All certifications / Azure Fundamentals / Cheat sheet
Azure Fundamentals AZ-900 cheat sheet
Domain 1: Describe cloud concepts (27%)
Exam tips
- Physical hosts, physical network, the datacenter and the hypervisor are always Microsoft's. Data, devices, accounts and identities are always yours. The guest OS is yours in IaaS and Microsoft's in PaaS and SaaS.
- Hybrid means private plus public; multicloud means more than one public provider. Managing non-Azure resources from Azure without moving them is Azure Arc, not Azure Migrate.
- No upfront cost, pay for what you use and stop paying when you stop using: that is the consumption-based model. A VM stopped from inside the OS is still billed; deallocate it to stop compute charges.
- Anything bought, owned and depreciated over years is CapEx. A monthly bill for cloud services you consume is OpEx. The cloud's consumption-based model is an OpEx model.
- Composite SLAs are found by multiplying and are always lower than the lowest individual SLA in the chain. More nines means less allowed downtime. Missing an SLA earns a service credit, not a guarantee.
- Up and down change the size of one resource; out and in change the number of resources. If the question says capacity changes automatically in response to demand, the answer is elasticity or autoscale.
- Performance predictability comes from autoscaling and load balancing. Cost predictability comes from the Pricing Calculator, TCO Calculator, Cost Management and budgets. Budgets alert; they do not stop resources.
- A feature acting on resources (autoscale, templates, monitoring, alerts) is management of the cloud. A way to access Azure (portal, CLI, PowerShell, Cloud Shell, APIs) is management in the cloud.
- If a scenario stresses maximum control, a custom or legacy OS configuration, or moving servers without changing them, the answer is IaaS. In IaaS, patching the guest OS is always the customer's job.
- If developers want to focus on code and not manage the OS, choose PaaS. If code should run only when an event happens and be billed per execution, think serverless, usually Azure Functions; low-code workflows point to Logic Apps.
- Match the scenario to the control needed: full OS control or lift-and-shift is IaaS, build-your-own-app without managing servers is PaaS, ready-to-use application is SaaS. Data, devices and identities are the customer's in all three.
Key terms
- Cloud computing
- Delivering computing services such as servers, storage, databases and software over the internet on demand.
- Shared responsibility model
- The division of security and management tasks between the cloud provider and the customer, which depends on the service type.
- Infrastructure as a service (IaaS)
- A service type where the provider runs the physical infrastructure and you manage the operating system and everything above it.
- Platform as a service (PaaS)
- A service type where the provider also manages the operating system and runtime, and you manage your application and data.
- Software as a service (SaaS)
- A complete application run by the provider that you configure and use, such as Microsoft 365.
- On-premises
- Infrastructure you own and run in your own datacenter, where you are responsible for every layer.
- Hypervisor
- The software on a physical host that runs virtual machines; in Azure it is always Microsoft's responsibility.
- Public cloud
- Cloud services owned and run by a provider and offered to many customers over the internet.
- Private cloud
- Cloud resources dedicated to a single organization, whether in its own datacenter or hosted by a third party.
- Hybrid cloud
- A combination of private and public cloud that lets data and applications work across both.
- Multicloud
- Using services from two or more public cloud providers.
- Azure Arc
- A service that projects servers, Kubernetes clusters and data services outside Azure into Azure Resource Manager so they can be managed and governed from Azure.
- Tenant
- A customer's isolated slice of a shared cloud, with its own resources and identities.
- Consumption-based model
- A pricing approach where you pay for the resources you actually use rather than buying capacity in advance.
- Pay-as-you-go
- Azure's default billing option, where usage is metered and billed after the fact with no upfront commitment.
- Meter
- The measurement Azure uses to bill a resource, such as compute hours or gigabytes stored.
- Deallocate
- Stopping a VM so that its compute resources are released and compute billing stops, while its disks remain.
- Azure Reservations
- A one-year or three-year commitment to a resource type in exchange for a discounted price.
- Economies of scale
- Lower unit costs a provider achieves by operating at very large scale, which can be passed on to customers.
