Microsoft Certification Study Guide
AZ-900 Microsoft Azure Fundamentals certification badge

AZ-900 Study Guide

Microsoft Azure Fundamentals

Free study notes for every skill the exam measures, plus the books, courses and practice tests I recommend.

The AZ-900 Study Guide helps you prepare for the Microsoft Azure Fundamentals exam, the usual first step for anyone moving into Azure and the one certification that assumes no cloud experience at all.

Everything here lines up with the skills Microsoft measures: free Microsoft Learn paths and my own study notes for self-study, plus the books, courses and practice tests I recommend when you want more. No exam dumps, ever.

Exam length
45 min
Passing score
700 / 1000
Skills measured
3 domains, 57 skills
Guide reviewed
September 2026

Resources by the way you like to study

11 hand-picked, free and paid

Books

3 resources

Many learners prefer studying from books, which is why Microsoft continues to publish the Exam Ref series. Just keep in mind that books can lag behind exam updates, so always check the publication date and whether the skills measured changed since.

AZ-900 is well served here: there is an official Exam Ref, and two independent study guides that take slower, more explanatory routes through the same material.

Exam Ref AZ-900 Microsoft Azure Fundamentals, book cover Recommended

Exam Ref AZ-900 Microsoft Azure Fundamentals

Microsoft's own study guide for the exam, organized by the skills measured so you can work through them in order. The closest thing to an official companion, and the one to pick if you want to study exactly what the exam covers and nothing else.

See price on Amazon (opens in a new tab)
Microsoft Certified Azure Fundamentals Study Guide Exam AZ-900, book cover

Microsoft Certified Azure Fundamentals Study Guide: Exam AZ-900

The Sybex guide, which spends longer explaining the concepts than the Exam Ref does and includes practice questions throughout. A good fit if cloud computing itself is new to you rather than just Azure.

See price on Amazon (opens in a new tab)
Microsoft Azure Fundamentals Certification and Beyond, book cover

Microsoft Azure Fundamentals Certification and Beyond

The Packt guide, which goes past the exam into what you would actually do with Azure afterwards. Worth it if you want the certification to lead somewhere rather than being the whole goal.

See price on Amazon (opens in a new tab)

On-Demand Video Training

4 resources

On-demand training lets you learn at your own pace, on your own schedule: expert-led video courses from Pluralsight or Udemy, or hands-on modules from Microsoft Learn, whenever you need them.

Not all platforms are the same. Pluralsight relies on vetted authors and curated content, while marketplaces vary in quality. I only recommend courses that are highly rated and closely aligned with the skills you need.

Pluralsight Recommended

Microsoft Certified: Azure Fundamentals (AZ-900) Certification Path

Practice test includedFree trial

The full certification path, covering all three domains in order: cloud concepts, then Azure architecture and services, then management and governance. A structured route through everything the exam measures, with a free trial if you want to try it first.

Watch on Pluralsight (opens in a new tab)
Udemy

Master Microsoft Azure Fundamentals: AZ-900 Exam Prep

Practice test included

A long-running and heavily reviewed AZ-900 course that works through the skills measured with plenty of demos. Good if you learn better by watching someone click through the portal than by reading about it.

Watch on Udemy (opens in a new tab)
Udemy

AZ-900 Bootcamp: Microsoft Azure Fundamentals

Practice test included

A faster-paced run at the same material, aimed at getting you exam-ready rather than at depth. A reasonable second pass if you have already studied and want the content again from another angle.

Watch on Udemy (opens in a new tab)
YouTube

AZ-900 Azure Fundamentals Certification Course

Free

John Savill's full AZ-900 course, 65 short videos running to about nine hours, working through every domain on a whiteboard. The strongest free option here if you learn by watching, and his handout of links and diagrams sits on GitHub alongside it.

Watch on YouTube (opens in a new tab)

Practice Tests

2 resources

These are practice exams, not dumps. Dumps ruin the value of a certification for everyone. Practice tests are a great way to check you are ready once you have studied everything in this guide.

Microsoft also publishes a free practice assessment for the AZ-900, and it is the closest match to the real question style.

Whizlabs Recommended

Microsoft Azure Exam AZ-900 Certification Practice Tests

A large question bank with explanations for every answer, which is the part that actually teaches you something. Use it to find the domains where you are weakest rather than to memorize questions.

Take the practice test (opens in a new tab)
Udemy

AZ-900: Microsoft Azure Fundamentals Original Practice Tests

Timed practice exams written to match the real exam's length and balance across domains. Worth taking under exam conditions once, so the timing on the day is not a surprise.

Take the practice test (opens in a new tab)

Microsoft Learn Modules

1 resource

Microsoft Learn is a great free way to learn the AZ-900 content. It is mostly text-based articles, with small quizzes at the end of every module.

The course syllabus below is Microsoft's own list of the learning paths and modules that cover the exam. When you want one topic rather than the whole curriculum, every skill in my study notes links the exact Microsoft Learn page for it.

Microsoft

Course AZ-900T00-A: Introduction to Cloud Infrastructure

Free

Microsoft's official AZ-900 course page. The syllabus lists every Microsoft Learn path and module the course teaches, and all of them are free to work through at your own pace.

Start on Microsoft Learn (opens in a new tab)

Live Training

1 resource

This is the Microsoft Official Course, which you can schedule at a Microsoft learning partner. The classes are presented by Microsoft Certified Trainers. It is the best way to learn any topic, since you can ask a live instructor questions.

Microsoft

Course AZ-900T00-A: Introduction to Cloud Infrastructure

Instructor-led

The official one-day instructor-led course covering the full exam content, delivered by a Microsoft Certified Trainer at a learning partner. The right choice if your employer pays for training and you want the material in a single guided day.

Find a class (opens in a new tab)

Some links on this page are affiliate links. If you use them, I may earn a commission at no extra cost to you.

Skills measured and study notes

57 skills, free to study here

Built for the skills measured Microsoft published on 20 July 2026.

0 of 57 studied

The AZ-900 exam covers three main domains. I have broken down every single skill measured below with explanations, key facts, and links to help you study. This is the same approach I use when preparing for Microsoft exams myself, and after helping IT professionals prepare for Microsoft certifications for years, I can tell you that understanding what each skill is really asking is the single most important step.

