Microsoft Azure Network Engineer Associate Training Course

Training course

This is a free, self-paced reading course for AZ-700: Designing and Implementing Microsoft Azure Networking Solutions — the associate-level credential for engineers who own the network side of an Azure estate. The distinction that matters is the one between knowing a virtual network exists and being able to build one that works: subnet planning that accounts for the five reserved addresses, gateway transit that flows in the direction you intended, private DNS zones linked to the right virtual networks, ExpressRoute peering that carries the traffic you expect, and firewall rules that inspect the hop you meant to inspect. This course is written to close that gap.

The course is organized as one module per official exam domain, in the order Microsoft publishes them, and each module carries the domain’s published weight. That matters more on AZ-700 than on most exams because the weighting is genuinely uneven: core networking infrastructure alone is 25–30%, and together with connectivity services it accounts for roughly half of the exam. Reading in published order also happens to be the right build order — addressing and DNS come before hybrid links, which come before what you put in front of the workload.

AZ-700 Associate level 5 modules Domain-weighted Self-paced No signup

What the course covers

Design and implement core networking infrastructure

Module 1 · 25–30%

The largest domain and the foundation everything else sits on. IP addressing and subnet planning, including the five reserved IPs in every subnet, subnet delegation for services such as SQL Managed Instance, and public IP prefixes with BYOIP; DNS design across public and private zones, virtual network links, and the DNS Private Resolver for hybrid name resolution; virtual network connectivity through peering, gateway transit, service chaining, and user-defined routes; the Azure Route Server for dynamic route exchange with network virtual appliances; NAT Gateway for outbound SNAT; and monitoring through Network Watcher, Azure Monitor for Networks, DDoS Protection, and Defender for Cloud.

Design, implement, and manage connectivity services

Module 2 · 20–25%

Hybrid connectivity, where most enterprise design decisions actually get made. Site-to-site VPN — active-active versus active-standby, policy-based versus route-based tunnels, VPN gateway SKU sizing, and local network gateway configuration. Point-to-site VPN and the OpenVPN, IKEv2, and SSTP trade-offs, with authentication by certificate, RADIUS, or Microsoft Entra ID. ExpressRoute end to end: circuit models, SKUs and tiers, private versus Microsoft peering, and the add-ons — Global Reach, FastPath, ExpressRoute Direct, and encryption over the circuit. Azure Virtual WAN closes the module as the managed hub-and-spoke transit fabric, with routing intent, secured hubs, and any-to-any connectivity.

Design and implement application delivery services

Module 3 · 15–20%

The layer-4 and layer-7 traffic distribution stack, and choosing correctly between its four options. Azure Load Balancer at layer 4 — Standard SKU capabilities, HA ports, zone redundancy, internal versus public frontends, cross-region load balancing, inbound NAT rules, and explicit outbound SNAT rules. Azure Application Gateway at layer 7 within a region — backend pools, health probes, path- and host-based routing, TLS termination and re-encryption, and rewrite rules. Azure Front Door at the global edge — Standard versus Premium, routing rules, caching, end-to-end TLS, and Private Link origins that let a global service front a private backend. Traffic Manager completes the set as the DNS-layer global router.

Design and implement private access to Azure services

Module 4 · 10–15%

The smallest domain by weight and the most heavily concept-tested. Private endpoints, which give a PaaS resource a private IP inside your virtual network, allow the public endpoint to be disabled, and depend on a linked private DNS zone such as privatelink.database.windows.net to resolve the resource’s FQDN to that private IP. Private Link service as the provider side: publishing a workload behind a Standard internal load balancer so customer virtual networks can connect through their own private endpoints, governed by visibility and auto-approval lists. Service endpoints as the older, lighter alternative — traffic still targets the public IP but takes an optimized backbone path, and can be narrowed with service endpoint policies. The module concentrates on when each option fits and, just as importantly, what breaks if you pick the other one.

