AZ-900 preparation is most efficient when cloud principles come before product names. Start with shared responsibility and service models, then Azure geography/resource hierarchy, compute/network/storage, identity/security, cost/governance, deployment tools and monitoring. This order mirrors the dependencies inside the current AZ-900 outline and keeps the largest Azure architecture/services domain central.
Phase one: learn cloud models and business benefits
Study public, private and hybrid cloud, consumption pricing, serverless, high availability, scalability, reliability, predictability, security, governance and manageability. Use simple business examples rather than memorized definitions.
Then compare IaaS, PaaS and SaaS by responsibility and use case.
Phase two: build the Azure geographic model
Learn regions, sovereign regions, region pairs, datacenters and availability zones. Draw one region with several zones and explain what each boundary means.
Do not jump into availability architecture beyond fundamentals; focus on purpose and terminology.
Phase three: master resource hierarchy
Create a simple diagram of management groups, subscriptions, resource groups and resources. Add ownership/cost/governance examples at each scope.
This hierarchy becomes the anchor for RBAC, Policy, cost management and administration.
Phase four: group Azure services by workload
Compare VMs, containers, functions, web apps and Azure Virtual Desktop. Then learn VNet/subnet/peering/DNS/VPN Gateway/ExpressRoute/public/private endpoints and the major Azure Storage patterns.
A core Azure concepts review should emphasize service purpose, not configuration syntax.
Phase five: learn data movement and migration choices
Review AzCopy, Storage Explorer and File Sync for file movement, plus Azure Migrate and Data Box for migration scenarios. Ask whether the requirement is online transfer, synchronization, assessment/migration or large offline data movement.
The simplest use-case clue usually identifies the correct tool.
Phase six: build identity and security vocabulary
Study Entra ID, Domain Services, SSO, MFA, passwordless authentication, external identities, Conditional Access and RBAC. Then add Zero Trust, defense in depth and Defender for Cloud.
A Zero Trust review helps when you remember it as an architecture principle rather than one product.
Phase seven: learn cost and governance together
Review factors affecting cost, Pricing Calculator, cost-management capabilities and tags. Then compare Azure Policy, resource locks and Microsoft Purview.
Build contrast pairs: tag vs Policy, RBAC vs Policy, Policy vs lock, estimate vs monitor actual cost.
Phase eight: learn management surfaces and IaC
Know the purpose of portal, Cloud Shell, CLI, PowerShell, Arc, Resource Manager and ARM templates. Create one small ARM/IaC example or at least read a simple template.
An ARM template exercise is sufficient when you can explain declarative deployment and resource consistency.
Phase nine: finish with monitoring distinctions
Compare Advisor, Service Health and Azure Monitor. Inside Azure Monitor, learn Log Analytics, alerts and Application Insights.
A monitoring model should answer whether the scenario wants recommendations, Azure service-impact information, platform/log telemetry or application observability.
Use the final week for scenario classification
The exam gives 45 minutes, so practice reading the requirement and classifying it quickly: cloud benefit, service model, architecture/service, identity/security, cost/governance, deployment/management or monitoring. Then choose the simplest matching Azure concept.
Keep one reference company through the entire study plan: for example, a small business moving a website and internal application to Azure. Use the same company to ask about cloud model, service type, region, networking, storage, identity, cost, governance and monitoring. Reuse makes the domains connect naturally.
During cloud-benefit study, create contrast pairs for high availability versus scalability, reliability versus predictability, manageability versus governance, and CapEx-style procurement versus consumption pricing. These distinctions prevent vague “cloud is better” answers.
During service-model study, take one business application and describe it as IaaS, PaaS and SaaS. Note which layers the customer manages under each approach. This is the fastest way to internalize shared responsibility.
During geography study, draw a region, two zones, another region and an edge location conceptually. Label what fails together and what business concern each boundary addresses. Avoid adding complex networking until the location model is clear.
During hierarchy study, create a fictional enterprise with two management groups, several subscriptions and resource groups. Apply one policy or RBAC idea at each scope. This makes inheritance and organizational scale easier to understand without needing a large Azure tenant.
During compute study, build a four-column comparison for VM, container, function and web app: control, management burden, scaling model and example workload. The current exam includes all four concepts and can test which is most appropriate for a basic scenario.
During networking study, write one sentence each for VNet, subnet, peering, Azure DNS, VPN Gateway, ExpressRoute, public endpoint and private endpoint. Then create business prompts and identify the matching term without looking at the list.
