certslothcertsloth
← AZ-900 overview

Azure Fundamentals / STUDY TOOLS

AZ-900 quick review

Shared service chapters include administrator-level detail. For AZ-900, prioritise service purpose, responsibility and the distinctions in this objective map; deployment syntax is extra depth.

Memory hook: Who manages it, where it runs, how it is governed.

Reviewed 10 October 2026. Read this once, then answer the last-pass checks without looking.

Scope/version: Shared service chapters include administrator-level detail. For AZ-900, prioritise service purpose, responsibility and the distinctions in this objective map; deployment syntax is extra depth.

Must remember by domain

Domain Rapid revision
Cloud models Public uses provider infrastructure; private serves one organization; hybrid connects environments. Consumption spending is variable operating expense, but idle capacity and commitments still cost money. Serverless hides server management, not execution limits or billing.
Responsibility and benefits IaaS: customer manages OS/runtime/apps. PaaS: provider manages more platform. SaaS: provider supplies the finished application. Customer identities, data and configuration remain customer responsibilities. Scalability increases capacity; elasticity follows changing demand; availability keeps service usable; reliability includes recovery.
Azure structure Tenant is an identity boundary; management groups organize subscriptions; subscriptions organize billing/access; resource groups contain resources. Zones separate supported failure domains inside a region. Region pairing does not automatically replicate your application.
Compute/network VM: OS control. App Service: managed web hosting. Functions: event code. Container Apps: managed container applications. AKS: Kubernetes. AVD: desktops/apps. VPN uses encrypted tunnels; ExpressRoute supplies private connectivity with separate encryption considerations.
Storage/migration Blob = objects; Files = shared files; disks = block storage. Hot/cool/cold are online tiers; archive needs rehydration. LRS = local copies; ZRS = zone copies; GRS/GZRS add asynchronous second-region copies. Azure Migrate assesses/moves workloads; Data Box transfers eligible offline datasets; AzCopy transfers storage data.
Identity/security Entra authenticates; MFA strengthens proof; Conditional Access evaluates access conditions; RBAC grants scoped actions. Zero Trust: verify explicitly, least privilege, assume breach. Defender for Cloud assesses posture/protects enabled workloads; Key Vault manages secrets/keys/certificates.
Management/governance Policy evaluates/enforces resource configuration; locks restrict management changes; tags label resources. Purview handles supported data governance/compliance. ARM is the management layer; Bicep/ARM templates declare resources; Arc extends supported management beyond Azure.
Cost/monitoring Pricing Calculator estimates; Cost Management analyzes; budgets notify; Advisor recommends. Azure Monitor measures resources/apps. Service Health reports relevant platform incidents/maintenance; Resource Health focuses on an individual resource. Service Trust Portal provides provider assurance material.

Exam traps

Budgets do not normally stop spending. Resource-group tags do not automatically become resource tags. A paired region is not a DR configuration. A public-cloud service can still use private access. Provider compliance does not automatically certify your workload.

Last-pass self-check

1. Need guest OS control: which service model?

IaaS, commonly a VM.

2. Need to prevent new resources in an unapproved region?

Azure Policy; RBAC answers who may act, not the permitted configuration.

3. Need to identify an Azure outage affecting your resources?

Service Health; use workload telemetry to assess application impact.

4. Can archived data satisfy immediate frequent reads?

No. Choose an online tier when immediate access is required.

5. Does an availability zone span regions?

No. It is a supported isolated location within one region.

Sources

Every topic at a glance

Open any topic to revisit its essential facts, decisions and exam traps. Use the full topic for active recall and supporting references.

01 · Cloud Concepts and the Azure Service Map

Memory hook: Choose the responsibility model, failure boundary and service purpose before remembering product names.

