Microsoft AZ-900: Current Exam Scope

AZ-900 remains Microsoft’s foundational Azure certification exam, but the live English skills measured changed on July 20, 2026. Candidates should therefore prepare from the current outline rather than older study notes that may use outdated service names or omit recent wording. The current AZ-900 exam gives candidates 45 minutes for the assessment, requires a scaled score of 700 or greater to pass, and continues to target foundational cloud and Azure knowledge rather than implementation depth.

The live blueprint has three weighted areas: Describe cloud concepts at 25–30%, Describe Azure architecture and services at 35–40%, and Describe Azure management and governance at 30–35%. Microsoft positions the exam for technology professionals who can explain compute, networking, storage, identity, security, governance and administration at a conceptual level.

Cloud concepts remains 25–30%

The first domain starts with what cloud computing is and why organizations use it. Candidates should understand public, private and hybrid cloud models, appropriate use cases, consumption-based economics, cloud pricing concepts and serverless computing. The shared responsibility model is especially important because customer responsibilities change as the service model becomes more managed.

Cloud benefits also include high availability, scalability, reliability, predictability, security, governance and manageability. The exam expects you to recognize which benefit a scenario is describing rather than design a detailed production architecture.

IaaS, PaaS and SaaS define responsibility boundaries

Infrastructure as a service gives customers more control over operating systems and deployed software, platform as a service removes more infrastructure management, and software as a service delivers completed applications. The service type affects both operational responsibility and what the customer configures.

A strong candidate can identify which model best matches a simple business requirement and explain why moving upward in abstraction usually reduces infrastructure-management work while preserving responsibility for data, identity and appropriate configuration.

Azure architecture and services is the largest domain at 35–40%

The architecture section covers Azure regions, region pairs, sovereign regions, availability zones, datacenters, resources, resource groups, subscriptions, management groups and the hierarchy that connects them. These are foundational organizing constructs: geography affects resilience and compliance, while management hierarchy affects governance and access.

A current Azure fundamentals model is easier to remember when you see resources nested inside resource groups, resource groups inside subscriptions, and subscriptions optionally governed through management groups.

Compute and networking remain core Azure service categories

The current outline asks candidates to compare containers, virtual machines and functions; understand Azure VMs, VM Scale Sets, availability sets and Azure Virtual Desktop; and recognize application-hosting options such as web apps, containers and VMs.

Networking includes virtual networks, subnets, peering, Azure DNS, VPN Gateway, ExpressRoute and public versus private endpoints. The exam is interested in purpose and fit, not subnet calculation or router configuration.

Storage includes service choice, tiers and redundancy

Candidates should compare Azure Storage services, storage tiers, redundancy options, account options and storage types. File-movement tools such as AzCopy, Storage Explorer and Azure File Sync are explicitly named, along with migration options including Azure Migrate and Azure Data Box.

The key is to associate the workload with the storage or movement pattern: object, file, disk, queue/table-style data, hot versus cooler access, online transfer versus large offline migration.

Identity, access and security use current Microsoft Entra terminology

The live scope includes Microsoft Entra ID and Microsoft Entra Domain Services, single sign-on, multifactor authentication, passwordless authentication, external identities, Conditional Access and Azure RBAC. Candidates should understand that authentication proves identity while authorization determines allowed actions.

The Zero Trust concept and defense-in-depth model are also explicit, alongside the purpose of Microsoft Defender for Cloud. These are conceptual security principles rather than configuration labs.

Management and governance accounts for 30–35%

This domain begins with Azure cost factors, Pricing Calculator, cost-management capabilities and tags. Cost can change with resource type, region, usage, data transfer, licensing, reservation or consumption pattern. Tags help organize ownership, environment, application or cost-center context but do not replace RBAC or policy.

A cost-optimization perspective can help connect fundamentals such as rightsizing, lifecycle and cost visibility without turning AZ-900 into a FinOps exam.

Governance and compliance centers on Purview, Policy and locks

The current study guide explicitly names Microsoft Purview, Azure Policy and resource locks. Purview supports data governance/compliance capabilities, Azure Policy evaluates or enforces resource standards, and locks protect resources from accidental deletion or modification depending on lock type.

The exam often tests purpose: Policy is about governance rules and compliance; RBAC is about who can perform actions; a resource lock protects the resource from particular changes.

Azure management now includes Arc and infrastructure as code

The live guide covers Azure portal, Cloud Shell, Azure CLI, Azure PowerShell, Azure Arc, infrastructure as code, Azure Resource Manager and ARM templates. Candidates should know these as management and deployment approaches rather than memorize commands.

An ARM template provides a concrete example of declarative infrastructure as code: desired resources can be described consistently and deployed through Azure Resource Manager.