Here is how the three domains break down by weight:

Tip: The heaviest domain is Azure architecture and services at 35-40%, and it is also the broadest. If you are short on study time, spend it there, but do not skip cloud concepts: those questions are quick marks if you know the vocabulary, and they are the ones people lose by guessing.

Domain 1 Describe Cloud Concepts 25-30% of the exam 0 / 15 studied

This domain is the vocabulary of cloud computing, and almost none of it is Azure-specific. It tests whether you can explain what the cloud is, why organizations move to it, and which service model fits a given situation. Expect scenario questions that describe a business and ask which model or which benefit applies.

Describe cloud computing

01

Define cloud computing

Cloud computing is the delivery of computing services over the internet, which Microsoft calls "the cloud". Those services include servers, storage, databases, networking, software and analytics. Instead of buying and running hardware yourself, you rent capacity from a provider and use it over a network.

What you need to know

  • The provider owns and maintains the physical hardware, the datacenters, the power and the cooling
  • You consume the services over a network rather than owning the equipment
  • Cloud services cover compute, storage, networking, databases, and higher level services built on top of those
  • The defining shift is from a capital purchase of hardware to an operating expense for a service

Microsoft Learn resource: What is cloud computing (opens in a new tab)

02

Describe the shared responsibility model

The shared responsibility model says that security and management duties are split between you and the cloud provider, and where the line sits depends on the service type. This is one of the most reliably tested concepts on the exam.

What you need to know

  • The provider is always responsible for the physical datacenter, the physical network and the physical hosts
  • You are always responsible for your data, your accounts and identities, and the devices that connect
  • The middle layers (operating system, network controls, applications) shift from you to the provider as you move from IaaS to PaaS to SaaS
  • With IaaS you carry the most responsibility; with SaaS you carry the least
  • Responsibility for information and data never transfers to the provider, whatever the model

Microsoft Learn resource: Describe the shared responsibility model (opens in a new tab)

Exam tip: If a question asks who is responsible for something, work out the service model first, then place the item. Data and identities are always yours.

03

Define cloud models, including public, private, and hybrid

A cloud model describes where the infrastructure lives and who can use it. The exam expects you to match a described situation to the right model.

What you need to know

  • Public cloud runs on the provider's hardware and is shared by many organizations, with no capital expense for you
  • Private cloud is used by a single organization, either in its own datacenter or hosted, and gives the most control at the highest cost
  • Hybrid cloud combines the two so workloads can run in either, which suits regulated data that must stay on premises
  • Multicloud means using more than one cloud provider, which is a different idea from hybrid
  • Azure Arc and Azure VMware Solution are the services named for hybrid and multicloud scenarios

Microsoft Learn resource: Define cloud models (opens in a new tab)

04

Identify appropriate use cases for each cloud model

Most cloud model questions are scenarios rather than definitions, so the skill being tested is matching a business constraint to a model.

What you need to know

  • Choose public when you want lowest cost, fastest scale and no hardware to manage
  • Choose private when regulation, data residency or legacy dependencies require your own hardware
  • Choose hybrid when some workloads must stay put but you want cloud scale for the rest, or when you need a gradual migration path
  • A burst of seasonal demand on top of a steady on-premises workload is the classic hybrid scenario
  • Wanting to avoid dependence on one vendor points to multicloud, not hybrid

Microsoft Learn resource: Define cloud models (opens in a new tab)

05

Describe the consumption-based model

The consumption-based model means you pay for what you actually use rather than for capacity you reserved in advance. It is the financial argument for the cloud and the exam tests that you can state it in business terms.

What you need to know

  • You pay only for the resources you consume, and you stop paying when you stop consuming
  • There is no upfront capital cost for hardware, so spending moves from capital expenditure to operating expenditure
  • You can grow or shrink capacity as demand changes rather than buying for peak
  • Better cost prediction comes from the pricing calculator and from cost management tools, not from a fixed bill
  • Deallocating a virtual machine stops compute charges, but storage for its disks continues to be charged

Microsoft Learn resource: Describe the consumption-based model (opens in a new tab)

Exam tip: Capital expenditure means buying the asset up front. Operating expenditure means paying for a service as you use it. The cloud moves you from the first to the second, and questions often use those exact words.

06

Compare cloud pricing models

Azure offers more than one way to pay, and choosing well is a large part of cost management.

What you need to know

  • Pay-as-you-go charges by usage with no commitment and the highest per-unit price
  • Reserved instances commit you to one or three years for a substantial discount on compute
  • Azure Hybrid Benefit lets you apply existing Windows Server and SQL Server licences with Software Assurance to reduce cost
  • Spot pricing gives deep discounts on interruptible capacity that Azure can reclaim, which suits batch work and never suits production workloads that must stay up
  • Reservations and Hybrid Benefit can be combined for the largest saving

Microsoft Learn resource: Describe the consumption-based model (opens in a new tab)

07

Describe serverless

Serverless computing means the provider manages the servers entirely, and you supply only code or configuration. Servers still exist; you simply never see or manage them.

What you need to know

  • You do not provision, patch or scale the underlying infrastructure
  • Scaling is automatic and usually driven by events or requests
  • Billing is by execution rather than by reserved capacity, so idle costs nothing
  • Azure Functions is the named serverless compute service, and Azure Logic Apps is the serverless workflow service
  • The trade-off is less control over the environment and, for some services, a cold start delay on the first request

Microsoft Learn resource: Describe Azure functions (opens in a new tab)

Describe the benefits of using cloud services

08

Describe the benefits of high availability and scalability in the cloud

High availability and scalability are two different promises that get confused, and the exam tests the difference directly.

What you need to know

  • High availability means the service keeps running when something fails, and it is expressed as an uptime guarantee in a service level agreement
  • Scalability means the service can handle more load by adding capacity
  • Vertical scaling means making a resource bigger, such as moving to a virtual machine with more CPU and memory
  • Horizontal scaling means adding more instances of a resource, which is how most cloud services scale
  • Availability zones and availability sets are the Azure features that deliver high availability inside a region

Microsoft Learn resource: Describe the benefits of high availability and scalability in the cloud (opens in a new tab)

Exam tip: Scaling up is vertical and scaling out is horizontal. If a question mentions adding instances, it is horizontal.

09

Describe the benefits of reliability and predictability in the cloud

Reliability and predictability are the two design promises the Azure Well-Architected Framework names, and they are tested as business benefits rather than as technical settings.

