projects with Azure and applying these concepts in real-world scenarios.&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2F2i9b53g1uzh2s4p7y3dr.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2F2i9b53g1uzh2s4p7y3dr.png" alt=" " width="800" height="766"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;Next step: keep learning, keep building and keep deploying. &lt;/p&gt;

</description>
      <category>azure</category>
      <category>beginners</category>
      <category>cloud</category>
      <category>cloudcomputing</category>
    </item>
  </channel>
</rss>
