BrainyBeeBrainyBee
ExploreBlogStart Studying
HomeDesigning Microsoft Azure Infrastructure Solutions (AZ-305)Unit 1 Roadmap — Design identity, governance, and monitoring solutions
Unit Roadmap639 words

Unit 1 Roadmap — Design identity, governance, and monitoring solutions

AZ-305 › Unit 1

Unit 1 Roadmap — identity, governance, and monitoring solutions

This roadmap turns the unit into a study sequence. The goal is to connect topic decisions, not memorize isolated product facts. The current exam blueprint allocates 25–30% to this domain.

Unit 1 release map

Blueprint range
25–30%
Topic cram sheets
3
Primary outcome
Defensible recommendation
Readiness evidence
Checkpoint plus design studio

Unit thesis

Turn organisational boundaries, duties, and evidence requirements into an operable control model.

Recommended learning sequence

  1. Start with observability requirements: signals, destinations, retention, query, alert, and response.
  2. Separate authentication, Azure resource authorization, directory roles, and workload identity.
  3. Place management groups, subscriptions, policy, and privileged access around durable business boundaries.
Loading Diagram...
Figure 1 — Mermaid diagram

Text equivalent: study each topic cram sheet, complete the unit checkpoint, then prove synthesis in a design studio.

Topic map

TopicArchitectural decisionFirst trap to reject
1. Design solutions for logging and monitoringDesign the signal path from collection to retention, query, alert, and automated response.Activity Log is not guest OS telemetry.
2. Design authentication and authorization solutionsSeparate who signs in, what they may do, how privilege activates, and how workloads obtain tokens.Reader does not imply service data access.
3. Design governancePlace boundaries, policy, cost ownership, compliance evidence, and privileged access at the right scope.Tags do not inherit without policy.

How to work this unit

For each topic, read the linked full lessons first when the service boundary is unfamiliar. Use the cram sheet to compress the decision rules. Then close the notes and answer the retrieval prompts. Finish with scenarios that force two or more topics to interact. A correct product name without a constraint-based explanation is not sufficient evidence of readiness.

When reviewing an answer, write a one-sentence recommendation in this form: Choose X because constraints A and B matter; reject Y because it fails C; accept trade-off D. This structure exposes guesses and makes technical review easier.

Unit-level traps

Using Azure Policy to grant access instead of govern resource state. Sending every signal to one workspace without residency, access, or cost analysis. Giving workloads stored credentials when managed identity is supported.

Pre-checkpoint checklist

  • I can state the decision boundary for every service family in this unit.
  • I can distinguish high availability, recovery, security, and governance controls when they appear together.
  • I can identify the strongest distractor and the requirement it fails.
  • I can draw the major dependency or signal flow without copying a diagram.
  • I can explain operational ownership and cost consequences, not only features.
  • I have corrected every missed retrieval prompt at least once from memory.

Common failure patterns

  • Using Azure Policy to grant access instead of govern resource state.
  • Sending every signal to one workspace without residency, access, or cost analysis.
  • Giving workloads stored credentials when managed identity is supported.
Loading flashcards…

Source and freshness

Aligned to the current AZ-305 study guide and grounded in the two attached corpus sources. Product details and limits must be checked against current Microsoft Learn documentation. Reviewed 2026-08-02.

All Designing Microsoft Azure Infrastructure Solutions (AZ-305) Study Resources

Related Notes

  • Unit 1 Capstone — Design identity, governance, and monitoring solutions668 words
  • Cram Sheet — Design authentication and authorization solutions632 words
  • Design Authentication and Authorization Solutions — Lesson4,263 words
  • Design Studio — Design authentication and authorization solutions734 words
  • Quick Note — Recommend an Authentication Solution758 words
  • Recommend an Authentication Solution — Lesson4,868 words
  • Quick Note — Recommend an Identity Management Solution796 words
  • Recommend an Identity Management Solution — Lesson5,982 words
  • Quick Note — Recommend a Solution for Authorizing Access to Azure Resources745 words
  • Recommend a Solution for Authorizing Access to Azure Resources — Lesson2,561 words
  • Quick Note — Recommend a Solution to Manage Secrets, Certificates, and Keys872 words
  • Recommend a Solution to Manage Secrets, Certificates, and Keys — Lesson5,324 words

Ready to study Designing Microsoft Azure Infrastructure Solutions (AZ-305)?

Practice tests, flashcards, and all study notes — free, no sign-up.

Start Studying

Ready to study Designing Microsoft Azure Infrastructure Solutions (AZ-305)?

Practice tests, flashcards, and all study notes — free, no sign-up needed.

Start Studying — Free
Designing Microsoft Azure Infrastructure Solutions (AZ-305) ResourcesExplore All HivesBlogHome

© 2026 BrainyBee. Free AI-powered exam prep.

Loading Diagram...
Flowchart, left to right. Unit 1: Design identity, governance, and monitoring solutions connects to Design solutions for logging and monitoring. Unit 1: Design identity, governance, and monitoring solutions connects to Design authentication and authorization solutions. Unit 1: Design identity, governance, and monitoring solutions connects to Design governance. T1 connects to Unit checkpoint. C connects to Unit design studio.

Unit 1 roadmap checkpoint

Card 1 of 3

Front of flashcard 1 of 3

What is the design lens for design solutions for logging and monitoring?

easy

Design the signal path from collection to retention, query, alert, and automated response.

az-305retrieval

Unit 1 roadmap checkpoint

Card 1

Front

What is the design lens for design solutions for logging and monitoring?

Back

Design the signal path from collection to retention, query, alert, and automated response.

Card 2

Front

What is the design lens for design authentication and authorization solutions?

Back

Separate who signs in, what they may do, how privilege activates, and how workloads obtain tokens.

Card 3

Front

What is the design lens for design governance?

Back

Place boundaries, policy, cost ownership, compliance evidence, and privileged access at the right scope.

Unit 1 roadmap checkpoint

Card 1

Front

What is the design lens for design solutions for logging and monitoring?

Back

Design the signal path from collection to retention, query, alert, and automated response.

Card 2

Front

What is the design lens for design authentication and authorization solutions?

Back

Separate who signs in, what they may do, how privilege activates, and how workloads obtain tokens.

Card 3

Front

What is the design lens for design governance?

Back

Place boundaries, policy, cost ownership, compliance evidence, and privileged access at the right scope.