{"id":26567,"date":"2026-10-06T09:40:33","date_gmt":"2026-10-06T09:40:33","guid":{"rendered":"https:\/\/www.examlabs.com\/certification\/?p=26567"},"modified":"2026-10-06T09:40:33","modified_gmt":"2026-10-06T09:40:33","slug":"microsoft-az-900-how-the-azure-fundamentals-skills-connect","status":"publish","type":"post","link":"https:\/\/www.examlabs.com\/certification\/microsoft-az-900-how-the-azure-fundamentals-skills-connect\/","title":{"rendered":"Microsoft AZ-900: How the Azure Fundamentals Skills Connect"},"content":{"rendered":"<p>The AZ-900 objectives form one cloud-adoption map rather than three unrelated sections. Cloud concepts explain why organizations use cloud and how responsibility changes. Azure architecture and services provide the building blocks. Management and governance explain how those resources are controlled, paid for, deployed and monitored. The current <a href=\"https:\/\/www.examlabs.com\/az-900-exam-dumps\">AZ-900<\/a> weights are 25\u201330%, 35\u201340% and 30\u201335% across those three layers.<\/p>\n<h3>Cloud value sits at the top of the map<\/h3>\n<p>Agility, elasticity, scalability, availability, reliability, predictability and manageability explain why cloud services can change how organizations deliver IT. Consumption-based pricing connects technical usage to financial outcomes.<\/p>\n<p>These benefits are not automatic. An organization still needs appropriate architecture, governance, identity, security and cost controls to realize them.<\/p>\n<h3>Shared responsibility connects service model with security<\/h3>\n<p>IaaS, PaaS and SaaS shift how much infrastructure Microsoft manages. Customers retain responsibility for their data, identities and configuration appropriate to the service, while Microsoft operates more of the underlying stack as abstraction increases.<\/p>\n<p>This concept should be drawn beside every service category because responsibility changes with the chosen model.<\/p>\n<h3>Azure geography supports resilience and regulatory choices<\/h3>\n<p>Regions, sovereign regions, region pairs, datacenters and availability zones describe where Azure services run. Availability zones provide isolated locations inside supported regions, while region choice can reflect latency, service availability, residency or business-continuity needs.<\/p>\n<p>The map should keep zone-level resilience separate from region-level geography.<\/p>\n<h3>Resource hierarchy supports organization and governance<\/h3>\n<p>Resources belong to resource groups; resource groups belong to subscriptions; subscriptions can be organized through management groups. Governance or access can often be applied at a higher scope and inherited downward.<\/p>\n<p>This hierarchy connects directly to Azure Policy, RBAC, cost organization and management.<\/p>\n<h3>Compute, networking and storage form the service core<\/h3>\n<p>Virtual machines, containers, functions and web apps provide different compute\/hosting models. Virtual networks, subnets, peering, DNS, VPN Gateway, ExpressRoute and endpoints provide connectivity. Azure Storage services provide object, file, disk and other data options.<\/p>\n<p>A <a href=\"https:\/\/www.examlabs.com\/certification\/exploring-the-core-concepts-of-microsoft-azure-a-comprehensive-guide-to-the-az-900-fundamentals\">fundamentals map<\/a> should begin with workload need and then choose the service category rather than memorizing product names in isolation.<\/p>\n<h3>Identity controls who can use the service core<\/h3>\n<p>Microsoft Entra ID, external identities, SSO, MFA, passwordless methods, Conditional Access and RBAC create identity and authorization boundaries around Azure resources.<\/p>\n<p>The map should separate authentication from authorization, and identity policy from resource governance.<\/p>\n<h3>Zero Trust and defense in depth shape protection<\/h3>\n<p>Zero Trust emphasizes explicit verification, least privilege and assuming breach. Defense in depth layers controls across identity, perimeter\/network, compute, application and data. Microsoft Defender for Cloud provides security-posture and protection capabilities in Azure.<\/p>\n<p>These concepts sit across the architecture rather than belonging to one resource group or subnet.<\/p>\n<h3>Cost and tags attach business context to resources<\/h3>\n<p>Pricing Calculator helps estimate, cost-management capabilities help analyze\/control spend, and tags can label resources by owner, environment, department or cost center. Cost is influenced by usage, service type, location, data transfer and commercial choices.<\/p>\n<p>A <a href=\"https:\/\/www.examlabs.com\/certification\/introduction-to-azure-cost-optimization\">cost-management<\/a> model belongs alongside architecture decisions because design and usage affect the bill.