Showing posts with label Networking. Show all posts
Showing posts with label Networking. Show all posts

Wednesday, 8 July 2026

The Hidden Career Boost from Your AZ-700 Azure Networking Exam

A futuristic, ascending digital pathway representing career progression, integrated with abstract Azure networking symbols, for the AZ-700 exam.

In an era where cloud infrastructure underpins nearly every major enterprise, the demand for skilled Azure networking professionals is skyrocketing. Organizations are rapidly migrating to Microsoft Azure, creating an urgent need for experts who can design, implement, and manage robust, secure, and scalable network solutions. This is where the AZ-700 Azure Networking exam comes into play, not just as another certification, but as a pivotal turning point in your career.

Many view certification exams as mere tests of knowledge, but the AZ-700 offers a hidden career boost, propelling IT professionals into specialized roles with significant impact and reward. Earning the Microsoft Certified - Azure Network Engineer Associate certification validates your expertise in a critical and complex domain, distinguishing you in a competitive job market. It's more than just passing an exam; it's about unlocking a new level of professional capability and opening doors to unparalleled opportunities.

This article will delve deep into how the AZ-700 exam can transform your career trajectory, detailing what you\'ll learn, how to effectively prepare, and the tangible benefits of becoming a Microsoft Certified - Azure Network Engineer Associate. If you\'re ready to solidify your position as a networking authority in the cloud, understanding the value of this certification is your first step towards an exciting future.

Why the AZ-700 Exam is Your Next Big Career Move

The digital transformation sweeping across industries has placed cloud computing at its forefront. Microsoft Azure, as a leading cloud platform, offers an extensive suite of networking services that are fundamental to deploying and managing highly available, secure, and performant applications. As businesses increasingly rely on Azure for their critical workloads, the expertise in `Designing and Implementing Microsoft Azure Networking Solutions` becomes indispensable.

Unprecedented Demand for Cloud Networking Specialists

The shift to cloud-native architectures and hybrid cloud environments means that traditional networking skills, while valuable, must evolve. Companies are actively seeking professionals who can navigate the complexities of Azure virtual networks, connectivity services, application delivery, and robust security measures. The AZ-700 Azure Networking exam directly addresses this gap, certifying individuals with the practical skills needed to design, implement, and manage these intricate systems.

This certification is not just about keeping pace; it's about leading the charge. With the continuous expansion of Azure services, the ability to architect and maintain sophisticated networking solutions is a core competency that directly translates into business success and innovation. Being proficient in Azure networking means you\'re critical to an organization\'s cloud strategy, performance, and security posture.

Elevated Earning Potential and Job Stability

Specialized skills almost always command higher salaries, and Azure networking is no exception. Holding the Microsoft Certified - Azure Network Engineer Associate certification positions you as a sought-after expert, often leading to competitive compensation packages. As reported by the U.S. Bureau of Labor Statistics, the demand for computer and information technology professionals is projected to grow significantly, indicating a stable and expanding career path for those with in-demand cloud skills. You can explore the current job outlook for computer and information technology professionals to understand the broader market context.

Furthermore, the foundational nature of networking in any cloud deployment ensures job stability. As long as businesses operate in the cloud, there will be a continuous need for professionals who can ensure seamless and secure communication between services, regions, and on-premises environments.

Gateway to Advanced Roles and Opportunities

Passing the AZ-700 Azure Networking exam and earning the MCA Azure Network Engineer Associate certification is often a stepping stone to more senior and architect-level positions. It demonstrates a deep understanding of core Azure networking principles, preparing you for roles such as:

  • Azure Network Engineer
  • Cloud Architect
  • Network Solutions Architect
  • DevOps Engineer (with a networking focus)
  • Cloud Security Engineer

This certification validates your ability to contribute significantly to an organization\'s cloud infrastructure, from initial design to ongoing optimization and troubleshooting. It showcases your expertise in a vital area that impacts performance, security, and scalability across the entire Azure ecosystem.

Prerequisites and Ideal Candidate Profile for AZ-700

While there are no strict prerequisites to take the AZ-700 Azure Networking exam, candidates are generally expected to have significant experience with Azure and networking concepts. Ideal candidates typically possess:

  • At least two years of experience with Azure administration.
  • Strong understanding of on-premises networking technologies, including routing, firewalls, and VPNs.
  • Familiarity with PowerShell, Azure CLI, and Azure portal for managing Azure resources.
  • A conceptual understanding of identity and security in Azure.

This background ensures that you can grasp the advanced concepts covered in the `Designing and Implementing Microsoft Azure Networking Solutions syllabus` and effectively apply them in real-world scenarios. Even if you don't meet every single prerequisite, a dedicated `AZ-700 learning path` and hands-on practice can bridge any knowledge gaps.

For a detailed breakdown of the exam topics and to begin your strategic preparation, you can refer to the detailed AZ-700 Azure Networking exam syllabus.

Deep Dive into the AZ-700: What You'll Master

The AZ-700 exam covers a comprehensive range of topics essential for becoming a proficient Azure Network Engineer. It tests your ability to translate business requirements into secure, scalable, and highly available Azure networking solutions. Let\'s explore the key areas:

Design and Implement Core Networking Infrastructure (25-30%)

This foundational section ensures you understand the building blocks of Azure networking. You\'ll master the art of `implementing Azure virtual networks AZ-700`, which are isolated networks within Azure that serve as the primary communication backbone for your resources. This includes:

  • Designing and Implementing Virtual Networks (VNETs) and Subnets: Understanding IP addressing schemes, subnetting, and how to logically segment your network for security and organization.
  • Configuring IP Addressing: Public and private IP addresses, NAT, and address spaces.
  • Implementing Custom DNS Settings: Integrating Azure DNS with custom DNS servers or third-party solutions for name resolution.
  • Configuring Virtual Network Peering: Connecting VNETs seamlessly across different regions or subscriptions, enabling resources in different VNETs to communicate directly and securely.
  • Designing and Implementing Routing: User-Defined Routes (UDRs), route tables, and understanding how traffic flows within and between VNETs and to the internet.
  • Implementing Network Interfaces: Associating network interface cards (NICs) with virtual machines and configuring their properties.

Mastering these core components is crucial, as they form the bedrock for all other networking services in Azure.

Design, Implement, and Manage Connectivity Services (20-25%)

This section focuses on connecting your Azure environment to other networks, including on-premises data centers and other Azure regions. This is vital for `designing hybrid network solutions Azure AZ-700` and ensuring robust cross-premises connectivity.