Must remember

  • Public cloud supplies shared provider infrastructure; private cloud serves a defined organisation; hybrid combines environments. IaaS leaves more guest/platform work to the customer; PaaS manages more runtime infrastructure; SaaS delivers a finished application. Customers still control their data, identities and use.
  • Scalability increases capacity; elasticity adjusts it with demand; availability keeps service usable; reliability includes recovery; agility reduces time to experiment. Consumption-based spending trades some upfront capital cost for variable operating expense, but idle resources and commitments can still bill.
  • Azure Regions contain deployment infrastructure; availability zones separate supported regional failure domains. Region pairs and service-specific replication rules are not a promise that every resource is automatically copied or fails over. Sovereign-cloud boundaries and data residency depend on the actual service deployment.
  • Resources belong to resource groups/subscriptions; management groups organise subscriptions; Entra tenants organise identities. Azure Resource Manager is the management layer. Portal, CLI, PowerShell, CloudShell, APIs and IaC provide different interfaces subject to authorisation.
  • VMs provide guest control; App Service hosts supported apps; containers package applications; Functions runs event-driven code; Virtual Desktop delivers desktops/apps. VNets, VPN and ExpressRoute provide different network connectivity. Blob is object storage, Files is shared files, disks are block storage. Storage tiers and redundancy trade cost, access time and resilience.
  • Azure Migrate supports assessment/migration planning; Data Box supports eligible offline data transfer; AzCopy, Storage Explorer and File Sync address different data-transfer/hybrid-access needs. Azure Arc extends supported management/governance beyond native Azure resources.
  • Entra provides identity; MFA/Conditional Access strengthen access controls; RBAC grants scoped resource actions. Zero Trust means verify explicitly, use least privilege and assume breach; defence in depth uses multiple controls. Defender for Cloud supports security posture/workload protection. Purview supports data governance/compliance capabilities; Policy evaluates resource configuration; locks protect supported management actions.
  • Pricing Calculator estimates designs; Cost Management analyses usage; budgets notify; Advisor recommends improvements. Service Health reports relevant service incidents/planned maintenance/advisories; Azure Monitor measures workloads. Check service-specific SLAs and dependencies: a component SLA is not automatically the application's SLA.

Choose under exam pressure

Requirement Choice and reason
Need OS administration IaaS VM.
Need managed web hosting App Service/PaaS when supported.
Need evidence of spend and ownership Cost Management with suitable tags and allocation.

Traps

  • Serverless has limits and costs.
  • A Region pair is not automatic application disaster recovery.
  • Compliance of a service does not certify every customer workload.

Practise this topic

02 · Subscriptions, Policy and Cost Governance

Memory hook: RBAC decides who may act; Policy evaluates what configuration is acceptable.

Must remember

  • A management-group hierarchy applies governance across subscriptions. Resources belong to resource groups and subscriptions, but not every resource type supports every move. Check dependencies, provider registration, quotas and move validation before changing scope.
  • Azure Policy definitions evaluate resource properties; initiatives group policies; assignments apply them at scopes with exclusions/exemptions. Effects include audit, deny, modify and deployIfNotExists. Existing noncompliant resources may need a remediation task and suitable managed-identity permissions.
  • A CanNotDelete lock blocks management-plane deletion; ReadOnly can block management operations that look like reads but use POST. Locks are inherited and are not a universal data-plane protection mechanism. A privileged user able to remove a lock can change its protection.
  • Tags support ownership and cost allocation, but tags do not automatically inherit from resource group to resource. Policy can enforce or add supported tags. Keep a naming/tagging convention and handle untaggable/shared resources explicitly.
  • Cost Management analyses spending; budgets notify configured thresholds; Advisor recommends improvements. A budget is not a universal immediate resource shutdown. Billing latency, reservations/savings commitments and shared costs affect interpretation.
  • Resource groups are useful for lifecycle management, but deleting a group is a broad action. Review dependencies and locks first. Region affects resource availability, residency and price; the resource group's metadata location does not force every contained resource into that Region.

Choose under exam pressure

Requirement Choice and reason
Prevent unsupported regions at deployment Azure Policy deny at the appropriate scope.
Let a team manage resources but not grant roles Contributor, constrained to the required scope.
Find an oversized idle workload Usage evidence plus Advisor/Cost Management recommendations.

Traps

  • Audit reports a problem; it does not block it.
  • A tag on a group is not automatic tag inheritance.
  • A budget alert is not a guaranteed spending cap.

Practise this topic

03 · Microsoft Entra ID and Azure RBAC

Memory hook: Entra identifies the principal; Azure RBAC authorises an action at a scope.

Must remember

  • A Microsoft Entra tenant is an identity directory. An Azure subscription is a billing/resource-management boundary associated with a tenant. Management groups organise subscriptions; resource groups organise resources. Do not treat tenant and subscription as synonyms.
  • Manage users, groups, properties, assigned licences and guest access deliberately. Security groups organise access; dynamic membership uses rules when licensing/features permit. B2B guests retain an external identity relationship. Self-service password reset needs appropriate eligibility, authentication methods and configuration.
  • An Azure role assignment is principal + role definition + scope. Scope can be management group, subscription, resource group or resource, with inheritance. Inspect effective assignments rather than only the nearest resource. Entra directory roles and Azure resource roles are different permission systems.
  • Owner can manage resources and access; Contributor manages resources but does not normally grant Azure roles; Reader reads management information. Data-plane roles, such as Storage Blob Data Reader, authorise data operations separately. Management-plane access is not always data access.
  • System-assigned managed identity follows one resource's lifecycle; user-assigned identity is an independent reusable resource. Both avoid embedded secrets for supported authentication. Grant the identity's service principal only the required target roles.
  • PIM supports time-bound/eligible privileged access; Conditional Access evaluates sign-in conditions and grant controls with appropriate licensing. MFA strengthens authentication; it does not create a missing resource role assignment. Keep a monitored emergency-access design.

