Microsoft AZ-900 Azure Fundamentals Readiness Matrix: How to Diagnose Your Weakest Exam Domains

 

AZ-900 is a fundamentals exam, but “fundamentals” does not mean a candidate can pass by memorizing a few product names. The current Microsoft study guide, with skills measured as of July 20, 2026, organizes the exam into three large areas: cloud concepts at 25–30 percent, Azure architecture and services at 35–40 percent, and Azure management and governance at 30–35 percent. Those percentages matter because a study plan that feels balanced can still be badly misallocated. A candidate may spend most of a week on virtual machines and networking while leaving governance, identity, cost management, or the shared responsibility model too shallow.

A readiness matrix solves a different problem from a study outline. An outline tells you what exists. A matrix tells you what you can actually explain, distinguish, and apply. The useful question is not “Have I read about Azure Policy?” It is “Can I tell Azure Policy apart from resource locks and tags in a scenario, explain what each one does, and reject the tempting wrong tool?” The same principle applies to regions versus availability zones, RBAC versus Conditional Access, and IaaS versus PaaS. This guide turns the current blueprint into evidence-based readiness checks so you can decide where more study time will produce the largest improvement.

Build the matrix around evidence, not confidence

Use three readiness states for every objective. Red means you cannot explain the concept without notes or you regularly confuse it with a neighboring concept. Yellow means you can define it but struggle to choose it in a scenario, compare it with alternatives, or explain its operational consequence. Green means you can explain it in plain language, identify when it applies, distinguish it from close alternatives, and answer a short scenario without relying on memorized wording.

The important word is evidence. A candidate can feel confident because a term looks familiar. Recognition is weaker than recall, and recall is weaker than application. For each row in your matrix, attach a tiny proof task: explain the concept aloud in thirty seconds, draw the relationship, classify two scenarios, or answer a question and justify why the other choices are wrong. When a row turns green only after you can produce evidence, the matrix becomes diagnostic instead of motivational.

Do not make the matrix so granular that maintaining it becomes another study project. The current AZ-900 blueprint has enough detail to create roughly twenty to thirty meaningful rows, grouped under the three weighted domains. That is sufficient to expose gaps without turning preparation into spreadsheet administration.

Domain 1: cloud concepts readiness, 25–30 percent

Cloud concepts are often underestimated because the language sounds familiar. That creates a specific risk: candidates remember slogans but cannot reason through boundaries. A strong Domain 1 matrix should test cloud computing, shared responsibility, deployment models, consumption economics, serverless, cloud benefits, and service models.

Start with cloud computing itself. Green readiness means you can explain cloud computing as on-demand access to computing resources and services delivered with flexible provisioning, rather than reducing the idea to “someone else’s datacenter.” You should be able to connect the definition to why organizations can provision faster, scale differently, and shift some operational responsibilities to a provider. If your explanation depends entirely on Azure product names, the conceptual foundation is still yellow.

Shared responsibility is a high-value diagnostic row

Shared responsibility becomes green when you can move responsibility boundaries as the service model changes. In an on-premises environment, the organization owns almost everything from physical facilities through the application and data. In IaaS, the cloud provider takes responsibility for physical datacenters, physical network, and physical hosts, while the customer still manages significant portions of operating systems, applications, identities, and data. In PaaS, the provider manages more of the platform stack. In SaaS, the provider manages still more, but the customer does not stop being responsible for data, identities, access decisions, and correct use of the service.

A good diagnostic asks what changes, not merely who is responsible. If a company moves a custom application from self-managed virtual machines to a managed application platform, which operational responsibilities shrink? If a user grants excessive permissions in a SaaS service, can the customer claim the provider is responsible because the software is hosted in the cloud? If you can answer those questions without falling back on a memorized chart, mark the row green.

Public, private, and hybrid cloud must be tied to use cases

Definitions alone are not enough. Public cloud uses provider-operated shared infrastructure delivered to customers as services. Private cloud dedicates cloud-style infrastructure to one organization, often for control or specific requirements. Hybrid cloud connects private or on-premises environments with public cloud resources. Green readiness means you can recognize why an organization might choose each model without assuming one is universally better.

Test yourself with constraints. A business needs rapid elasticity for a new customer-facing service but must keep a legacy system on premises for technical reasons. That is a strong hybrid-cloud scenario. Another organization wants cloud operating characteristics but has a hard requirement to keep infrastructure dedicated under its own control. Private cloud may be relevant. A startup wants fast provisioning with minimal infrastructure ownership. Public cloud is a natural fit. The exam is testing the concept-to-scenario match.

