Azure offers many service names, but foundational architecture becomes manageable when each service is connected to a problem. A business needs somewhere to run an application, a route for its traffic, storage for its files and a way to organize the resources. Microsoft AZ-900 covers these building blocks so candidates can distinguish compute, networking and storage options without needing to configure every advanced feature. The task is to recognize which category of service answers a given need and where its limitations begin.
Imagine an online retailer building a replacement storefront. The shopping application must serve web requests, hold product images, connect to an inventory database and remain available during a regional promotion. The retailer also has internal finance systems that may stay on-premises. The cloud design will involve several service families and architectural containers. Choosing one product name before describing requirements is the wrong starting point.
Resource hierarchy: where a service belongs
A resource is an individual managed Azure item, such as a virtual machine, storage account or virtual network. Related resources can be organized in resource groups for lifecycle and administrative purposes. A subscription provides a billing and access management boundary and contains resource groups. Management groups can organize multiple subscriptions so broad governance can be applied across a larger estate. These levels form an administrative hierarchy; a management group is not a substitute for a network or a storage account.
The retailer might use separate subscriptions for production and nonproduction to improve accountability, with resource groups representing application components or lifecycle groups. Different legitimate organizations choose different structures, but naming and scope must be deliberate. Moving a resource group or deleting it can have significant consequences for the resources inside. In an exam scenario, identify whether a requirement concerns billing, policy scope or collective resource management before selecting the hierarchical level.
Azure Resource Manager underlies deployments and provides an approach to expressing infrastructure configuration, including templates and tools such as Bicep. AZ-900 candidates need the architectural concept rather than advanced scripting. A repeatable deployment reduces manual inconsistencies, but it also repeats errors when a template is wrong. Governance and review matter when one declaration can create or alter many resources. The hands-on scope of Microsoft AZ-104 goes much deeper into these operational choices.
Regions and zones serve different failure and location needs
Azure regions are deployment locations within defined geographies. Organizations choose regions based on service availability, latency, data residency, cost and recovery requirements. Availability zones, where provided, are separate datacenter locations within a region designed to reduce correlated failures. Selecting a region alone does not necessarily distribute an application’s resources across zones. Likewise, geographic separation may help disaster recovery, but requires an explicit service and data protection strategy.
If the storefront must remain online during a localized datacenter incident, a zone-aware deployment can help. If it must survive a broader regional event, the design may need replicated services and a failover plan across regions. Neither strategy makes broken application code harmless. Think in terms of failure domains: one process, one host, one zone, one region or an external dependency. The correct building block depends on the failure that the business wants to tolerate.
Sovereign or specialized cloud environments may be relevant for particular compliance or national requirements and are not interchangeable with standard region selection. Even within ordinary regions, a service or feature may not be available in every location. Cloud architecture starts with verifying the actual service capability and organizational requirements rather than copying a diagram from another geography.
Match compute services to operational control
Virtual machines offer operating-system control and can host software that expects a traditional server. The price of that control is responsibility for the guest OS, patching, security configuration and application operations. Virtual Machine Scale Sets can manage groups of similar compute instances for suitable scalable workloads, while availability sets and zone configurations address particular placement and resilience needs. The deployment choice should follow the application architecture rather than the assumption that every workload needs a VM.
App Service and related managed hosting platforms can run web applications while removing much of the underlying server-management burden. Container-based options package application components and dependencies but still require decisions about orchestration, security and state. Azure Functions can execute event-driven code under supported triggers and hosting plans. ‘Serverless’ describes the management abstraction, not the absence of infrastructure. A retailer with short event-driven image-processing jobs might benefit from functions, while an older enterprise application requiring specific OS components may need virtual machines during migration.
Azure Virtual Desktop serves a different use case: delivering desktop and application experiences to users. It is not simply a faster way to host a public web storefront. In a service-selection question, identify whether the workload is application hosting, user desktops, container orchestration or event processing. The broader design perspective of Microsoft AZ-305 adds detailed tradeoffs; AZ-900 should establish the vocabulary and basic suitability first.
