Career upgrade: Learn practical AI skills for better jobs and higher pay.
Level up
Cheat sheet

Azure AZ-900 Cheat Sheet

Quick Facts

Exam
AZ-900
Credential
Azure Fundamentals
Time
45 min
Pass
700/1000
Level
Foundational
Skill
Match service
Blueprint
Jan 14 2026

Responsibility

IaaS > PaaS > SaaS

IaaS: most yoursPaaS: app/dataSaaS: config/users

Scale vs Elasticity

Scalability

  • Add capacity
  • Up/out
  • Planned growth

Elasticity

  • Autoscale
  • Demand spikes
  • Dynamic capacity

Can grow vs auto-grow

Cloud Benefits

HA
UptimeSLA
Scalability
Add capacity
Elasticity
Autoscale demand
Reliability
Recover failures
Predictability
Forecast cost/perf
Governance
Rules at scale
Manageability
Tools + automation

Cloud Models

Public
Shared provider cloud
Private
Dedicated organization cloud
Hybrid
Public + private
Multicloud
Multiple providers
CapEx
Upfront spend
OpEx
Pay as used

Service Models

IaaS
You manage OS
PaaS
You deploy app
SaaS
You configure users
Serverless
Code + triggers
VM
Classic IaaS
App Service
Classic PaaS

Storage Redundancy

LRS=Local | ZRS=Zone | GRS=Geo

LRS: datacenterZRS: zonesGRS: paired regionGZRS: zone+geo

Entra ID vs RBAC

Entra ID

  • Authenticate
  • Users/groups
  • SSO/MFA

RBAC

  • Authorize
  • Azure resources
  • Role assignments

Sign in vs do

Service Picker

  1. Need OS controlVM(IaaS)
  2. Managed web/APIApp Service(PaaS)
  3. Event triggerFunctions(Serverless)
  4. Quick containerACI(No orchestration)
  5. Many containersAKS(Kubernetes)
  6. Cloud desktopsAVD(VDI)
  7. Unstructured filesBlob(Object store)
  8. Private networkVNet(Isolation)

Azure Hierarchy

MG
Subscription governance
Subscription
Billing + access
Resource group
Lifecycle bundle
Resource
Service instance
Region
Geography location
Zone
Datacenter isolation

Access Tiers

Hot -> Cool -> Cold -> Archive

Hot: frequentCool: monthlyCold: rareArchive: offline

VPN vs ExpressRoute

VPN

  • Encrypted internet
  • Site-to-site
  • Lower cost

ExpressRoute

  • Private circuit
  • Provider link
  • Predictable latency

Internet vs private

Compute

VM
OS control
VMSS
Identical VM scale
Availability set
Rack/update spread
Availability zone
Datacenter spread
AVD
Cloud desktops
Functions
Event code
ACI
Quick container
AKS
Kubernetes orchestration

Networking

VNet
Private network
Subnet
VNet segment
Peering
VNet to VNet
DNS
Name resolution
VPN Gateway
Encrypted internet
ExpressRoute
Private circuit
Public endpoint
Internet reachable
Private endpoint
Private Link IP

Storage

Blob
Objects/files/media
Files
SMB/NFS shares
Queues
Simple messages
Tables
Key-value NoSQL
Managed disks
VM block storage
AzCopy
CLI transfer
Storage Explorer
Desktop GUI
Data Box
Offline transfer

Identity + Security

Entra ID
Cloud identity
SSO
One login
MFA
Extra factor
Passwordless
No password
Conditional Access
Risk-based rules
RBAC
Resource authorization
Zero Trust
Verify explicitly
Defender
Security posture

Governance Stack

MG -> Sub -> RG -> Resource

MG: hierarchySub: billingRG: lifecycleResource: instance

Policy vs Lock

Policy

  • Allow/deny
  • Audit rules
  • Required tags

Lock

  • No delete
  • No modify
  • Override mistakes

Standard vs protection

Cost Picker

  1. Estimate AzurePricing Calc
  2. Compare on-premTCO Calc
  3. Track spendCost Mgmt
  4. Group chargesTags
  5. Alert spendBudgets
  6. Optimize resourcesAdvisor

Cost + Governance

Pricing Calc
Future Azure cost
TCO Calc
On-prem comparison
Cost Mgmt
Actual spend
Budgets
Spend alerts
Tags
Cost metadata
Policy
Enforce rules
Locks
Prevent changes
Purview
Data governance

Service Health vs Monitor

Service Health

  • Azure incidents
  • Region issues
  • Maintenance

Azure Monitor

  • Your metrics
  • Logs/alerts
  • Telemetry

Provider vs workload

Monitoring Picker

  1. Azure outageService Health
  2. Resource metricsAzure Monitor
  3. Query logsLog Analytics
  4. App telemetryApp Insights
  5. RecommendationsAdvisor

Operate

Portal
Browser UI
Cloud Shell
Browser shell
CLI
az commands
PowerShell
Az cmdlets
ARM
Control plane
ARM template
JSON IaC
Azure Arc
Hybrid manage
Advisor
Best practices

Pricing vs TCO

Pricing

  • Azure estimate
  • Service choices
  • Future spend

TCO

  • Migration case
  • On-prem baseline
  • Savings view

Azure cost vs migration

Common Traps

Identity vs permission

Entra signs in RBAC grants actions

Rules vs locks

Policy enforces Locks prevent changes

Estimate vs track

Calculators estimate Cost Mgmt tracks

Outage vs telemetry

Health is Azure Monitor is yours

Tier vs redundancy

Tier is access Redundancy is copies

Private vs encrypted

ExpressRoute private VPN encrypted internet

Last Minute

  1. 1.Weights: 25-30 / 35-40 / 30-35
  2. 2.IaaS = OS control
  3. 3.PaaS = deploy app
  4. 4.SaaS = configure users
  5. 5.Entra = login; RBAC = permissions
  6. 6.Policy = rules; Locks = protection
  7. 7.Pricing = estimate; Cost Mgmt = actuals
  8. 8.Monitor = workloads; Health = Azure
  9. 9.VPN = internet; ExpressRoute = private
  10. 10.Tiers = access; redundancy = copies
Same family resources

Explore More Microsoft Azure Certifications

Continue into nearby exams from the same family. Each card keeps practice questions, study guides, flashcards, videos, and articles in one place.