Study guide · Core notes

Azure Fundamentals Notes: concepts and the boundary

Reference notes for AZ-900: what the cloud changes, how Azure is organized, which service matches a need, and how cost, policy, and monitoring fit together.

Study guide: July 20, 202611 modulesReviewed October 2026

How to read these notes: Items tagged Extra are outside the July 20, 2026 skill list, such as Azure Key Vault and Bicep. Learn the unmarked items first. New to the exam? Start with the overview for the format and domain weights. Vendor-neutral cloud models are in the networking and cloud notes.

Module 1: Cloud concepts

Cloud computing is on-demand delivery of computing services over the network, with capacity you can provision and release, usually on a consumption-based bill. You stop buying a data center for a peak you might not reach.

High availability and scalability

High availability keeps a workload running through a failure, often by using more than one availability zone. Scalability is the ability to handle more load. Vertical scaling makes one resource larger. Horizontal scaling adds more copies. Elasticity adds and removes that capacity as demand changes.

Reliability and predictability

Reliability is the ability to recover and keep working correctly. Predictability covers both performance, so a workload behaves as expected, and cost, so the bill is understandable before it arrives.

Security, governance, and manageability

The cloud provider can offer identity controls, compliance tooling, and a single way to deploy and watch resources. You still decide who may access your data and how your applications are configured.

Consumption-based pricing

You pay for what you use instead of a large capital expense up front. That is an operating expense. Reservations and other commitments trade flexibility for a lower rate. They are still pricing choices, not a different cloud model.

Public cloud is shared infrastructure operated by a provider such as Microsoft. Private cloud is dedicated to one organization and can run on-premises. Hybrid cloud connects the two, for example an on-premises network linked to Azure. Serverless means you run code or a small unit of work without managing the servers underneath. Azure Functions is the usual Azure example. The servers still exist. You just do not patch them.

Module 2: IaaS, PaaS, and SaaS

The shared responsibility line moves as you give the provider more of the stack.

Cloud service types named in the AZ-900 study guide. You still own your data and identities in every row.
TypeYou manageAzure example
IaaSOperating system, middleware, applications, and data. The provider runs the hardware and hypervisor.Azure Virtual Machines
PaaSApplications and data. The provider runs the operating system and the platform.Azure App Service
SaaSThe data you put in the application, and who may use it. The provider runs the application.Microsoft 365
ServerlessYour code and its permissions. The provider runs the servers and scales the execution.Azure Functions

Choose IaaS when you need a specific operating system or existing software that you install yourself. Choose PaaS when you want to deploy an application without patching a server. Choose SaaS when the finished application is what you need.

Module 3: Regions, zones, and the resource hierarchy

An Azure region is a set of datacenters deployed inside a latency-defined perimeter. An availability zone is a physically separate datacenter group in that region, with independent power, cooling, and networking. A region pair is two regions in the same geography that Microsoft links for platform replication and prioritized recovery. You do not pick the pair. Sovereign regions, such as Azure Government and Azure operated by 21Vianet in China, are separate clouds. You do not casually move a resource from global Azure into one of them.

The management hierarchy, from the widest scope to a single object.
LevelWhat it groups
Management groupSubscriptions, and other management groups. Use it to apply policy and access above a single subscription.
SubscriptionA billing boundary and an access boundary. Resources are billed to one subscription.
Resource groupA logical container for resources that share a lifecycle. The group has a location for its metadata. Resources inside it can live in other regions.
ResourceA manageable item, such as a virtual machine, a storage account, or a virtual network. A resource belongs to one resource group.

An availability set is not a zone. It groups virtual machines in one datacenter into fault domains, which separate power and network, and update domains, which Microsoft updates one at a time. It protects against a rack failure and against a planned update. It does not protect against the loss of a whole datacenter. A virtual machine is placed in an availability set or in an availability zone, not both, and you choose that placement when you create the virtual machine.

Module 4: Compute and application hosting

Name the unit of compute before you name the product.

