Microsoft AZ-900: Cloud Concepts That Look Alike

Cloud fundamentals become confusing when every service name seems to mean the same thing: high availability, backup, scaling, governance and security all sound like promises the cloud should simply deliver. Microsoft AZ-900 tests whether a candidate can separate those promises, recognize the responsibility behind each, and choose a broad Azure model that fits a business requirement. It is a conceptual exam, but practical reasoning makes its vocabulary stick.

The current exam is Microsoft Azure Fundamentals . Microsoft’s July 2026 outline covers cloud concepts, Azure architecture and services, and management and governance. The Microsoft AZ-900 can support revision after the candidate understands why these distinctions matter; memorizing definitions alone will not resolve scenario questions.

Shared responsibility is about layers

Consider three ways to host a company website: a virtual machine, an Azure application platform, or a fully managed software product. With infrastructure as a service, the customer has more control over the guest operating system, application and configuration. Platform as a service reduces operating-system management but does not absolve the customer of protecting identities, application data and access. Software as a service shifts more of the underlying management to the provider, while customer data governance and user administration remain relevant.

Rather than memorize IaaS, PaaS and SaaS as abstract acronyms, ask who installs patches, who configures access, who monitors application behavior and who designs data retention. The answer changes by service. The shared responsibility model explains why moving a database to a managed platform can reduce maintenance without removing the need to assign permissions and protect sensitive information.

Availability is not the same as recoverability

An availability zone helps isolate certain datacenter failures within a supported region. A region pair expresses a broader geographic consideration, but it does not automatically replicate each customer’s workload or guarantee immediate failover. A backup addresses recovery from data loss or corruption; redundancy addresses some forms of component or site failure. Confusing these concepts leads to expensive, fragile designs.

Imagine a small retailer whose website must stay available during host maintenance while the business also needs last week’s order data after an accidental deletion. These are separate requirements. Scaling up a VM changes its size; scaling out adds instances. High availability, elasticity, disaster recovery and backups solve different questions. In a fundamentals scenario, identify the failure type or workload pressure before choosing the term.

The resource hierarchy defines control boundaries

Management groups, subscriptions, resource groups and individual resources form governance scopes. A subscription can provide a billing and access boundary; a resource group organizes related resources for management, but it is not a subnet or an availability zone. Azure role-based access control assigns permissions at a scope. Azure Policy evaluates or enforces resource configuration rules. Resource locks and tags serve different purposes again.

Picture a company with separate production and development subscriptions. A central team may need to define permitted regions and tagging requirements without granting every developer ownership of production. The design can combine management-group policies, scoped role assignments and budgets. A policy denying unapproved regions does not make a resource encrypted; a role assignment granting read access does not govern resource creation standards. Examine each control’s actual function.

Recognize service families by the job they perform

For compute, distinguish virtual machines, containers, App Service and serverless execution at a high level. For networking, differentiate virtual networks, VPN Gateway, ExpressRoute and public load-balancing or application-delivery tools. For storage, understand blobs, files, queues and disks as different access patterns rather than interchangeable containers for bytes. Managed databases and analytics platforms address different application and data needs.

The point is not to learn advanced configuration for every service. AZ-900 requires enough of the architecture to choose between broad alternatives. A remote user needs a connection, not a backup product. A static web asset needs a different storage and serving approach from a transactional relational database. Keep the requirement at the center of the comparison.

Costs, trust and governance complete the picture

Consumption-based billing can align spending to demand, but fixed reservations, resource sizing, licensing and data transfer affect the final bill. Budgets and alerts help track spending; they do not necessarily shut off resources when a threshold is reached. Pricing and total-cost tools help estimate rather than guarantee a future invoice. Understand the distinction between service-level agreements, service health, Azure Advisor recommendations and operational telemetry.

To prepare, design a simple company environment on paper. Assign subscriptions, resource groups, identity roles, a hosting model, storage and availability controls, then explain who manages each component and what it costs in principle. Deliberately ask what would happen if one user deletes data, one server fails or demand doubles. AZ-900 is mastered when the candidate can answer these questions in plain language without mixing concepts that happen to share a cloud label.

  • img