What you need to know

  • Reliability is the ability of a system to recover from failure and keep working, and it comes from designing for failure rather than hoping to avoid it
  • Decentralized cloud design means a failure in one region does not have to take down the whole application
  • Predictability covers both performance and cost, so you can forecast both
  • Performance predictability comes from autoscaling, load balancing and high availability
  • Cost predictability comes from the pricing calculator, the total cost of ownership calculator, and cost alerts and budgets

Microsoft Learn resource: Describe the benefits of reliability and predictability in the cloud (opens in a new tab)

10

Describe the benefits of security and governance in the cloud

This skill is about the governance benefits a cloud platform gives you rather than about any single security product.

What you need to know

  • Cloud templates and policy let you apply a standard configuration to every resource rather than configuring each by hand
  • Azure Policy can audit resources against your rules and flag or block non-compliant ones
  • Cloud services can patch and update themselves on your behalf, depending on the service model
  • Governance features help you meet regulatory requirements and demonstrate compliance during an audit
  • In IaaS you retain more control and therefore more of the security work, which is a governance choice as much as a technical one

Microsoft Learn resource: Describe the benefits of security and governance in the cloud (opens in a new tab)

11

Describe the benefits of manageability in the cloud

Manageability splits into two ideas that sound similar and are tested separately: managing the resources in the cloud, and managing the cloud itself.

What you need to know

  • Management in the cloud means automatic scaling, automatic redeployment of failed resources, templated deployment, and health monitoring with alerts
  • Management of the cloud means the tools you use to interact with Azure: the portal, the command line, the APIs and PowerShell
  • Templates let you create a resource group full of resources from a single definition, repeatedly and identically
  • Automation reduces the human error that causes a large share of outages

Microsoft Learn resource: Describe the benefits of manageability in the cloud (opens in a new tab)

Describe cloud service types

12

Describe infrastructure as a service (IaaS)

Infrastructure as a service gives you the most control and the most responsibility. You rent the hardware and everything above the hypervisor is yours.

What you need to know

  • You are responsible for the operating system, patching, and everything you install
  • The provider handles the physical hosts, the physical network and the datacenter
  • Azure Virtual Machines is the flagship IaaS service
  • It suits lift-and-shift migrations, where an existing server moves to the cloud largely unchanged
  • It also suits test and development environments that need to match production exactly

Microsoft Learn resource: Describe Infrastructure as a Service (opens in a new tab)

13

Describe platform as a service (PaaS)

Platform as a service gives you a managed environment to run your application in. You bring the application; the provider brings and maintains everything underneath.

What you need to know

  • The provider manages the operating system, the runtime, the patching and the underlying infrastructure
  • You manage your application and your data
  • Azure App Service and Azure SQL Database are the commonly named PaaS examples
  • It suits development teams who want to ship an application without maintaining servers
  • You give up control of the underlying environment in exchange for that

Microsoft Learn resource: Describe Platform as a Service (opens in a new tab)

14

Describe software as a service (SaaS)

Software as a service is a finished application you subscribe to and use. You manage almost nothing except your data and who has access.

What you need to know

  • The provider manages everything except your data, your devices, your accounts and your access
  • Microsoft 365 is the example Microsoft uses most often
  • You typically pay per user per month
  • It gives the least control and the fastest time to value
  • Customizing beyond the configuration options the vendor exposes is generally not possible

Microsoft Learn resource: Describe Software as a Service (opens in a new tab)

15

Identify appropriate use cases for each cloud service type (IaaS, PaaS, and SaaS)

As with cloud models, most questions here are scenarios. The skill is matching what the organization wants to control against what each model lets them control.

What you need to know

  • Choose IaaS when you need full control of the operating system, or when you are migrating an existing server as is
  • Choose PaaS when you want to build and run an application without maintaining the platform underneath it
  • Choose SaaS when a finished product solves the problem and you have no wish to build anything
  • A team that wants to deploy code and not think about servers is describing PaaS
  • An organization that needs email without running mail servers is describing SaaS

Microsoft Learn resource: Describe cloud service types (opens in a new tab)

Exam tip: Read for the word "control". The more control the scenario demands, the further toward IaaS the answer sits.

Domain 2 Describe Azure Architecture and Services 35-40% of the exam 0 / 27 studied

This is the largest domain and the one with the most named services. It tests whether you can place Azure's building blocks in the right order, pick the right compute or storage option for a described need, and explain what each identity and security feature is for. You do not need to configure anything, but you do need to know what each service is called and what problem it solves.

Describe the core architectural components of Azure

16

Describe Azure regions, region pairs, and sovereign regions

A region is a set of datacenters close enough together to act as one deployment location. When you create a resource you choose a region, and that choice affects latency, cost and data residency.

What you need to know

  • A region is a geographical area containing at least one, usually several, datacenters connected by a low-latency network
  • Most Azure services require you to pick a region when you deploy
  • Region pairs are two regions in the same geography, usually at least 300 miles apart, used for replication and recovery
  • Planned Azure updates roll out to one region in a pair at a time, so both halves are never updated together
  • Sovereign regions are physically isolated instances of Azure for specific governments, such as Azure Government and Azure China, and they are not part of the public cloud

Microsoft Learn resource: Describe Azure physical infrastructure (opens in a new tab)

Exam tip: Region pairs matter for disaster recovery and for the order in which Azure applies updates. Both facts get tested.

17

Describe availability zones

Availability zones protect against the failure of a single datacenter inside a region. They are the main high availability feature you can use without leaving a region.

What you need to know

  • An availability zone is one or more datacenters with independent power, cooling and networking
  • A region that supports zones has a minimum of three, and they are physically separated within the region
  • Zonal services let you pin a resource to a specific zone; zone-redundant services spread it across zones automatically
  • Zones protect against a datacenter failure, not against a whole region going down, which is what region pairs are for
  • Not every region supports availability zones, and not every service supports them

Microsoft Learn resource: Describe Azure physical infrastructure (opens in a new tab)

18

Describe Azure datacenters

Datacenters are the physical buildings underneath everything else, and the exam only asks you to place them correctly in the hierarchy.

What you need to know

  • A datacenter is a physical facility with servers, power, cooling and networking
  • You never choose a datacenter directly; you choose a region, and Azure places the resource
  • One or more datacenters make up an availability zone, and one or more zones make up a region
  • Microsoft is responsible for datacenter physical security under the shared responsibility model, in every service model

Microsoft Learn resource: Describe Azure physical infrastructure (opens in a new tab)

19

Describe Azure resources and resource groups

A resource is anything you create in Azure, and a resource group is the container you must put it in. Getting the rules of resource groups right is worth easy marks.