- Capital expenditure (CapEx)
- Upfront spending on physical assets that the organization owns and uses over several years.
- Operational expenditure (OpEx)
- Ongoing spending on services or products as they are used, recorded in the period it is incurred.
- Depreciation
- Spreading the cost of an owned asset over its useful life as its value declines.
- Refresh cycle
- The regular replacement of owned hardware every few years as it ages.
- Budget
- A spending limit in Azure Cost Management that sends alerts as costs approach or exceed thresholds.
- Availability
- The percentage of time a service is running and usable.
- High availability
- A design that keeps a service running when individual components fail, usually through redundancy.
- Service-level agreement (SLA)
- Microsoft's formal commitment to a service's uptime or connectivity, with credits if the target is missed.
- Service credit
- A discount on the affected service's bill that you can claim when an SLA is not met.
- Composite SLA
- The overall availability of an application that depends on several services, found by multiplying their SLAs.
- Single point of failure
- Any component whose failure stops the whole system because there is no redundant copy.
- Redundancy
- Running extra copies of a component so that one can take over if another fails.
- Scalability
- The ability to add or remove resources to match demand.
- Vertical scaling (scale up/down)
- Changing the size or power of an existing resource, such as more CPU or memory.
- Horizontal scaling (scale out/in)
- Changing the number of instances of a resource, such as adding VMs.
- Autoscale
- Automatic scaling driven by metric rules or schedules within a minimum and maximum instance count.
- Elasticity
- The ability to scale automatically in both directions as demand rises and falls.
- Virtual machine scale set
- A group of identical, load-balanced VMs that can scale out and in automatically.
- Reliability
- The ability of a system to recover from failures and keep functioning.
- Performance predictability
- Confidence that an application will have the resources it needs for a consistent user experience.
- Cost predictability
- The ability to forecast and control cloud spending.
- Pricing Calculator
- A tool that estimates the cost of Azure resources before you deploy them.
- Total Cost of Ownership (TCO) Calculator
- A tool that compares the cost of running workloads on-premises with running them in Azure.
- Microsoft Cost Management
- The Azure service for analysing, forecasting and budgeting actual cloud spending.
- Azure Site Recovery
- A service that replicates workloads to another location so they can fail over during an outage.
- Governance
- Setting rules for how resources may be created and used, and checking that they comply.
- Azure Policy
- A service that evaluates resources against rules and can audit or block non-compliant ones.
- Resource lock
- A setting that prevents a resource from being deleted or modified by accident.
- Management of the cloud
- Managing cloud resources themselves, for example with autoscale, templates, monitoring and alerts.
- Management in the cloud
- The tools used to reach and manage the environment, such as the portal, CLI, PowerShell and APIs.
- Distributed denial-of-service (DDoS)
- An attack that floods a service with traffic from many sources to make it unavailable.
- Azure Cloud Shell
- A browser-based shell with Azure CLI and Azure PowerShell already installed and signed in.
- Virtual machine (VM)
- A software-based computer running an operating system on shared physical hardware.
- Lift-and-shift (rehost)
- Moving existing servers to cloud VMs with little or no change to the application.
- Image
- A template containing an operating system, and sometimes software, used to create a VM.
- VM size
- The combination of virtual CPUs, memory and other capacity allocated to a VM.
- Azure Migrate
- A service that discovers and assesses on-premises servers and helps move them to Azure.
- Azure App Service
- A PaaS service for hosting web apps, REST APIs and mobile back ends without managing servers.
- Azure SQL Database
- A fully managed relational database service where Microsoft handles patching, backups and high availability.
- Serverless computing
- A model where the provider fully manages servers, scales automatically and bills only for execution.
- Azure Functions
- Event-driven serverless compute that runs code in response to triggers such as HTTP requests, queue messages or timers.
- Azure Logic Apps
- A low-code service for building automated workflows that connect apps and services.
- Trigger
- The event that causes a serverless function or workflow to run.