Design and implement Azure network security services

Module 5 · 15–20%

Network security groups and how rule priority is evaluated, application security groups for tag-based grouping, virtual network flow logs, IP Flow Verify, and effective security rules for troubleshooting. Azure Virtual Network Manager security admin rules, which evaluate ahead of NSGs and cannot be overridden by workload owners — the enterprise enforcement layer. Azure Firewall across the Basic, Standard, and Premium SKUs, with the Premium capabilities called out separately (TLS inspection, IDPS, URL filtering, web categories), plus DNAT rule design and Firewall Manager for hierarchical policy across multiple firewalls. Web Application Firewall on both Application Gateway and Front Door, covering detection versus prevention mode, custom rules, and exclusions for false positives.

How to use it

Read a module, then work the matching portion of the AZ-700 practice exam before moving on. AZ-700 rewards the ability to choose between options that all technically work, so the useful signal is not whether you recognize Azure Front Door but whether you can say why it beats Application Gateway for a given requirement — and that only surfaces when you answer questions. The exam also includes case studies and, on some sittings, hands-on portal labs, so reading alone will not carry you: pair each module with a subscription and actually build the peering, the private endpoint, and the firewall policy you are reading about.

Do module 1 properly even if you find it familiar; addressing, DNS, and routing mistakes cascade into every later domain, and it is the heaviest block on the exam. For exam logistics — question types, timing, the 700-of-1000 scaled cut score, pricing, and how the compensatory scoring model works — see the AZ-700 certification guide.

Course not found.

Frequently asked questions about the AZ-700 training course

Is the AZ-700 training course free?

Yes. The course is free to read and requires no signup or account. It is funded by the same practice-exam catalogue it sits alongside.

How is the course structured?

One module per official AZ-700 exam domain, in Microsoft’s published order, with each module weighted to the domain’s published percentage range. Within each module the material is broken into short lessons, followed by key terms and further reading.

Does this replace Microsoft’s official training?

No. Microsoft Learn publishes free official learning paths for AZ-700, and they are the authoritative source. This course is an independent study companion — written to be read quickly and to slot alongside practice questions — not a substitute for the official study guide.

Do I need AZ-104 before starting?

There are no formal prerequisites, but AZ-700 assumes AZ-104-level Azure experience or the hands-on equivalent. A candidate who is still learning to navigate the portal will spend the exam on basics rather than on networking. If that describes you, work through the AZ-104 training course first — AZ-700 goes far deeper into the same virtual networking material AZ-104 introduces.

What should I do after finishing the course?

Move to the AZ-700 practice exam and keep working until you are clearing 70% across every domain rather than only the two heavy ones. The exam is compensatory, so a strong module 1 can offset a weaker module 4, but you should not plan around that. Then book with Pearson VUE.

Is the course current with the latest AZ-700 outline?

The course is built against the outline as updated on April 24, 2026, which brought minor refinements across all five domains — no weightings shifted, and no domains were added or removed. Microsoft can revise the outline at any time; verify the current study guide on Microsoft Learn before you sit the exam.

Trademark notice & independence. Certifym.net is operated by Certifym Exam Services, LLC and is not affiliated with, endorsed by, or sponsored by Microsoft Corporation. Microsoft®, Azure®, Microsoft Certified, Microsoft Entra™, and Azure Network Engineer Associate are trademarks or registered trademarks of Microsoft Corporation. AZ-700 is Microsoft’s exam code for the Designing and Implementing Microsoft Azure Networking Solutions exam and is used here nominatively to identify the certification these study materials are intended for. The AZ-700 study guide and its skills outline are the property of Microsoft Corporation; candidates should review the official, current study guide directly on Microsoft Learn.

All course content, questions, answers, and explanations on Certifym are original content created for study purposes. Nothing here is drawn from actual exam content, from Microsoft’s official practice assessment, or from any third-party question bank, and none of it is represented as Microsoft training material. Domain names and weightings are cited from Microsoft’s publicly published exam skills outline. Studying with these materials does not guarantee a passing result on any live certification exam. Exam requirements, format, domain weights, pricing, and renewal policies are set by Microsoft and may change; always verify current details on Microsoft Learn before scheduling your exam.