Consumption-based pricing should connect usage to cost behavior

Cloud economics is another area where vague familiarity creates false confidence. Green readiness means you can explain that consumption-based models align charges with measured usage and can reduce the need to purchase infrastructure far in advance. You should understand the general difference between capital expenditure patterns and operational expenditure patterns without treating cloud as automatically cheaper in every situation.

A useful proof task is to explain why an idle resource can still create cost, why right-sizing matters, and why predictable workloads may use pricing commitments differently from highly variable workloads. You do not need to memorize every Azure price. You do need to understand that service choice, region, resource size, usage, data transfer, redundancy, and commercial commitments can all influence cost.

Serverless is an execution model, not “no servers exist”

Mark serverless green only if you can explain the abstraction correctly. Servers still exist, but the customer does not manage them in the traditional sense. The platform allocates and operates the underlying infrastructure while the customer focuses on code or workload logic. Serverless can align well with event-driven or variable workloads, and billing often reflects executions or consumption rather than continuously allocated servers.

A common yellow-state mistake is to equate serverless with SaaS. They are not the same concept. Serverless describes how application logic can be executed with infrastructure management abstracted away; SaaS is a service model in which customers consume a complete application. If you can explain that distinction and choose a serverless pattern in a scenario, the row is genuinely ready.

Diagnose the benefits of cloud services by mechanism

The blueprint asks about high availability, scalability, reliability, predictability, security, governance, and manageability. Do not memorize those as a list. For each benefit, ask what mechanism produces it and what it does not guarantee.

High availability concerns keeping services accessible despite failures or maintenance. Scalability concerns changing capacity to meet demand. Reliability concerns designing systems to recover from failures and continue delivering expected outcomes. Predictability can apply to performance and cost when architectures, monitoring, and pricing models are understood. Security and governance improve because cloud platforms provide centralized controls and built-in capabilities, but customers must configure them correctly. Manageability improves through portals, APIs, command-line tools, templates, and automation.

A green response should also resist absolute claims. Cloud does not make an application highly available simply because it runs in Azure. A single virtual machine can fail. Governance tools do not help if policies are not designed and assigned properly. Cost is not automatically predictable if resources are created without ownership, budgets, or monitoring. Fundamentals questions often reward the candidate who understands the benefit and its conditions.

IaaS, PaaS, and SaaS: use a decision ladder

For each service model, record four things in the matrix: what the customer consumes, what the provider manages, what flexibility remains, and what operational burden remains. IaaS provides the most infrastructure-level control of the three and leaves more management with the customer. PaaS abstracts more infrastructure and platform management so teams can focus more on applications and data. SaaS delivers a finished application experience with the provider managing most of the underlying stack.

A practical decision ladder is useful. If the scenario requires operating-system-level control, IaaS becomes more plausible. If developers want to deploy an application without managing the underlying operating system, PaaS becomes more plausible. If users simply need a complete business application, SaaS is likely. Green readiness means you can explain the tradeoff, not just select the acronym.

Domain 2: Azure architecture and services readiness, 35–40 percent

This is the largest current domain, and it contains several clusters that candidates often study separately even though exam scenarios combine them. Your matrix should cover architectural hierarchy, compute and networking, storage, and identity/access/security.

Regions, zones, and datacenters require a spatial model

Draw them. An Azure datacenter is a physical facility. A region is a geographic area containing one or more datacenters connected through a network. Availability zones are physically separate locations within a region, designed with independent power, cooling, and networking to reduce correlated failure. Region pairs and sovereign regions serve different purposes and should not be collapsed into the availability-zone concept.

Green readiness means you can reason about fault boundaries. If the requirement is protection from a datacenter-level failure within one region, availability zones are relevant. If the design needs disaster recovery across geographic regions, a multi-region strategy is relevant. If the requirement is a specialized geography with separate compliance or operational boundaries, sovereign-region concepts may matter. If your answer is always “use another region,” the row is still yellow.

Resource hierarchy is one of the best readiness tests

You should be able to draw management groups, subscriptions, resource groups, and resources in the correct relationship. Management groups can organize subscriptions for governance at scale. Subscriptions are billing and access-management boundaries that contain resource groups and resources. Resource groups are logical containers for related Azure resources and are useful for lifecycle, access, policy assignment, and organization.