- Microsoft 365
- Microsoft's SaaS suite of email, office apps, file storage and collaboration tools.
- Customer relationship management (CRM)
- Software for managing interactions with customers and sales prospects.
- Per-user licensing
- A pricing model where you pay a recurring fee for each person who uses the application.
- Service type
- The category of cloud service, IaaS, PaaS or SaaS, which determines how responsibility is shared.
- Configuration responsibility
- The customer's duty to set a SaaS application's options, such as sharing and sign-in rules, securely.
Domain 2: Describe Azure architecture and services (38%)
Exam tips
- Region pairs help with disaster recovery, prioritized recovery and staggered updates; availability zones help within one region. Azure in China is operated by 21Vianet, not Microsoft, and Azure Government is for US government use.
- A VM placed in 'zone 2' is zonal; ZRS storage is zone-redundant. Zone-enabled regions have at least three zones. Zones protect against datacenter failures, not whole-region failures.
- Order from top to bottom: management groups, subscriptions, resource groups, resources. Resource groups cannot be nested; management groups can. A resource belongs to exactly one resource group; policies and RBAC inherit downward.
- Scale sets are about many identical VMs and autoscale; availability sets spread VMs across fault and update domains inside one datacenter; zones protect against a datacenter loss; Azure Virtual Desktop delivers desktops to users.
- Single container, simplest: ACI. Microservices without managing Kubernetes: Container Apps. Orchestrating many containers with full control: AKS. Code on events billed per execution: Functions. Web app hosting without managing servers: App Service.
- Peering connects VNets and requires non-overlapping address spaces; it is not transitive. A private endpoint gives a PaaS service a private IP in your VNet. Azure DNS hosts records but does not sell domain names.
- If traffic must not cross the public internet, the answer is ExpressRoute. VPN Gateway traffic is encrypted but travels over the internet. One laptop means point-to-site; a whole office means site-to-site.
- Archive is offline and needs rehydration that can take hours, and it can be set only per blob. Minimum retention periods are Cool 30 days, Cold 90 days and Archive 180 days. Queue is for messages, Table is NoSQL key-value data, Files is SMB/NFS shares.
- Match the failure to the option: disk or rack failure, LRS; datacenter or zone failure, ZRS; region failure, GRS or GZRS. Need to read the secondary without a failover? Pick the RA- version. Redundancy is not backup.
- Scriptable command line: AzCopy. Graphical tool: Storage Explorer. Keep on-premises Windows file servers synced with the cloud: Azure File Sync. Assess and migrate servers: Azure Migrate. Too much data for the network: Data Box.
- Entra ID is the cloud identity service using modern protocols. Entra Domain Services is for legacy apps needing domain join, LDAP or Kerberos without managing domain controllers. MFA adds a factor; passwordless removes the password; SSO reduces the number of sign-ins.
- Partners and suppliers who need access to your apps: B2B collaboration. Public customers signing up for your app: customer identity (Azure AD B2C or External ID for customers). 'Require MFA only when signing in from outside the office' is Conditional Access.
- Contributor can manage resources but cannot assign access; Owner can do both. RBAC controls who can do what; Azure Policy controls what configurations are allowed. The Zero Trust principles are verify explicitly, least privilege and assume breach.
Key terms
- Region
- A geographical area containing one or more Azure datacenters connected by a low-latency network.
- Geography
- A market, such as Europe or the United States, containing regions that share data-residency and compliance boundaries.
- Region pair
- Two regions in the same geography linked for disaster recovery, prioritized recovery and staggered updates.
- Sovereign region
- An Azure instance isolated from public Azure for legal or compliance reasons.
- Azure Government
- A sovereign cloud for US government agencies and their partners, run by screened US personnel.
- Azure operated by 21Vianet
- Azure in China, operated by a separate local company rather than directly by Microsoft.
- Geo-redundant storage (GRS)
- A storage option that replicates data to the paired region for protection against regional outages.
- Datacenter
- A physical facility of servers, storage and networking with its own power, cooling and security.
- Availability zone
- A physically separate location within a region, with independent power, cooling and networking.
