Core Solutions and Management Tools on Azure: An AZ-900 Guide for Beginners
Introduction: Why Core Solutions and Management Tools Matter in AZ-900
For AZ-900, one distinction matters more than most: core solutions are the Azure services that run workloads, while management tools are how you deploy, configure, monitor, govern, and optimize those workloads. If you keep that split clear, a lot of Azure starts to make sense.
Core solutions include compute, networking, storage, databases, analytics, AI, IoT, and serverless services. Management tools include Azure Portal, Azure CLI, Azure PowerShell, Azure Cloud Shell, Azure Resource Manager (ARM), ARM templates, and Bicep. Governance and operations tools sit alongside them: RBAC, Azure Policy, locks, tags, Azure Monitor, Service Health, Advisor, and Cost Management.
Exam cue: run workloads with services like VMs, App Service, Blob Storage, and Azure SQL Database. Manage and deploy them with Portal, CLI, PowerShell, ARM, and Bicep.
Azure Infrastructure Basics: Regions, Zones, and Resiliency
Azure is a global cloud platform built from geographies, regions, and in some cases availability zones. A region is a geographic area containing one or more datacenters connected by low-latency networking. When you choose a region, you’re choosing where most regional resources are deployed and where data residency requirements are often applied. One important nuance: not all Azure services or SKUs are available in every region.
Availability zones are separate physical locations within a region, each with independent power, cooling, and networking. Zone support varies by region and by service. Some services are deployed as zonal resources pinned to one zone, while others can be zone-redundant across zones.
Region pairs support platform resiliency and planned update sequencing, but they are not an automatic failover mechanism for every workload. They are useful in disaster recovery planning, but your actual recovery design still depends on service capabilities, architecture, and business requirements. Also, there are Azure-specific exceptions to the usual pairing model.
For VM resiliency, you may also see availability sets, which spread VMs across fault and update domains within a datacenter environment. For AZ-900, the key idea is simple: zones help with high availability inside a region, while cross-region design helps with disaster recovery.
Exam cue: not all regions support all services, not all regions are zone-enabled, and region pairs do not mean automatic failover for every service.
Core Solutions on Azure
Compute: Choosing the Right Hosting Model
Azure compute services differ mainly by how much control you want and how much infrastructure you want Microsoft to manage.
| Service | Best fit | Cloud model | Key trade-off |
|---|---|---|---|
| Azure Virtual Machines | Full OS control, legacy apps, lift-and-shift | IaaS | Most control, most admin effort |
| Azure App Service | Web apps and APIs with less infrastructure management | PaaS | Less control over underlying platform |
| Azure Kubernetes Service (AKS) | Containerized apps and microservices | Managed orchestration | Powerful but more complex |
| Azure Functions | Event-driven code and automation | Serverless | Great for triggers, not every workload |
Azure Virtual Machines give you on-demand servers in Azure. You choose the image, size, disks, and network settings, and you manage the guest OS, patching, and much of the security configuration. Common design choices include VM size, OS disk and data disk type, backup, and resiliency using availability sets, zones, or scale sets. If an app needs custom software, full admin access, or a straightforward migration from on-premises, VMs are often the answer.
Azure App Service is a managed platform for web apps and APIs. Microsoft handles much of the platform maintenance, while you focus on code and configuration. Key concepts worth recognizing are App Service plans, scaling, custom domains, SSL/TLS, authentication integration, deployment slots, and VNet integration. It is a common choice for web apps that need fast deployment with less operational overhead than VMs.
AKS is Azure’s managed Kubernetes service. Azure manages the Kubernetes control plane, while you manage worker nodes, pods, deployments, and application configuration. At a fundamentals level, remember nodes run containers, Kubernetes orchestrates them, and AKS is best when teams need container orchestration at scale. It can be too much for a simple app that would run perfectly well in App Service.
Azure Container Instances are also worth recognizing: they run containers without managing VMs or Kubernetes. For AZ-900, think of ACI as a simpler container option than AKS.
Azure Functions runs code in response to triggers such as HTTP requests, timers, queue messages, or blob uploads. Functions supports bindings to services like Storage and Service Bus, which reduces boilerplate integration code. On Consumption-based hosting plans, you typically pay for executions and execution time rather than idle server capacity; other plans such as Premium or Dedicated use different billing and performance models. This is ideal for event-driven processing, scheduled jobs, and lightweight automation.
Mini scenario: file uploaded to Blob Storage → Azure Function triggers → image is resized and metadata is written to a database. That is classic serverless design.
Networking and Connectivity
Azure Virtual Network (VNet) is the core private network boundary in Azure. Inside a VNet, you define address spaces and subnets. You can control traffic with Network Security Groups (NSGs), connect VNets with VNet peering, and use Azure DNS for name resolution. VNets are foundational for private communication, segmentation, and hybrid connectivity.