  • Designing and Implementing VPN Gateways: Creating secure, encrypted connections over the public internet (Site-to-Site, Point-to-Site VPNs) to link on-premises networks with Azure VNETs. Understanding different SKUs, routing types, and high availability configurations.
  • Designing and Implementing ExpressRoute: Establishing private, high-bandwidth, low-latency connections to Azure data centers. This includes understanding circuits, peering locations, and connectivity models.
  • Designing and Implementing Azure Virtual WAN: A unified connectivity solution for large-scale branch-to-branch connectivity, global VNET peering, and secure VPN termination.
  • Configuring Network Connections: Managing connection objects, monitoring connectivity, and ensuring resilience.
  • Troubleshooting Connectivity Issues: Utilizing Azure Network Watcher and other tools to diagnose and resolve common network problems.

These services are critical for organizations adopting hybrid cloud strategies or requiring high-performance, private links to Azure.

Design and Implement Application Delivery Services (15-20%)

Ensuring that applications are highly available, scalable, and responsive requires robust application delivery mechanisms. This section of the AZ-700 Azure Networking exam covers:

  • Designing and Implementing Azure Load Balancer: Distributing incoming network traffic across multiple backend resources, ensuring high availability and fault tolerance for applications at the network layer. Understanding standard vs. basic, internal vs. public.
  • Designing and Implementing Azure Application Gateway: A web traffic load balancer that enables you to manage traffic to your web applications. It provides HTTP/S load balancing, web application firewall (WAF) capabilities, and SSL termination.
  • Designing and Implementing Azure Front Door: A scalable, secure, and highly available entry point for fast global web application delivery. It offers global load balancing, SSL offload, and WAF capabilities at the edge of Microsoft\'s global network.
  • Designing and Implementing Azure Traffic Manager: A DNS-based traffic load balancer that distributes traffic across global Azure regions based on various routing methods, ensuring application availability and responsiveness.
  • Implementing Azure Content Delivery Network (CDN): Caching static web content at strategically located points-of-presence (PoPs) to minimize latency and improve performance for global users.

Mastering these services is vital for delivering a seamless and high-performing user experience for cloud-hosted applications.

Design and Implement Private Access to Azure Services (10-15%)

Security and data privacy are paramount in cloud deployments. This section focuses on ensuring that Azure services can be accessed privately and securely, minimizing exposure to the public internet.

  • Designing and Implementing Azure Private Link: Providing private connectivity from your Azure virtual networks to Azure PaaS services (like Azure SQL Database, Storage Accounts) and customer-owned/partner services. This keeps traffic on the Microsoft backbone network, enhancing security.
  • Designing and Implementing Virtual Network Service Endpoints: Allowing Azure resources in a virtual network to securely connect to supported Azure PaaS services over an optimized route on the Azure backbone network.
  • Implementing Private DNS Zones: Ensuring proper name resolution for resources accessed via Private Link or Service Endpoints within your private network.
  • Configuring Inbound and Outbound Private Access: Managing access controls and ensuring secure communication flows for private endpoints.

These features are crucial for building highly secure and compliant cloud environments.

Design and Implement Azure Network Security Services (15-20%)

Network security is non-negotiable in the cloud. This section covers the tools and strategies to protect your Azure network infrastructure from threats.

  • Designing and Implementing Network Security Groups (NSGs) and Application Security Groups (ASGs): Filtering network traffic to and from Azure resources based on rules, ports, and protocols. ASGs simplify security management by allowing you to define security rules based on application workloads.
  • Designing and Implementing Azure Firewall: A managed, cloud-based network security service that protects your Azure Virtual Network resources. It\'s a fully stateful firewall as a service with built-in high availability and unrestricted cloud scalability.
  • Designing and Implementing Azure DDoS Protection: Safeguarding Azure resources from Distributed Denial of Service (DDoS) attacks with standard and basic tiers.
  • Implementing Azure Bastion: Providing secure and seamless RDP/SSH connectivity to your virtual machines directly through the Azure portal over SSL, eliminating the need for public IP addresses on VMs.
  • Configuring Azure Sentinel for Network Security Monitoring: Integrating network security logs and data into Azure Sentinel for threat detection, investigation, and response.

A strong grasp of these security services is essential for any professional aspiring to be an `MCA Azure Network Engineer`.

Preparing for Success: Your AZ-700 Study Path

Passing the AZ-700 Azure Networking exam requires a structured approach and consistent effort. Here\'s a comprehensive `Microsoft AZ-700 exam preparation` guide to help you succeed:

Leverage Official Microsoft Learning Resources

Microsoft provides an excellent starting point for your `AZ-700 training course`. The official `AZ-700T00-A: Design and Implement Microsoft Azure Network Solutions` course is specifically designed to cover all the exam objectives. This course, available through various learning partners and often as self-paced modules on Microsoft Learn, provides in-depth theoretical knowledge and practical labs.

Beyond the formal course, Microsoft Learn offers free learning paths directly aligned with the AZ-700 exam objectives. These modules are invaluable for self-study, providing conceptual explanations, hands-on exercises, and knowledge checks.

Utilize a Comprehensive AZ-700 Study Guide

A good `AZ-700 study guide` can help organize your learning. Look for guides that break down each syllabus topic, provide real-world examples, and offer practice questions. Complement this with official documentation from Microsoft, which serves as the ultimate source of truth for all Azure services.

Creating your own study notes, flashcards, and concept maps can also reinforce learning and help with retention, especially for complex networking concepts like routing protocols or firewall rules.

Practice, Practice, Practice with AZ-700 Practice Exams

One of the most effective ways to prepare is by taking `AZ-700 practice exams`. These simulate the real exam environment, helping you get accustomed to the question format, time constraints, and overall experience. Look for high-quality `AZ-700 practice exams` that provide detailed explanations for correct and incorrect answers. This feedback is crucial for identifying your weak areas and focusing your study efforts where they\'re most needed.

Don\'t just memorize answers; understand the underlying concepts. Practice exams are a diagnostic tool, not just a measure of readiness.

Gain Hands-On Experience with Azure Networking

Theoretical knowledge alone is often insufficient. The AZ-700 Azure Networking exam emphasizes practical application. Set up an Azure free account or use your existing subscription to get hands-on experience:

  • Deploy virtual networks and subnets.
  • Configure NSGs and route tables.
  • Set up a VPN Gateway or ExpressRoute simulation.
  • Deploy an Application Gateway or Azure Firewall.
  • Implement Private Link and Service Endpoints.