- Zonal service
- A resource pinned to a single zone that you choose, such as a VM in zone 1.
- Zone-redundant service
- A service the platform replicates across zones automatically, such as ZRS storage.
- Zone-redundant storage (ZRS)
- A storage redundancy option that keeps copies of data in three zones in the region.
- Non-regional service
- A global service, such as Microsoft Entra ID, that is not tied to a single region.
- Resource
- A single manageable item in Azure, such as a VM, storage account or virtual network.
- Resource group
- A logical container for resources that share a lifecycle; it cannot be nested.
- Subscription
- A unit of billing, access control and scale that contains resource groups and trusts one Entra tenant.
- Management group
- A container above subscriptions used to apply policy and access to many subscriptions at once; it can be nested.
- Root management group
- The single top-level management group in a directory, above all other management groups and subscriptions.
- Inheritance
- The flow of policies and role assignments from a higher level of the hierarchy to everything below it.
- Azure Resource Manager (ARM)
- The deployment and management service through which all Azure resources are created and managed.
- Virtual machine (VM)
- An IaaS compute resource that runs a full Windows or Linux operating system you manage.
- Virtual machine scale set
- A set of identical, load-balanced VMs that can scale automatically and span zones.
- Availability set
- A grouping of VMs spread across fault and update domains to survive hardware failures and maintenance in one datacenter.
- Fault domain
- A group of hardware sharing power and network, so a single hardware failure affects only that group.
- Update domain
- A group of VMs that may be rebooted together during planned maintenance.
- Azure Virtual Desktop
- A service that delivers Windows desktops and apps running in Azure to users on almost any device.
- Multi-session
- A Windows edition that lets several users share one VM in Azure Virtual Desktop.
- Container
- A lightweight package of an application and its dependencies that shares the host OS kernel.
- Azure Container Instances (ACI)
- The simplest way to run a single container in Azure, with no VMs or orchestrator to manage.
- Azure Container Apps
- A serverless platform for containerized apps and microservices that hides Kubernetes and can scale to zero.
- Azure Kubernetes Service (AKS)
- A managed Kubernetes service where Azure runs the control plane and you manage nodes and workloads.
- Orchestration
- Automated deployment, scaling, networking and healing of many containers across a cluster.
- Azure Functions
- Event-driven serverless compute that runs code on triggers and bills per execution on consumption plans.
- Deployment slot
- A separate staging instance of an App Service app that can be swapped into production.
- Virtual network (VNet)
- An isolated private network in Azure, in one region and subscription, with its own address space.
- Subnet
- A range of addresses within a VNet used to group and secure resources.
- Network security group (NSG)
- A set of allow and deny rules that filters traffic to subnets or network interfaces.
- VNet peering
- A private connection between two VNets over Microsoft's backbone; global peering links VNets in different regions.
- Azure DNS
- A service that hosts DNS zones and records on Azure infrastructure; it does not register domain names.
- Private endpoint
- A network interface with a private IP in your VNet that connects privately to an Azure PaaS service.
- Public endpoint
- An address reachable from the internet, such as a public IP or a service's default public URL.
- Virtual private network (VPN)
- An encrypted tunnel that connects networks or devices across an untrusted network such as the internet.
- Azure VPN Gateway
- A virtual network gateway that sends encrypted traffic between a VNet and other locations over the internet.
- Site-to-site (S2S) VPN
- A VPN connecting an entire on-premises network to Azure through a VPN device.
- Point-to-site (P2S) VPN
- A VPN connecting an individual computer to an Azure VNet using client software.
- Azure ExpressRoute
- A private connection from on-premises to Microsoft's cloud through a connectivity partner that does not use the public internet.
- GatewaySubnet
- The dedicated subnet, with that exact name, where a VNet's gateway is deployed.
- ExpressRoute Global Reach
- A feature that links on-premises sites to each other through their ExpressRoute circuits.
- Storage account
- A container for Azure Storage data services that provides a globally unique namespace and endpoints.