What you need to know

  • A resource is a single manageable item: a virtual machine, a storage account, a virtual network, a database
  • Every resource must belong to exactly one resource group, and it cannot belong to two
  • Resource groups cannot be nested inside other resource groups
  • Resources in a group can be in different regions, and the group's own region only stores its metadata
  • Deleting a resource group deletes every resource inside it, which is the fastest way to clean up and the easiest way to cause an accident
  • A resource can be moved to another resource group, and permissions applied to the group are inherited by the resources inside it

Microsoft Learn resource: Describe Azure management infrastructure (opens in a new tab)

Exam tip: Two facts get tested constantly: a resource lives in exactly one resource group, and resource groups cannot nest.

20

Describe subscriptions

A subscription is the billing and access boundary. Everything you deploy is billed to a subscription, and subscriptions are how larger organizations separate environments and departments.

What you need to know

  • A subscription is a logical container for resource groups, and it is the unit of billing
  • An account can hold more than one subscription, and each generates its own invoice
  • Subscriptions also act as a boundary for access management and for service limits and quotas
  • Organizations commonly separate subscriptions by environment, such as production and development, or by department for chargeback
  • Policies and role assignments applied at the subscription level flow down to every resource group and resource inside it

Microsoft Learn resource: Describe Azure management infrastructure (opens in a new tab)

21

Describe management groups

Management groups sit above subscriptions and exist so you can apply governance to many subscriptions at once instead of repeating yourself.

What you need to know

  • A management group is a container for subscriptions and for other management groups
  • Policy and role assignments made at a management group are inherited by everything beneath it
  • Management groups can be nested, unlike resource groups
  • Every Azure directory has a single root management group at the top that contains everything
  • They are how you enforce a rule such as "no virtual machines outside these regions" across a whole organization in one place

Microsoft Learn resource: Describe Azure management infrastructure (opens in a new tab)

22

Describe the hierarchy of resource groups, subscriptions, and management groups

The hierarchy is one of the most reliably tested facts in the whole exam, because it is a single ordered list and it is easy to write a question about.

What you need to know

  • Top to bottom the order is: management groups, subscriptions, resource groups, resources
  • Settings applied higher up are inherited by everything below
  • Management groups can nest inside management groups; resource groups cannot nest inside resource groups
  • A resource belongs to one resource group, a resource group belongs to one subscription, and a subscription belongs to one management group
  • The root management group contains every other management group and subscription in the directory

Microsoft Learn resource: Describe Azure management infrastructure (opens in a new tab)

Exam tip: Learn the four-level order as a sentence and you will answer several questions from it.

Describe Azure compute and networking services

23

Compare compute types, including containers, virtual machines, and functions

Azure offers several ways to run code, and the exam tests which one fits a described need rather than how to configure any of them.

What you need to know

  • Virtual machines give full control of the operating system and are the IaaS option, best for lift and shift
  • Containers package an application with its dependencies, start far faster than virtual machines, and do not include a full operating system
  • Functions are serverless and event-driven, so they run on a trigger and you pay per execution
  • Azure Container Instances runs single containers; Azure Kubernetes Service orchestrates many of them
  • The trade-off runs from most control and most management with virtual machines, to least of both with functions

Microsoft Learn resource: Describe Azure compute services (opens in a new tab)

24

Describe virtual machine options, including Azure virtual machines, Azure Virtual Machine Scale Sets, availability sets, and Azure Virtual Desktop

These four names all appear in the skills measured, so each needs a clear one-line purpose.

What you need to know

  • Azure Virtual Machines are individual servers you create, size and manage
  • Virtual Machine Scale Sets create and manage a group of identical virtual machines and can autoscale the count with demand
  • Availability sets spread virtual machines across fault domains and update domains inside one datacenter, so a hardware failure or a host update does not take them all out
  • Azure Virtual Desktop delivers a Windows desktop and applications from Azure to any device, and supports multi-session Windows
  • Availability sets protect inside a datacenter; availability zones protect across datacenters in a region

Microsoft Learn resource: Describe Azure virtual machines (opens in a new tab)

Exam tip: Fault domains cover hardware failure, update domains cover planned maintenance. If a question names one, it is asking about availability sets.

25

Describe the resources required for virtual machines

Creating a virtual machine creates several other resources with it, and the exam asks what they are.

What you need to know

  • Every virtual machine needs a size, which sets its CPU, memory and storage capability
  • It needs storage for its operating system disk, and may have additional data disks
  • It needs a virtual network and a network interface to connect
  • A public IP address is optional, and a virtual machine without one has no inbound access from the internet
  • The operating system image comes from the Azure Marketplace or from your own image

Microsoft Learn resource: Describe Azure virtual machines (opens in a new tab)

26

Describe application hosting options, including web apps, containers, and virtual machines

This skill overlaps with compute types but is framed around hosting an application rather than running code.

What you need to know

  • Azure App Service hosts web apps, APIs and mobile back ends as a managed platform service, with built-in scaling and deployment slots
  • Containers suit applications that need a consistent environment across development and production, or a microservices architecture
  • Virtual machines suit applications with specific operating system requirements or dependencies a platform service cannot provide
  • Azure Functions suits an application that responds to events rather than running continuously
  • App Service removes the need to patch or manage the underlying servers

Microsoft Learn resource: Describe application hosting options (opens in a new tab)

27

Describe virtual networking, including the purpose of Azure virtual networks, subnets, peering, Azure DNS, Azure VPN Gateway, and ExpressRoute

Six named networking components, each with a distinct job. Learn them as a list of purposes.

What you need to know

  • Azure Virtual Network is the private network your Azure resources live in, isolated from other customers
  • Subnets divide a virtual network so you can group resources and apply different rules to each
  • Peering connects two virtual networks so resources can talk over the Microsoft backbone rather than the public internet
  • Azure DNS hosts your domain's DNS records on Azure's name servers
  • VPN Gateway connects your on-premises network to Azure over an encrypted tunnel across the public internet
  • ExpressRoute provides a private connection to Azure that does not travel over the public internet at all, with higher reliability and lower latency

Microsoft Learn resource: Describe Azure virtual networking (opens in a new tab)

Exam tip: VPN Gateway goes over the internet encrypted, ExpressRoute does not use the internet. That distinction is the question.