Choose under exam pressure

Requirement Choice and reason
App needs storage access without stored credentials Managed identity plus an appropriate data role.
User can manage a storage account but cannot read blobs Check data-plane permissions.
Temporary privileged operations Eligible/time-bound access using PIM where available.

Traps

  • Entra administrator is not automatically Owner of every Azure subscription.
  • Contributor and Owner differ in access-management privileges.
  • A role at a parent scope can remain effective after a narrower assignment is removed.

Practise this topic

04 · Storage Access, Encryption and Redundancy

Memory hook: Network reachability, authorisation and encryption are separate storage controls.

Must remember

  • Storage accounts expose supported services such as blobs, files, queues and tables. Choose the account kind/features, Region and redundancy before relying on a capability. Names and endpoints have service-specific scope rules.
  • Prefer Entra/managed-identity authorisation where supported. Account keys are broad credentials; rotate them with a staged client update. A SAS delegates selected operations for a time window and resource scope. User-delegation SAS uses Entra-backed delegation for supported Blob access; service/account SAS have different signing and capabilities.
  • A stored access policy can centrally control/revoke associated supported service SAS permissions; it does not apply to every SAS type. Time skew, expiry, signed permissions, protocol and network restrictions can explain an otherwise valid token's failure.
  • SAS recall: service SAS is signed with an account key and can reference a stored access policy; account SAS is signed with an account key and can cover supported account/service operations; user-delegation SAS is signed with an Entra-backed delegation key for supported Blob access. Stored access policies do not apply to account SAS or user-delegation SAS. Choose scope and revocation requirements before choosing the token type.
  • Storage firewalls restrict network access. A service endpoint uses supported service networking and VNet rules; a private endpoint gives a private IP path and requires correct private DNS. Neither substitutes for authorisation. Disable public access deliberately when the requirement demands it.
  • LRS replicates within one location; ZRS spans zones in a Region; GRS/GZRS add asynchronous geographic replication; RA variants allow supported secondary reads. Geo-replication lag affects possible data loss. Redundancy is not backup against authorised deletion.
  • Storage encryption protects at-rest data; customer-managed keys add key lifecycle and access responsibilities. Object replication between supported blob accounts has prerequisites and scope; it is not a universal synchronisation of every storage service.
  • Use Storage Explorer for interactive data management and AzCopy for scripted transfer. Choose an authentication method and validate source/destination permissions; success transferring a subset does not prove the entire dataset reconciles.

Choose under exam pressure

Requirement Choice and reason
Temporary restricted blob access A suitably scoped SAS, preferably user delegation when it fits.
Private IP access from a VNet Private endpoint plus DNS and data authorisation.
Regional AZ resilience without a second Region ZRS where supported.

Traps

  • A private endpoint does not automatically disable the public endpoint.
  • RA-GRS secondary data may lag.
  • A management role can lack permission to read stored data.

Practise this topic

05 · Virtual Machines, Disks and Scale Sets

Memory hook: Size for the bottleneck, place for failure and distinguish stopped from deallocated.

Must remember

  • Choose VM family/size using CPU, memory, storage throughput, networking and compatibility. Availability differs by Region and quota. Resizing may require restart/deallocation or a compatible host allocation; check disk and NIC limits too.
  • Managed disks have performance and redundancy options. OS disks, data disks and temporary disks have different purposes; temporary storage is not durable business data. Snapshots capture disk state, but application consistency may require additional coordination.
  • Availability sets distribute supported VMs across fault/update domains; availability zones distribute across zonal failure domains. A VM Scale Set manages a group of instances with selected orchestration, upgrade and autoscale behaviour. Health probes and application readiness affect safe replacement.
  • Stopped within the guest can leave compute allocated and billed; deallocated releases allocation, though retained disks, snapshots and other resources can still bill. Public/private address behaviour depends on address configuration and lifecycle.
  • Encryption at host protects supported host-side storage paths; disk encryption and guest/application encryption solve related but distinct requirements. Use trusted boot/security features where the workload and VM generation support them.
  • Moving a resource group/subscription is a management-scope operation; moving to another Region generally involves a supported relocation/redeployment process. Validate dependencies, identity/role assignments, network addresses, extensions and backup settings after any move.
  • Use Bastion or appropriate controlled administration paths. VM extensions and cloud-init/custom-data mechanisms help configure guests, but failed bootstrap scripts need logs and exit-status investigation. Never assume the portal's running state means the app is ready.