There are numerous labs available online, including those within the official training course and on Microsoft Learn. This practical experience is invaluable for solidifying your understanding and preparing you for scenario-based questions.

Understand Exam Logistics and Objectives

Familiarize yourself with the `AZ-700 exam cost`, `AZ-700 prerequisites`, exam duration (120 minutes), number of questions (40-60), and the `AZ-700 pass score` (700 out of 1000). Knowing these details helps you manage your expectations and time during the exam.

Always review the official `AZ-700 exam objectives` on the Microsoft certification page. This provides the most accurate and up-to-date outline of what will be tested. Focus your study efforts heavily on the percentage weighting of each section, dedicating more time to areas with higher percentages, such as "Design and Implement Core Networking Infrastructure." For additional strategies to ace your Microsoft certification exams, you might find valuable insights in this comprehensive article.

The Certification Advantage: Beyond the Exam

Passing the AZ-700 Azure Networking exam is just the beginning. The Microsoft Certified - Azure Network Engineer Associate certification offers a multitude of benefits that extend far beyond the day you receive your digital badge.

Enhanced Credibility and Professional Recognition

The `Microsoft Certified - Azure Network Engineer Associate benefits` include immediate recognition of your specialized skills. This certification is a globally recognized standard, signifying to employers, clients, and peers that you possess a verified level of expertise in designing and implementing Azure networking solutions. It adds significant weight to your resume and LinkedIn profile, helping you stand out in a competitive talent pool.

Increased Confidence and Problem-Solving Acumen

The rigorous preparation for the AZ-700 exam builds a deep understanding of Azure networking. This knowledge translates into increased confidence in your abilities to tackle complex networking challenges in real-world scenarios. You\'ll be better equipped to troubleshoot issues, design resilient architectures, and implement secure solutions, becoming an invaluable asset to any team.

Networking Opportunities and Community Engagement

Becoming certified often opens doors to professional networking groups, forums, and communities focused on Microsoft Azure. Engaging with these communities allows you to share knowledge, learn from others, and stay updated on the latest Azure developments. This can lead to mentorship opportunities, job referrals, and collaborative projects, further enriching your career.

Your Career Trajectory After AZ-700

The `Microsoft Azure Network Engineer Associate job outlook` is exceptionally bright. As organizations continue their journey into the cloud, the need for professionals who can effectively manage and secure their network infrastructure will only intensify. This certification provides a clear pathway to several high-demand roles.

Specialized Job Roles

With your AZ-700 certification, you are ideally positioned for roles such as:

  • Azure Network Engineer: Responsible for designing, implementing, and maintaining Azure network infrastructure.
  • Cloud Solutions Architect: Architecting end-to-end cloud solutions, with a strong focus on networking components.
  • Hybrid Cloud Engineer: Bridging the gap between on-premises and Azure environments, particularly in networking.
  • Network Security Engineer: Specializing in securing Azure networks using services like Azure Firewall, NSGs, and DDoS Protection.

These roles are critical for ensuring the performance, security, and scalability of cloud applications and services.

Continuous Learning and Further Certifications

The cloud landscape is constantly evolving. Your AZ-700 certification provides a strong foundation, but continuous learning is key. Consider pursuing advanced Azure certifications to further specialize, such as:

  • Azure Solutions Architect Expert (AZ-305): For designing comprehensive cloud solutions.
  • Azure Security Engineer Associate (AZ-500): To deepen your expertise in cloud security.
  • Azure DevOps Engineer Expert (AZ-400): If you aim to integrate networking with DevOps practices.

This commitment to ongoing professional development ensures that your skills remain relevant and highly valuable in the fast-paced world of cloud computing.

Frequently Asked Questions About the AZ-700 Azure Networking Exam

1. What is the AZ-700 Azure Networking exam about?

The AZ-700 Azure Networking exam, officially known as Designing and Implementing Microsoft Azure Networking Solutions, validates your expertise in designing, implementing, and managing core Azure networking infrastructure, connectivity services, application delivery, private access, and network security services within Microsoft Azure.

2. How much does the AZ-700 exam cost?

The AZ-700 exam typically costs $165 USD, though pricing can vary by region. It's always best to check the official Pearson VUE scheduling portal for the most accurate and up-to-date pricing for your location.

3. What are the best AZ-700 study materials?

The best study materials include the official Microsoft Learn learning paths, the AZ-700T00-A instructor-led course, high-quality third-party `AZ-700 study guide` books, and reliable `AZ-700 practice exams`. Hands-on lab experience with an Azure subscription is also crucial for practical understanding.

4. Is the AZ-700 certification difficult to pass?

The AZ-700 exam is considered challenging and requires a solid understanding of both general networking principles and specific Azure networking services. Success depends on thorough preparation, practical experience, and a deep dive into the exam objectives. Many candidates find the scenario-based questions particularly demanding.

5. What kind of job roles can I get after passing the AZ-700 exam?

After passing the AZ-700 exam and earning the Microsoft Certified - Azure Network Engineer Associate certification, you can pursue roles such as Azure Network Engineer, Cloud Architect, Network Solutions Architect, Hybrid Cloud Engineer, or Cloud Security Engineer, all highly sought after in today's cloud-centric IT landscape.

Conclusion

The AZ-700 Azure Networking exam is far more than just a test; it\'s an investment in your professional future. By demonstrating your expertise in `Designing and Implementing Microsoft Azure Networking Solutions`, you unlock a hidden career boost, positioning yourself at the forefront of cloud technology. This certification validates your ability to build robust, secure, and scalable network infrastructures in Azure, a skill set that is in immense demand and continues to grow in value.

The journey to becoming a Microsoft Certified - Azure Network Engineer Associate will challenge you, but the rewards are substantial. From increased earning potential and career stability to access to advanced roles and a vibrant community of cloud professionals, the benefits are clear. Embrace the learning path, engage with the hands-on experience, and confidently prepare for this transformative certification.

Don\'t let this opportunity pass you by. Take the decisive step towards a brighter, more impactful career in cloud networking. Start your preparation today and prepare to schedule your AZ-700 Azure Networking exam to certify your expertise. For further insights on how to pass your certification exams, explore this guide to mastering Microsoft certifications.

