AZ-900 Azure Security and Network Security Features: What You Need to Know

Here’s a version that says the same thing, but in a more natural, easygoing way: Azure security gets confusing fast. Why? Because the services sound alike, yet solve very different problems. Very different. And the AZ-900 exam—what does it really want from you? Mainly this: can you identify what a service does, why it exists, and how it fits into Microsoft’s broader cloud security model. That’s the game. So the easiest way to stay organized is to group services by purpose. Identity, authorization, governance, network protection, private connectivity, monitoring, data protection... all of it. Keep that mental map handy, or the whole thing starts to blur. This guide stays exam-focused, yes—but without getting sloppy or vague. Azure security isn’t a single lock on a single door. It’s layered. Stacked. Built that way on purpose. And you don’t rely on one product either—bad idea, honestly. In practice, you’re usually looking at a mix of controls—MFA, Conditional Access, least-privilege RBAC, segmentation, private endpoints, logging, and regular posture checks. It’s the whole stack, really. Not one thing. A system of things. That difference matters, and exam writers love asking about it. Spin up a VM in Azure and—surprise—you still carry a lot of the security responsibility. A hefty chunk of it, really. So no, the cloud doesn’t magically remove your chores. A clean mental model helps here. Otherwise everything runs together. Authentication is more than just username and password. Much more. And here’s a subtle one—small on the surface, big in practice: Entra roles are not the same as Azure RBAC roles. Not interchangeable. Not close enough. Different jobs entirely. Also, some Azure services split permissions into two layers: control plane and data plane. Easy to miss. Important to remember. Azure Policy is governance. The rulebook, basically. It governs configuration. Locks are there to stop accidental changes or deletions, which is actually really useful when people are moving fast. One defines shape; the other prevents clumsy interference. Different tools. Different purposes. Microsoft Sentinel is Microsoft’s cloud-native SIEM and SOAR platform—where logs get pulled together, correlated, and turned into something you can actually investigate. And yes, security operations depend on logs. No logs, no ops. Harsh, but true. The key idea behind DDoS protection is straightforward: it keeps public services available during volumetric attacks. That’s the exam-friendly version, anyway. Public services getting hammered... still standing. ExpressRoute, meanwhile, gives you private connectivity to Microsoft cloud services through a connectivity provider or partner. In other words, not over the public internet. A common Azure design is hub-and-spoke. Still very common. For good reason too. It’s defense in depth in practice—not just a phrase, but a working design. Even for AZ-900, a few troubleshooting habits help you choose the right service. What should you look for? The function. Always the function. If you want to pass AZ-900 security questions, the best move is simple: don’t memorize services in isolation. Sort them by what problem they solve. That’s the real shortcut. If you’d like, I can make it even more conversational or tighten it up into a polished article version without changing the meaning.