28

Define public and private endpoints

Endpoints control how a service is reached, and the two names are easy to confuse under time pressure.

What you need to know

  • A public endpoint is reachable over the public internet, and many Azure services have one by default
  • A private endpoint gives a service a private IP address inside your virtual network, so traffic stays on the Microsoft network
  • A private endpoint keeps the service off the public internet, which is usually the point of using one
  • Service endpoints are a related but different feature: they secure a service to a subnet without giving it a private IP
  • Private endpoints are the answer when a question asks how to reach a platform service without internet exposure

Microsoft Learn resource: Describe Azure virtual networking (opens in a new tab)

Describe Azure storage services

29

Compare Azure Storage services

A storage account can hold several different kinds of data, and the exam asks which one fits a described need.

What you need to know

  • Blob Storage holds unstructured data such as documents, images, backups and logs
  • Azure Files provides fully managed file shares reachable over SMB and NFS, which can be mounted like a network drive
  • Queue Storage holds messages for asynchronous communication between application components
  • Table Storage stores structured NoSQL data as key-value pairs without a fixed schema
  • Azure Disks provides the block storage that virtual machines use for their operating system and data disks

Microsoft Learn resource: Describe Azure storage services (opens in a new tab)

30

Describe storage tiers

Access tiers trade storage cost against access cost, and the exam gives you a usage pattern and asks for the tier.

What you need to know

Tier Storage cost Access cost Minimum stay Read it by
Hot highest lowest none reading it
Cool lower higher 30 days reading it
Cold lower still higher still 90 days reading it
Archive lowest highest 180 days rehydrating first, which takes hours

Archive is the only tier that is offline: the data is there, but nothing can read it until it has been rehydrated to an online tier. Lifecycle management policies move blobs down the tiers automatically as they age, which is how most organizations actually use them.

Microsoft Learn resource: Describe Azure storage services (opens in a new tab)

Exam tip: Match the words in the question. "Rarely accessed" and "can wait hours" means Archive. "Accessed every day" means Hot.

31

Describe redundancy options

Redundancy decides how many copies of your data exist and where. The four names differ in one dimension each, so learn them as a progression.

What you need to know

Option Copies Spread across Survives
Locally redundant storage (LRS) 3 one datacenter a drive or rack failure
Zone-redundant storage (ZRS) 3 three availability zones in one region the loss of a datacenter
Geo-redundant storage (GRS) 6 LRS in the primary region, LRS in the paired region the loss of a region
Geo-zone-redundant storage (GZRS) 6 ZRS in the primary region, LRS in the paired region the loss of a region, with zone protection as well

The read-access variants, RA-GRS and RA-GZRS, add the ability to read from the secondary region. Without them the secondary copy exists but is unreadable until Microsoft or you fail over to it.

Microsoft Learn resource: Describe Azure storage redundancy (opens in a new tab)

32

Describe storage account options and storage types

The storage account is the container that holds your data services, and its settings are chosen at creation.

What you need to know

  • A storage account provides a unique namespace, and its name must be globally unique across all of Azure
  • The performance tier is either standard, backed by hard disks, or premium, backed by solid state disks
  • Account kinds include general purpose v2, which supports all services and is the default recommendation
  • Premium accounts are specialized by workload: block blobs, file shares or page blobs
  • Redundancy and access tier are set on the account, though individual blobs can override the tier

Microsoft Learn resource: Describe Azure storage accounts (opens in a new tab)

33

Identify options for moving files, including AzCopy, Azure Storage Explorer, and Azure File Sync

Three named tools, each suiting a different situation.

What you need to know

  • AzCopy is a command line tool for copying data to and from Azure Storage, and it suits scripted and bulk transfers
  • Azure Storage Explorer is a graphical desktop application for browsing and managing storage, and it uses AzCopy underneath
  • Azure File Sync keeps an on-premises Windows Server file share synchronized with an Azure file share, and can tier cold files to the cloud
  • File Sync lets a local server act as a fast cache while the authoritative copy lives in Azure
  • For very large transfers where bandwidth is the constraint, a physical transfer service is the better answer

Microsoft Learn resource: Identify Azure file movement options (opens in a new tab)

34

Describe migration options, including Azure Migrate and Azure Data Box

Two named migration services with different jobs: one plans and moves workloads, the other moves bulk data physically.

What you need to know

  • Azure Migrate is a hub for discovering, assessing and migrating on-premises servers, databases and web applications to Azure
  • It provides assessment of readiness and sizing, and cost estimates, before you move anything
  • Azure Data Box is a physical device Microsoft ships you, which you fill with data and ship back to be uploaded into Azure
  • Data Box suits very large transfers where the network would take too long, or where bandwidth is limited or expensive
  • Data Box also works in reverse, to export data out of Azure

Microsoft Learn resource: Identify Azure data migration options (opens in a new tab)

Exam tip: If a scenario stresses terabytes and a slow or costly connection, the answer is Data Box, not a network copy.

Describe Azure identity, access, and security

35

Describe directory services in Azure, including Microsoft Entra ID and Microsoft Entra Domain Services

Identity is where the security domain starts, and the two named services solve related but different problems.

What you need to know

  • Microsoft Entra ID is Microsoft's cloud-based identity and access management service, used to sign in to Azure, Microsoft 365 and thousands of other applications
  • It is not a cloud version of Active Directory Domain Services; it uses modern protocols rather than Kerberos and LDAP, and has no organizational units or group policy
  • Microsoft Entra Domain Services provides managed domain services such as domain join, group policy, LDAP and Kerberos, without you running domain controllers
  • Domain Services suits legacy applications that need traditional domain features but should not require you to manage servers
  • Microsoft Entra ID is the identity provider behind Azure role-based access control

Microsoft Learn resource: Describe Azure directory services (opens in a new tab)

36

Describe authentication methods in Azure, including single sign-on (SSO), multifactor authentication (MFA), and passwordless

Three named authentication ideas, and the exam tests what each achieves rather than how to switch it on.

