Skip to content

Azure Architecture and Services

This domain currently represents 35–40% of the AZ-900 exam. It is the largest section.

Lessons

  1. Core architectural components
  2. Compute choices: VMs, containers, and functions
  3. VM options and required resources
  4. Application hosting: Web Apps, containers, and virtual machines
  5. Azure networking: VNets, connectivity, security, and traffic distribution
  6. Public and private endpoints
  7. Azure Storage services and account types
  8. Storage tiers and redundancy
  9. File movement and migration tools
  10. Microsoft Entra ID and Domain Services
  11. Authentication: SSO, MFA, passwordless, and Conditional Access
  12. Authorization and security: RBAC, Zero Trust, defense in depth, and Defender for Cloud
  13. Exam cheat sheet
  14. Practice quiz
  15. Answer key

High-value comparisons

Requirement Likely answer
VM instances managed and scaled together Virtual Machine Scale Sets
Connect a VM privately to a subnet Network interface with a private IP
Persistent operating system storage for a VM Managed OS disk
Isolated private network in Azure Virtual Network
Encrypted hybrid connection over the public internet VPN Gateway
Private hybrid connection that avoids the public internet ExpressRoute
Rule-based traffic filtering on a subnet Network security group
Route web traffic by URL path, or block web attacks Application Gateway, with WAF
RDP or SSH to a VM with no public IP Azure Bastion
Objects such as images, video, and backups Blob Storage
Managed SMB/NFS file share Azure Files
Identity directory Microsoft Entra ID
Who can perform an action at a scope Azure RBAC

The lesson list follows the current official AZ-900 skills measured.

Some foundational topics were introduced earlier in the study sequence and are also covered directly by this section:

Review those pages if you need a refresher before starting this section.