In 2023, when I prepared for the AZ-900, I was studying Computer Science and had limited hands-on experience with cloud infrastructure. What stood out when studying was the exam's scope: it doesn't start with Azure services but with cloud computing fundamentals, which makes it useful for both technical and non-technical profiles.
The AZ-900 (Microsoft Azure Fundamentals) is the introductory certification to the Azure ecosystem. It doesn't require prior tech experience, doesn't assume knowledge of programming, and doesn't expect you to have administered a server. It's designed for anyone who wants to understand how Microsoft's cloud works, both from the technical side and the organizational and financial one.
How I got to this exam
I got access through a program run by Microsoft and the Fundación Tomás Alva Edison in Mendoza, Argentina. The foundation has a partnership with Microsoft to bring these certifications to students and young people in the region.
Today the exam is available through two channels. Most people book it through Pearson Vue, either in person at an authorized testing center or remotely from home through its OnVUE system. Students and educators can also book it through Certiport, which was the platform I used myself back in 2023 and remains active today as an option for that audience.
I'm a Microsoft Student Ambassador, and part of what I do in that role is help other students work through this same path. That's why I put together a study plan on Microsoft Learn that organizes all the official modules in the order I'd recommend going through them: AZ-900 Study Plan. You can start it right now while you read this.
What the exam covers
The AZ-900 has between 40 and 60 questions, requires a minimum score of 700 out of 1000 to pass, and you'll have 45 minutes to complete the assessment. There are no hands-on labs or case studies, and there's no penalty for wrong answers, so it's always worth answering even when you're not sure.
The cost is $99 USD in the United States, though Microsoft adjusts pricing by country. In Argentina, the official price is $59 USD. Check the exact price for your region on the official scheduling page before booking.
The content is organized into three major areas.
Cloud concepts
The first area covers foundational concepts and is the most theoretical of the three. Before getting into Azure services specifically, the exam evaluates whether you understand what the cloud is and why it exists.
The consumption model
One of the most important concepts is the difference between CapEx and OpEx. CapEx (Capital Expenditure) is the upfront investment in physical infrastructure you own: you buy servers, set them up, maintain them, and that cost stays with you for the life of the equipment. OpEx (Operational Expenditure) is the operating expense model: you pay for what you use, when you use it, with no upfront hardware investment. The cloud operates under OpEx, and that shifts the financial equation entirely, especially for smaller organizations.
The service models
IaaS (Infrastructure as a Service) gives you the highest level of control. You rent the infrastructure (virtual servers, networking, storage) and you manage everything running on top: the operating system, middleware, applications, and data. A virtual machine on Azure is the clearest example. Think of it like renting an empty apartment where the building is already there but you decide everything that goes inside.
PaaS (Platform as a Service) removes the responsibility for the operating system and underlying infrastructure. You get a ready-to-use environment for building and deploying applications. Azure App Service fits here: you push your code and the platform handles the rest. It's like working at a coworking space where the desk, internet, and infrastructure are already set up and you just show up to work.
SaaS (Software as a Service) is the model most people use every day without thinking about it. Microsoft 365, Teams, Gmail, and Notion are all SaaS. You use a finished application without thinking about any of the infrastructure underneath.
Deployment models
Public cloud is infrastructure the provider shares across multiple customers. Private cloud is infrastructure dedicated exclusively to a single organization. Hybrid cloud combines both, which is especially useful for organizations with legacy systems they can't fully migrate.
The study plan covers all of this with hands-on exercises where you can practice without needing your own subscription.
Azure architecture and services
This is the most extensive area of the exam and the one that covers the greatest number of individual services. It's also the one that requires the most study time.
Regions and availability zones
Azure is physically distributed across more than 70 regions worldwide. A region is a geographic area containing one or more datacenters. When you create a resource, you choose which region it lives in, and that choice affects latency, cost, and your organization's data residency requirements.
Within many regions there are availability zones, which are physically separate datacenters within that same region, connected by low-latency networks. If one zone fails, the others keep running. Azure also has region pairs: each primary region has a secondary region that's geographically distant, for disaster recovery at a larger scale.
Subscriptions and resource groups
Every Azure resource lives inside a well-defined hierarchy. The top level is the Microsoft Entra ID tenant, which represents your organization. Within the tenant there are subscriptions, which are the billing unit. Within each subscription you create resource groups, which are logical containers that group related services for a project or application. Every Azure resource always belongs to exactly one resource group.
Compute
Azure Virtual Machines are the classic IaaS model: a full server in the cloud that you manage from the operating system upward. They're the most flexible option and also the one that carries the most management overhead.
Azure App Service is the PaaS platform for web apps and APIs. It supports .NET, Java, Node.js, Python, and PHP, and you don't manage the underlying server.
Azure Functions is the serverless option. Functions execute only when something triggers them (an HTTP request, an event, a queue message) and you pay only for actual execution time.
Azure Kubernetes Service (AKS) is the managed Kubernetes service for orchestrating containers at scale. Azure Container Instances is the simpler option for running individual containers without needing a full cluster.
