Microsoft AZ-900: A Practical Study Plan

AZ-900 is a fundamentals exam, but a good study plan should still include hands-on Azure experience. The objective is not to become an administrator before taking a beginner certification. It is to make cloud concepts concrete enough that service categories, security models, governance tools, and cost decisions stop feeling like abstract vocabulary.

The current AZ-900 exam uses the July 20, 2026 blueprint: Describe cloud concepts at 25–30 percent, Describe Azure architecture and services at 35–40 percent, and Describe Azure management and governance at 30–35 percent. Those weights suggest a simple plan: understand cloud first, spend the most time on how Azure is structured and what major services do, then learn how organizations govern, secure, monitor, and pay for them.

You can prepare without a large lab. A free or low-cost Azure environment, Microsoft Learn guided exercises, and a notebook of small architecture scenarios are enough if you focus on understanding why a service exists.

Days one and two should establish the cloud model

Start with public, private, and hybrid cloud; IaaS, PaaS, and SaaS; consumption-based pricing; shared responsibility; high availability; scalability; elasticity; agility; reliability; and predictability.

The Azure Fundamentals certification should create vocabulary you can reuse later. Do not memorize definitions without examples. Ask how patching responsibility changes between a virtual machine and a managed platform service, or how elasticity differs from simply buying a larger server.

Create a table with one business scenario for each cloud model and service model. The goal is to recognize the operating model behind the technology.

Add shared responsibility to every row. For an IaaS virtual machine, the customer remains responsible for the guest operating system, applications, identities, and data even though Microsoft operates the physical datacenter and host infrastructure. In a managed PaaS service, Microsoft manages more of the underlying stack. The exact boundary changes by service, which is why shared responsibility is better learned through examples than a single memorized sentence.

Learn Azure geography by drawing it

Regions, region pairs, availability zones, sovereign or specialized cloud considerations, and Azure’s global infrastructure make more sense when drawn. Start with a user, an Azure Region, multiple availability zones, and one globally distributed service.

Ask what problem each layer solves. A Region is a deployment location. Availability zones provide physically separate infrastructure inside supported regions. Global services can provide routing, identity, management, or content delivery that is not confined to one application subnet.

The Azure cloud fundamentals can reinforce the service map, but the current Microsoft study guide should control your exam scope.

Compute, networking, and storage should be studied as service families

For compute, compare virtual machines, containers, serverless functions, and managed application platforms at a fundamentals level. For networking, understand VNets, subnets, peering, VPN, ExpressRoute, load balancing, DNS, and public versus private connectivity. For storage, understand account types and the broad roles of blob, file, disk, queue, and table storage.

Do not attempt AZ-104 depth. You should know what the service is for, what kind of workload it supports, and which broader cloud characteristic it demonstrates.

Use one guided project to make the categories tangible. Create a resource group, deploy a small resource such as storage or a simple compute service, add a tag, view the resource in the portal, and then remove it when the exercise is complete. The point is not configuration mastery. It is seeing how subscription, resource group, resource, region, identity, and cost concepts appear in the same management experience.

Candidates who continue to AZ-104 will later configure these services in depth. AZ-900 should establish a reliable mental map of the choices.

Identity and security need more than the word “Entra”

Understand Microsoft Entra ID, authentication, authorization, role-based access control, multifactor authentication, Conditional Access at a conceptual level, Zero Trust, defense in depth, and the distinction between directory roles and Azure resource roles.

Practice one access scenario: a user signs in to Azure, then attempts to manage a resource. Authentication proves identity. Authorization determines whether the user can perform the action. RBAC assignments express resource permissions. Governance controls can further constrain what is allowed.

The SC-900 exam is a natural next fundamentals step for candidates who enjoy identity, security, compliance, and governance topics.

Governance should be studied through “who can do what where?”

Learn management groups, subscriptions, resource groups, resources, tags, Azure Policy, resource locks, RBAC, and the purpose of governance controls. Draw the hierarchy and place one policy or role assignment at each level.

