Microsoft Azure Azure Architecture & Governance

Azure Infrastructure Services: Virtual Networks, Compute, and Storage Management

⏱ 12 min read • Level: Intermediate • Updated: Sep 30, 2026

1. Executive Overview & Industry Context

Infrastructure as a Service (IaaS) forms the foundational operational substrate of enterprise cloud architecture within Microsoft Azure. While cloud-native architectures increasingly leverage managed serverless and container orchestration engines, mission-critical enterprise workloads—ranging from enterprise resource planning (ERP) databases to legacy monolithic web tiers and distributed data pipelines—continue to rely on high-performance compute virtual machines, software-defined software networks, and resilient object storage fabrics.

Designing production-grade IaaS on Azure requires deep systems engineering knowledge across three interconnected domains: software-defined networking, elastic compute provisioning, and multi-tiered data storage. Engineering teams must design networks that isolate sensitive data while facilitating seamless hybrid cross-premises connectivity; deploy virtual machines with mathematically verified uptime SLAs across Availability Zones; and configure storage repositories with lifecycle management policies that guarantee both data durability and cost predictability.

2. Core Learning Objectives

By concluding this technical module, cloud architects and systems engineers will demonstrate verifiable competency in the following capabilities:

  • Virtual Networking Topologies: Implement hub-spoke virtual networks (VNets), subnets, Network Security Groups (NSGs), Application Security Groups (ASGs), and Azure Bastion.
  • Compute Sizing & High Availability: Deploy Virtual Machines across Availability Zones, scale sets (VMSS), and dedicated hosts with custom SLA configurations.
  • Blob & Enterprise Storage: Configure Azure Storage Accounts, Blob access tiers (Hot, Cool, Cold, Archive), immutability policies, and Azure Files SMB/NFS shares.
  • Disaster Recovery & Backup: Design backup vaults, geo-redundant storage (GRS/GZRS), and Azure Site Recovery replication workflows.

3. Theoretical Foundations & Architecture

An Azure Virtual Network (VNet) is an isolated private network within the Azure cloud. VNets provide address space isolation via private RFC 1918 IP address ranges (e.g., 10.0.0.0/16). The recommended enterprise topology is the Hub-and-Spoke model: a central Hub VNet hosts shared networking services (Azure Firewall, VPN/ExpressRoute gateways, Azure Bastion, DNS resolvers), while Spoke VNets host application workloads. Spokes connect to the hub via low-latency VNet Peering, routing non-local traffic through the central firewall via User Defined Routes (UDRs / Route Tables).

Network traffic filtering is enforced by Network Security Groups (NSGs) containing stateful 5-tuple security rules (Source IP, Source Port, Destination IP, Destination Port, Protocol). NSGs evaluate rules in numerical order (priority 100 to 4096), terminating evaluation upon the first matching rule. By pairing NSGs with Application Security Groups (ASGs), architects define security policies based on logical application tiers (e.g., asg-web-servers to asg-database-tier) rather than brittle, volatile static IP addresses.

In compute architecture, Azure offers Virtual Machines categorized into specialized families: General Purpose (D-series), Compute-Optimized (F-series), Memory-Optimized (E-series), and Storage-Optimized (L-series). High availability is achieved through Availability Zones—physically separate locations within an Azure region, each equipped with independent power, cooling, and networking. Deploying VMs across two or more Availability Zones guarantees an industry-leading 99.99% VM uptime SLA. For horizontal auto-scaling, Virtual Machine Scale Sets (VMSS) automatically add or remove instances in response to telemetry thresholds.

Storage architecture centers on the Azure Storage Account, delivering petabyte-scale capacity with four distinct data services: Blob (object storage for unstructured data), Files (managed SMB/NFS cloud shares), Queues (messaging decoupling), and Tables (NoSQL key-value store). Blob storage provides four access tiers optimized for lifecycle economics: Hot (frequently accessed data), Cool (infrequently accessed, stored $ge 30$ days), Cold (rarely accessed, stored $ge 90$ days), and Archive (offline long-term compliance storage, stored $ge 180$ days, requiring multi-hour rehydration).

4. Step-by-Step Implementation Guide & CLI Workflows

The following workflow illustrates establishing a segmented VNet, deploying an NSG with an Application Security Group, and provisioning a secure, zone-redundant storage account:

# 1. Provision a Virtual Network with Web and Database subnets
az network vnet create 
  --name "vnet-workload-eastus" 
  --resource-group "rg-core-networking-prod-eastus" 
  --address-prefixes "10.100.0.0/16" 
  --subnet-name "snet-web" 
  --subnet-prefixes "10.100.1.0/24"

az network vnet subnet create 
  --name "snet-db" 
  --vnet-name "vnet-workload-eastus" 
  --resource-group "rg-core-networking-prod-eastus" 
  --address-prefixes "10.100.2.0/24"

# 2. Create Application Security Groups for logical tier grouping
az network asg create 
  --name "asg-web" 
  --resource-group "rg-core-networking-prod-eastus" 
  --location "eastus"

az network asg create 
  --name "asg-db" 
  --resource-group "rg-core-networking-prod-eastus" 
  --location "eastus"