Thursday, 21 March 2024

Microsoft open sources Retina: A cloud-native container networking observability platform

Microsoft open sources Retina: A cloud-native container networking observability platform

The Microsoft Azure Container Networking team is excited to announce Retina, a cloud-native container networking observability platform that enables Kubernetes users, admins, and developers to visualize, observe, debug, and analyze Kubernetes’ workload traffic irrespective of Container Network Interface (CNI), operating system (OS), and cloud. We are excited to release Retina as an open-source repository that helps with DevOps and SecOps related networking cases for your Kubernetes clusters and we invite the open-source community to innovate along with us.

Embracing and advancing open-source software


Cloud native technologies like Kubernetes have made building applications that can run anywhere, easier. At the same time, many applications have become more complex, and managing them in the cloud is increasingly difficult. As companies build cloud-native applications composed of interconnected services and then deploy them to multiple public clouds as well as their private infrastructure, network related observability, troubleshooting, and debugging has become increasingly difficult.

With the power of extended Berkley Packet Filter (eBPF), it is now possible to offer actionable network insights including how containerized micro-services interact and do so in non-intrusive ways without any change in the applications itself—that’s exactly what Retina sets out to achieve. Retina will help democratize network observability and troubleshooting by bringing new focus to the experience of application developers. Retina provides developers with simple ways to observe and troubleshoot their applications for issues such as packet drops and latency without worrying about the complexities of the underlying network infrastructure and transformations.

Based on our positive experience in the community with eBPF and Cilium, we are excited to build on this relationship and engage both more closely and with more communities. We believe that by opening Retina to the community, we can benefit from informed feedback, innovative ideas, and collaborative efforts that will help enhance and expand Retina’s capabilities.

Retina solutions and capabilities


Drawing from our extensive experience managing multiple container networking services for the Azure Kubernetes Service (AKS), we identified critical gaps in network monitoring, the collection of network metrics and traces from Kubernetes clusters. Retina is a cutting-edge solution that closes these gaps and is designed to tackle the complex challenges of managing and supporting Kubernetes networks providing infrastructure- and site-reliability engineers comprehensive insights into cluster networking. Retina also provides deep traffic analysis with Kubernetes-specific context, translating metrics into either industry-standard Prometheus or network flow logs.

Existing open-source solutions are often tightly coupled with specific CNI’s, OS, or data planes, thereby limiting their versatility and use. For this reason, Retina has been designed and developed to be a highly versatile, adaptable, and extensible framework of plugins capable of working seamlessly with any CNI, OS, or cloud provider—making it a valuable addition to any existing toolset. Retina supports both Linux and Windows data planes, ensuring it meets the diverse needs of infrastructure- and site-reliability engineers, while maintaining a minimal memory and CPU footprint on the cluster—this remains true even at scale. Retina’s pluggability design ethos helps us easily extend and adapt to address new use cases without depending on any specific CNI, OS, or data plane.

Microsoft open sources Retina: A cloud-native container networking observability platform
Figure 1: Architecture overview of Retina

One of Retina’s key features provides deep network traffic insights that include Layer 4 (L4) metrics, Domain Name System (DNS) metrics, and distributed packet captures. It seamlessly integrates the Kubernetes app model offering pod-level metrics with detailed context. It emits actionable networking observability data into industry-standard Prometheus metrics providing node-level metrics (for example, forward, drop, Transmission Control Protocol (TCP), User Datagram Protocol (UDP), and Linux utility) and pod-level metrics (such as basic metrics, DNS, and API server latency.)

Retina’s distributed packet captures are label-driven—allowing users to specify what, where, and who to capture packets from. Additionally, it provides historical context of network flow logs and advanced debugging capabilities that enhance network troubleshooting and performance optimization.

Our vision for Retina


Many enterprises are multi-cloud and want solutions that work well not just on Microsoft Azure, but on other clouds as well as on-premises. Retina is open-source and multi-cloud from day one. By open-sourcing Retina, we aim to share our knowledge and vision for Kubernetes networking observability with the broader cloud-native ecosystem. Our hope is that Retina will evolve and grow through collaboration with other developers and organizations who share similar experiences and goals in this field.

In terms of architecture, extensibility was key from the outset and will remain going forward. Retina offers extensibility in data collection—allowing users to easily add new metrics and insights. It also offers extensibility in exporters—enabling users to integrate with other monitoring systems and tools. This flexibility ensures that Retina can adapt to different use cases and environments, making it a versatile and powerful platform for Kubernetes networking observability. In conclusion, we envision Retina as a platform allowing anyone to contribute, extend, and innovate on ultimately creating a robust, purpose-built, and comprehensive solution for Kubernetes networking observability.

Source: microsoft.com

Thursday, 1 February 2024

Unwrapping the 2023 holiday season: A deep dive into Azure’s DDoS attack landscape

Unwrapping the 2023 holiday season: A deep dive into Azure’s DDoS attack landscape

As the holiday season of 2023 unfolded, it brought not only cheer and celebration but also a surge in Distributed Denial-of-Service (DDoS) attacks. This year’s trends in DDoS attacks reveal a complex and evolving threat landscape. From misconfigured Docker API endpoints enabling botnet delivery to the emergence of NKAbuse malware exploiting blockchain technology for DDoS attacks, the tactics and scale of these attacks have shown significant sophistication and diversification.

The 2023 holiday season attack landscape in Azure


In our monitoring of the attack landscape during the holiday season, we observed a notable shift in some of the attack patterns compared to the previous year. This change underscores the relentless efforts of malicious actors to refine their threat tactics and attempt to circumvent DDoS protection strategies.

Daily Attack Volume: Azure’s robust security infrastructure automatically mitigated a peak of 3,500 attacks daily. Notably, large-scale attacks, exceeding 1 million packets per second (pps), constituted 15%-20% of these incidents.*

Unwrapping the 2023 holiday season: A deep dive into Azure’s DDoS attack landscape
Figure 1: Number of daily DDoS attacks towards resources in Azure.

Geographical origins: A shift in attack origins was observed, with the top two origin countries being China with 42% of the attacks and the USA with 18%. All other countries make up 40% of attacks.* This marks a change from the previous year, where both countries were equally represented as the top two regional sources.

Unwrapping the 2023 holiday season: A deep dive into Azure’s DDoS attack landscape
Figure 2: Source countries for DDoS Attacks on Azure.