<\/p>\n<h3>Policy, locks and Purview establish governance<\/h3>\n<p>Azure Policy can audit or enforce resource standards; locks protect against accidental change\/deletion; Microsoft Purview addresses data governance and compliance capabilities. RBAC still answers a different question: who may perform an action.<\/p>\n<p>This distinction is useful in scenario questions where multiple governance tools sound plausible.<\/p>\n<h3>Management and monitoring close the feedback loop<\/h3>\n<p>Portal, Cloud Shell, CLI, PowerShell, Arc and ARM\/IaC provide management\/deployment surfaces. Azure Advisor recommends improvements, Service Health reports Azure service conditions and Azure Monitor\/Log Analytics\/Application Insights observe workloads.<\/p>\n<p>The map should show consumption economics beside scalability because capacity choices and billing are connected. A workload that scales out during a peak and back in afterward can align spend with demand; a workload that never releases resources may still incur high cloud cost. Cloud flexibility requires operational governance.<\/p>\n<p>Public, private and hybrid cloud should sit above service selection. Public cloud provides shared provider infrastructure, private cloud is dedicated to one organization, and hybrid combines environments. Hybrid is an architectural operating model, not simply \u201csome servers are old.\u201d<\/p>\n<p>IaaS, PaaS and SaaS should be drawn as a responsibility gradient. Moving from VM infrastructure to managed platforms or finished software reduces the layers customers operate, but data protection, identities, governance and correct configuration remain customer concerns.<\/p>\n<p>The architecture branch should include region pairs and sovereign regions because some scenario questions use regulatory or continuity wording rather than availability zones. Pairing supports certain platform resiliency patterns, while sovereign boundaries address special jurisdiction or government requirements.<\/p>\n<p>Resource groups should connect to lifecycle because deleting a resource group can remove contained resources, and group-level RBAC or Policy can apply to the group. This makes grouping an operational decision, not only cosmetic organization.<\/p>\n<p>Subscriptions should connect cost and governance. Separate subscriptions can provide billing, quota and administrative boundaries for departments, environments or business units. Management groups then let organizations organize subscriptions under common governance.<\/p>\n<p>Compute should also show control versus abstraction. VMs provide OS-level control, containers package applications with less overhead, functions provide event-driven serverless execution, and App Service-style web hosting removes more infrastructure operations. The map should place each at the appropriate management level.<\/p>\n<p>Virtual networking should show both Azure-to-Azure and Azure-to-on-premises paths. Peering connects VNets, VPN Gateway creates encrypted tunnels, ExpressRoute offers dedicated private connectivity, and Azure DNS provides name-resolution services. The key is matching the connectivity model to the stated requirement.<\/p>\n<p>Storage should include movement and migration branches. AzCopy is a command-line transfer tool, Storage Explorer is a graphical management tool, File Sync extends file-server scenarios, Azure Migrate supports workload migration and Data Box addresses large offline transfer. Similar goals can require different mechanisms.<\/p>\n<p>Identity should show a flow from user\/device to authentication and then authorization. Entra ID establishes identity, MFA\/passwordless strengthen authentication, Conditional Access evaluates conditions, and RBAC determines allowed Azure-resource actions. This order prevents \u201cMFA gives permissions\u201d confusion.<\/p>\n<p>External identities belong on the boundary between the organization and partners\/customers. Azure can allow collaboration without creating unmanaged permanent internal accounts for every external person. The concept is identity federation\/collaboration with governance, not anonymous access.<\/p>\n<p>Defender for Cloud should sit between security posture and workload protection. It can identify recommendations or risks across Azure and supported environments. It complements, rather than replaces, Entra identity controls and Azure Policy.<\/p>\n<p>Tags should connect resources to business metadata. A tag such as CostCenter or Environment can improve reporting and automation, but tags do not inherently prevent a user from changing a resource. Access and governance require RBAC, Policy or locks depending on the requirement.<\/p>\n<p>Azure Policy should connect to compliance at scale. Policies can evaluate resources and, depending on effect and design, deny, audit or remediate certain conditions. The conceptual point is desired standards across resource scopes.