AZ-900Exam Domain

Describe Azure Architecture and Services (35–40%)AZ-900 Study Guide

65 chapters
~1625 min total
Free — no signup required

Quick Answer

Azure Architecture and Services covers the core components of Azure—compute, networking, storage, databases, identity, and management—and how they work together to build cloud solutions, tested through scenario-based questions on service selection and architectural concepts.

The Azure Architecture and Services domain is the heart of the AZ-900 exam, covering the core building blocks of Microsoft Azure. In plain English, this domain is about understanding the fundamental components that make up Azure's cloud infrastructure—things like virtual machines, storage accounts, databases, networking, and identity services. You'll learn how these pieces fit together to create scalable, secure, and cost-effective solutions. For example, you'll explore how Azure Virtual Machines let you run Windows or Linux in the cloud, how Azure Blob Storage stores massive amounts of unstructured data like photos or videos, and how Azure SQL Database provides a managed relational database service. This domain also introduces key architectural concepts like regions (geographic locations of data centers), availability zones (isolated data centers within a region for high availability), and resource groups (logical containers for managing related resources). Understanding these basics is crucial because they form the foundation for everything else in Azure.

Why is this important for real-world IT, security, and cloud work? Because Azure is one of the leading cloud platforms, and professionals across all IT roles need to know how to design and manage cloud solutions. For instance, a system administrator might need to decide between using Azure VMs or Azure App Service to host a web application, weighing factors like scalability, maintenance, and cost. A security analyst must understand Azure's shared responsibility model—where Microsoft secures the physical infrastructure (data centers, network) and you secure your data, identities, and access. Without grasping these architectural components, you can't make informed decisions about cloud adoption, cost optimization, or security. Real-world scenarios include setting up a disaster recovery plan using Azure Site Recovery, or configuring Azure Active Directory for single sign-on across multiple apps. This domain gives you the vocabulary and mental model to talk about these solutions with colleagues and clients.

On the AZ-900 exam, this domain tests your knowledge of Azure's core services and how they work together. Specifically, you'll need to identify the right service for a given business requirement. For example, a question might ask: "Which Azure service should you use to host a web app that automatically scales based on demand?" (Answer: Azure App Service). Or "Which storage option is best for storing virtual machine disks?" (Answer: Azure Managed Disks). You'll also be tested on high-level architectural concepts like the difference between IaaS, PaaS, and SaaS, and when to use each. The exam doesn't require deep technical skills—you won't be asked to write code or configure a network—but you must understand the purpose and typical use cases of each service. Expect questions about Azure regions, availability zones, resource groups, and management tools like Azure Portal, Azure CLI, and Azure PowerShell. The weight of this domain (35-40%) means you'll see many questions here, so it's critical to master it.

To approach studying this domain effectively, start by creating a mental map of Azure's service categories: compute, networking, storage, databases, identity, and management. Use Microsoft's official documentation and free learning paths on Microsoft Learn, which include interactive modules and sandboxes. For each service, ask yourself: What problem does it solve? When would I use it? What are its key features? Then, reinforce your learning with practice exams that mimic the real test format. Focus on scenarios that require choosing between similar services, like Azure SQL Database vs. SQL Server on a VM, or Azure Blob vs. Azure Files. Finally, use mnemonic devices to remember tricky concepts—for example, remember that availability zones protect against data center failures, while region pairs protect against regional disasters. By building this foundational knowledge, you'll not only pass the exam but also be prepared for real-world Azure work.

What the exam tests

  • Identify the appropriate Azure compute service (e.g., VMs, App Service, Functions) for a given workload scenario
  • Differentiate between Azure storage options (Blob, Disk, File, Queue, Table) based on use case
  • Understand Azure networking concepts (VNet, load balancer, VPN Gateway, CDN) and their purposes
  • Describe Azure database services (SQL Database, Cosmos DB, Azure Database for MySQL/PostgreSQL) and when to use each
  • Explain Azure identity services (Azure AD, RBAC, MFA) and their role in security
  • Recognize Azure management tools (Portal, CLI, PowerShell, Cloud Shell) and their typical uses

Common exam traps

  • Confusing Azure Blob Storage (unstructured data) with Azure Files (managed file shares) or Azure Disk (VM disks)
  • Thinking that availability zones and region pairs are the same thing—zones protect within a region, pairs protect across regions
  • Assuming all virtual machines are IaaS, but Azure VMs are IaaS while App Service is PaaS—know the difference for scenario questions
  • Mixing up Azure SQL Database (PaaS) with SQL Server on Azure VM (IaaS) in terms of management responsibility
  • Forgetting that Azure AD is for identity and access management, not just Active Directory in the cloud—it's a separate service

Describe Azure Architecture and Services (35–40%) Chapters

11

Azure Regions and Geographies

Objective 2.1 · Azure Architecture Services

25m
12

Availability Zones and Region Pairs

Objective 2.1 · Azure Architecture Services

25m
13

Azure Resource Manager (ARM)

Objective 2.1 · Azure Architecture Services

25m
14

Azure Subscriptions and Management Groups

Objective 2.1 · Azure Architecture Services

25m
15

Azure Virtual Machines

Objective 2.2 · Azure Architecture Services

25m
16

Azure Container Instances and AKS

Objective 2.2 · Azure Architecture Services

25m
17

Azure App Service

Objective 2.2 · Azure Architecture Services

25m
18

Azure Functions (Serverless)

Objective 2.2 · Azure Architecture Services

25m
19

Azure Virtual Networks (VNet)