- Blob storage
- Object storage for large amounts of unstructured data, organized into containers.
- Azure Files
- Fully managed cloud file shares that can be mounted over SMB or NFS.
- Queue storage
- A service for storing messages so application components can communicate asynchronously.
- Table storage
- A NoSQL store for structured, schema-less key-value data.
- Access tier
- A Hot, Cool, Cold or Archive setting on blob data that trades storage cost against access cost.
- Rehydration
- Changing an archived blob to an online tier so it can be read, which can take hours.
- Lifecycle management
- Rules that move blobs between tiers or delete them automatically based on age or access.
- Locally redundant storage (LRS)
- Three copies of data within a single datacenter in the primary region; the lowest-cost option.
- Geo-zone-redundant storage (GZRS)
- ZRS in the primary region plus asynchronous replication to LRS in the secondary region.
- Read-access (RA-GRS, RA-GZRS)
- Variants of the geo options that let you read the secondary copy at any time through a secondary endpoint.
- Failover
- Switching a storage account so the secondary region becomes the primary after a regional outage.
- Last sync time
- The point up to which data is guaranteed to have been replicated to the secondary region.
- AzCopy
- A command-line tool for copying data to, from and between Azure storage accounts, with one-way sync.
- Azure Storage Explorer
- A free graphical desktop app for managing storage accounts that uses AzCopy for transfers.
- Azure File Sync
- A service that synchronizes Windows file servers with Azure Files and can tier cold files to the cloud.
- Cloud tiering
- A File Sync feature that keeps frequently used files locally and stores rarely used files only in Azure.
- Azure Migrate
- A hub for discovering, assessing and migrating on-premises servers, databases and apps to Azure.
- Azure Data Box
- A physical device service for moving large volumes of data into or out of Azure offline.
- Shared access signature (SAS)
- A signed token appended to a storage URL that grants limited, time-bound access.
- Microsoft Entra ID
- Microsoft's cloud identity and access management service, formerly Azure Active Directory.
- Tenant
- A dedicated instance of Entra ID that represents one organization.
- Microsoft Entra Domain Services
- A managed domain providing domain join, Group Policy, LDAP and Kerberos without managing domain controllers.
- Microsoft Entra Connect
- A tool that synchronizes on-premises Active Directory identities to Entra ID for hybrid identity.
- Single sign-on (SSO)
- Signing in once to access many applications without re-entering credentials.
- Multifactor authentication (MFA)
- Requiring two or more different kinds of evidence (know, have, are) to sign in.
- Passwordless authentication
- Signing in without a password, using a device-bound credential plus biometrics or a PIN.
- FIDO2 security key
- A hardware key or passkey that uses public-key cryptography for phishing-resistant sign-in.
- Microsoft Entra External ID
- The set of capabilities that let external users, partners or customers, access your apps with their own identities.
- B2B collaboration
- Inviting external partners into your tenant as guest users who sign in with their own credentials.
- Guest user
- An external identity represented in your directory and granted access to specific resources.
- Customer identity (B2C)
- A service for consumer-facing apps providing branded sign-up and sign-in with local or social accounts.
- Conditional Access
- An Entra ID feature that uses signals in if-then policies to allow, block or require extra controls at sign-in.
- Signal
- Information such as user, location, device, app or risk that Conditional Access evaluates.
- Report-only mode
- A Conditional Access setting that logs what a policy would do without enforcing it.
- Azure RBAC
- The authorization system that grants access to Azure resources through role assignments.
- Role assignment
- The combination of a security principal, a role definition and a scope.
- Scope
- The level where a role applies: management group, subscription, resource group or resource.
- Least privilege
- Granting only the minimum access needed, for the minimum scope and time.
- Zero Trust
- A security model built on verify explicitly, least privilege access and assume breach.
- Defense in depth
- Layering multiple security controls so that one failure does not expose the data.
- Microsoft Defender for Cloud
- A service for security posture management and threat protection across Azure, other clouds and on-premises.
- Secure score
- A Defender for Cloud measure of security posture that rises as you apply recommendations.
