LEARNING AZURE / YOUR CLOUD LEARNING SPACE
No account neededAbout
Build & deploy / Lesson 4
Automation / 40–50 min

Describe infrastructure with Bicep

Create a repeatable network definition, preview its proposed changes, and understand the difference between an infrastructure description and a deployment operation.

What you’ll be able to do

  • Read parameters, resource declarations, and properties in Bicep.
  • Run a resource-group-scoped what-if preview.
  • Explain why reviewing a plan is valuable before deployment.
Before you beginLessons 1 and 3, Azure CLI with Bicep support, and permissions for the resources and deployment operations. What-if requires appropriate permissions too. Use a separate resource group rg-learningazure-iac to isolate this exercise.

Get the idea

Declare the intended result

Bicep describes Azure resources using declarative syntax. Instead of clicking through a wizard each time, keep a reviewed definition in source control. Use parameters for values that differ between environments.

Scope matters

This example targets a resource group and defines one virtual network. A resource-group deployment command is different from a subscription-scoped deployment. Match the template’s scope to the deployment command.

Preview before applying

What-if estimates changes without applying that deployment. It is a review tool, not proof that a production rollout is risk-free. Quota, policy, permissions, and service conditions still affect execution.

Try it yourself

  1. Create rg-learningazure-iac with az group create, selecting an approved region.
  2. Save the Bicep example below as main.bicep in your working directory.
  3. Run az bicep build --file main.bicep to check compilation. This produces an ARM JSON representation; it does not deploy resources.
  4. Run the what-if command below. Identify the proposed virtual network and subnet changes. Do not run a create deployment command in this lesson.
  5. Change the networkName parameter and preview again. Explain why a different resource name can imply an additional resource rather than a rename.

Example · main.bicep

param location string = resourceGroup().location
param networkName string = 'vnet-iac-lab'
resource network 'Microsoft.Network/virtualNetworks@2023-11-01' = {
  name: networkName
  location: location
  properties: {
    addressSpace: { addressPrefixes: ['10.43.0.0/16'] }
    subnets: [{ name: 'app', properties: { addressPrefix: '10.43.1.0/24' } }]
  }
}
output networkId string = network.id
az deployment group what-if --resource-group rg-learningazure-iac --template-file main.bicep
Check your resultBicep compiles, what-if shows the intended network, and you can identify how a parameter changes the plan.

Finish the lab

Delete the empty rg-learningazure-iac group if you will not use it for the capstone. This lesson previews a network rather than deploying it; inspect the group before deletion.

Quick knowledge check

Does compiling a Bicep file create the resources in Azure?

Reveal the explanation

No. Compilation produces a template. Deployment is a separate operation, and what-if previews the intended changes without applying that deployment.

Take this with you

Keep infrastructure reviewable, parameterized, and scoped.

Go deeper

AI-assisted lesson · Reference links checked October 3, 2026. Exercises are teaching examples; they have not been executed against your Azure subscription.