Choose under exam pressure

Requirement Choice and reason
Scale a replaceable VM fleet VM Scale Sets with health-aware policy.
Survive a zone loss Sufficient working capacity across zones and resilient state.
Stop paying for allocated compute during a pause Deallocate, then account for retained resources.

Traps

  • Guest shutdown and deallocation differ.
  • Temporary disk data must be reproducible.
  • A Region move is not merely changing a resource-group label.

Practise this topic

06 · App Service and Container Platforms

Memory hook: Separate image storage, execution, application configuration and the hosting plan.

Must remember

  • ACR stores container images/artifacts. Authenticate pushes/pulls with appropriate identities and roles; prefer immutable image digests for a known release. Registry access does not grant the running application permission to its database.
  • Container Instances runs container groups without managing a cluster. Container Apps provides managed application environments, revisions, ingress and event-driven scaling capabilities. AKS gives Kubernetes orchestration with greater platform control and responsibility; it is not the default answer for every container.
  • Size container CPU/memory and configure health/startup behaviour. Container Apps scaling rules and minimum replicas affect availability, cold starts and cost. Separate revision traffic from image publishing; pushing an image alone is not necessarily deployment.
  • An App Service plan determines shared compute capacity, Region and pricing tier; apps run within it. Scale up changes plan capability; scale out changes instance count. Apps sharing a plan can compete for its resources.
  • Deployment slots support staged releases and swaps on eligible tiers. Mark environment-specific settings as slot settings where needed. Warm up and validate the target before swapping; external database changes require their own compatibility plan.
  • Configure custom-domain ownership, DNS records and TLS bindings separately. VNet integration primarily handles supported outbound access; private endpoints support private inbound access. Access restrictions, DNS and the destination's permissions still matter.
  • Backup support depends on plan/features and configuration; define a restore test. Managed identity and Key Vault references reduce stored credentials. Inspect app logs and dependency/network failures before simply increasing plan size.

Choose under exam pressure

Requirement Choice and reason
Run a small container without managing nodes Container Instances or Container Apps, according to application/scaling needs.
Test a web release before moving users App Service deployment slot.
App needs private database access Supported VNet integration plus routes, DNS and authorisation.

Traps

  • A registry is not a container runtime.
  • VNet integration is not equivalent to private inbound access.
  • A slot swap does not reverse database writes.

Practise this topic

07 · Virtual Networks, Routes and Secure Access

Memory hook: Check the effective route and the effective rule in both directions.

Must remember

  • VNets contain address spaces and subnets. Plan non-overlapping ranges and future growth; supported peering requires compatible addresses. Peering connects VNets but is not automatically transitive through a third VNet.
  • Azure selects routes using prefix specificity and route-source precedence for equal prefixes; inspect effective routes when system, BGP and user-defined routes interact. A UDR can direct traffic to a virtual appliance, but the appliance must forward it and the return path must work.
  • For ordinary equal-prefix comparisons, remember UDR → BGP → system; first compare the destination prefix length. A matching /24 normally beats a /16 regardless of that general source order. Service-specific routes have exceptions: service-endpoint routes cannot simply be overridden by a UDR. Inspect the effective route rather than treating the mnemonic as universal.
  • Azure reserves the first four and last IPv4 addresses of each subnet. A /27 contains 32 addresses, leaving 27 usable; service-specific subnet sizing can require more than the generic minimum. Subnet capacity planning must include service reservations and scale-out needs.
  • NSGs are stateful network filtering with priority-ordered allow/deny rules. They can apply at subnet and NIC scopes; evaluate the effective combination. Application security groups group supported VM interfaces for rule targeting; they are not application-layer WAFs.
  • Public IP addresses have SKU/allocation/zone properties. NAT Gateway supports explicit outbound SNAT for associated subnets; consider port use and destination patterns. Do not assume new workloads receive default outbound internet access.
  • Bastion provides managed administration through supported private VM access without exposing a public management port on each VM. It still needs the required deployment/network configuration and authorised users.
  • Service endpoints extend supported service access from a VNet using its public service endpoint and service-side rules. Private endpoints use a private IP for a specific resource/subresource; DNS must resolve appropriately. Endpoint creation and resource approval are separate checks.
  • Diagnose with Network Watcher tools, Connection Monitor, effective security rules/routes, name resolution and application listener checks. Existing stateful flows may not behave like brand-new test connections after a rule change.