Attack protocols: The 2023 holiday season saw a predominant use of UDP-based attacks, targeting gaming workloads and web applications, accounting for 78% of the attacks. These include UDP reflected/amplified attacks, which predominantly leverage domain name system (DNS) and simple service discovery protocol (SSDP), as well as quick UDP internet connections (QUIC) for reflection purposes. Notably, QUIC is emerging as a more common attack vector, either by reflection or by DDoS stressors that utilize UDP port 443 randomly. This year’s holiday season attack patterns contrast sharply with the previous year, where TCP-based attacks dominated 65% of all attacks.*

Unwrapping the 2023 holiday season: A deep dive into Azure’s DDoS attack landscape

Unwrapping the 2023 holiday season: A deep dive into Azure’s DDoS attack landscape
Figure 3: Attacks protocols distribution.

Record-breaking attack: A staggering UDP attack, peaking at 1.5 terabits per second (Tbps), targeted a gaming customer in Asia. This attack, originating from China, Japan, the USA, and Brazil, was highly randomized, involving numerous source IPs and ports, yet was fully mitigated by Azure’s defenses.

Botnet evolution: In the past year, cybercriminals increasingly leveraged cloud resources, particularly virtual machines, for DDoS attacks. This trend continued to evolve during the holiday season, with attackers trying to exploit discounted Azure subscriptions globally. From mid-November 2023 and until end of year, we monitored compromised account attempts in 39 Azure regions, with Europe and the USA being the primary targets, accounting for about 67% of these incidents.* Azure’s defense mechanisms successfully neutralized these threats.

Unwrapping the 2023 holiday season: A deep dive into Azure’s DDoS attack landscape
Figure 4: Azure regions where attempts to exploit resources for DDOS attacks occurred.

Contextualizing the threat


The 2023 DDoS attack trends in Azure mirror global patterns. Attacks are becoming politically motivated as we highlighted earlier last year, fueled by geopolitical tensions.

The emergence of DDoS-for-hire services, commonly known as “stressers” and “booters” remain popular amongst attackers. These platforms, readily available on cybercriminal forums, have democratized the ability to launch powerful DDoS attacks, making them accessible to less sophisticated criminals for minimal costs. Recent years have seen an uptick in the availability and use of these services, confirmed by international law enforcement agencies through operations like Operation PowerOFF, which last year in May targeted 13 domains associated with DDoS-for-hire platforms. Despite these efforts, stressers continue to thrive, offering a range of attack methods and power, with some capable of attacks up to 1.5 Tbps.

Cloud power: Combating the evolving DDoS threats


The rise of botnets at scale and DDoS-for-hire services poses a significant risk to online services and business operations. To fight these threats, more cloud computing power is needed to absorb the leading wave of the attack until patterns can be identified, spurious traffic diverted, and legitimate traffic preserved. When tens of thousands of devices constitute an attack, the cloud is our best defense, due to the scale needed to mitigate the largest attacks. In addition, due to the global distribution of the cloud, closer proximity helps to block attacks closest to the sources.

Ensuring robust protection


In an era where digital threats are constantly evolving, ensuring robust protection against DDoS attacks has never been more critical. Here’s how Azure’s comprehensive security solutions are designed to safeguard your digital infrastructure.

DDoS Protection Service: With the high risk of DDoS attacks, it’s essential to have a DDoS protection service like Azure DDoS Protection. This service provides always-on traffic monitoring, automatic attack mitigation upon detection, adaptive real-time tuning, and full visibility on DDoS attacks with real-time telemetry, monitoring, and alerts.

Multi-Layered Defense: For comprehensive protection, set up a multi-layered defense by deploying Azure DDoS Protection with Azure Web Application Firewall (WAF). Azure DDoS Protection secures the network layer (Layer 3 and 4), while Azure WAF safeguards the application layer (Layer 7). This combination provides protection against various types of DDoS attacks.

Alert Configuration: Azure DDoS Protection can identify and mitigate attacks without user intervention. Configuring alerts for active mitigations can keep you informed about the status of protected public IP resources.

2024: Rising against DDoS threats


The 2023 holiday season has underscored the relentless and evolving threat of DDoS attacks in the cyber landscape. As we transition into the new year, it becomes crucial for organizations to enhance and adapt their cybersecurity strategies. This period should be a learning curve, focusing on fortifying defenses against such DDoS attacks and staying vigilant against new tactics. The resilience of Azure against these sophisticated DDoS threats highlights the critical need for robust and adaptive security measures, not just in protecting digital assets but also in ensuring uninterrupted business operations.

* Based on internal data

Source: microsoft.com

Tuesday, 9 May 2023

Azure Virtual WAN introduces its first SaaS offering

Today we are excited to announce the preview of Palo Alto Networks Cloud Next Generation Firewall (NGFW) for Azure, available as a software as a service (SaaS) offering in Azure Virtual WAN. Azure Virtual WAN (vWAN), networking as a service brings networking, security, and routing functionalities together to simplify networking in Azure. With ease of use and simplicity built in, vWAN is a one-stop shop to connect, protect, route traffic, and monitor your wide area network.

Virtual WAN’s deep integration with the Palo Alto Networks managed firewall service allows you to enjoy the simplicity of a SaaS security offering without the hassles of managing provisioning, scaling, resiliency, software updates, or routing. A SaaS model enables a customer to deploy a solution by simply supplying necessary parameters and abstracting themselves from the management of network virtual appliances.

In this blog, we will focus on the Virtual WAN use case, followed by a brief overview of the behind-the-scenes secret sauce that makes it happen, and then understanding key Palo Alto Networks differentiating features.

The use case


Customers of Azure Virtual WAN can now use Palo Alto Networks Cloud NGFW for Azure to secure their traffic through their Virtual WAN deployments. 

The different traffic flows that are supported by a customer’s vWAN deployment are illustrated below. Flows are numbered in the table below with the following assumptions:

◉ ‘B’ stands for a Branch which is a customer’s on-premises network connected to Azure through ExpressRoute circuits, Branch/Site-to-site VPN, or Remote user/Point-to-site connections.
◉ ‘V’ stands for VNet—Azure Virtual networks hosting customer services and connected to a Virtual WAN hub. It may also be referred to as spoke VNet.
◉ ‘I’ stands for internet, which means the customer traffic that originates from or terminates in the internet and traverses through Azure Virtual WAN.
◉ ‘H’ stands for Azure Virtual hub.
◉ Traffic flows across a single hub are traffic flows originating and terminating on endpoints connected to the same virtual hub. These may also be referred to as Intra-hub flows.
◉ Inter-hub flows are traffic flows that traverse across 2 virtual hubs to get to the destination.

Azure Virtual WAN, Azure Exam, Azure Exam Prep, Azure Prep, Azure Prepartion, Azure Tutorial and Materials, Azure Certification
Figure 1: Supported use case and traffic flows in Azure Virtual WAN with Palo Alto Networks Cloud NGFW.