Azure Load Balancer is a Layer 4 load balancer for TCP/UDP traffic. It can be public or internal, uses health probes, and distributes traffic across backend instances. This is different from Azure Application Gateway, which is Layer 7 and HTTP/HTTPS-aware. At a recognition level, Azure Front Door is a global HTTP/HTTPS entry point for web applications.
VPN Gateway provides encrypted connectivity over the public internet. It supports site-to-site, point-to-site, and VNet-to-VNet connections. ExpressRoute is the private dedicated connectivity option that does not traverse the public internet in the same way. For exam questions, VPN Gateway = encrypted tunnel over the internet; ExpressRoute = private dedicated link.
| Service | Main use |
|---|---|
| Load Balancer | Layer 4 traffic distribution |
| Application Gateway | Layer 7 web traffic routing |
| VPN Gateway | Encrypted hybrid connectivity over internet |
| ExpressRoute | Private dedicated connectivity |
Storage Options in Azure
Azure Blob Storage is object storage for unstructured data such as backups, media, logs, and documents. It supports access tiers such as Hot, Cool, and Archive, plus lifecycle management for moving data between tiers. Redundancy options include LRS, ZRS, GRS, and GZRS, each balancing cost and resiliency differently.
Azure Files provides managed file shares accessible over SMB and other supported methods. Use it when applications need shared file storage rather than object storage.
Azure Disk Storage provides block storage for VM operating system and data disks. If the exam asks what storage type is used for a VM OS disk, think Disk Storage, not Blob or Files.
At a recognition level, Azure Storage also includes queue and table capabilities. For security, storage supports encryption and can be combined with private endpoints and access controls.
Database Services at a Glance
Azure SQL Database is a managed relational database service. Azure Database for PostgreSQL and Azure Database for MySQL provide managed open-source relational database options. Azure Cosmos DB is a globally distributed NoSQL database for low-latency, flexible data models.
The exam-level pattern is straightforward: relational workloads often fit Azure SQL Database or managed PostgreSQL/MySQL, while globally distributed NoSQL scenarios point toward Cosmos DB. Managed databases reduce work around patching, backups, and availability compared with running your own database VM.
AI, Analytics, IoT, and End-User Services
Azure also includes higher-level solution categories. Azure AI services help applications process language, speech, vision, and other intelligent workloads. Azure Machine Learning supports model development and operationalization. Azure Synapse Analytics and Azure Data Factory are common names in analytics and data integration. Azure IoT Hub supports device connectivity and telemetry ingestion. Azure Virtual Desktop is worth recognizing as a desktop virtualization service delivered from Azure.
For AZ-900, you do not need deep implementation detail here. You do need to recognize the service families and the business problems they solve.
How You Manage Azure
Azure can be managed through graphical tools, command-line tools, and infrastructure as code. These paths all interact with the Azure management layer.
Azure Portal is the browser-based GUI. Azure CLI is the cross-platform command-line tool. Azure PowerShell is the PowerShell-based management option. Azure Cloud Shell is a browser-based shell that provides CLI and PowerShell without local installation; in many scenarios it uses an associated storage account for persistence.
Azure Resource Manager (ARM) is the management layer and deployment model behind Azure resource operations. Portal, CLI, PowerShell, SDKs, REST APIs, ARM templates, and Bicep all ultimately submit requests through ARM.
ARM templates are JSON infrastructure-as-code files. Bicep is a more readable declarative language that transpiles to ARM template JSON before deployment. Key ideas: declarative deployment, parameterization, dependencies, validation, and idempotency—deploying the same template again should converge the environment toward the defined state.
Example commands:
az group create --name az900-rg --location uksouth
New-AzResourceGroup -Name az900-rg -Location uksouthDifferent tools, same ARM-backed result.
Minimal Bicep example:
param storageAccountName string
param location string = resourceGroup().location resource sa 'Microsoft.Storage/storageAccounts@2023-01-01' = { name: storageAccountName location: location sku: { name: 'Standard_LRS' } kind: 'StorageV2'
}Storage account names must be globally unique, so parameterization is safer than hardcoding a name.
Resource Organization, Governance, and Security
The Azure hierarchy is: Management Groups → Subscriptions → Resource Groups → Resources.
Management groups organize subscriptions at scale. Subscriptions are billing, access, and governance boundaries. Resource groups are logical containers for related resources. Resources are the actual deployed services. Resource groups are not nested, and resources in the same resource group do not all have to be in the same region. They do, however, belong to one resource group and one subscription.
RBAC answers: who can do what? Azure RBAC uses identities from Microsoft Entra ID (the new name for Azure Active Directory) and can be assigned at management group, subscription, resource group, or resource scope. Permissions inherit downward. Common built-in roles include Reader, Contributor, and Owner.