Domain 3: Describe Azure management and governance (35%)
Exam tips
- Inbound data transfer is generally free; outbound is billed. Reservations reward a long-term commitment; Hybrid Benefit reuses licenses you already own. The same service can cost different amounts in different regions, and a stopped VM must be deallocated to stop compute charges.
- Comparing on-premises with Azure, or building a migration business case: TCO Calculator. Estimating the cost of specific Azure resources: Pricing Calculator. Seeing what you actually spent: Cost Management. Neither calculator needs a subscription.
- Budgets alert; they do not stop spending by themselves. Tags are not inherited by default; use Azure Policy to require or inherit them. Cost Management shows actual and forecast spending, unlike the calculators, which only estimate.
- Finding, classifying and tracing lineage of your own data across locations: Microsoft Purview. Downloading Microsoft's compliance and audit reports such as ISO or SOC: Service Trust Portal. Microsoft's certifications cover only Microsoft's side of shared responsibility.
- Policy is about what is allowed (configuration); RBAC is about who can act. An initiative groups definitions; an assignment applies them to a scope. Deny blocks non-compliant changes; Audit only reports them. Policies apply even to Owners.
- CanNotDelete still allows changes; ReadOnly blocks changes and deletion. Locks apply even to Owners and are inherited by child resources, with the most restrictive lock winning. To delete a locked resource, remove the lock first.
- Commands starting with az are Azure CLI; Verb-AzNoun cmdlets such as Get-AzVM are Azure PowerShell. Cloud Shell needs no local installation and supports both Bash and PowerShell. Every tool goes through Azure Resource Manager.
- Arc manages resources where they are; it does not move them. If the scenario says 'apply Azure Policy to on-premises or other-cloud servers' or 'manage hybrid and multicloud from one place', the answer is Azure Arc. Moving workloads into Azure is Azure Migrate.
- Every tool, including the portal, goes through Azure Resource Manager. ARM templates are JSON and declarative; Bicep is a simpler language that compiles to ARM JSON. Declarative means you describe the end state; idempotent means redeploying gives the same result.
- Recommendations to improve your resources: Advisor. Global outage page for everyone: Azure status. Outages, maintenance and advisories affecting your services and regions: Service Health. Health of one specific resource: Resource Health.
- Metrics are numbers over time; logs are detailed records queried with KQL in Log Analytics. Application Insights monitors applications (requests, exceptions, dependencies), not just infrastructure. Alerts use action groups to notify or automate.
Key terms
- Pay-as-you-go
- Paying only for the resources you consume, with no upfront commitment.
- Azure Reservations
- A one-year or three-year commitment to a specific resource in return for a discounted rate.
- Azure savings plan for compute
- A commitment to a fixed hourly spend across eligible compute services in exchange for lower prices.
- Spot virtual machine
- A VM using spare capacity at a low price that can be evicted when Azure needs the capacity.
- Ingress and egress
- Data entering Azure (generally free) and data leaving Azure (billed).
- Azure Hybrid Benefit
- Using existing Windows Server, SQL Server or some Linux licenses on Azure to reduce cost.
- Deallocate
- Stopping a VM so its compute resources are released and compute billing stops.
- Azure Pricing Calculator
- A free web tool that estimates the cost of specific Azure services you plan to deploy.
- Total Cost of Ownership (TCO) Calculator
- A free web tool that compares on-premises infrastructure costs with running the same workloads in Azure.
- Estimate
- A projected cost based on your inputs, not a binding price or actual bill.
- Assumptions
- TCO inputs such as electricity cost, labor rates and datacenter space that shape the savings report.
- Business case
- A justification for a project, often built with the TCO Calculator for migrations.
- Microsoft Cost Management
- The service that reports actual and forecast Azure spending, unlike the calculators.
- Cost analysis
- The Cost Management view for exploring, grouping and filtering costs and forecasts.
- Budget
- A spending amount for a scope and period that triggers alerts at chosen thresholds.