The most common misconception is treating resource groups as folders that can be nested arbitrarily. They are not a general filesystem hierarchy. Another is believing a resource belongs to several resource groups simultaneously. It does not. Green readiness means you can decide whether a control belongs at management-group, subscription, resource-group, or resource scope and explain how inheritance affects lower scopes.

Compute readiness is about choosing the abstraction

The current blueprint expects comparison of containers, virtual machines, and functions, plus awareness of virtual machine options such as Azure Virtual Machines, Virtual Machine Scale Sets, availability sets, and Azure Virtual Desktop. It also asks candidates to understand resources required for virtual machines and application-hosting options such as web apps, containers, and VMs.

Mark this cluster green when you can map requirements to control and operational effort. A legacy application requiring full operating-system control points toward virtual machines. A stateless web application that benefits from a managed hosting platform may fit a web app. A packaged service requiring consistent runtime dependencies may fit containers. Event-driven code with bursty execution may fit functions. The exam does not require you to be an Azure administrator, but it does expect you to choose the right level of abstraction.

Networking readiness should follow traffic paths

A virtual network provides a private network boundary in Azure. Subnets segment address space. Peering connects virtual networks. Azure DNS provides name-resolution services. VPN Gateway can create encrypted connectivity over the public internet, while ExpressRoute provides private connectivity through a connectivity provider rather than traversing the public internet. Public and private endpoints affect how a service is reached.

To test readiness, sketch a path. A company wants branch offices to reach Azure through an encrypted tunnel over the internet: VPN Gateway is relevant. A company needs private dedicated connectivity from its network to Microsoft cloud services: ExpressRoute is relevant. Two Azure virtual networks need direct connectivity: peering is relevant. A platform service should be reachable from a virtual network through a private IP path instead of a public endpoint: a private endpoint is relevant. If you can reason from path requirements to the feature, mark the row green.

Storage readiness: separate service, tier, and redundancy decisions

Candidates often mix three independent decisions. The storage service answers what kind of data or access pattern is needed. The access tier answers how frequently data is expected to be accessed and the tradeoff between storage and retrieval costs. Redundancy answers how copies are maintained to increase durability and availability.

Your matrix should test Azure Blob Storage, Azure Files, queue and table concepts at an appropriate fundamentals level, storage account options, access tiers, and redundancy choices. You should also recognize file-movement tools such as AzCopy, Azure Storage Explorer, and Azure File Sync, plus migration options such as Azure Migrate and Azure Data Box.

A green candidate can classify a scenario without turning every storage question into Blob Storage. Shared file access through SMB-style semantics points toward Azure Files. Object data such as images or backups commonly fits Blob Storage. Large-scale offline transfer can make Data Box relevant. A synchronization requirement between Windows file servers and Azure Files points toward Azure File Sync. The diagnostic should emphasize why the option fits.

Identity, access, and security readiness: distinguish control planes

This cluster deserves separate rows because the names can sound interchangeable. Microsoft Entra ID provides cloud identity and directory capabilities. Microsoft Entra Domain Services provides managed domain services for scenarios that need traditional domain features without managing domain controllers. Authentication methods include SSO, MFA, and passwordless approaches. External identities address collaboration with users outside the organization. Conditional Access evaluates signals and conditions to enforce access decisions. Azure RBAC authorizes what identities can do to Azure resources.

A fast proof task is to answer “who are you?” versus “what can you do?” Authentication establishes identity. Authorization determines permitted actions. Conditional Access applies access policies based on signals and conditions. RBAC assigns roles to principals at scopes so they can perform resource actions. Confusing these layers is a reliable indicator that more study is needed.

Zero Trust and defense in depth are conceptual rows. Zero Trust emphasizes explicit verification, least-privilege access, and assuming breach rather than implicit trust based on network location. Defense in depth uses multiple layers of controls so one failure does not become total compromise. Microsoft Defender for Cloud belongs in the security posture and protection discussion, not as a substitute for identity governance or network design.

Domain 3: management and governance readiness, 30–35 percent

This domain is large enough to decide an exam result, yet it is often left for the final day. Your matrix should treat cost management, governance/compliance, management/deployment tools, and monitoring as separate clusters.

Cost management: prove that you can identify cost drivers

Green readiness means you can name the kinds of factors that affect Azure cost and connect them to a scenario: resource type and size, runtime or usage, region, data transfer, storage configuration, licensing, and commercial commitments. You should know the purpose of the Azure pricing calculator and understand that cost management capabilities help analyze, allocate, budget, and monitor spending.