Azure Virtual WAN, Azure Exam, Azure Exam Prep, Azure Prep, Azure Prepartion, Azure Tutorial and Materials, Azure Certification

User experience


Customers can add Palo Alto Networks Cloud NGFW to an Azure Virtual WAN Hub in the Azure portal. After a hub is created, click on the hub name and navigate to Third-party Providers -> SaaS solutions –> Create SaaS and choose the Palo Alto Networks Cloud NGFW option.

Azure Virtual WAN, Azure Exam, Azure Exam Prep, Azure Prep, Azure Prepartion, Azure Tutorial and Materials, Azure Certification
Figure 2: Discover Palo Alto Networks Cloud NGFW.

After clicking “Create”, you’ll be taken to a wizard experience where you can configure and customize your Cloud NGFW SaaS deployment. You can customize key networking and security attributes of your SaaS such as selecting public Ips, DNS proxy settings, security policies, and security settings.

Azure Virtual WAN, Azure Exam, Azure Exam Prep, Azure Prep, Azure Prepartion, Azure Tutorial and Materials, Azure Certification
Figure 3: Create and set up security settings in Palo Alto Networks Cloud NGFW.

After the Cloud NGFW has been successfully provisioned, you can manage your SaaS Firewall by navigating to your Virtual Hub -> Third-party providers -> SaaS solutions -> Manage SaaS. Explore here for more information on available options.

How does this all work within Virtual WAN


As mentioned in the prior section, Virtual WAN supports multiple flows. To illustrate the behind-the-scenes workings in Virtual WAN, we will use East-West (V2V) traffic flows.

Azure Virtual WAN, Azure Exam, Azure Exam Prep, Azure Prep, Azure Prepartion, Azure Tutorial and Materials, Azure Certification
Figure 4: Traffic flows within Virtual WAN for East-West (V2V) traffic to-fro Palo Alto Networks Cloud NGFW.

As you can see, the complexities of traffic engineering, and infrastructure management are completely removed and the user gets to just focus on securing the right security policies for their network traffic.

Key highlights of the Palo Alto Networks Cloud NGFW for Azure integration with Virtual WAN


Palo Alto Networks Cloud NGFW for Azure integrates with Azure Virtual WAN deployments, enabling customers to protect traffic across their entire network. While there are several cool and turn-key features built into the integration, a few that are worth calling out are below:

◉ Machine learning powered NGFW: Cloud NGFW for Azure uses AI and machine learning to detect and stop known, unknown, and zero-day threats, enabling customers to stay ahead of sophisticated adversaries.

◉ Consistent Security and Management from On-Premises to Azure: Cloud NGFW for Azure is integrated with Panorama, Palo Alto Networks policy management solution. The integration of Panorama with Cloud NGFW for Azure offers a host of benefits to customers. Firstly, it enables seamless security policy extension from on-prem to Azure, simplifying operations and reducing administrative workload and total cost of ownership. More importantly, this integration enforces the same high standards of security in the cloud, ensuring that customers’ cloud environments are secure and protected against cyber threats. Additionally, the integration provides centralized visibility, providing valuable insights into the threats on their network enabling customers to manage their security policies through their existing Panorama console, streamlining management, allowing their cloud teams to focus on application migration and new application development.

◉ Ease of use: Palo Alto Networks Cloud NGFW is designed to be incredibly easy to use. Similar to Virtual WAN product principles for simplicity and ease of use, this Palo Alto Networks integrated solution allows customers to procure and deploy the solution directly from the Azure portal in just a few minutes, providing instant protection against cyber threats. The solution is also painless to operate as Palo Alto Networks takes care of scaling, resilience, and software updates. This integration gives customers the agility and flexibility they need to manage their cloud security while focusing on their core business objectives.

Source: microsoft.com

Thursday, 6 April 2023

Connect, secure, and simplify your network resources with Azure Virtual Network Manager

Enterprise-scale management and configuration of your network resources in Azure are key to keeping costs down, reducing operational overhead, and properly connecting and securing your network presence in the cloud. We are happy to announce Azure Virtual Network Manager (AVNM), your one-stop shop for managing the connectivity and security of your network resources at scale, is generally available.

What is Azure Virtual Network Manager?


AVNM works through a main process of group, configure, and deploy. You’ll group your network resources across subscriptions, regions, and even tenants; configure the kind of connectivity and security you want among your grouped network resources; and finally, deploy those configurations onto those network groups in whichever and however many regions you’d like.

Common use cases

Common use cases for AVNM include the following and can be addressed by deploying AVNM’s connectivity and security admin configurations onto your defined network groups:

  • Interconnected virtual networks (VNets) that communicate directly with each other.
  • Central infrastructure services in a hub VNet that are shared by other VNets.
    • Establishing direct connectivity between spoke VNets to reduce latency.
  • Automatic maintenance of connectivity at scale, even with the addition of new network resources.
  • Enforced standard security rules on all existing and new VNets without risk of change.
    • Keeping flexibility for VNet owners to configure network security groups (NSGs) as needed for more specific traffic dictation.
  • Application of default security rules across an entire organization to mitigate the risk of misconfiguration and security holes.
  • Force-allowance of services’ traffic, such as monitoring services and program updates, to prevent accidental blocking through security rules.

Connectivity configuration


Hub and spoke topology

When you have some services in a hub VNet, such as an Azure Firewall or ExpressRoute, and you need to connect several other VNets to that hub to share those services, that means you’ll have to establish connectivity between each of those spoke VNets and the hub. In the future, if you provision new VNets, you’ll also need to make sure those new VNets are correctly connected to the hub VNet.

With AVNM, you can create groups of VNets and select those groups to be connected to your desired hub VNet, and AVNM will establish all the necessary connectivity between your hub VNet and each VNet in your selected groups behind the scenes. On top of the simplicity of creating a hub and spoke topology, new VNets that match your desired conditions can be automatically added to this topology, reducing manual interference from your part.

For the time being, establishing direct connectivity between the VNets within a spoke network group is still in preview and will become generally available (GA) at a later date.

Mesh

If you want all of your VNets to be able to communicate with each other regionally or globally, you can build a mesh topology with AVNM’s connectivity configuration. You’ll select your desired network groups and AVNM will establish connectivity between every VNet that is a part of your selected network groups. The mesh connectivity configuration feature is still in preview and will become generally available at a later date.

