LEARNING AZURE / YOUR CLOUD LEARNING SPACE
No account neededAbout
Operate & govern / Lesson 3
Capstone / 60–90 min

Build and hand off a small cloud environment

Bring the course together in a small, reviewable deployment. Your deliverable is an environment another IT professional can understand, operate, and retire.

What you’ll be able to do

  • Plan resource scope, access, address space, and cost before deployment.
  • Deploy and verify the Bicep network from lesson 7.
  • Produce a short operations handoff and execute a deliberate cleanup.
Before you beginComplete lessons 1–9. Use a dedicated non-production subscription or approved learning scope, resource and deployment permissions, and a supported region. Confirm your network ranges do not overlap relevant connected networks.

Get the idea

A complete handoff includes decisions

A resource list is not enough. Record why you chose the region, address ranges, permission model, and ownership tags. Someone should be able to inspect the environment without guessing which resources belong to the lab.

Verification follows intent

Compare what you planned with what exists. A successful deployment result is one piece of evidence; inspect network properties and scope as well. Do not claim application connectivity when no application or VM has been deployed.

Retirement is part of operations

An environment should have a clear end-of-life plan. Review the resource list and ensure it is dedicated to the exercise before deleting the group. Keep the template and notes so the learning can be repeated.

Try it yourself

  1. Write a plan: one dedicated group named rg-learningazure-capstone, one network, one subnet, an approved region, and Environment=Learning tags. Note that this exercise deploys no VM, public IP, or application.
  2. Create the dedicated group. Save the lesson 7 Bicep file, choose non-overlapping practice ranges, and run what-if against the capstone group. Review every proposed change.
  3. If the plan is correct and approved for your learning scope, run the deployment command below. Inspect provisioningState and the deployed network in the portal.
  4. List role assignments without changing production access. Inspect resource configuration and add appropriate tags. Produce a handoff containing resource IDs, network ranges, intended permissions, verification evidence, and cleanup instructions.
  5. Inspect the group’s resource list. Once you confirm it contains only this capstone’s resources, delete that dedicated group through the portal and verify it disappears. Keep main.bicep and the handoff notes.

Example · commands or prompt

az group create --name rg-learningazure-capstone --location eastus --tags Environment=Learning
az deployment group what-if --resource-group rg-learningazure-capstone --template-file main.bicep
# Run the next command only after reviewing the proposed changes.
az deployment group create --resource-group rg-learningazure-capstone --template-file main.bicep
az resource list --resource-group rg-learningazure-capstone --output table
Check your resultYour deployed resources match the plan, your handoff states what was and was not verified, and the dedicated environment is removed after review.

Finish the lab

Delete only rg-learningazure-capstone after checking its contents. Also review the earlier lessons’ dedicated resources, budgets, and test assignments. Confirm no lab VM disks or storage accounts remain unintentionally.

Quick knowledge check

What should the handoff say about application connectivity in this capstone?

Reveal the explanation

It should say connectivity was not tested because no application or VM was deployed. Accurate evidence is more useful than an unsupported success claim.

Take this with you

A dependable operator plans, verifies, documents, and cleans up.

Go deeper

AI-assisted lesson · Reference links checked October 3, 2026. Exercises are teaching examples; they have not been executed against your Azure subscription.