AZ-900 architecture and services explained
Describe Azure architecture and services is the largest AZ-900 domain at 35–40% of the exam. It covers four areas: the core architectural components of Azure, compute and networking, storage, and identity, access and security. It is also the broadest domain, and most wrong answers come from confusing two similar services. Learn each service together with the one it is most often mistaken for.
Core architectural components
Physical structure
| Component | What it is | Protects against |
|---|---|---|
| Datacenter | A facility full of servers | — |
| Availability zone | One or more datacenters in a region with independent power, cooling and networking | Loss of a datacenter |
| Region | A geographic area with one or more datacenters close together | — |
| Region pair | Two regions in the same geography, paired for recovery and staggered updates | Loss of a whole region |
| Sovereign region | An isolated instance of Azure for government or legal requirements | Compliance, not outages |
Not every region has availability zones. Services that use zones are either zonal (pinned to one zone) or zone-redundant (replicated across zones).
Logical structure
From the top down: management groups contain subscriptions, which contain resource groups, which contain resources.
- A resource is one thing you create: a VM, a storage account, a database.
- A resource group holds resources that share a lifecycle. Deleting it deletes everything in it. A resource belongs to exactly one resource group.
- A subscription is a unit of billing and access. Organisations often use separate subscriptions per department or environment.
- A management group organises subscriptions so policies and access can be applied to many at once. Management groups can nest.
Settings applied at a level — policies, role assignments — are inherited by everything below. That single fact answers a surprising number of questions.
Compute and networking
Compute options
| Option | Choose it when |
|---|---|
| Virtual machines | You need full control of the OS (IaaS) |
| Virtual Machine Scale Sets | You need many identical VMs that scale automatically |
| Availability sets | You need VMs spread across fault and update domains inside one datacenter |
| Azure Virtual Desktop | Users need a Windows desktop delivered from the cloud |
| Containers | You want lightweight, portable app packaging without a full VM |
| Azure Functions | You want event-driven code with no servers to manage |
A VM is not a single resource. It needs a disk, a network interface, a virtual network and usually a public IP or other way in. The outline names “the resources required for virtual machines”, so expect a question on it.
For application hosting, the outline lists web apps (Azure App Service), containers and virtual machines. App Service is the answer when a scenario wants to host a web app or API with the least management.
Networking
- Virtual network (VNet): a private network in Azure. Resources in it can talk to each other.
- Subnet: a range inside a VNet to segment resources.
- Peering: connects two VNets, including across regions, so they communicate privately.
- Azure DNS: hosts DNS domains on Azure’s infrastructure.
- VPN Gateway: an encrypted tunnel to Azure over the public internet.
- ExpressRoute: a private connection to Azure through a connectivity provider, not over the internet.
- Public endpoint: reachable from the internet. Private endpoint: a private IP address inside your VNet for an Azure service.
VPN Gateway versus ExpressRoute is a favourite: if the scenario says the traffic must not cross the public internet, it is ExpressRoute.
Storage
Services
| Service | Stores |
|---|---|
| Blob Storage | Unstructured objects: files, images, video, backups |
| Azure Files | File shares accessible over SMB or NFS |
| Queue Storage | Messages between application components |
| Table Storage | Structured NoSQL key-attribute data |
| Disk Storage | Managed disks for VMs |
Access tiers
Hot, cool, cold and archive. The colder the tier, the cheaper it is to store data and the more expensive and slower it is to read it. Archive data is offline and must be rehydrated before it can be read.
Redundancy
| Option | Copies kept | Survives |
|---|---|---|
| LRS | Three copies in one datacenter | Disk or server failure |
| ZRS | Three copies across availability zones in one region | Loss of a datacenter |
| GRS | LRS in the primary region plus LRS in a secondary region | Loss of a region |
| GZRS | ZRS in the primary region plus LRS in a secondary region | Loss of a datacenter or a region |
RA-GRS and RA-GZRS add read access to the secondary region.
Moving data
AzCopy is a command-line copy tool. Azure Storage Explorer is a graphical app. Azure File Sync keeps on-premises Windows file servers in sync with Azure Files. For whole migrations, Azure Migrate discovers and moves servers, and Azure Data Box is a physical device shipped to you for moving large volumes offline.
Identity, access and security
- Microsoft Entra ID: Azure’s cloud identity service for users, groups and applications.
- Microsoft Entra Domain Services: managed domain services such as domain join and Group Policy, for legacy apps that need them, without running domain controllers.
- Authentication methods: SSO (one sign-in for many apps), MFA (two or more factors) and passwordless (for example Windows Hello or an authenticator app).
- External identities: letting partners and customers sign in with their own identities.
- Conditional Access: rules that grant, block or require MFA based on signals such as user, location or device.
- Azure RBAC: assigns roles to users at a scope — who can do what, where.
- Zero Trust: verify explicitly, use least privilege, assume breach.
- Defense in depth: layers of protection, from physical security to data, so one failure does not expose everything.
- Microsoft Defender for Cloud: monitors security posture and detects threats across Azure, on-premises and other clouds.
Authentication proves who you are; authorisation decides what you may do. Entra ID and MFA are authentication; RBAC is authorisation.
Three practice questions
Question 1. Your company has an on-premises network and must connect it to Azure. Traffic must not travel over the public internet and needs predictable performance. What should you use?
- A. Azure VPN Gateway
- B. Virtual network peering
- C. Azure DNS
- D. Azure ExpressRoute
Show answer
Answer: D
ExpressRoute provides a private connection to Azure through a connectivity provider, so traffic does not cross the public internet. VPN Gateway encrypts traffic but sends it over the internet. Peering connects Azure virtual networks to each other, not to on-premises. Azure DNS resolves names and carries no traffic.
Want more questions like this? Full AZ-900 practice tests →
Question 2. A team stores project files that are read daily for a month and then almost never, but must be kept for seven years. Which approach minimises storage cost?
- A. Keep all files in the hot tier
- B. Use the hot tier for recent files and move older files to the archive tier
- C. Move all files to premium storage
- D. Change the redundancy from LRS to GRS
Show answer
Answer: B
Keeping recent files in the hot tier and moving older files to the archive tier matches cost to access patterns: hot suits frequent reads and archive has the lowest storage cost for data that is rarely read. Keeping everything hot pays hot prices for years. Premium storage costs more. Changing redundancy affects durability, not the access cost trade-off.
Want more questions like this? Full AZ-900 practice tests →
Question 3. Users must be required to complete multifactor authentication only when they sign in from outside the corporate network. What should you configure?
- A. Microsoft Entra Conditional Access
- B. Azure role-based access control
- C. Azure Policy
- D. Microsoft Defender for Cloud
Show answer
Answer: A
Microsoft Entra Conditional Access evaluates signals such as location and can require MFA only when conditions are met. RBAC assigns permissions but does not change sign-in requirements. Azure Policy governs resource settings, not user sign-in. Defender for Cloud assesses security posture and does not enforce MFA.
Want more questions like this? Full AZ-900 practice tests →
How to study this domain
Split it in two, as the study plan does: architecture, compute and networking in one week; storage, identity and security in the next. Build a table of confused pairs as you go. The practice test gives this domain eight of its twenty questions, matching its weight.