Monitoring closes the current blueprint

Azure Advisor, Service Health and Azure Monitor are all in scope. Azure Monitor includes Log Analytics, alerts and Application Insights. The distinction matters: Advisor provides recommendations, Service Health communicates service-impact information, and Monitor collects/uses telemetry for workloads and resources.

The July 20, 2026 update did not rewrite the exam from scratch, but Microsoft notes minor changes in compute/networking, management/deployment tools and monitoring. That is enough to make older summaries risky as the sole source. Candidates should use the live Microsoft Learn guide for final terminology and treat older articles as background only.

The cloud-concepts domain also expects candidates to understand predictability. Predictability can refer to performance and cost when workloads, scaling patterns, reservations or budgets are understood. Cloud does not remove uncertainty, but standardized services, telemetry and consumption models can make capacity planning and spending more measurable.

Manageability is another core benefit because cloud resources can be provisioned and controlled through APIs, portals, command-line tools and templates. This is distinct from management hierarchy: manageability is the operational capability; management groups/subscriptions/resource groups are organizational scopes in Azure.

Serverless should be understood as an operating model in which the customer does not manage the underlying servers directly. Azure Functions is a common example, but the concept is broader: the platform allocates infrastructure and the customer focuses more on code, events and configuration. Costs and scaling often follow execution or consumption patterns.

Region pairs and sovereign regions deserve separate attention. Region pairs are a resiliency/maintenance concept between selected Azure regions, while sovereign regions serve particular governments or regulatory environments with separate boundaries. Neither is the same as an availability zone inside one region.

Resource groups are logical containers, not physical deployment zones. Resources in one resource group can exist in different Azure regions, and a resource generally belongs to one resource group at a time. Resource groups are useful for lifecycle, permissions, policy and organization, but they do not automatically create high availability.

Subscriptions provide billing and management boundaries and can be associated with different policies or access assignments. Management groups provide a hierarchy above subscriptions so large organizations can apply governance at broader scope. This hierarchy is high-yield because many Azure governance services operate at multiple scopes.

VM Scale Sets and availability sets solve different concerns. Scale Sets help create/manage groups of VMs with scaling and consistency, while availability sets distribute VMs across fault/update domains in classic availability patterns. Availability zones are a separate datacenter-isolation model. AZ-900 asks candidates to distinguish their purpose rather than configure them.

Azure Virtual Desktop is included to ensure candidates recognize managed virtual desktop/app delivery as a compute/end-user service. It is not the same as creating one ordinary VM and using Remote Desktop. The service supports centrally delivered Windows desktops/apps with Azure integration.

Public and private endpoints represent how services are reached. Public endpoints are accessible through public network addresses subject to controls; private endpoints place a private IP from a virtual network context against supported services. The exam tests the concept of private connectivity, not detailed DNS troubleshooting.

Storage redundancy should be learned as a durability/availability choice. Locally redundant, zone-redundant and geo-redundant approaches keep additional copies across different fault/geographic boundaries, with cost and recovery implications. Candidates should know why an organization chooses more redundancy instead of memorizing every acronym mechanically.

Azure Migrate and Data Box address different migration constraints. Migrate supports assessment and movement of supported workloads into Azure, while Data Box is useful when large datasets need physical/offline transfer because network transfer would be too slow or impractical. The requirement determines the service.

Conditional Access should be recognized as policy-driven access evaluation based on signals such as identity, device, location, risk or application. It works with authentication controls such as MFA but is not itself simply “MFA.” This distinction becomes important in both AZ-900 and later identity certifications.

Microsoft Defender for Cloud provides cloud-security posture and workload-protection capabilities. At AZ-900 depth, candidates need the purpose: security recommendations, posture visibility and protection across supported environments. They do not need to configure every plan or alert.

Microsoft Purview is a broad data governance/compliance family. On AZ-900, the important point is that Purview helps organizations understand, govern and protect data/compliance contexts; Azure Policy governs resource configuration, while Purview addresses data/governance concerns at a different layer.

Azure Arc is a hybrid/multicloud management concept. It can extend Azure management and governance experiences to supported servers, Kubernetes or other resources outside native Azure. This is why “must manage on-premises without migrating it” is a strong Arc clue.

Application Insights, Log Analytics and alerts sit inside Azure Monitor but answer different operational needs. Application Insights emphasizes application telemetry, Log Analytics supports querying collected log data, and alerts notify based on conditions. Understanding the hierarchy is more useful than memorizing separate product logos.

For final scope control, treat the official skills at a glance as the priority map: 25–30% cloud concepts, 35–40% architecture/services, and 30–35% management/governance. That balance means a candidate who only memorizes core services but neglects cost, Policy, Arc or Monitor is not aligned with the current exam.

A Application Insights example helps show how application-level telemetry fits inside the broader monitoring stack. Within the wider Microsoft certification path, AZ-900 remains a fundamentals exam: explain what these services and concepts are for, and leave deep implementation to role-based certifications.