What you need to know

  • Single sign-on lets a user authenticate once and reach multiple applications without signing in again, which reduces password fatigue and the risk that comes with it
  • Multifactor authentication requires two or more of: something you know, something you have, something you are
  • A password plus a code from an authenticator app is the classic example of two factors
  • Passwordless removes the password entirely, using Windows Hello for Business, the Microsoft Authenticator app, or a FIDO2 security key
  • Passwordless is both more secure and easier for the user, which is unusual and worth remembering

Microsoft Learn resource: Describe Azure authentication methods (opens in a new tab)

Exam tip: Two of the same kind is not multifactor. A password and a security question are both something you know.

37

Describe external identities in Azure

External identities cover the people outside your organization who still need access to something you own.

What you need to know

  • Business to business (B2B) collaboration invites external users as guests, using their own credentials from their own organization
  • The guest does not get a second password to manage, because authentication stays with their home directory
  • Business to customer (B2C) is a separate offering for customer-facing applications, letting people sign in with social or local accounts
  • External identities let you share applications and resources without creating and managing accounts for outsiders
  • Guest access can be governed with the same conditional access and access review features as internal accounts

Microsoft Learn resource: Describe Azure external identities (opens in a new tab)

38

Describe Microsoft Entra Conditional Access

Conditional Access is the policy engine that decides whether a sign-in is allowed, and under what extra conditions.

What you need to know

  • It evaluates signals such as user, location, device state, application and risk level, then applies a decision
  • The decision can be to allow, to block, or to allow only if a requirement is met such as multifactor authentication or a compliant device
  • It is often described as an if-then statement: if these signals, then this requirement
  • It enables fine-grained control, such as requiring multifactor authentication only when a sign-in comes from an unfamiliar location
  • Conditional Access is a Microsoft Entra ID feature and requires the appropriate licence tier

Microsoft Learn resource: Describe Azure conditional access (opens in a new tab)

39

Describe Azure role-based access control (RBAC)

Azure RBAC is how you grant permissions to resources, and the exam tests the principle of least privilege and where assignments apply.

What you need to know

  • A role assignment combines a security principal, a role definition and a scope
  • Scope can be a management group, a subscription, a resource group or a single resource, and permissions are inherited downward
  • Built-in roles include Owner (full access including granting access), Contributor (full access except granting access), and Reader (view only)
  • User Access Administrator exists specifically to manage access without managing the resources themselves
  • RBAC follows least privilege: grant the narrowest role at the narrowest scope that does the job

Microsoft Learn resource: Describe Azure role-based access control (opens in a new tab)

Exam tip: The difference between Owner and Contributor is the ability to grant access to others. That single distinction is the question.

40

Describe the concept of Zero Trust

Zero Trust is a security model rather than a product, and the exam tests whether you can state its principles.

The guiding phrase is "never trust, always verify": being inside the network perimeter grants nothing on its own.

The three guiding principles:

  1. Verify explicitly: authenticate and authorize on every available signal, every time, including identity, location, device health and the resource being asked for
  2. Use least privileged access: just-enough access, just-in-time, bounded by risk-based policies, so a compromised account reaches as little as possible
  3. Assume breach: design as though an attacker is already inside, segmenting access, encrypting end to end and watching for what gets past the other two

The model exists because the traditional network perimeter stopped matching how people actually work.

Microsoft Learn resource: Describe Zero Trust model (opens in a new tab)

41

Describe the purpose of the defense-in-depth model

Defense in depth layers protections so that no single failure exposes everything. The exam often asks about the order of the layers.

The seven layers, from the outside in:

  1. Physical security: the datacenter itself, and Microsoft's responsibility in every service model
  2. Identity and access: who gets in at all, with multifactor authentication and Conditional Access
  3. Perimeter: distributed denial of service protection and the edge firewall
  4. Network: segmentation, network security groups, and denying traffic by default
  5. Compute: securing the virtual machines and containers themselves, and closing unused ports
  6. Application: building without vulnerabilities and keeping secrets out of code
  7. Data: encryption at rest and in transit, and access control on the data itself

Data sits at the centre because it is usually what an attacker is after and what regulation protects. Each layer slows an attacker down and gives you another chance to notice, so that a breach of one layer does not become a breach of everything.

Microsoft Learn resource: Describe defense-in-depth (opens in a new tab)

42

Describe the purpose of Microsoft Defender for Cloud

Defender for Cloud is the posture management and workload protection service, and it is the last named service in this domain.

What you need to know

  • It continuously assesses your resources against security best practice and reports a secure score
  • It gives specific, actionable recommendations to raise that score
  • It protects workloads running in Azure, on premises, and in other clouds
  • It provides threat protection alerts for resources such as virtual machines, storage accounts and databases
  • It can enforce regulatory compliance standards and show where you fall short of them

Microsoft Learn resource: Describe Microsoft Defender for Cloud (opens in a new tab)

Domain 3 Describe Azure Management and Governance 30-35% of the exam 0 / 15 studied

The last domain is about running Azure once things are deployed: what drives the bill, how you keep resources compliant, which tool you reach for to deploy or manage something, and how you find out when something is wrong. It is heavy on named tools, and most questions are "which tool would you use" rather than "how do you configure it".

Describe cost management in Azure

43

Describe factors that can affect costs in Azure

Several things move the bill, and the exam asks you to identify them from a scenario.

What you need to know

  • Resource type matters, because different services are metered differently and on different units
  • Consumption matters, since pay-as-you-go charges for what you use and reservations pre-pay for a commitment
  • Location matters, because prices differ between regions for the same service
  • Bandwidth matters: inbound data transfer is generally free, outbound data transfer out of a region is generally charged
  • The billing zone your region sits in affects the data transfer price
  • Leaving resources running when idle is the most common avoidable cost, because a stopped but allocated virtual machine still bills

Microsoft Learn resource: Describe factors that can affect costs in Azure (opens in a new tab)

Exam tip: Inbound is free, outbound costs. If a question is about data transfer charges, that is the fact it wants.

44

Explore the pricing calculator

The pricing calculator estimates what a planned deployment will cost before you build it.

What you need to know

  • It is a free web tool that estimates cost for a combination of Azure services you configure
  • You choose services, regions, tiers and quantities, and it produces a total with a breakdown
  • Estimates can be saved, shared and exported
  • It is for planning ahead; it does not show what you have actually spent
  • The total cost of ownership calculator is a different tool, for comparing on-premises cost against Azure cost

Microsoft Learn resource: Explore the pricing calculator (opens in a new tab)

45

Describe cost management capabilities in Azure

Microsoft Cost Management is the tool for what you have actually spent and what you are about to spend.