Azure Policy answers: what is allowed or required? Policy can audit, deny, append, modify, and in some cases deployIfNotExists to support compliance and remediation. Policies can be grouped into initiatives and assigned at multiple scopes.
Resource locks protect resources from accidental change. The two lock types are CanNotDelete and ReadOnly. Locks can block actions even if a user has RBAC permissions, unless that user can remove the lock.
Tags are metadata such as environment, owner, costCenter, or application. They help with organization and cost allocation, but only if tagging is applied consistently. Some charges and historical views may not inherit tags uniformly.
Defender for Cloud is also worth recognizing at fundamentals level: it helps with security posture, recommendations, and threat protection signals.
Practical governance example: assign Reader at a resource-group scope, apply a Policy requiring a costCenter tag, and add a CanNotDelete lock to a production database. Three controls, three different purposes.
Monitoring, Health, Diagnostics, and Optimization
Azure Monitor is the umbrella monitoring service for metrics, logs, alerts, and dashboards. Metrics are numerical time-series data such as CPU or response time. Logs contain more detailed records for investigation and analysis. Azure Monitor Logs stores log data in a Log Analytics workspace, where it can be queried and analyzed. Application Insights is commonly used for application-level telemetry and is part of Azure Monitor.
It also helps to distinguish Activity Log from resource logs: Activity Log tracks subscription-level control-plane events such as create, update, and delete operations, while resource logs capture service-specific operational data.
Azure Service Health shows incidents, planned maintenance, and advisories affecting your subscriptions and services. It is personalized. Azure Status provides a broad public view of Azure service status overall.
Azure Advisor provides recommendations in Microsoft’s standard categories: Reliability, Security, Performance, Operational Excellence, and Cost.
Troubleshooting flow:
- User cannot modify a VM: check RBAC, then check for a ReadOnly or CanNotDelete lock.
- Deployment to East US is denied: check Azure Policy for allowed locations or required tags.
- App is slow: check Azure Monitor metrics, logs, and Application Insights.
- Users report widespread outage: check Service Health first; use the general Azure platform status view if you suspect a broader issue.
- Unexpected bill spike: check Cost Management, Advisor recommendations, and tagging quality.
Hybrid Management, Cost, and Optimization Basics
Azure Arc extends Azure management to selected non-Azure resources such as servers, Kubernetes clusters, and some Azure data services running outside Azure. It does not migrate those resources into Azure. Its value is centralized governance, visibility, and policy/RBAC consistency across hybrid or multicloud environments.
Microsoft Cost Management helps analyze and control spend. The Pricing Calculator helps estimate future costs, and the TCO Calculator helps compare on-premises and Azure cost models. Budgets can generate alerts, but they do not automatically stop resource consumption.
Common cost drivers include resource type, region, size, usage, storage redundancy choice, and network egress. Common optimization tools and methods include right-sizing, autoscaling where appropriate, shutting down unused resources, using tags for chargeback, and reviewing Advisor recommendations. At a recognition level, Azure also offers reservations and savings plans for some workloads.
Exam Alert: Common Traps and Final AZ-900 Cram Sheet
| Common confusion | Correct distinction |
|---|---|
| ARM vs ARM templates/Bicep | ARM is the management layer; templates and Bicep are IaC definitions submitted to ARM |
| RBAC vs Azure Policy | RBAC = who can do what; Policy = what is allowed or required |
| Azure Monitor vs Service Health vs Advisor | Monitor = telemetry; Service Health = Azure issues affecting you; Advisor = recommendations |
| Subscription vs Resource Group | Subscription = billing/access boundary; Resource Group = logical container |
| VPN Gateway vs ExpressRoute | VPN Gateway = encrypted tunnel over internet; ExpressRoute = private dedicated connectivity |
| Blob vs Files vs Disks | Blob = object storage; Files = managed file shares; Disks = VM block storage |
| Load Balancer vs Application Gateway | Load Balancer = Layer 4; Application Gateway = Layer 7 web traffic |
One-sentence memory cues:
- RBAC = who can do what.
- Policy = what is allowed.
- Lock = protect from accidental change.
- Monitor = your telemetry.
- Service Health = Azure problems affecting you.
- Advisor = how to improve.
- Arc = Azure management beyond Azure.
Fast review questions:
- Which service enforces allowed locations? Azure Policy
- Which tool reports planned Azure maintenance affecting your subscription? Azure Service Health
- Which service provides private dedicated connectivity to Azure? ExpressRoute
- Which storage type is used for VM operating system disks? Azure Disk Storage
- Which service is best for event-driven code triggered by a blob upload? Azure Functions
If you can explain those distinctions in plain English, you’re in strong shape for AZ-900. That is the real goal: not just memorizing names, but understanding what runs workloads, what manages them, what governs them, and what helps you operate them well.