Choose under exam pressure

Requirement Choice and reason
One private PaaS resource endpoint Private Link/private endpoint with private DNS.
Traffic must traverse a network appliance UDR plus forwarding and a symmetric return path.
VM administration without a VM public IP Bastion where appropriate.

Traps

  • Peering is not automatically transitive.
  • A service endpoint does not put the service itself inside your subnet.
  • An NSG allow does not create a route.

Practise this topic

08 · DNS and Load Balancing

Memory hook: DNS answers names; Layer 4 forwards connections; Layer 7 routes application requests.

Must remember

  • Azure DNS hosts authoritative public zones; domain registration is a separate function. Delegate with the correct name servers. Private DNS zones require links to the VNets that need resolution; autoregistration is a specific feature, not universal record creation.
  • Azure DNS Private Resolver supports hybrid resolution through inbound/outbound endpoints and forwarding rulesets. Avoid loops and test from the real client network. DNS TTL and negative caching can make a corrected record appear stale.
  • Azure Load Balancer operates at Layer 4 for supported TCP/UDP traffic, with public or internal frontends, backend pools, probes and rules. Probe success depends on the actual response and permitted probe path. An inbound NAT rule is not the same as balancing to a pool.
  • Application Gateway provides regional HTTP/S routing and WAF integration. Front Door provides global HTTP/S application delivery and edge features. Traffic Manager uses DNS routing and is not a reverse proxy for every request.
  • TLS can terminate at an application gateway/edge, with a separate encrypted connection to the origin where configured. Host headers, certificate names, SNI and backend settings must align. A valid frontend certificate does not prove origin TLS works.
  • Troubleshoot the client DNS answer, frontend connectivity, rule, backend health and application listener in order. A health probe can be too shallow: test a path that reflects usable service without making every shared dependency trigger an unnecessary fleet-wide outage.

Choose under exam pressure

Requirement Choice and reason
Regional path-based HTTP routing Application Gateway.
Global HTTP application delivery Front Door.
TCP/UDP load distribution Azure Load Balancer.

Traps

  • Traffic Manager decisions can remain cached.
  • A healthy probe is only as useful as its tested condition.
  • Private-zone association is not inherited through every network connection.

Practise this topic

09 · Azure Monitor, Logs and Alerts

Memory hook: Metrics quantify, logs explain, traces connect and alerts start a response.

Must remember

  • Azure Monitor combines metrics and logs; Log Analytics workspaces hold queryable log data. Activity Log records management-plane events; resource/application logs require relevant collection configuration. Diagnostic settings route supported categories to selected destinations.
  • Azure Monitor Agent uses data collection rules for supported guest telemetry. VM, Storage and Network Insights provide focused views; Application Insights adds application performance and tracing with suitable instrumentation. Guest memory/disk metrics are not automatically identical to platform metrics.
  • KQL pipelines transform tables: where filters, project selects columns, summarize aggregates, bin() groups time intervals, and joins combine data. Example: Heartbeat | summarize LastSeen=max(TimeGenerated) by Computer finds each computer's latest recorded heartbeat; absence can mean collection failure, not only host failure.
  • Alert rules define signal, scope, evaluation and condition. Action groups define notifications/actions. Alert processing rules modify processing such as suppression under selected conditions; they do not change the source telemetry. Use dynamic thresholds where appropriate and test missing-data behaviour.
  • Network Watcher and Connection Monitor help inspect path and connectivity. Logs, effective routes/rules and an application test answer different questions. Narrow time windows and correlation IDs reduce noise; retention and ingestion volume affect cost.
  • Monitor the collection pipeline itself. Permissions, network access, workspace configuration and data collection rules can break visibility. Avoid logging secrets and unnecessary personal data, and define retention according to operational/evidence requirements.

Choose under exam pressure

Requirement Choice and reason
Who changed an Azure resource? Activity Log and relevant audit evidence.
Notify an operations group on a metric breach Alert rule linked to an action group.
Investigate recurring connection failures Connection Monitor plus route, rule and application evidence.

Traps

  • No logs can mean no collection.
  • Action groups do not define the alert threshold.
  • Average response time can conceal severe tail latency.

Practise this topic

Search across every published topic.