AZ-900 Exam Domains
The AZ-900 skills outline measured as of July 20, 2026 has three domains: Cloud concepts (25-30%), Azure architecture and services (35-40%), and Azure management and governance (30-35%).
- The guide's detailed tasks show what to study under each heading.
- Use the weights to allocate review time; they do not promise a fixed number of questions on your exam form.
On this page7 sections
The active AZ-900 outline
Microsoft's AZ-900 study guide says the skills are measured as of July 20, 2026. The outline groups them into three domains: Cloud concepts, 25 to 30%; Azure architecture and services, 35 to 40%; and Azure management and governance, 30 to 35%. Microsoft also publishes task bullets beneath each domain. Those task statements are the best map for study because they name the concepts candidates should be able to describe.
| Domain | Weight range | Main content |
|---|---|---|
| Cloud concepts | 25-30% | Cloud computing, cloud benefits, cloud deployment models, service types, pricing, and shared responsibility. |
| Azure architecture and services | 35-40% | Azure geography and hierarchy, compute, networking, storage, identity, access, and security. |
| Azure management and governance | 30-35% | Cost tools, governance and compliance, deployment tools, resource management, and monitoring. |
The ranges are relative weights, not exact item counts. The number of questions varies, and Microsoft does not promise that a candidate will receive a fixed number from a particular topic. Some exam items may be unscored and are not identified. Use percentages to guide study time, then prepare all the listed skills.
Microsoft updates the English exam first. Localized versions generally follow later, but the timing can vary. The skills guide also notes that bullets illustrate assessment and related topics may appear. Most questions cover generally available features, though commonly used preview features may be included. Use current documentation and avoid relying on a feature that has changed or is no longer available.
Cloud concepts: 25 to 30%
This domain begins with cloud computing: using computing resources delivered as services rather than operating every component yourself. Learn public, private, and hybrid cloud models and recognize use cases. Public cloud can provide flexible access to provider-operated infrastructure. Private cloud dedicates an environment to an organization. Hybrid cloud connects on-premises or private environments with public cloud services. The right model depends on control, location, compliance, integration, and operational needs.
Consumption-based pricing ties charges to resources used under the service's billing model. It can reduce upfront investment and let capacity change as demand changes, but it also requires cost visibility. A forgotten resource or overprovisioned environment can generate unnecessary spend. Compare this with capital expenditure and operating expenditure at a descriptive level; do not assume that moving to cloud automatically reduces total cost.
Serverless computing lets a developer run code or application logic without managing servers in the same way as a virtual machine. The cloud provider handles more of the infrastructure operations, while the customer still writes and manages the code, data, identity, and configuration relevant to the service. Serverless is not ‘no servers exist’; it describes the abstraction available to the user.
Understand the benefits of high availability, scalability, reliability, predictability, security, governance, and manageability. These are related but distinct. Scalability is the ability to adjust capacity; high availability concerns keeping service accessible; reliability concerns consistent operation; predictability concerns behavior or performance. Cloud services provide capabilities that support these outcomes, but architecture and configuration determine whether a workload achieves them.
IaaS, PaaS, and SaaS describe different service responsibilities. IaaS offers virtualized compute, networking, and storage with more customer control over the operating system and application. PaaS manages more of the runtime and hosting platform so a customer can deploy code. SaaS provides a complete application for use. The higher the abstraction, the more infrastructure the provider operates, while the customer still owns appropriate identity, data, access, and configuration responsibilities.
The shared responsibility model changes by service type. A virtual machine customer manages more of the guest operating system than a customer using a managed application service. SaaS shifts additional application operations to the provider, but does not remove the customer's duty to manage users and data. A useful study exercise is to compare who manages physical facilities, network, operating system, application, identity, and information in each model.
Azure architecture and services: 35 to 40%
The architecture domain begins with Azure geography. A region is a geographic area containing datacenters. Region pairs support certain continuity and recovery strategies. Sovereign regions address distinct operational and compliance needs. Availability zones are separate physical locations within a region that can support resiliency for services designed to use them. These terms describe different location and availability concepts; they should not be used as synonyms.
Learn the Azure resource hierarchy: management groups can organize subscriptions, subscriptions organize resource access and billing boundaries, and resource groups logically collect related resources. Resources are the individual services or components deployed in Azure. A management group is not a resource group, and a subscription is not simply a folder. Think about the scope at which access, billing, organization, or governance needs to apply.
Compute questions compare virtual machines, containers, and functions. Virtual machines provide virtualized operating systems and give customers control of the guest environment. Containers package an application and its dependencies with a lighter abstraction than a full virtual machine. Functions run code in response to events with an execution model that reduces server management. The best option depends on control, workload shape, portability, and operations.
The outline also names virtual machine scale sets, availability sets, Azure Virtual Desktop, and resources required for virtual machines. Candidates should know their purpose at an overview level and recognize how they relate to scaling, availability, or hosted desktops. Application hosting options include web apps, containers, and virtual machines. The exam expects descriptive understanding, not a full deployment procedure.
Networking includes Azure virtual networks and subnets, peering, Azure DNS, VPN Gateway, ExpressRoute, and public versus private endpoints. A virtual network creates a logical network boundary in Azure; subnets divide address space and support organization or segmentation. Peering connects virtual networks. VPN Gateway uses encrypted connectivity over a network path, while ExpressRoute provides private connectivity through a provider. Public and private endpoints affect how a service is reached.
Storage topics include Azure Storage services, tiers, redundancy, account options, and storage types. Learn the purpose of common storage choices and what redundancy options protect against. Distinguish file movement from migration. AzCopy and Storage Explorer help transfer or manage data, Azure File Sync supports synchronization scenarios, Azure Migrate assesses and helps move workloads, and Azure Data Box physically transports data for certain migration needs.