How to implement connectivity configurations with existing environments

Let’s say you have a cross-region hub and spoke topology in Azure that you’ve set up through manual peerings. Your hub VNet has an ExpressRoute gateway and your dozens of spoke VNets are owned by various application teams.

Here are the steps you would take to implement and automate this topology using AVNM:

1. Create your network manager.
2. Create a network group for each application team’s respective VNets using Azure Policy definitions that can be conditionally based on parameters including (but not limited to) subscription, VNet tag, and VNet name.
3. Create a connectivity configuration with hub and spoke selected. Select your desired hub VNet and your network groups as the spokes.
4. By default, all connectivity established with AVNM is additive after the connectivity configuration’s deployment. If you’d like AVNM to clean up existing peerings for you, this is an option you can select; otherwise, existing connectivity can be manually cleaned up later if desired.
5. Deploy your hub and spoke connectivity configuration to your desired regions.

In just a few clicks, you’ve set up a hub and spoke topology among dozens of VNets from all application teams globally through AVNM. By defining the conditions of VNet membership for your network groups representing each application team, you’ve ensured that any newly created VNet matching those conditions will automatically be added to the corresponding network group and receive the same connectivity configuration applied onto it. Whether you choose to have AVNM delete existing peerings or not, there is no downtime to connectivity between your spoke VNets and hub VNet.

Security feature


AVNM currently provides you with the ability to protect your VNets at scale with security admin configurations. This type of configuration consists of security admin rules, which are high-priority security rules defined similarly to, but with precedence over NSG rules.

The security admin configuration feature is still in preview and will GA at a later date.

Enforcement and flexibility

With NSGs alone, widespread enforcement on VNets across several applications, teams, or even entire organizations can be tricky. Often there’s a balancing act between attempts at centralized enforcement across an organization and handing over granular, flexible control to teams. The cost of hard enforcement is higher operational overhead as admins need to manage an increasing number of NSGs. The cost of individual teams tailoring their own security rules is the risk of vulnerability as misconfiguration or opened unsafe ports is possible. Security admin rules aim to eliminate this sliding scale of choosing between enforcement and flexibility altogether by providing central governance teams with the ability to establish guardrails, while intentionally allowing traffic for individual teams to flexibly pinpoint security as needed through NSG rules.

Difference from NSGs


Security admin rules are similar to NSG rules in structure and input parameters, but they are not the exact same construct. Let’s boil down these differences and similarities:

  TARGET AUDIENCE APPLIED ON  EVALUATION ORDER  ACTION TYPES PARAMETERS
SECURITY ADMIN RULES  Network admins, central governance team Virtual networks  Higher priority  Allow, Deny, Always Allow  Priority, protocol, action, source, destination
NSG RULES  Individual teams Subnets, NICs  Lower priority, after security admin rules  Allow, Deny

One key difference is the security admin rule’s Allow type. Unlike its other action types of Deny and Always Allow, if you create a security admin rule to Allow a certain type of traffic, then that traffic will be further evaluated by NSG rules matching that traffic. However, Deny and Always Allow security admin rules will stop the evaluation of traffic, meaning NSGs down the line will not see or handle this traffic. As a result, regardless of NSG presence, administrators can use security admin rules to protect an organization by default.

Azure Career, Azure Skills, Azure Tutorial and Materials, Azure Prep, Azure Guides, Azure Learning, Azure Tutorial and Materials

Key Scenarios


Providing exceptions

Being able to enforce security rules throughout an organization is useful, to say the least. But one of the benefits of security admin rules that we’ve mentioned is its allowance for flexibility by teams within the organization to handle traffic differently as needed. Let’s say you’re a network administrator and you’ve enforced security admin rules to block all high-risk ports across your entire organization, but an application team 1 needs SSH traffic for a few of their resources and has requested an exception for their VNets. You’d create a network group specifically for application team 1’s VNets and create a security admin rule collection targeting only that network group—inside that rule collection, you’d create a security admin rule of action type Allow for inbound SSH traffic (port 22). The priority of this rule would need to be higher than the original rule you created that blocked this port across all of your organization’s resources. Effectively, you’ve now established an exception to the blocking of SSH traffic just for application team 1’s VNets, while still protecting your organization from that traffic by default.

Azure Career, Azure Skills, Azure Tutorial and Materials, Azure Prep, Azure Guides, Azure Learning, Azure Tutorial and Materials

Force-allowing traffic to and from monitoring services or domain controllers

Security admin rules are handy for blocking risky traffic across your organization, but they’re also useful for force-allowing traffic needed for certain services to continue running as expected. If you know that your application teams need software updates for their virtual machines, then you can create a rule collection targeting the appropriate network groups consisting of Always Allow security admin rules for the ports where the updates come through. This way, even if an application team misconfigures an NSG to deny traffic on a port necessary for updates, the security admin rule will ensure the traffic is delivered and doesn’t hit that conflicting NSG.

How to implement security admin configurations with existing environments

Let’s say you have an NSG-based security model consisting of hundreds of NSGs that are modifiable by both the central governance team and individual application teams. Your organization implemented this model originally to allow for flexibility, but there have been security vulnerabilities due to missing security rules and constant NSG modification.

Here are the steps you would take to implement and enforce organization-wide security using AVNM:

1. Create your network manager.

2. Create a network group for each application team’s respective VNets using Azure Policy definitions that can be conditionally based on parameters including (but not limited to) subscription, VNet tag, and VNet name.

3. Create a security admin configuration with a rule collection targeting all network groups. This rule collection represents the standard security rules that you’re enforcing across your entire organization.

4. Create security admin rules blocking high-risk ports. These security admin rules take precedence over NSG rules, so Deny security admin rules have no possibility of conflict with existing NSGs. Redundant or now-circumvented NSGs can be manually cleaned up if desired.

5. Deploy your security admin configuration to your desired regions.

You’ve now set up an organization-wide set of security guardrails among all of your application teams’ VNets globally through AVNM. You’ve established enforcement without sacrificing flexibility, as you’re able to create exceptions for any application team’s set of VNets. Your old NSGs still exist, but all traffic will hit your security admin rules first. You can clean up redundant or avoided NSGs, and your network resources are still protected by your security admin rules, so there is no downtime from a security standpoint.

Source: microsoft.com

Tuesday, 28 March 2023

Monitor Azure Virtual Network Manager changes with event logging

Today, our customers establish and manage their Azure virtual networks at scale. As their number of network resources grows, the question of how to maintain connectivity and security among their scale of resources arises. This is where Microsoft Azure Virtual Network Manager comes in—your one-stop shop for managing the connectivity and security of your network resources at scale (currently in preview). And when customers use Azure Virtual Network Manager, they also need visibility into what kind of changes were made so that they can audit those events, analyze those changes over time, and debug issues along the way. This capability is now a reality—Azure Virtual Network Manager event logging is now in preview.