Virtual networks provide structure, not magic isolation
An Azure virtual network establishes a logical network boundary with address spaces and subnets. Subnets organize connected resources and help scope certain network controls, while virtual network peering can connect networks through supported Azure networking mechanisms. Routing, security rules and name resolution determine what actually communicates. The existence of a subnet does not by itself authorize or deny access to all traffic. A virtual network also does not automatically connect a corporate office to Azure.
VPN Gateway enables encrypted connectivity over supported public-network routes, while ExpressRoute provides private connectivity options through supported providers and connectivity models. They serve different operational and network requirements. For the retailer’s finance system, the choice may depend on bandwidth, resilience, compliance, provider availability and budget. Neither link should be treated as a replacement for application authentication or end-to-end authorization. Microsoft AZ-700 explores the networking design in more depth.
Private and public endpoints also solve different reachability problems. A publicly reachable service may still enforce strong authentication, while a private endpoint can make supported service access possible through private addressing within a network architecture. Private connectivity reduces some exposure but does not eliminate the need to manage identity, DNS and access policies. When an exam asks which service allows a particular connection, first determine where the clients are, where the target is, and whether traffic must remain on a private path.
Storage services differ by access pattern and durability
Blob Storage is commonly associated with unstructured object data, such as product images and backup artifacts. Azure Files provides managed file shares accessible through supported file protocols. Queue Storage addresses simple messaging needs; Table Storage provides a different kind of nonrelational data store. Managed disks serve VM-related storage requirements. These offerings are not merely different prices for the same storage shape. Application access pattern, consistency needs, protocol expectations and operational control determine the category.
Storage tiers such as hot, cool and archive suit different retrieval frequency and access requirements in applicable services. The cheapest per-gigabyte tier may involve retrieval charges, minimum retention or latency that makes it wrong for storefront images requested every second. Data redundancy options affect resilience and cost; choose them with the failure domain in mind. Local redundancy protects against certain hardware failures within a region, while geographically redundant options introduce broader replication behavior subject to service configuration. Know that redundancy and backup are not synonyms: replicated accidental deletion can remain an accidental deletion.
Moving data also has its own tools. AzCopy and Storage Explorer support particular transfer workflows, while Azure File Sync, Azure Migrate and Data Box address different migration or synchronization situations. A retailer moving many terabytes from a constrained office connection may consider an offline transfer service; synchronizing ongoing file changes is a different problem. Exam answers improve when you notice whether the requirement is one-time migration, continuous sync or day-to-day object operations.
Combine services into a coherent and manageable system
Return to the retailer. The storefront can use managed web hosting, store product images as objects, connect to a suitable data platform and place components within an organized subscription and resource-group model. Network controls and identity permissions then govern access. Regional and zone decisions should reflect continuity requirements, and monitoring should reveal actual reliability. There is no universal ‘best Azure architecture’ independent of these constraints.
Costs emerge from the combination: allocated compute, storage capacity, operations, network egress, premium connectivity and support. Reusing a service you already understand can reduce operational risk, but choosing a virtual machine for every small task can create unnecessary maintenance. Conversely, migrating a tightly coupled legacy app to many managed services in one step can increase complexity. Cloud adoption involves tradeoffs that should be visible in the design.
AZ-900 questions often distinguish broad classes. If the requirement is ‘run code in response to an event,’ think about functions. If it is ‘access the same file share from multiple clients,’ examine file services. If it is ‘connect an on-premises network to Azure,’ focus on gateway or private-connectivity options. If it is ‘apply common governance to many subscriptions,’ think management groups. Understanding the nouns and responsibilities lets candidates eliminate plausible but mismatched answers without memorizing every portal screen.
A solid foundation is a mental map: hierarchy organizes resources, regions and zones place them, compute runs workloads, networking connects them and storage preserves data in service-specific forms. Once those relationships are clear, the long Azure catalog becomes an understandable set of choices rather than a list of names.