Microsoft AZ-900: Skills Candidates Struggle With
AZ-900 is a fundamentals exam, but candidates often struggle because Azure terminology appears at several layers at once. A resource can live in a resource group inside a subscription governed by management groups, while identity is controlled through Microsoft Entra ID and permissions through RBAC. The services are not individually difficult; the challenge is knowing how the layers relate.
The current AZ-900 exam uses the skills measured as of July 20, 2026. Microsoft weights Cloud Concepts at 25–30 percent, Azure Architecture and Services at 35–40 percent, and Azure Management and Governance at 30–35 percent.
The best way to fix weak areas is to build one Azure mental map. Put cloud models and shared responsibility at the top, Regions and the resource hierarchy underneath, service families in the middle, and identity, governance, monitoring, and cost around the outside.
Candidates often memorize the phrase “shared responsibility” without applying it. With an Azure virtual machine, Microsoft manages physical infrastructure and the hypervisor, while the customer still manages the guest operating system, applications, identities, data, and many configuration responsibilities.
With managed platform services, Microsoft operates more of the underlying stack. With SaaS, the provider operates even more, while the customer still remains responsible for areas such as identities, data classification, and appropriate use.
The Azure Fundamentals certification is designed to establish this operating model before candidates move into administrator-level configuration.
An Azure Region is a geographic deployment area. Availability zones provide physically separate infrastructure within supported regions. Some Azure services are regional while others operate at broader scopes.
Do not treat “multi-zone” and “multi-region” as synonyms. Zones protect against a narrower location failure inside a Region. Multiple Regions address a larger geographic failure at greater architectural complexity.
The existing AZ-900 fundamentals material becomes more useful when candidates draw these failure boundaries rather than memorize definitions.
Azure resources belong to resource groups, which belong to subscriptions, which can be organized under management groups. Policies and permissions can be assigned at different scopes and inherited downward.
Draw one management group with two subscriptions and several resource groups. Apply an imaginary policy at the management group and an RBAC assignment at one resource group. Ask which resources each configuration affects.
Candidates who continue to AZ-104 will implement these controls directly, but AZ-900 should establish the hierarchy first.
RBAC controls who can perform actions. Azure Policy evaluates or enforces resource configuration. Resource locks protect against certain management changes or deletion. Tags attach metadata that can support organization, automation, or cost analysis.
The Azure Policy and RBAC distinction is especially important because both can affect the same resource while solving different questions.
When a scenario asks “who may change this?” think RBAC. When it asks “which configurations are allowed?” think Policy. When it asks “prevent accidental deletion,” think lock.
Virtual machines give customers significant operating-system control. App Service provides a managed application platform. Functions provide event-driven serverless compute. Containers package applications consistently, while services such as AKS support orchestration at a more advanced level.
AZ-900 does not require administrator depth. It requires recognition of why one model reduces management responsibility or supports a particular deployment style.
Start from the workload need: full OS control, managed web application hosting, event-driven code, or containerized workload. The service family follows the operating model.
Blob storage is designed for object data, Azure Files provides managed file shares, managed disks provide block storage for virtual machines, and other storage services solve queue or table-oriented needs.
Redundancy choices also matter. Local, zone, and geo-oriented replication patterns protect against different failure scopes and have different cost or access implications.
The exam expects high-level matching rather than memorization of every account setting. Think about object, file, block, durability, access, and geographic resilience.
Microsoft Entra ID provides identity and authentication for users, groups, applications, and other principals. Azure RBAC governs access to Azure resources. Security services and network controls protect workloads at other layers.
The SC-900 exam is an adjacent fundamentals path for candidates who want more depth in security, compliance, and identity after AZ-900.
Keep authentication and authorization separate in your notes. A user can sign in successfully and still lack permission to change a resource.
Azure pricing depends on service type, region, usage, duration, storage, data transfer, performance tier, and other resource-specific factors. AZ-900 does not expect a memorized price catalog.
Know the purpose of the Pricing Calculator, Cost Management, budgets, tags, and advisor-style recommendations. Create examples where shutting down development compute, choosing a different storage tier, or reserving predictable capacity changes the cost model.
The AZ-900 study material is strongest when cost concepts are tied to actual resource behavior.
Azure Monitor provides metrics, logs, and monitoring capabilities. Service Health provides information about Azure service issues relevant to the environment. Azure Advisor provides recommendations across areas such as reliability, security, performance, operational excellence, and cost.
Match the tool to the question. “Why is my application slow?” is a monitoring question. “Is Microsoft experiencing a service problem?” is a health question. “What improvements does Azure recommend?” points toward Advisor.
The wider Microsoft certifications let candidates specialize after fundamentals, but AZ-900’s purpose is to make these categories clear before implementation depth.
For final practice, take a fictional company and place its identities, subscriptions, VNets, compute, storage, policies, monitoring, and cost controls onto one architecture sketch. Then explain which part Microsoft operates and which part the customer operates.
The AI-901 exam is another adjacent fundamentals route for candidates moving into Azure AI, but do not let AI topics dilute the AZ-900 objective: broad cloud and Azure literacy.
If you can identify the layer, scope, responsibility, and service family for each scenario, the exam stops feeling like hundreds of unrelated Azure terms and starts looking like one coherent cloud platform.
Networking fundamentals can also be confusing because VNet, subnet, peering, VPN Gateway, ExpressRoute, Load Balancer, Application Gateway, DNS, and public or private endpoints all appear in the architecture domain. At AZ-900 level, learn the primary purpose of each family. Deep routing configuration belongs later; fundamentals means recognizing whether the requirement is isolation, hybrid connectivity, name resolution, traffic distribution, or private access.
Cloud service models should be applied to familiar applications. Take a business web application and imagine hosting it on virtual machines, App Service, containers, and serverless functions. Compare which operating responsibilities remain with the customer. This makes IaaS, PaaS, serverless, and managed services concrete instead of leaving them as acronym definitions.
Governance questions become easier when scope is included in the sentence. “Deny creation of public IP resources across every subscription in the organization” points toward a higher-scope policy. “Let one team restart VMs in this resource group” is an RBAC question at a narrower scope. Scope and control type should be solved together.
Cost questions should also distinguish estimation from monitoring. The Pricing Calculator helps estimate before deployment. Cost Management and budgets help observe and govern real spending. Advisor can recommend improvements. Tags can support allocation. Choosing the right tool depends on whether the question is planning, tracking, alerting, or optimization.
During the final week, explain each Azure term without using the product name in the definition. “A control that decides who may perform resource actions” should lead to RBAC. “A service for metrics and logs” should lead to Azure Monitor. If you can identify the function first and the product second, distractors become much easier to reject.
Support and service-lifecycle concepts can also appear at fundamentals level. Know that Azure products can move through preview, general availability, retirement, or deprecation, and that organizations need to plan for service changes. You do not need to memorize every product lifecycle date, but you should understand why production teams prefer supported services and monitor Azure communications.
Azure Marketplace and subscriptions are worth placing on the mental map as well. Marketplace provides third-party and Microsoft solutions that can be deployed into Azure, while the subscription remains a billing and management boundary. This helps candidates understand why “an Azure resource” does not always mean the service was built by Microsoft.
Use a final mixed quiz where no two consecutive questions come from the same domain. Fundamentals readiness is the ability to switch from cloud model to storage to governance to identity to cost without losing the hierarchy. That flexibility is more valuable than memorizing one domain perfectly.
Keep the last review broad. AZ-900 is designed to confirm that the cloud platform makes sense as a whole, so balanced understanding across architecture, services, security, governance, cost, and operations matters more than deep configuration in any one product.
That broad map is the real AZ-900 skill.