Tags are often included in cost discussions, but do not overstate what they do. Tags are metadata used to organize and categorize resources. They can support cost allocation and operations, but a tag does not by itself stop overspending or enforce a security configuration. If the scenario requires enforcement, look at policy or other controls instead.

Governance: tags, Policy, locks, and Purview solve different problems

Azure Policy evaluates resources against rules and can help enforce or audit organizational standards. Resource locks help protect resources from accidental deletion or modification, depending on lock type. Tags classify resources with metadata. Microsoft Purview supports data governance and related capabilities. These tools can appear in the same scenario but are not interchangeable.

A strong diagnostic gives you a requirement and asks for the primary control. “Prevent accidental deletion of a critical resource” points toward a resource lock. “Require resources to meet an organizational standard” points toward Azure Policy. “Group spending by cost center” can use tags. “Understand and govern data across the estate” points toward Purview. If you can make those selections and explain the rejected options, the governance row is green.

Management and deployment tools: know the interface versus the model

The Azure portal is a graphical management interface. Azure Cloud Shell provides a browser-accessible shell environment with command-line tooling. Azure CLI and Azure PowerShell provide command-line and scripting approaches. Azure Arc extends Azure management and governance concepts to resources outside Azure. Infrastructure as code describes managing infrastructure through declarative or scripted definitions rather than manual clicking. Azure Resource Manager is Azure’s deployment and management service, and ARM templates provide declarative infrastructure definitions.

The readiness test is to avoid tool-name association without purpose. A candidate should understand that portal, CLI, and PowerShell can often manage the same resource through different interfaces. IaC improves repeatability and consistency. ARM provides the control-plane model for resources and deployments. Arc is relevant when the organization wants Azure management capabilities across hybrid or multicloud resources. Green means you can explain the role each plays in an operating model.

Monitoring: Advisor, Service Health, and Azure Monitor are a classic comparison

Azure Advisor provides personalized recommendations related to areas such as reliability, security, performance, operational excellence, and cost. Azure Service Health communicates Azure service issues, planned maintenance, and health information relevant to your environment. Azure Monitor collects and analyzes telemetry, with capabilities that include Log Analytics, alerts, and Application Insights.

Create three scenarios in your matrix. “Which service warns that an Azure platform incident is affecting resources?” points toward Service Health. “Which service provides recommendations to improve a deployed environment?” points toward Advisor. “Which service collects metrics and logs and can trigger alerts from telemetry?” points toward Azure Monitor. If you hesitate among those three, keep the cluster yellow until the distinction is automatic.

Turn every yellow row into a targeted exercise

A matrix is useful only if it changes what you do next. For each yellow or red row, select the smallest exercise that can prove improvement. For hierarchy, draw the scopes and place a policy assignment. For networking, draw a traffic path and choose the connectivity feature. For storage, classify five workloads by service, tier, and redundancy concern. For governance, compare tags, Policy, and locks using three requirements. For identity, separate authentication, authorization, Conditional Access, and RBAC in one scenario.

The AZ-900 practical preparation guide is most useful after the matrix exposes a weak area, because hands-on or diagram-based exercises then have a clear purpose. Do not perform a lab simply to accumulate activity. Perform it to answer a specific readiness question.

For cloud concepts, a focused conceptual review can be more valuable than provisioning resources. If your weakest row is the relationship among public, private, and hybrid models, or the boundary between IaaS, PaaS, and SaaS, the cloud concepts deep dive provides a better next step than another portal walkthrough.

Use a weighted score without pretending it predicts the exact exam

You can calculate a rough readiness score by assigning zero points to red, one to yellow, and two to green, then weighting each domain by the current blueprint range. Keep the result approximate. Microsoft uses scaled scoring, exam forms vary, and the blueprint percentages are ranges rather than exact question counts. A home-built score is a study-management tool, not a prediction of your final mark.

The useful signal is the pattern. If cloud concepts are almost entirely green but management and governance contain several reds, you have a clear priority. If all three domains are mostly yellow, the problem may be insufficient scenario practice rather than missing content. If the score looks high but you cannot explain why wrong answers are wrong, your evidence standard is too weak.

Run a second-pass matrix using mixed scenarios

The first pass can test objectives individually. The second pass should mix them. Real decisions cross domain boundaries. A company may need a highly available web application, private connectivity, role-based administration, cost controls, and monitoring. Even at fundamentals depth, you should be able to identify which Azure concepts address each part and avoid assigning one product to every requirement.