<\/p>\n<p>Resource locks should connect to operational protection. A delete lock can protect a critical resource from accidental removal even by users who otherwise have permissions. Locks are not a complete security control because they do not determine who can read data or authenticate.<\/p>\n<p>Azure Arc belongs on the management edge to show that Azure governance is not limited to Azure-hosted resources. Hybrid servers and Kubernetes can participate in supported Azure management experiences, which is why Arc appears in a fundamentals management objective.<\/p>\n<p>ARM\/Resource Manager belongs under deployment and control-plane operations. Templates describe desired infrastructure and Resource Manager processes deployments at defined scope. Portal, CLI, PowerShell and Cloud Shell are different interfaces into the management plane.<\/p>\n<p>Monitoring should show recommendation \u2192 service status \u2192 telemetry. Advisor recommends improvements, Service Health reports Azure service conditions relevant to the environment, and Azure Monitor observes metrics\/logs\/app telemetry. Choosing among them begins by asking what kind of evidence is needed.<\/p>\n<p>Azure Virtual Desktop should be placed on the end-user compute branch because it delivers centrally managed Windows desktops and applications rather than one ordinary server workload. This helps distinguish user-computing services from general VM hosting.<\/p>\n<p>Availability sets and VM Scale Sets belong on different parts of the compute map. Availability sets distribute VMs across fault\/update domains in supported designs, while Scale Sets manage groups of similar VMs and scaling. Availability zones are a separate physical-isolation concept.<\/p>\n<p>Storage tiers should be linked to access frequency and retrieval expectations. Hot data favors frequent access, while cooler\/archive tiers trade lower storage cost for different retrieval characteristics. Tier choice is an economics and usage decision, not a security classification.<\/p>\n<p>Storage redundancy should be connected to failure scope. Locally redundant copies remain within one datacenter boundary, zone-redundant designs span zones, and geo-redundant choices extend protection across regions according to the selected option. More resilience can mean higher cost and different recovery behavior.<\/p>\n<p>Microsoft Entra Domain Services should sit beside Entra ID but not be treated as the same product. Domain Services provides managed domain capabilities for workloads that need traditional domain features, while Entra ID is the cloud identity platform used broadly across Microsoft cloud services.<\/p>\n<p>Conditional Access should connect identity to Zero Trust because access decisions can use signals and conditions rather than granting permanent trust solely after one successful login. It complements MFA, passwordless methods and device or risk context.<\/p>\n<p>Purview should be drawn on the data-governance branch rather than inside resource-policy enforcement. This helps prevent a common confusion: Azure Policy governs resource configurations, while Purview addresses data\/governance\/compliance capabilities.<\/p>\n<p>Advisor should connect cost, reliability, security, performance and operational recommendations conceptually. It does not continuously enforce those recommendations by itself. The organization still decides whether and how to act on them.<\/p>\n<p>The completed map is cloud need \u2192 service model\/responsibility \u2192 geography\/resource hierarchy \u2192 compute\/network\/storage \u2192 identity\/security \u2192 cost\/governance \u2192 deployment\/monitoring. That is the structure behind the current <a href=\"https:\/\/www.examlabs.com\/microsoft-certification-exams\">Microsoft Azure Fundamentals<\/a> exam.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>The AZ-900 objectives form one cloud-adoption map rather than three unrelated sections. Cloud concepts explain why organizations use cloud and how responsibility changes. Azure architecture and services provide the building blocks. Management and governance explain how those resources are controlled, paid for, deployed and monitored. The current AZ-900 weights are 25\u201330%, 35\u201340% and 30\u201335% across [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[1648,1647],"tags":[],"_links":{"self":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/26567"}],"collection":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/comments?post=26567"}],"version-history":[{"count":1,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/26567\/revisions"}],"predecessor-version":[{"id":26568,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/26567\/revisions\/26568"}],"wp:attachment":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/media?parent=26567"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/categories?post=26567"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/tags?post=26567"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}