Networking
A Virtual Network (VNet) is the private network where your Azure resources live. You can segment it into subnets, control traffic with Network Security Groups (NSGs), and connect your on-premises network to Azure through VPN Gateway or Azure ExpressRoute, which provides a private dedicated connection that doesn't go through the public internet.
Azure Load Balancer distributes traffic across multiple instances to ensure availability. Azure Application Gateway does something similar at the application layer and includes a Web Application Firewall. Azure CDN brings static content closer to users by distributing it across points of presence around the world.
Storage
Azure Blob Storage is Azure's object storage service, designed for unstructured data like files, images, videos, and backups. It has three access tiers based on how frequently data is needed: Hot for frequent access, Cool for data accessed less than once a month, and Archive for data that's rarely retrieved and where hours of retrieval latency is acceptable.
Azure Files provides a shared file system compatible with the SMB protocol and accessible from Windows, Linux, and macOS. Azure Queue Storage is a messaging service for decoupling components of an application.
On the redundancy side, LRS replicates data three times within a single datacenter, ZRS replicates across availability zones, GRS replicates to a secondary region, and GZRS combines zone redundancy with geo-replication.
Identity and access
Microsoft Entra ID (formerly Azure Active Directory) is Microsoft's cloud identity service. It manages authentication and authorization for Azure, Microsoft 365, and third-party applications.
Role-Based Access Control (RBAC) lets you assign specific permissions to users, groups, or service identities over specific resources, following the principle of least privilege. The most common built-in roles are Owner, Contributor, and Reader.
Multi-Factor Authentication (MFA) adds a second verification layer beyond the password. Conditional Access lets you define policies that evaluate the context of an access attempt, such as location, device, or application, before allowing or blocking it.
Management and governance
The third area covers how to manage, monitor, and control costs in Azure. It's the one most people underestimate during study and the one that carries real weight in the actual exam.
Management tools
The Azure Portal is the main web interface for creating and managing resources. Azure CLI and Azure PowerShell are the command-line alternatives for those who prefer automation or scripting. Azure Cloud Shell is a terminal available directly from the browser, with Azure CLI and PowerShell already configured, with no local installation needed.
Azure Resource Manager (ARM) is the layer that processes all resource creation, modification, and deletion requests, whether they come from the portal, the CLI, or an API. ARM templates and Bicep allow you to define infrastructure as code and deploy it repeatably.
Azure Arc extends Azure's management capabilities to resources running outside of Azure, like servers in other clouds or in on-premises datacenters.
Costs
Azure Cost Management lets you see your detailed spending, set budgets, and configure automatic alerts when consumption approaches a defined limit. The Azure Pricing Calculator helps estimate the cost of an architecture before deploying anything. The Total Cost of Ownership (TCO) Calculator helps compare the cost of maintaining on-premises infrastructure against migrating to the cloud.
Pay-as-you-go lets you pay for what you use with no prior commitments. Azure Reservations let you reserve specific capacity for one or three years in exchange for discounts of up to 72% compared to the pay-as-you-go price.
Governance
Azure Policy lets you define and enforce rules on resources within a subscription, for example requiring that all new resources have mandatory tags, or restricting which VM sizes can be created. Resource Locks protect critical resources from accidental deletion or modification, even for accounts with administrator-level permissions.
Monitoring
Azure Monitor is the platform's central monitoring service. It collects metrics and logs from all your resources and lets you create alerts, dashboards, and analysis workbooks.
Application Insights is an Azure Monitor extension built specifically for applications. It tracks response times, exceptions, dependencies, and user behavior in real time.
Azure Service Health reports on the current status of Azure services in each region and on any incidents or planned maintenance that might affect your resources.
Microsoft Defender for Cloud assesses the security posture of your resources and generates concrete recommendations for reducing risk.
How to prepare
Study time varies depending on your background. Without any prior tech experience, two to four weeks of consistent study is realistic. With a technical foundation already in place, under two weeks is very doable.
Microsoft Learn has the official learning path completely free, with interactive modules and sandboxes where you can practice directly in Azure without needing your own subscription or a credit card. Microsoft also offers a free official practice assessment that lets you get familiar with the real exam format before the day you sit for it.
The free Azure account includes $200 in credit to use within your first 30 days, plus permanent access to a set of always-free services. It's useful for experimenting beyond Learn's sandboxes.
The study plan I put together organizes the Microsoft Learn modules in the order I'd recommend working through them, grouped by exam area. You can complete each module at your own pace and track your progress as you go.
To close
Once you pass the AZ-900, the natural next steps on the technical Azure path are the AZ-104 (Administrator) or the AZ-204 (Developer). On the AI side, the AI-900 is the equivalent introductory cert before moving to the AI-102 or AI-103.
If you'd like to study alongside others, on October 15 we're organizing an event where we'll go through the most important exam topics together. Leave a comment or reach out directly if you're interested.
The study plan is already there: AZ-900 Study Plan on Microsoft Learn.
Top comments (0)