Try a scenario in which a retailer hosts a customer application in Azure. Demand spikes during promotions. The application must remain available if one datacenter fails. Administrators need least-privilege access. Finance wants cost allocation by business unit. Operations needs alerts when application telemetry crosses a threshold. That single scenario touches scalability, availability zones, RBAC, tags, and Azure Monitor. If you can separate those requirements cleanly, your conceptual model is becoming robust.

Final readiness signals for the last study phase

Before moving into final review, look for four signals. First, there should be no red rows in high-weight clusters. Second, most yellow rows should be narrow rather than foundational; for example, you may occasionally mix up two migration tools, but you should not still confuse resource groups with subscriptions. Third, you should be able to explain major concepts without notes. Fourth, practice questions should produce stable reasoning rather than lucky recognition.

Do one timed set only after you have repaired obvious knowledge gaps. For every miss, record whether the cause was concept, comparison, scenario interpretation, or careless reading. A concept miss goes back to the matrix. A comparison miss needs a side-by-side distinction. A scenario miss needs more mixed examples. A reading miss needs exam-execution discipline. This prevents “more questions” from becoming an unfocused substitute for learning.

AZ-900 readiness is not the number of hours you have spent studying. It is the coverage and quality of the explanations you can produce under modest time pressure. The current blueprint rewards candidates who can connect cloud concepts to Azure services and then connect those services to governance and management decisions. A readiness matrix makes those connections visible. Use it to direct effort toward weak evidence, turn yellow rows into specific exercises, and enter final review only when your understanding is broad enough to survive unfamiliar wording.

Audit the matrix with a one-hour evidence sprint

A useful way to validate the matrix is to run a one-hour evidence sprint without opening notes. Divide the hour into six ten-minute blocks. In the first block, explain the shared responsibility model, cloud models, consumption pricing, serverless, and the differences among IaaS, PaaS, and SaaS. Do not aim for polished definitions; aim for accurate distinctions. In the second block, draw the Azure hierarchy from management groups down to resources and then add regions, availability zones, and the idea of fault isolation. If the drawing becomes confused, mark the related rows yellow immediately.

Use the third block for compute and networking. Given five short requirements, choose among virtual machines, containers, functions, web apps, VPN Gateway, ExpressRoute, peering, and private endpoints. Explain why the unused alternatives are weaker fits. The fourth block should cover storage and identity. Classify sample workloads by storage service, access pattern, and movement method, then separate Entra ID, authentication methods, Conditional Access, and RBAC in a single access scenario. These are areas where one mistaken mental model can cause several questions to fail.

Use the fifth block for governance and deployment. Explain tags, Azure Policy, locks, Purview, the portal, Cloud Shell, CLI, PowerShell, Azure Arc, ARM, templates, and IaC in terms of purpose rather than product description. The sixth block is monitoring and cost. Distinguish Advisor, Service Health, and Azure Monitor, then identify cost drivers and explain how pricing tools, budgets, tagging, and resource choices contribute to financial control. At the end, compare your evidence against the matrix. Any row that needed prompting or vague language should not remain green.

Watch for “green by familiarity” and other false-positive signals

A matrix can fail if you grade yourself generously. The most common false positive is green by familiarity: you recognize a term instantly and assume you understand it. Replace recognition with a production test. Close the material and explain the concept to an imaginary colleague who has never used Azure. If you cannot state what problem the feature solves, what it is commonly confused with, and one scenario where it fits, your evidence is incomplete.

Another false positive is green by one perfect example. You may know that ExpressRoute is used for private connectivity and still fail when the wording emphasizes predictable private network connectivity rather than naming the service. Test each important row with at least two differently worded scenarios. A third false positive is green by procedure: you remember the clicks from a portal lab but cannot explain the underlying concept. AZ-900 is not an administration exam, so procedural memory should support conceptual understanding, not replace it.

Finally, avoid marking a row red merely because you cannot recall an obscure feature detail. The exam is foundational and the blueprint tells you the level of description expected. Focus on purpose, relationships, use cases, and meaningful distinctions. Your matrix should direct attention toward concepts that change decisions, not encourage trivia collection. When the grading standard is strict about reasoning but proportionate about depth, the matrix becomes a realistic preparation instrument rather than a confidence chart.

Popular posts

img