# 3. Create a Network Security Group and enforce database tier isolation
az network nsg create 
  --name "nsg-database-tier" 
  --resource-group "rg-core-networking-prod-eastus" 
  --location "eastus"

# Allow SQL traffic ONLY from the web application tier, denying all other inbound traffic
az network nsg rule create 
  --name "Allow-Web-To-Database" 
  --nsg-name "nsg-database-tier" 
  --resource-group "rg-core-networking-prod-eastus" 
  --priority 200 
  --direction Inbound 
  --access Allow 
  --protocol Tcp 
  --source-asg-names "asg-web" 
  --destination-asg-names "asg-db" 
  --destination-port-ranges 1433

# 4. Associate the NSG to the Database Subnet
az network vnet subnet update 
  --name "snet-db" 
  --vnet-name "vnet-workload-eastus" 
  --resource-group "rg-core-networking-prod-eastus" 
  --network-security-group "nsg-database-tier"

# 5. Provision a Storage Account with Zone-Redundant Storage (ZRS) & strict TLS 1.2
az storage account create 
  --name "stdataappprodeastus01" 
  --resource-group "rg-core-networking-prod-eastus" 
  --location "eastus" 
  --sku "Standard_ZRS" 
  --kind "StorageV2" 
  --access-tier "Hot" 
  --min-tls-version "TLS1_2" 
  --allow-blob-public-access false 
  --https-only true

5. Real-World Case Studies & Enterprise Production Scenarios

An enterprise retail platform preparing for Black Friday shopping surges operated on-premises virtualized infrastructure subject to recurrent network bottlenecks and storage IOPS exhaustion. Migrating to Microsoft Azure, the engineering team architected a multi-zone VM Scale Set utilizing D4s_v5 instances running across Availability Zones 1, 2, and 3, fronted by an Azure Application Gateway with Web Application Firewall (WAF v2).

To support high-throughput media asset delivery, product catalog imagery was migrated to an Azure Blob Storage container with standard zone-redundant storage (ZRS) fronted by Azure Front Door CDN. During the 72-hour peak retail event, consumer traffic surged by 780%. The VMSS automatically scaled from 6 to 64 virtual machine instances in under 8 minutes without dropping a single TCP connection. Average page delivery latency dropped from 840ms to 92ms, while the multi-zone architecture endured a localized datacenter power disruption in Zone 2 with zero customer impact.

6. Common Pitfalls, Anti-Patterns & Misconceptions

Production cloud engineers regularly encounter several critical configuration anti-patterns when designing Azure core infrastructure:

  • Direct Public IP Exposure on Virtual Machines: Binding public IPv4 addresses directly to VM network interfaces (NICs) exposes management ports (SSH port 22, RDP port 3389) directly to brute-force internet attacks. Remedy: Eliminate public IPs on compute instances; mandate secure management ingress exclusively via Azure Bastion or VPN.
  • Overlapping VNet Address Spaces: Creating multiple VNets with identical or overlapping CIDR blocks (e.g., 10.0.0.0/16) completely precludes VNet Peering and cross-premises hybrid routing. Remedy: Plan a non-overlapping corporate IP address management (IPAM) space before provisioning.
  • Premature Archive Tiering: Moving objects to the Archive tier that require frequent, unexpected access results in substantial rehydration fees and multi-hour latency delays. Remedy: Implement Lifecycle Management rules that evaluate lastAccessTimeTracking rather than arbitrary modification dates.
  • Relying on Default Outbound Ingress: Depending on Azure’s default outbound internet access for VMs without a NAT Gateway or Firewall exposes instances to intermittent SNAT port exhaustion during traffic spikes. Remedy: Attach an Azure NAT Gateway to all production subnets.

7. Best Practices, Security Hardening & Performance Checklists

Adhere to this production engineering checklist for Microsoft Azure compute and networking:

  • Enable Accelerated Networking: Ensure all supported VM sizes have Accelerated Networking enabled on their network interfaces to bypass the host virtualization layer and achieve microsecond latencies via Single Root I/O Virtualization (SR-IOV).
  • Mandate Storage Immutability (WORM): For financial, medical, and legal records, enforce time-based retention or legal hold policies on Blob containers to guarantee Write Once, Read Many compliance.
  • Enforce Custom DNS via Private Endpoints: Connect to Azure PaaS services (SQL Database, Blob Storage, Key Vault) exclusively via Azure Private Endpoints (Private Link), completely eliminating public internet traversal.
  • Configure Multi-Region Geo-Redundancy (GZRS): For mission-critical repositories, configure Geo-Zone-Redundant Storage to combine local three-zone resilience with asynchronous replication to a paired region 300+ miles away.

8. Summary & Certification Readiness Review

In the SkillCertify Azure Fundamentals Assessment, infrastructure components represent substantial blueprint weight. Candidates must demonstrate verifiable comprehension of Virtual Network segmentation, NSG filtering rules, Availability Zones, VMSS scaling metrics, Storage Account replication options (LRS, ZRS, GRS, GZRS), and Blob access tier tradeoffs. Review the authoritative references below to ensure comprehensive readiness before scheduling your exam.

Formative Practice

Test Your Understanding of Azure Architecture & Governance

Apply what you just learned with curated practice questions and in-depth explanations.

Practice Questions →
Advertisement