Virtual machines

An Azure virtual machine needs a size, storage for its disks, and a virtual network. You patch the guest operating system. Stopped (deallocated) releases the compute and stops that charge. A VM that is only stopped inside the guest may still be billed for compute. Disks can still incur storage charges after deallocation.

Scale sets and availability

A Virtual Machine Scale Set runs a set of identical virtual machines and can grow or shrink with demand. Azure Virtual Desktop delivers virtualized Windows desktops and apps. It is not the same thing as a single server virtual machine you administer for one application.

Web apps, containers, and functions

App Service hosts web apps and APIs without you managing the host operating system. A container packages an application and its dependencies so it runs the same way on different hosts. Azure Functions runs code in response to an event and scales the execution for you.

Module 5: Virtual networking

An Azure virtual network is your private network in a region. Subnets divide its address space. Virtual network peering connects two virtual networks. Traffic uses the Microsoft backbone. Peering is not transitive: if A peers with B and B peers with C, A does not automatically reach C.

Connectivity choices named in the AZ-900 study guide.
ChoiceUse it when
VPN GatewayYou need an encrypted tunnel over the public internet between Azure and another network, or between virtual networks.
ExpressRouteYou need a private connection through a connectivity provider. Traffic does not travel across the public internet.
Azure DNSYou host DNS records for a domain, or you need name resolution for resources on a virtual network.
Public endpointThe service is reachable from a public IP address.
Private endpointA PaaS service gets a private IP address on your virtual network, so clients reach it without a public address.

Module 6: Storage, tiers, and moving data

Pick the storage type from the shape of the data, then the redundancy from the failure you need to survive.

Azure Storage types a fundamentals exam expects you to separate.
TypeHolds
BlobUnstructured objects such as images, backups, and logs. Access tiers are hot, cool, cold, and archive.
FilesManaged file shares, used like a network file share.
QueueMessages between application components.
TableNoSQL key and attribute data.
DiskBlock storage for virtual machines.

Hot is for data you read often. Cool, cold, and archive cost less to store and more to read, and they are meant for data you keep longer. Archive data is offline until you rehydrate it. Redundancy is a separate choice. Locally redundant storage keeps copies in one datacenter. Zone-redundant storage copies data across availability zones in the region. Geo-redundant storage adds an asynchronous copy in the paired region. Read-access geo-redundant storage lets you read that secondary copy. The secondary of plain geo-redundant storage is not readable until a failover.

AzCopy copies data from the command line. Azure Storage Explorer is the graphical tool. Azure File Sync keeps a Windows Server file share in step with Azure Files. Azure Migrate assesses and migrates servers, databases, and applications. Azure Data Box is a physical device for moving large data sets when the network is the wrong path.

Module 7: Identity, access, and security

Microsoft Entra ID is the cloud directory for users, groups, and applications. It provides single sign-on, multifactor authentication, and passwordless sign-in. Microsoft Entra Domain Services is different: it is a managed domain that supports domain join and legacy protocols such as LDAP and Kerberos, without you running domain controllers. External identities cover people outside your organization, including guests and customer-facing sign-in.

Conditional Access

An if-then policy. For example, require multifactor authentication when a sign-in comes from outside the office, or block a sign-in from a noncompliant device.

Azure RBAC

A role assignment is a security principal, a role, and a scope. Owner manages resources and access. Contributor manages resources but cannot grant access. Reader can view. An assignment at a subscription applies to the resource groups and resources under it.

Zero Trust and defense in depth

Zero Trust means verify explicitly, use least privilege, and assume breach. Defense in depth stacks controls, from physical security through identity, network, compute, application, and data, so one missed control is not the whole breach.

Microsoft Defender for Cloud

Security posture and threat protection for your cloud resources, with a secure score and recommendations. It is not Azure Policy, and it is not a resource lock.

Extra Azure Key Vault stores secrets, keys, and certificates. It is useful, and it is not named in the July 20, 2026 skill list.

Module 8: What changes an Azure bill

The study guide asks for factors, the pricing calculator, cost management, and tags.