What you need to know

  • Cost analysis shows current and historic spend, broken down by service, resource group, subscription or tag
  • Budgets set a spending threshold and trigger alerts as you approach or exceed it
  • A budget alert notifies; it does not automatically stop resources from running
  • Cost alerts cover budget alerts, credit alerts and spending quota alerts
  • Azure Advisor contributes cost recommendations, such as resizing or shutting down underused virtual machines

Microsoft Learn resource: Describe the Microsoft Cost Management tool (opens in a new tab)

46

Describe the purpose of tags

Tags are name and value pairs attached to resources, and they are the mechanism behind most reporting and much automation.

What you need to know

  • A tag is a name and value pair, such as Environment and Production, or CostCenter and Finance
  • Tags are used to organize resources for billing, reporting, automation and governance
  • Tags are not inherited by default: a tag on a resource group does not automatically appear on the resources inside it
  • Azure Policy can require a tag, or apply one automatically, which is how organizations enforce tagging in practice
  • Cost analysis can group and filter by tag, which is how departmental chargeback works

Microsoft Learn resource: Describe the purpose of tags (opens in a new tab)

Exam tip: Tags do not inherit. That single fact is the most common tag question on the exam.

Describe features and tools in Azure for governance and compliance

47

Describe the purpose of Microsoft Purview in Azure

Purview is the data governance and compliance family, and at fundamentals level you need its purpose rather than its configuration.

What you need to know

  • It provides unified data governance across on-premises, multicloud and software as a service data
  • It builds a map of your data estate so you can find and classify what you hold
  • It supports data discovery, classification and lineage, which shows where data came from and where it went
  • It helps meet regulatory obligations by making it possible to demonstrate what data exists and how it is handled
  • It works across sources beyond Azure, not only Azure services

Microsoft Learn resource: Describe the purpose of Microsoft Purview (opens in a new tab)

48

Describe the purpose of Azure Policy

Azure Policy enforces rules about what can be created and how it must be configured, which is the difference between policy and RBAC.

What you need to know

  • Policy governs what resources can be created and how they must be configured; RBAC governs who can do things
  • A policy definition states a rule and an effect, such as deny, audit or append
  • Policies can be grouped into initiatives, so a set of related rules is assigned together
  • Policies are assigned at a scope such as a management group, subscription or resource group, and are inherited downward
  • Typical uses are restricting which regions may be used, requiring a tag, or blocking expensive virtual machine sizes
  • Policy evaluates existing resources too, so it reports non-compliance rather than only blocking new deployments

Microsoft Learn resource: Describe the purpose of Azure Policy (opens in a new tab)

Exam tip: Policy is what, RBAC is who. Questions are usually decided by that one line.

49

Describe the purpose of resource locks

Resource locks protect against accidental change or deletion, including by people who otherwise have permission.

What you need to know

  • There are two lock types: Delete, which prevents deletion, and ReadOnly, which prevents any modification as well
  • ReadOnly is the stricter of the two, because it blocks changes and deletion both
  • Locks apply to everyone, regardless of their role, so an Owner is still blocked
  • Locks can be applied at subscription, resource group or resource level, and they are inherited by everything below
  • To delete a locked resource you must remove the lock first, which is the point: it forces a deliberate second step
  • Locks and RBAC are complementary: RBAC controls who can act, locks protect the resource from anyone acting

Microsoft Learn resource: Describe the purpose of resource locks (opens in a new tab)

Describe features and tools for managing and deploying Azure resources

50

Describe the Azure portal

The portal is the graphical way into Azure and the tool most people meet first.

What you need to know

  • It is a web-based unified console for creating, managing and monitoring everything from a simple virtual machine to a complex deployment
  • It gives a graphical alternative to command line tools and does not require you to write code
  • Dashboards can be customized and shared with colleagues
  • It is resilient and available from any modern browser, from any location with a network connection
  • It suits exploring, one-off tasks and learning, while scripted tools suit repetition

Microsoft Learn resource: Describe tools for interacting with Azure (opens in a new tab)

51

Describe Azure Cloud Shell, Azure CLI, and Azure PowerShell

Three command line options, and the exam tests which suits which person rather than their syntax.

What you need to know

  • Azure Cloud Shell is a browser-based shell, already authenticated, with the tools preinstalled and nothing to set up locally
  • Cloud Shell offers both Bash and PowerShell, and requires an Azure file share to persist files between sessions
  • Azure CLI is a cross-platform command line tool using commands in the form az followed by a group and an action
  • Azure PowerShell is a set of cmdlets in the verb-noun form familiar to Windows administrators, such as New-AzVM
  • Choosing between CLI and PowerShell is largely a matter of which scripting background the administrator has, since both can do the work

Microsoft Learn resource: Describe tools for interacting with Azure (opens in a new tab)

52

Describe the purpose of Azure Arc

Azure Arc extends Azure management to resources that are not in Azure, which is the hybrid and multicloud story.

What you need to know

  • It lets you manage servers, Kubernetes clusters and some data services that run on premises or in other clouds
  • Arc-enabled resources appear in the Azure portal and can be organized with resource groups and tags like native resources
  • Azure governance tools such as Policy and role-based access control can then be applied to them
  • It gives a single control plane and a single inventory across environments
  • It is about management and governance reach, not about moving the workload into Azure

Microsoft Learn resource: Describe the purpose of Azure Arc (opens in a new tab)

53

Describe infrastructure as code (IaC)

Infrastructure as code means defining infrastructure in files you can version, review and reuse, rather than clicking through a portal.

What you need to know

  • Infrastructure is described in a declarative file that states the desired end state
  • The same file deploys the same environment every time, which removes configuration drift between environments
  • Definitions live in source control, so changes are reviewed and versioned like application code
  • It makes environments repeatable and disposable, which is what enables reliable test and development environments
  • Declarative means you state what you want; imperative means you state the steps to get there

Microsoft Learn resource: Describe Azure Resource Manager and Azure ARM templates (opens in a new tab)

54

Describe Azure Resource Manager (ARM) and ARM templates

Azure Resource Manager is the deployment and management layer every request goes through, whichever tool you used.