During storage study, compare Blob/object, Files, managed disks and queue/table-style storage conceptually. Add hot/cool/archive-style access tiers and redundancy choices. The exam is not asking for storage-account engineering, but it expects you to know what kind of data/service need each option addresses.
During migration study, create a decision ladder: online file copy/sync, migration assessment/tooling, or offline appliance transfer. This keeps AzCopy, Storage Explorer, File Sync, Azure Migrate and Data Box from becoming an undifferentiated list.
During identity study, practice scenario wording: “prove who I am” → authentication, “what may I do” → authorization/RBAC, “require MFA under conditions” → Conditional Access, “partner user” → external identities, “managed directory-compatible domain services” → Entra Domain Services.
During security principles, explain Zero Trust and defense in depth to a nontechnical stakeholder. If you can describe explicit verification/least privilege/assume breach and layered controls without product names, you understand the concept at AZ-900 depth.
During cost study, estimate one small environment with Pricing Calculator and list the factors that could change the estimate: region, size, runtime, data transfer, storage tier and licensing. Then explain how Cost Management differs once resources are running.
During governance study, compare tags, Policy, locks and Purview with one requirement each. “Label owner” → tag; “enforce allowed location” → Policy; “prevent accidental deletion” → lock; “understand/govern data” → Purview. Contrast-based study is highly efficient.
During management-tool study, open portal and Cloud Shell if available, then identify how CLI and PowerShell could perform management tasks. The exam does not require syntax, but real exposure makes the tools easier to recognize.
During Arc study, take one on-premises server scenario and ask whether the goal is migrate or manage. If it must stay outside Azure but participate in Azure management/governance, Arc is the conceptual clue.
During monitoring study, create one incident for each tool: Advisor recommends rightsizing, Service Health reports an Azure service degradation, Azure Monitor alerts on a resource metric and Application Insights reveals a slow request path. This makes the distinctions durable.
Practice 45-minute exam pacing with short mixed sets rather than one-domain blocks. The real exam can move quickly between cloud economics, Entra, storage and monitoring. Fast classification matters more than performing configuration steps.
In the final 48 hours, use the official Microsoft change log to confirm current terminology and do not add deep administrator subjects such as complex routing, Kubernetes operations or advanced Entra configuration. Staying at the right depth is part of effective fundamentals preparation.
Add one service-model exercise where you explain the same application as a VM, a managed web platform and a SaaS product. For each, identify who manages the OS, middleware, application and data. This converts shared responsibility from theory into a comparison you can recall quickly.
Add one resource-hierarchy exercise using a fictional enterprise with development and production subscriptions under separate management groups. Decide where a Policy or RBAC assignment should live if it must apply broadly. The exercise makes governance inheritance intuitive.
Add one storage-redundancy review after storage services. Match locally, zone and geo-redundant concepts to failure scenarios and cost trade-offs. This prevents redundancy acronyms from becoming disconnected memorization.
Add one external-identity scenario where a partner needs temporary access. Compare external identities with creating a local employee account. Then explain where Conditional Access and RBAC would fit after the external identity exists.
Add one Purview-versus-Policy exercise. “Govern enterprise data” points toward Purview; “require approved regions or tags” points toward Policy. These tools can coexist, but they operate at different governance layers.
Add one Advisor-versus-Monitor comparison late in study. Advisor tells you how a resource could be improved; Monitor tells you what telemetry says is happening. Service Health adds the separate question of whether Azure itself is experiencing an issue.
Finish each week by explaining one Azure concept without using the product name. For example, describe “dedicated private connectivity from on-premises to Azure” and then name ExpressRoute. Definition-from-requirement practice is closer to exam wording than flashcards alone.
Add one week-ending review of the Azure management plane. Explain how portal, CLI, PowerShell, Cloud Shell, Resource Manager and ARM templates relate: different interfaces or declarative definitions ultimately manage resources through Azure’s control plane. This connection is more useful than memorizing each tool separately.
Add a final service-family cleanup session. Group every AZ-900 term you still confuse into compute, network, storage, identity/security, governance, management/deployment or monitoring. Then write one business verb next to each service. Category plus verb is a fast recall system for a 45-minute fundamentals exam.
During the final mock, avoid answering from brand familiarity alone. Read the requirement, identify the category and responsibility level, then choose the Azure concept that directly satisfies it. If an answer adds implementation complexity the question never requested, it is often weaker at AZ-900 depth.
The current Azure Fundamentals update should control final study wording. Within the Microsoft certification track, AZ-900 rewards clear foundational distinctions, not deep administrator procedures.