AZ-900 architecture and services: draw the hierarchy and the three failure levels
Azure architecture and services is the largest AZ-900 group, at 35 to 40 per cent. Draw the hierarchy from management groups down to resources, learn availability sets, zones and region pairs as three failure levels, and separate VPN Gateway, ExpressRoute and peering.
Candidates who skim the largest group lose marks where the weight is highest.
The biggest group
Candidates memorise definitions of IaaS, PaaS and SaaS, then run out of study time. Azure architecture and services is the largest group, at 35 to 40 per cent of the exam. In a 30-hour plan it gets 12 hours, against 10 for management and governance and 8 for cloud concepts.
The group has four skill areas: core architectural components, compute and networking services, storage services, and identity, access and security.
Picture one: the hierarchy
Management groups contain subscriptions, subscriptions contain resource groups, and resource groups contain resources. Policies and access set at a higher level flow down to everything beneath.
Draw it on paper: four boxes, each inside the one above. Then label where you would apply a rule for a whole department, where you would apply one for a single project, and where you would delete a set of practice resources in one move.
A typical question asks which level sits directly above resource groups. The answer is subscriptions. Management groups are the runner-up, because they sit above subscriptions.
Picture two: three failure levels
| Level | Protects against |
|---|---|
| Availability sets | Rack failure in one datacentre |
| Availability zones | Datacentre failure in a region |
| Region pairs | A regional disaster |
Read the table from top to bottom as a growing scale. A question about keeping a service running if one datacentre in a region fails points at availability zones. Availability sets protect at a smaller scale.
Picture three: three network links
| Service | What it is |
|---|---|
| VPN Gateway | An encrypted link over the internet |
| ExpressRoute | A private dedicated connection |
| Virtual network peering | Links two Azure virtual networks |
A private, dedicated connection that does not cross the public internet is ExpressRoute. VPN Gateway is the runner-up because it also links a network to Azure, but over the internet.
Identity in one line
Microsoft Entra ID is cloud identity and sign-in, the renamed Azure Active Directory. Microsoft Entra Domain Services provides managed domain features for older applications. This area also covers single sign-on, multifactor authentication, passwordless sign-in, Conditional Access, Azure RBAC, Zero Trust, defence in depth and Defender for Cloud.
Storage and compute in one glance
Storage questions ask where data lives and how many copies are kept, so learn tiers, redundancy options and account types together. Compute questions ask which way to run a workload: containers, virtual machines or functions. Use one sentence per option in your notes, such as "virtual machine: I manage the system", and the choice becomes a question about how much you want to manage.
A two-session drill
Session one: redraw the hierarchy and the failure table from memory, then check them. Session two: explain aloud, without notes, the difference between each pair of look-alike services above.
Your practice misses show the habit. Missing questions on the hierarchy or on availability usually means mixing up scale levels, so redraw both from memory. Missing questions on network links usually means picking the service that sounds close, so redo the three-link table aloud.
Questions readers ask
Which AZ-900 group has the highest weight?
What sits directly above resource groups?
What is the difference between VPN Gateway and ExpressRoute?
This article is independent and is not endorsed by Microsoft. Facts change: confirm them on the official page before you act.