Objective 2.3 · Azure Architecture Services

25m
20

Azure DNS and Load Balancer

Objective 2.3 · Azure Architecture Services

25m
21

Azure VPN Gateway and ExpressRoute

Objective 2.3 · Azure Architecture Services

25m
22

Azure Blob Storage

Objective 2.4 · Azure Architecture Services

25m
23

Azure Storage Account Types

Objective 2.4 · Azure Architecture Services

25m
24

Azure SQL Database

Objective 2.4 · Azure Architecture Services

25m
25

Azure Cosmos DB

Objective 2.4 · Azure Architecture Services

25m
26

Microsoft Entra ID (Azure AD)

Objective 2.5 · Azure Architecture Services

25m
27

Azure Authentication Methods

Objective 2.5 · Azure Architecture Services

25m
28

Conditional Access and MFA

Objective 2.5 · Azure Architecture Services

25m
29

Role-Based Access Control (RBAC)

Objective 2.5 · Azure Architecture Services

25m
30

Microsoft Defender for Cloud

Objective 2.5 · Azure Architecture Services

25m
63

Azure Resource Groups

Objective 2.1 · Azure Architecture Services

25m
64

Azure Management Groups Hierarchy

Objective 2.1 · Azure Architecture Services

25m
65

Azure Tenants and Directories

Objective 2.1 · Azure Architecture Services

25m
66

Azure VM Scale Sets

Objective 2.2 · Azure Architecture Services

25m
67

Azure Spot Virtual Machines

Objective 2.2 · Azure Architecture Services

25m
68

Azure Reserved Instances

Objective 2.2 · Azure Architecture Services

25m
69

Azure Dedicated Hosts

Objective 2.2 · Azure Architecture Services

25m
70

Azure Kubernetes Service (AKS)

Objective 2.2 · Azure Architecture Services

25m
71

Azure Container Registry

Objective 2.2 · Azure Architecture Services

25m
72

Azure Logic Apps

Objective 2.2 · Azure Architecture Services

25m
73

Azure Event Grid

Objective 2.2 · Azure Architecture Services

25m
74

Azure Service Bus Messaging

Objective 2.2 · Azure Architecture Services

25m
75

Azure Event Hubs

Objective 2.2 · Azure Architecture Services

25m
76

Azure API Management

Objective 2.2 · Azure Architecture Services

25m
77

Azure Content Delivery Network (CDN)

Objective 2.3 · Azure Architecture Services

25m
78

Azure Traffic Manager

Objective 2.3 · Azure Architecture Services

25m
79

Azure Front Door

Objective 2.3 · Azure Architecture Services

25m
80

Azure Application Gateway and WAF

Objective 2.3 · Azure Architecture Services

25m
81

Azure Network Security Groups (NSG)

Objective 2.3 · Azure Architecture Services

25m
82

Azure DDoS Protection

Objective 2.3 · Azure Architecture Services

25m
83

Azure Private Link and Private Endpoints

Objective 2.3 · Azure Architecture Services

25m
84

Azure VNet Peering

Objective 2.3 · Azure Architecture Services

25m
85

Azure Bastion

Objective 2.3 · Azure Architecture Services

25m
86

Azure Firewall

Objective 2.3 · Azure Architecture Services

25m
87

Azure Route Tables and UDRs

Objective 2.3 · Azure Architecture Services

25m
88

Azure Files and File Sync

Objective 2.4 · Azure Architecture Services

25m
89

Azure Queue Storage

Objective 2.4 · Azure Architecture Services

25m
90

Azure Managed Disks

Objective 2.4 · Azure Architecture Services

25m
91

Azure Data Lake Storage

Objective 2.4 · Azure Architecture Services

25m
92

Azure Database for MySQL and PostgreSQL

Objective 2.4 · Azure Architecture Services

25m
93

Azure Synapse Analytics

Objective 2.4 · Azure Architecture Services

25m
94

Azure Cache for Redis

Objective 2.4 · Azure Architecture Services

25m
95

Azure AI Cognitive Services

Objective 2.2 · Azure Architecture Services

25m
96

Azure Machine Learning Overview

Objective 2.2 · Azure Architecture Services

25m
97

Azure OpenAI Service

Objective 2.2 · Azure Architecture Services

25m
98

Microsoft Sentinel (SIEM)

Objective 2.5 · Azure Architecture Services

25m
99

Azure Key Vault

Objective 2.5 · Azure Architecture Services

25m
100

Microsoft Entra Identity Protection

Objective 2.5 · Azure Architecture Services

25m
101

Privileged Identity Management (PIM)

Objective 2.5 · Azure Architecture Services

25m
102

Azure VM Storage Options

Objective 2.2 · Azure Architecture Services

25m
103

Azure Networking Concepts Overview

Objective 2.3 · Azure Architecture Services

25m
104

Azure Site Recovery (Disaster Recovery)

Objective 2.1 · Azure Architecture Services

25m
105

Azure Backup Service

Objective 2.1 · Azure Architecture Services

25m
106

Azure Storage Redundancy Options (LRS/GRS)

Objective 2.4 · Azure Architecture Services

25m
107

Azure Hybrid Benefit

Objective 2.2 · Azure Architecture Services

25m

Other AZ-900 Domains

Test your Describe Azure Architecture and Services (35–40%) knowledge

Free AZ-900 practice questions with full explanations. Test what you learn chapter by chapter.

AZ-900 Practice Questions