Identity, access, and security includes Microsoft Entra ID and Entra Domain Services, authentication methods, external identities, Conditional Access, Azure RBAC, Zero Trust, defense in depth, and Defender for Cloud. Authentication verifies identity; authorization controls what an identity may do. RBAC grants permissions on Azure resources at a scope. Conditional Access evaluates access conditions. These tools work at different levels and should not be confused.
Azure management and governance: 30 to 35%
Cost management starts with factors that influence charges, such as resource type, configuration, usage, storage, data transfer, and location. The pricing calculator helps estimate costs before deployment. Azure cost management capabilities help monitor or analyze spend. Tags can add metadata that supports organization, reporting, and cost allocation. A tag does not itself limit access or stop a resource from running.
Governance and compliance includes Microsoft Purview, Azure Policy, and resource locks. Purview supports data governance and compliance capabilities. Azure Policy can audit or enforce standards across resources. A resource lock helps prevent accidental deletion or modification at a scope. RBAC controls who can perform authorized actions; a lock protects resources from certain changes. Understand which need each tool addresses.
Management and deployment includes the Azure portal, Cloud Shell, Azure CLI, and Azure PowerShell. The portal is a graphical interface; command-line tools support repeatable administrative work. Cloud Shell provides an environment for using command tools. Azure Arc extends management to resources outside Azure. Infrastructure as code describes and manages infrastructure through declarative files or templates. Azure Resource Manager and ARM templates support deployment and resource management.
Monitoring tools have different purposes. Azure Advisor provides recommendations for improving resources. Azure Service Health provides information about Azure service issues and planned maintenance relevant to subscriptions or regions. Azure Monitor collects and analyzes monitoring data; Log Analytics queries logs, alerts notify on conditions, and Application Insights supports application performance monitoring. If a question asks whether Azure itself has an outage, Service Health is more relevant than an application analytics tool.
How domain skills combine
A candidate should expect concepts to overlap. A scenario about moving a customer database might involve storage, a region, a migration tool, redundancy, network connection, identity, and cost. The domain label alone does not identify a single answer. Start with the requirement: move a large volume of files, preserve a database application, protect service availability, or estimate monthly cost. Then select the service or concept that directly addresses that need.
Consider a company with an existing application that needs a fast move to Azure but depends on operating-system settings. A virtual machine may preserve control and compatibility, though the customer still manages the OS and workload. If the company can modify its app and wants Microsoft to operate more of the hosting platform, PaaS may reduce administration. The service model follows the workload requirement.
Now suppose the company also wants to prevent accidental deletion. A resource lock can help protect the resource, while RBAC limits which identities can manage it and backup design supports recovery. Azure Policy can enforce a required configuration. These controls are complementary, but each solves a different problem. A question may ask for one specific outcome, so avoid choosing the broadest tool by default.
For resilience, identify what failure the organization wants to tolerate. Availability zones address physical separation within a region for supported services. Region selection affects geography and compliance. A region pair has a separate relationship. High availability is an outcome supported by architecture, not a property guaranteed merely because an organization chose Azure.
A domain-by-domain study method
Make a task checklist from Microsoft's guide and mark each line ‘can explain,’ ‘partly understand,’ or ‘new.’ For a line you know, create one sentence that defines it and one practical example. For a line you partly know, compare it with the nearest service. For a new item, study the official documentation and then explain its purpose without using product marketing language.
Use two-way comparisons. Compare IaaS with PaaS, a region with an availability zone, resource groups with subscriptions, RBAC with Azure Policy, and Service Health with Azure Monitor. Explain not only what each does but which scenario makes it a better fit. This exposes confusions that a list of definitions can hide.
Review the larger architecture-and-services range more often, but balance preparation across all three domains. The published percentages are ranges, not a contract for a particular form. A candidate weak in governance may need extra attention there even though it is not the largest range. Schedule mixed practice to force recognition of the right concept without seeing a domain label first.
Microsoft's bullets are illustrative of assessment, and related topics may be tested. That means candidates should understand the neighboring ideas, not only recite a bullet. For example, if you learn VPN Gateway, understand why a company might want private connectivity and what makes ExpressRoute different at a high level. Do not expand into detailed command memorization beyond the fundamentals scope.
Changes and version control
The current study guide identifies July 20, 2026 as the skills-measured date. It includes a change log comparing the outline with its previous version. Review the live guide before preparing for a later exam date because Microsoft periodically updates English skills first and localized versions may lag. The scope on an older preparation book may not exactly match the current guide.
Most questions cover generally available features. Microsoft says preview features may appear when they are commonly used. Candidates should focus on stable purpose and role for named services and check the current guide and documentation for changes. Do not base a study plan on a speculative list of exact questions or features.
The exam has a scaled passing score of 700, but the domain percentages are not pass thresholds. A candidate cannot pass one domain at a minimum percentage while failing another, nor calculate an exact raw cutoff from the weights. The reported overall result and score report are the official outcomes.
The most useful interpretation of the outline is practical: know the purpose and boundary of each service, apply it to a stated need, and recognize how security, governance, reliability, and cost affect the choice. When a question supplies a requirement, let that requirement guide the answer rather than selecting a familiar product name.
Common questions
What are the AZ-900 domains in 2026?
The domains measured as of July 20, 2026 are Cloud concepts (25-30%), Azure architecture and services (35-40%), and Azure management and governance (30-35%).
What is the largest AZ-900 domain?
Azure architecture and services has the largest published range at 35-40%.
Do the weights tell me the exact number of exam questions per domain?
No. They are domain weight ranges, not a guaranteed count on an individual exam form.
How often does Microsoft update the AZ-900 outline?
Microsoft updates exam skills periodically and publishes the current skills-measured date and change log in the study guide.