What you need to know

  • Every request from the portal, the CLI, PowerShell or the REST API goes through Azure Resource Manager
  • Because everything goes through one layer, you get consistent results and consistent access control whichever tool you used
  • ARM templates are JSON files that declare the resources to deploy, and they are Azure's infrastructure as code format
  • Template deployment is idempotent, so deploying the same template repeatedly produces the same result
  • Resource Manager orchestrates the order of deployment where resources depend on each other, and can deploy in parallel where they do not
  • Bicep is a newer, simpler language that compiles to the same ARM template JSON

Microsoft Learn resource: Describe Azure Resource Manager and Azure ARM templates (opens in a new tab)

Describe monitoring tools in Azure

55

Describe the purpose of Azure Advisor

Advisor is the recommendation engine, and the exam tests its five categories.

What you need to know

  • It analyses your resources and gives personalized recommendations
  • The categories are reliability, security, performance, cost and operational excellence
  • Cost recommendations include resizing or shutting down underused resources
  • Recommendations come with an action and can be postponed or dismissed
  • It is free, and it is proactive rather than a response to an incident

Microsoft Learn resource: Describe the purpose of Azure Advisor (opens in a new tab)

56

Describe Azure Service Health

Service Health tells you when the problem is Microsoft's rather than yours, which is exactly the distinction the exam tests.

What you need to know

  • Azure Status is a public page showing outages with a broad impact across regions and services
  • Service Health is personalized to your subscriptions and the services you actually use
  • Resource Health goes to the individual resource level and reports whether your specific resource is healthy
  • Service Health covers service issues, planned maintenance and health advisories
  • You can set alerts so you are notified about incidents affecting the services you depend on

Microsoft Learn resource: Describe Azure Service Health (opens in a new tab)

Exam tip: Azure Status is everyone's view, Service Health is your view, Resource Health is one resource's view. Questions turn on which scope is described.

57

Describe Azure Monitor, including Log Analytics, Azure Monitor alerts, and Azure Monitor Application Insights

Azure Monitor is the umbrella, and the three named components sit underneath it.

What you need to know

  • Azure Monitor collects, analyses and acts on telemetry from Azure, on-premises and other clouds
  • Log Analytics is where you write and run queries against the collected log data, using Kusto Query Language
  • Azure Monitor alerts fire when a condition is met and can notify a person or trigger an automated action
  • Application Insights monitors application performance and availability, including request rates, response times and failures
  • Application Insights can also run availability tests against a web application from multiple locations
  • Metrics are numeric and time-series; logs are records with varied structure, which is why they are queried differently

Microsoft Learn resource: Describe Azure Monitor (opens in a new tab)

Quick reference: where to go for what

Task Where to go
Estimate the cost of a planned deployment Azure pricing calculator
Compare on-premises cost against Azure Total cost of ownership calculator
See what you have actually spent Microsoft Cost Management > Cost analysis
Get alerted before you overspend Microsoft Cost Management > Budgets
Restrict which regions can be used Azure Policy assigned at a management group
Require a tag on every new resource Azure Policy
Stop a resource being deleted by accident Resource lock (Delete or ReadOnly)
Grant someone read-only access to a resource group Azure RBAC, Reader role at the resource group scope
Let someone manage access without managing resources Azure RBAC, User Access Administrator role
Require multifactor authentication from untrusted locations Microsoft Entra Conditional Access
Give an external partner access to an application Microsoft Entra External Identities (B2B)
Join a virtual machine to a managed domain Microsoft Entra Domain Services
Check how secure your environment is Microsoft Defender for Cloud > Secure score
Find out whether an outage is Microsoft's fault Azure Service Health
Check whether one specific virtual machine is healthy Azure Monitor > Resource Health
Query collected log data Azure Monitor > Log Analytics
Monitor an application's performance and failures Application Insights
Get recommendations to cut cost or improve reliability Azure Advisor
Manage an on-premises server from Azure Azure Arc
Deploy the same environment repeatedly and identically ARM template or Bicep
Run Azure commands without installing anything Azure Cloud Shell
Move terabytes of data when the network is too slow Azure Data Box
Assess on-premises servers before migrating Azure Migrate
Keep an on-premises file share in sync with Azure Azure File Sync
Store data that is rarely read and can wait hours Blob Storage, Archive tier
Protect data against a whole region failing Geo-redundant storage (GRS or GZRS)
Reach a platform service without using the public internet Private endpoint
Connect on-premises to Azure without the public internet ExpressRoute

Additional tips

The best thing you can do after reading this guide is to open a free Azure account and play with the services. Create a resource group, put a virtual machine and a storage account in it, then delete the group and watch everything go with it. The exam questions feel very different once you have done that.

Before exam day, explore the exam interface in the Microsoft exam sandbox (opens in a new tab), so the question types and the navigation hold no surprises.

Study resource

Azure free account

Free

A free account with a credit for the first 30 days and a set of services that stay free beyond that. Enough to try everything in this guide without spending anything, as long as you shut resources down when you finish.

Start a free trial (opens in a new tab)
Microsoft

Microsoft Learn practice assessment for AZ-900

Free

Microsoft's own free practice assessment, written in the same style as the real exam. Take it once early to find your gaps and once the week before to confirm you closed them.

Start on Microsoft Learn (opens in a new tab)

Frequently asked questions

How long should I study for the AZ-900?

Most people with some IT background can be ready in two to four weeks of steady study. If you have never worked with a cloud platform before, plan for four to six weeks and start with the three Microsoft Learn paths, which cover every domain between them. The exam is fundamentals level, so it rewards broad familiarity rather than deep expertise in any one service.

Do I need hands-on Azure experience to pass?

No, the exam is knowledge-based and you can pass without ever deploying anything. That said, an afternoon in the portal creating a resource group, a virtual machine and a storage account makes the vocabulary stick in a way that reading does not. You can do all of it on a free Azure account, which includes a credit and a set of always-free services.

Is the AZ-900 worth taking if I already work in IT?

It depends on what you want from it. If you work with Azure daily it will feel basic, and AZ-104 is the better target. If you are moving into cloud from another part of IT, or you need to speak confidently with a team that uses Azure, it is a fast way to get the vocabulary straight and prove it.

How often does the AZ-900 change?

Microsoft updates the skills measured periodically, usually when enough has changed in the platform to matter. The study guide page on Microsoft Learn always shows the current version and the date it was last updated, and it carries a change log at the bottom listing what moved. Check it before you book, because study material written against an older version can send you down the wrong path.

Maintained by Vlad Catrinescu, reviewed September 2026 · All study guides