Factors

Resource type and size, the region, how long compute runs, the storage tier and redundancy, and outbound data transfer. Inbound data transfer is typically not the expensive direction. Reservations commit to one or three years for a lower rate. Spot virtual machines use spare capacity and can be evicted. Azure Hybrid Benefit applies existing Windows Server or SQL Server licenses.

Pricing calculator

An estimate before you deploy. Change the region or the redundancy option and the estimate changes. It is not an invoice.

Cost Management

Analysis of spend you already have, forecasts, and budgets that alert you when cost or usage crosses a threshold. Azure Advisor can add cost recommendations on top of that.

Tags

Name and value metadata, often used to group cost by project or owner. Tags do not grant permission. They do not automatically copy from a resource group onto every resource unless you enforce that with policy.

Module 9: Policy, locks, and Purview

Azure Policy evaluates resources against rules, such as allowed locations or a required tag. A deny effect blocks a noncompliant deployment. An audit effect reports it and still allows it. Policy answers "what is allowed to exist." RBAC answers "who may act."

A resource lock is narrower. CanNotDelete lets you read and change a resource but not delete it. ReadOnly blocks changes and deletion. Locks inherit to child resources. They do not replace RBAC, and a reader was already unable to change the resource. Someone with permission to manage locks has to remove the lock before a protected delete can succeed.

Microsoft Purview is the data-governance service: discover, classify, and catalog data. It is not the tool that denies a virtual machine in the wrong region. That is Azure Policy.

Module 10: Ways to manage and deploy

The same resource can be created from more than one tool. The study guide wants the purpose of each tool.

Management and deployment tools named in the July 20, 2026 study guide.
ToolPurpose
Azure portalThe browser interface for interactive work.
Azure Cloud ShellA browser shell that is already authenticated, with the Azure CLI and Azure PowerShell available.
Azure CLICross-platform commands for scripting Azure.
Azure PowerShellPowerShell cmdlets for the same kind of management and automation.
Azure Resource ManagerThe deployment and management layer. Requests from the portal, CLI, and PowerShell go through it.
ARM templatesJSON infrastructure as code. You describe the resources and deploy that file again with the same result.
Azure ArcProject servers and other resources that live outside Azure into Azure management, so you can apply policy, inventory, and monitoring.

Extra Bicep is a language that compiles to ARM templates. The study guide names ARM and ARM templates, not Bicep.

Module 11: Advisor, Service Health, and Monitor

Azure Advisor

Personalized recommendations for reliability, security, performance, cost, and operational excellence. It looks at how you configured resources. It does not page you about an Azure platform outage.

Azure Service Health

Problems, planned maintenance, and health advisories that affect the Azure services you use. Resource Health, a related view, shows whether a specific resource is available, degraded, or unavailable.

Azure Monitor

The platform for metrics, logs, and traces. Log Analytics stores and queries logs. Alerts fire when a signal crosses a condition you set. Application Insights watches an application's requests, failures, and dependencies.

Frequently asked questions

Who manages the operating system on an Azure virtual machine?

You do. A virtual machine is infrastructure as a service, so you patch the guest operating system and your applications. On Azure App Service, Microsoft manages the operating system. On a SaaS application, Microsoft manages the application as well.

What is the difference between Azure Policy and Azure RBAC?

Azure RBAC decides who can take an action at a scope. Azure Policy decides whether a resource is allowed to exist, for example by limiting regions or requiring a tag. A resource lock blocks delete or modification. A tag does not grant or deny permission.

Which tool estimates cost before you deploy, and which one reviews spend you already have?

The Azure pricing calculator estimates cost before you deploy. Azure Cost Management reviews actual and forecast spend and can alert you from a budget. Azure Advisor can recommend changes that reduce cost, but it is not the bill.

Continue the Azure Fundamentals study path

Drill the distinctions, then test them under a timer.

Azure Fundamentals hub →
Available

Overview

Exam format, the 700 passing score, domain weights, and a study plan.

Available · You are here

Core Notes

Reference notes for models, architecture, services, identity, cost, and monitoring.

Available

Practice Exams

200 original questions with custom exams, explanations, and a score report by domain.

Related Tools

Useful companions while you study.

All study topics →