Azure Virtual Network Manager (AVNM) uses Azure Monitor for telemetry collection and analysis like many other Azure services. AVNM now provides event logs that you can interact with through Azure Monitor’s Log Analytics tool in the Azure Portal, as well as through a storage account. You can also send these logs to an event hub or partner solution.

With this preview announcement, Azure Virtual Network Manager will provide a log category for network group membership change. In the context of AVNM, network groups are defined by the user to contain virtual networks. The membership of a network group can be manually provided (such as by selecting VNetA, VNetB, and VNetC to be a part of this network group) as well as conditionally set through Azure Policy (such as by defining that any virtual network within a certain subscription that contains some string in its name will be added to this network group). The network group membership change log category tracks when a particular virtual network is added to or removed from a network group. This can be used to track network group membership changes over time, to capture a snapshot of a particular virtual network’s network group membership, and more.

What attributes are part of this event log category?


This network group membership change category emits one log per network group membership change. So, when a virtual network is added to or removed from a network group, a log is emitted correlating to that single addition or removal for that particular virtual network. If you’re looking at one of these logs from your storage account, you’ll see several attributes:

Attribute Description 
time  Datetime when the event was logged.
resourceId  Resource ID of the network manager. 
location  Location of the virtual network resource. 
operationName  Operation that resulted in the virtual network being added or removed. Always the “Microsoft.Network/virtualNetworks/networkGroupMembership/write” operation. 
category  Category of this log. Always “NetworkGroupMembershipChange.” 
resultType  Indicates successful or failed operation. 
correlationId  GUID that can help relate or debug logs. 
level  Always “Info.” 
properties  Collection of properties of the log. 

Within the properties attribute are several nested attributes:

Properties attribute Description 
Message Basic success or failure message.
MembershipId Default membership ID of the virtual network.
GroupMemberships Collection of what network groups the virtual network belongs to. There may be multiple “NetworkGroupId” and “Sources” listed within this property since a virtual network can belong to multiple network groups simultaneously.
MemberResourceId Resource ID of the virtual network that was added to or removed from a network group.

Within the GroupMemberships attribute are several nested attributes:

GroupMemberships attribute Description 
NetworkGroupId ID of a network group the virtual network belongs to.
Sources

Collection of how the virtual network is a member of the network group.


Within the Sources attribute are several nested attributes:
 
Sources attribute Description
Type Denotes whether the virtual network was added manually (“StaticMembership”) or conditionally via Azure Policy (“Policy”).
StaticMemberId If the “Type” value is “StaticMembership,” this property will appear.
PolicyAssignmentId

If the “Type” value is “Policy,” this property will appear. ID of the Azure Policy assignment that associates the Azure Policy definition to the network group.

PolicyDefinitionId

If the “Type” value is “Policy,” this property will appear. ID of the Azure Policy definition that contains the conditions for the network group’s membership.


How do I get started?


The first step you’ll need to take is to set up your Log Analytics workspace or your storage account, depending on how you want to consume these event logs. You should note that if you’re using a storage account or event hub, it will need to be in the same region of the network manager you’re accessing logs from. If you’re using a Log Analytics workspace, it can be in any region. The network manager you’re accessing the logs of won’t need to belong to the same subscription as your Log Analytics workspace or storage account, but permissions may restrict your ability to access logs cross-subscription.

Note that at least one virtual network must be added or removed from a network group in order to generate logs. A log will generate for this event a couple minutes later.

Accessing Azure Virtual Network Manager’s event logs with Log Analytics

The first step is to navigate to your desired network manager and select the Diagnostic settings blade under the Monitoring section. Then you can select Add diagnostic setting and select the option to send the logs to your Log Analytics workspace.

Monitor Azure Virtual Network Manager, Azure Exam, Azure Exam Prep, Azure Tutorial and Materials, Azure Learning, Azure Certification, Azure Prep, Azure Preparation, Azure Guides, Azure Learning

Then you can navigate to your Log Analytics workspace directly through your network manager by selecting the Logs blade under the Monitoring section.

Monitor Azure Virtual Network Manager, Azure Exam, Azure Exam Prep, Azure Tutorial and Materials, Azure Learning, Azure Certification, Azure Prep, Azure Preparation, Azure Guides, Azure Learning

Monitor Azure Virtual Network Manager, Azure Exam, Azure Exam Prep, Azure Tutorial and Materials, Azure Learning, Azure Certification, Azure Prep, Azure Preparation, Azure Guides, Azure Learning

Alternatively, you can also navigate to your Log Analytics workspace in the Azure Portal and select the Logs blade.

Monitor Azure Virtual Network Manager, Azure Exam, Azure Exam Prep, Azure Tutorial and Materials, Azure Learning, Azure Certification, Azure Prep, Azure Preparation, Azure Guides, Azure Learning

From either place, you can run your own queries on your network manager’s emitted logs for network group membership changes, or you can also run our preloaded queries. Our preloaded queries can fetch the most recent network group membership changes and failed network group membership changes.

Accessing Azure Virtual Network Manager’s event logs with a storage account

The first step is to again navigate to your desired network manager and select the Diagnostic settings blade under the Monitoring section. Then you can select Add diagnostic setting and select the option to archive the logs to your storage account.

Then you can navigate to your storage account and select the Storage browser blade.

Monitor Azure Virtual Network Manager, Azure Exam, Azure Exam Prep, Azure Tutorial and Materials, Azure Learning, Azure Certification, Azure Prep, Azure Preparation, Azure Guides, Azure Learning

Select Blob containers. A blob container will be automatically generated once network group membership changes occur.

Monitor Azure Virtual Network Manager, Azure Exam, Azure Exam Prep, Azure Tutorial and Materials, Azure Learning, Azure Certification, Azure Prep, Azure Preparation, Azure Guides, Azure Learning

Navigate down the blob container’s file path until you reach a JSON file for the datetime specified by that file path.

Monitor Azure Virtual Network Manager, Azure Exam, Azure Exam Prep, Azure Tutorial and Materials, Azure Learning, Azure Certification, Azure Prep, Azure Preparation, Azure Guides, Azure Learning

Download the JSON file to view the raw logs for the file path’s datetime.

Source: microsoft.com