Unit 1 Roadmap — Design identity, governance, and monitoring solutions
AZ-305 › Unit 1
Unit 1 Roadmap — identity, governance, and monitoring solutions
This roadmap turns the unit into a study sequence. The goal is to connect topic decisions, not memorize isolated product facts. The current exam blueprint allocates 25–30% to this domain.
Unit 1 release map
- 25–30%
- 3
- Defensible recommendation
- Checkpoint plus design studio
Unit thesis
Turn organisational boundaries, duties, and evidence requirements into an operable control model.
Recommended learning sequence
- Start with observability requirements: signals, destinations, retention, query, alert, and response.
- Separate authentication, Azure resource authorization, directory roles, and workload identity.
- Place management groups, subscriptions, policy, and privileged access around durable business boundaries.
Text equivalent: study each topic cram sheet, complete the unit checkpoint, then prove synthesis in a design studio.
Topic map
| Topic | Architectural decision | First trap to reject |
|---|---|---|
| 1. Design solutions for logging and monitoring | Design the signal path from collection to retention, query, alert, and automated response. | Activity Log is not guest OS telemetry. |
| 2. Design authentication and authorization solutions | Separate who signs in, what they may do, how privilege activates, and how workloads obtain tokens. | Reader does not imply service data access. |
| 3. Design governance | Place boundaries, policy, cost ownership, compliance evidence, and privileged access at the right scope. | Tags do not inherit without policy. |
How to work this unit
For each topic, read the linked full lessons first when the service boundary is unfamiliar. Use the cram sheet to compress the decision rules. Then close the notes and answer the retrieval prompts. Finish with scenarios that force two or more topics to interact. A correct product name without a constraint-based explanation is not sufficient evidence of readiness.
When reviewing an answer, write a one-sentence recommendation in this form: Choose X because constraints A and B matter; reject Y because it fails C; accept trade-off D. This structure exposes guesses and makes technical review easier.
Pre-checkpoint checklist
- I can state the decision boundary for every service family in this unit.
- I can distinguish high availability, recovery, security, and governance controls when they appear together.
- I can identify the strongest distractor and the requirement it fails.
- I can draw the major dependency or signal flow without copying a diagram.
- I can explain operational ownership and cost consequences, not only features.
- I have corrected every missed retrieval prompt at least once from memory.
Common failure patterns
- Using Azure Policy to grant access instead of govern resource state.
- Sending every signal to one workspace without residency, access, or cost analysis.
- Giving workloads stored credentials when managed identity is supported.
Source and freshness
Aligned to the current AZ-305 study guide and grounded in the two attached corpus sources. Product details and limits must be checked against current Microsoft Learn documentation. Reviewed 2026-08-02.