Design Studio744 words

Design Studio — Design solutions for logging and monitoring

AZ-305 › Unit 1 › Design solutions for logging and monitoring

Design Studio — Design solutions for logging and monitoring

This studio turns the topic into an architecture exercise. Produce a recommendation that another engineer could challenge, implement, and validate. There is no credit for a list of Azure products without flows, constraints, failure behaviour, and trade-offs.

Studio brief

1
Design identity, governance, and monitoring solutions
4
45–60 minutes

Client brief

Fabrikam is modernising a production workload in this domain: Design the signal path from collection to retention, query, alert, and automated response. The workload serves internal teams and external customers, carries regulated data, and must remain supportable by a small platform team. The client has supplied incomplete requirements; part of the exercise is to state assumptions and identify questions that would materially change the recommendation.

The initial requirements are:

  1. The design must address platform metrics and logs with explicit assumptions and measurable acceptance evidence.
  2. The design must address cross-resource analytics with explicit assumptions and measurable acceptance evidence.
  3. The design must address application telemetry with explicit assumptions and measurable acceptance evidence.
  4. The design must address long retention or siem with explicit assumptions and measurable acceptance evidence.
  5. The solution must use Microsoft Entra identities, private connectivity where justified, infrastructure as code, and observable health signals.
  6. The design must state a recovery path, operational owner, cost driver, and one deliberate compromise.

Candidate decision anchors

Requirement threadCandidate starting pointQualification rule
Platform metrics and logsAzure Monitor and diagnostic settingsRoute only required categories to deliberate destinations
Cross-resource analyticsLog Analytics workspacePartition for residency, ownership, access, retention, and cost
Application telemetryApplication InsightsUse distributed traces, dependencies, failures, and sampling
Long retention or SIEMStorage/Event Hubs/Microsoft SentinelChoose archive, streaming, or security operations deliberately

These are starting points, not an answer key. You may select a different service when a stated assumption or constraint justifies it. Every deviation must identify the requirement it serves and the new operational cost it introduces.

Studio workflow

  1. Clarify

    Write five questions whose answers could change the architecture. Mark hard constraints separately from preferences.

Required submission

  1. A one-page architecture diagram with a text equivalent.
  2. A decision record containing context, decision, alternatives, consequences, and validation evidence.
  3. A requirement-to-control matrix that maps every hard constraint to a component or operating process.
  4. A failure table covering component, zone, region, identity, network, and operator-error failures where applicable.
  5. Three validation tests: one functional, one reliability/security, and one operational or cost test.

Review traps

  • Activity Log is not guest OS telemetry.
  • Alerts need an action path, not only a threshold.
  • Workspace centralisation is not automatically least privilege.

Assessment rubric

Dimension0 — Missing1 — Partial2 — Release quality
RequirementsProducts chosen before constraintsSome constraints mappedHard constraints, assumptions, and change-driving questions are explicit
ArchitectureComponent listMain flow shownIdentity, traffic/data, dependencies, and failure boundaries are coherent
Trade-offsNo alternativeAlternative namedStrongest alternative rejected using a stated requirement
OperabilityMonitoring mentionedSome runbook detailHealth, capacity, deployment, recovery, ownership, and cost evidence defined
CurrencyNo sourcesSecondary/undated sourceCurrent Microsoft primary source linked and reviewed date recorded

Reflection

  • Which requirement eliminated the most attractive alternative?
  • Which assumption creates the greatest residual risk?
  • What would you test in a pilot before approving production deployment?
  • How would the recommendation change if the operations team doubled in size or the recovery objective tightened?

Source and freshness

Grounded in the current AZ-305 skills outline and both attached course sources. Current service contracts must be verified in Microsoft Learn during the studio. Reviewed 2026-08-02.

Ready to study Designing Microsoft Azure Infrastructure Solutions (AZ-305)?

Practice tests, flashcards, and all study notes — free, no sign-up needed.

Start Studying — Free