The difference between Azure Policy and RBAC is especially important. RBAC controls who may perform actions. Policy evaluates or enforces what configurations are allowed. They can work together, but they solve different problems.

Add a resource lock to the mental model as another distinct control: it protects against certain management changes or deletion, not against unauthorized sign-in.

Then place management groups and subscriptions above the resource group in your diagram. Apply an imaginary policy at a higher scope and ask which lower resources would inherit it. Do the same with an RBAC assignment. This creates an intuitive understanding of scope and inheritance, which is more useful than memorizing the resource hierarchy as a static list.

Cost management should use small business scenarios

Study the pricing calculator, Cost Management, budgets, tags, reservations or savings concepts at a high level, service factors that affect cost, data transfer, and the difference between capital and operational expenditure.

The Azure pricing model becomes easier when you create examples: a VM that runs all month, storage that grows over time, data sent to users, and a development environment that can be shut down when not in use.

AZ-900 does not require you to memorize changing price lists. It expects you to understand which usage characteristics affect spending and which Azure tools help estimate, allocate, and monitor cost.

Monitoring and management tools should be matched to questions

Learn the purpose of Azure Monitor, Service Health, Advisor, the Azure portal, Cloud Shell, Azure CLI, PowerShell, ARM templates, and infrastructure-as-code concepts at a recognition level.

When you study a tool, write the question it answers. Is a service outage affecting my Region? Use service-health information. Is a resource performing badly? Use monitoring and metrics. Do I need recommendations on reliability, cost, security, or performance? Advisor is relevant.

This habit prevents the common fundamentals mistake of remembering product names without knowing why an administrator or architect would choose them.

AI-901 is adjacent, not required

Some candidates take Azure Fundamentals before moving into AI. The AI-901 exam focuses on AI and machine-learning concepts and Microsoft AI services, while AZ-900 remains focused on cloud concepts, Azure architecture, and governance.

The overlap is mostly platform literacy. Knowing Regions, identity, networking, governance, and cost makes later Azure AI study easier, but do not dilute AZ-900 preparation with deep model or agent topics.

Use the final days before the exam to strengthen the current blueprint, not to explore every interesting Azure service.

Use the final week for mixed scenarios

Create short prompts that mix domains: a company needs to reduce hardware ownership, deploy across zones, restrict who can manage resources, enforce required tags, estimate cost, and monitor service health. Identify the Azure concept or tool for each requirement.

The AWS Cloud Practitioner and AZ-900 can help candidates see which concepts are cloud-general and which are Azure-specific without turning the study plan into a multi-cloud detour.

A fundamentals exam is easiest when the mental model is coherent. If every service is a separate flashcard, you will forget them. If each service has a role in architecture, security, governance, or operations, the questions become easier to reason through.

Finish with a one-page map of Azure rather than a giant glossary. Put geography at the top, the resource hierarchy beside it, identity and governance across the management layer, major service families in the workload layer, and monitoring plus cost management around the outside. If you can point to any exam term and explain where it belongs in that map, the study plan has done its job.

You are ready when you can explain the shared responsibility model, identify the role of major Azure service families, describe the resource hierarchy, distinguish identity from governance controls, and choose the right tool for cost, health, or monitoring questions.

The wider Microsoft certifications provide many directions after fundamentals, including administration, security, data, AI, and architecture. AZ-900 does not lock you into one path.

Use hands-on exploration to make the concepts real, but keep the exam’s level in mind. The strongest candidate understands why Azure is organized the way it is and can recognize the right category of solution without needing administrator-level command depth.

Keep the lab inexpensive and clean. Delete resources after guided exercises, review the Cost Management view, and notice which objects remain after a resource is removed. This small habit reinforces governance, lifecycle, and cost awareness at the same time. AZ-900 is a fundamentals exam, but learning to create and clean up cloud resources responsibly is a useful professional habit from the first day.

That small cleanup habit also makes the shared-responsibility and cost-management ideas feel practical instead of theoretical.

img