Azure Policy or RBAC? The Azure services AZ-900 candidates confuse, one difference at a time
Many wrong AZ-900 answers come from services with similar purposes. Azure Policy sets rules for what resources may be like; Azure RBAC decides who may do what; resource locks stop deletion or change. Azure Advisor recommends improvements, Service Health reports Azure's own outages, and Azure Monitor tracks your resources. Learn each group as a contrast, then learn how responsibility shifts from IaaS to SaaS.
You can define Azure Policy and Azure RBAC perfectly and still lose the mark. The question asks how to stop anyone creating resources outside two approved regions, and both options sound right. Eight groups of look-alike services cause many of those lost marks, and a failed attempt means paying the fee again.
Why do look-alike services cost so many marks?
AZ-900 rarely asks what a service is called. It describes a short need and asks which service, tool or model fits. When two options both protect, monitor or connect, a definition will not separate them. You need the one difference that answers the question.
Read the last line first, so you know what you are choosing. Then remove every option that does something different from the need described.
These groups sit across seven skill areas, all in Azure architecture and services and in management and governance. The AZ-900 skills measured in plain English sets out all 11 with their weights.
Which Azure services do candidates confuse, and when do you use each?
| Group | Service | Use this when |
|---|---|---|
| Rules and permissions | Azure Policy | You need rules for what resources may be like, such as allowed regions |
| Azure RBAC | You need to control who may do what, and where | |
| Resource locks | You need protection against deletion or change | |
| Monitoring | Azure Advisor | You want recommendations to improve your resources |
| Azure Service Health | You need to know about Azure's own outages and maintenance | |
| Azure Monitor | You need your resources' metrics, logs and alerts | |
| Resilience | Availability sets | You need protection against rack failure in one datacentre |
| Availability zones | You need protection against datacentre failure in a region | |
| Region pairs | You need protection against a regional disaster | |
| Connections | VPN Gateway | You need an encrypted link over the internet |
| ExpressRoute | You need a private, dedicated connection | |
| Virtual network peering | You need to link two Azure virtual networks | |
| Cost tools | Pricing calculator | You need a cost estimate before you build |
| Cost Management | You need to track and analyse what you have spent | |
| Identity | Microsoft Entra ID | You need cloud identity and sign-in |
| Microsoft Entra Domain Services | You need managed domain features for older applications | |
| Protection | Microsoft Purview | You need to govern and protect data |
| Microsoft Defender for Cloud | You need resources assessed and protected against threats | |
| Management reach | Azure Arc | You need to manage servers and resources outside Azure |
| Azure Resource Manager | You need the layer that deploys and manages resources inside Azure |
RBAC stands for role-based access control: you give a person or group a role, such as Reader, at a chosen scope. A virtual network is your own private network inside Azure. Older applications often expect a traditional Windows domain, which Entra Domain Services provides without you running domain controllers.
How do you tell the hardest groups apart?
Azure Policy, RBAC or a lock. Ask what the question is controlling. A rule about the resource itself, such as its region, points to Azure Policy. A limit on a person's actions points to RBAC. Stopping a mistaken deletion, even by an owner, points to a resource lock.
Advisor, Service Health or Monitor. Ask whose problem it is. An outage or planned maintenance in Azure itself is a Service Health question. Data about your own resources, with alerts, is Azure Monitor. Advice to save money or improve security is Advisor.
Availability sets, zones or region pairs. Ask how large the failure is. A rack inside one datacentre points to an availability set. A whole datacentre points to availability zones, which are separate datacentres within one region. A disaster across a region points to region pairs.
VPN Gateway, ExpressRoute or peering. Ask what is being joined, and how. An office reaching Azure over the internet, encrypted, uses VPN Gateway. An office that must avoid the public internet uses ExpressRoute. Two Azure virtual networks use peering.
One more contrast is not between services at all. It is about who is responsible.
How does shared responsibility change from IaaS to PaaS to SaaS?
The shared responsibility model sets out which security duties belong to Microsoft and which belong to you. The service types and the model go together: the more managed the service, the less you are responsible for.
| Responsibility | IaaS | PaaS | SaaS |
|---|---|---|---|
| Physical datacentre and hosts | Microsoft | Microsoft | Microsoft |
| Operating system | You | Microsoft | Microsoft |
| Network controls | You | Shared | Microsoft |
| Applications | You | Shared | Shared |
| Identities and users | You | You | You |
| Information and data | You | You | You |
Infrastructure as a service, IaaS, gives you virtual machines, storage and networks, and you manage the operating system. Platform as a service, PaaS, runs the operating system and runtime, so you deploy only your code. Software as a service, SaaS, is a finished application you sign in to and use, such as web-based email.
Three rows never move. Microsoft always owns the physical datacentre and hosts. You always own your information and data, and the identities and users who reach it.
A common slip is to answer "Microsoft" when asked who protects the data in a SaaS application. Microsoft runs the application, but the data and the accounts remain yours.
Which ideas get mixed up?
The same habit of contrast works for ideas as well as services. Zero Trust and defence in depth sit in the identity and security skill area. The rest are cloud concepts.
- Zero Trust or defence in depth. Zero Trust assumes breach and verifies every request. Defence in depth protects in layers.
- Scalability or elasticity. Scalability is adjusting resources, up or down, to meet demand. Elasticity is doing that automatically as demand changes.
- Consumption-based or capital expenditure. Paying only for what you use is consumption-based. Buying equipment up front is capital expenditure.
- Hybrid or private cloud. Your own datacentre combined with a public cloud is hybrid. A private cloud serves one organisation alone.
What to do next
Cover the right-hand column of the table and say each difference aloud. The book's readiness test asks you to explain every contrast this way, without notes.
When you review a practice set, label each wrong answer with the group it confused. Move hours now towards the skill areas behind your most common errors, not in the final week.
A little time in the portal makes services easier to tell apart, though the exam does not test building. Set a budget alert first. How to build your AZ-900 study plan gives the full order. Then test yourself under exam conditions with the AZ-900 practice questions.
Every service name here was checked against Microsoft Learn's documents in October 2026. Chapter 7 of the book gives the five-step safe practice subscription and five short portal tasks, each linked to a skill area. Appendix G adds 17 practice questions with explanations.
- Cover the right-hand column of the contrast table and say each difference aloud, without notes.
- Label every wrong answer in your last practice set with the group it confused.
- Draw the shared responsibility table for IaaS, PaaS and SaaS from memory, then check it against this page.
- Create a budget with an email alert in Cost Management before you build anything in a practice subscription.
Questions readers ask
Which old service names should I watch for in study material?
What does Conditional Access do?
Which storage access tier suits data that is rarely read?
How does the Azure hierarchy affect these services?
- Azure Fundamentals certification page (Microsoft Learn)
- AZ-900 study guide
This guide is independent and is not endorsed by Microsoft. Facts change: confirm them on the official page before you act.