- Budget alert
- A notification sent when actual or forecast cost crosses a budget threshold.
- Action group
- An Azure Monitor collection of notifications and automated actions triggered by alerts.
- Tag
- A name-value pair applied to resources, resource groups or subscriptions to organize and report on them.
- Chargeback
- Allocating cloud costs back to the departments or projects that incurred them.
- Data governance
- Knowing what data you have, where it is and how it is used, and applying rules to it.
- Microsoft Purview
- A family of solutions for data governance, risk and compliance across on-premises, multicloud and SaaS data.
- Data lineage
- A record of where data originated and how it moved and changed across systems.
- Data classification
- Automatically identifying and labeling data by type or sensitivity, such as credit card numbers.
- Data loss prevention (DLP)
- Policies that detect and prevent sensitive data from leaving the organization.
- Service Trust Portal
- Microsoft's site for audit reports, compliance documents and information about how Microsoft cloud services protect data.
- Audit report
- An independent assessment showing that a service meets a standard such as ISO/IEC 27001 or SOC 2.
- Azure Policy
- A service that enforces rules on resource configurations and reports compliance across scopes.
- Policy definition
- A JSON rule describing a condition and the effect to apply when a resource matches.
- Effect
- The action a policy takes, such as Deny, Audit, Modify or DeployIfNotExists.
- Initiative (policy set)
- A group of related policy definitions managed and assigned as one unit.
- Assignment
- The application of a definition or initiative to a scope, with parameters and optional exclusions.
- Compliance state
- Whether a resource meets the assigned policies, shown on the Compliance page.
- Remediation task
- A job that brings existing non-compliant resources into compliance using Modify or DeployIfNotExists.
- Resource lock
- A setting that prevents a resource from being deleted or modified regardless of the user's role.
- CanNotDelete
- A lock level that allows reading and modifying a resource but blocks deletion.
- ReadOnly
- A lock level that allows reading a resource but blocks updates and deletion.
- Lock inheritance
- A lock at a subscription or resource group applies to all resources within it, including new ones.
- Control plane
- Management operations on resources handled by Azure Resource Manager, which locks affect.
- Data plane
- Operations on the data inside a resource, such as reading or writing blobs, which locks do not block.
- Azure portal
- A web-based graphical console for creating, managing and monitoring Azure resources.
- Azure Cloud Shell
- A browser-based, pre-authenticated shell offering Bash or PowerShell with Azure tools preinstalled.
- Azure CLI
- A cross-platform command-line tool for Azure whose commands begin with az.
- Azure PowerShell
- The Az PowerShell module providing Verb-AzNoun cmdlets for managing Azure.
- Cmdlet
- A PowerShell command following a Verb-Noun pattern, such as Get-AzVM.
- Azure mobile app
- A phone app for monitoring Azure resources and running quick actions.
- Azure Resource Manager
- The management layer that every Azure tool sends its requests through.
- Azure Arc
- A service that extends Azure management and governance to resources running outside Azure.
- Arc-enabled servers
- Windows or Linux machines outside Azure that are projected into Azure Resource Manager for management.
- Connected Machine agent
- The lightweight agent installed on a server to connect it to Azure Arc.
- Arc-enabled Kubernetes
- Kubernetes clusters running anywhere that are connected to Azure for management and configuration.
- Hybrid cloud
- An environment that combines on-premises infrastructure with public cloud services.
- Multicloud
- Using services from more than one public cloud provider.
- Single pane of glass
- One console and toolset for managing resources across many environments.
- Azure Resource Manager (ARM)
- The deployment and management layer that processes every request to create, change or delete Azure resources.
- Resource provider
- An Azure service, such as Microsoft.Compute, that supplies a type of resource through Resource Manager.
- Infrastructure as code (IaC)
- Defining and deploying infrastructure from code files kept in source control.
- ARM template
- A JSON file that declaratively defines Azure resources to deploy.
- Bicep
- A concise Microsoft language for declarative Azure deployments that transpiles to ARM JSON.
- Declarative
- Describing the desired end state and letting the platform work out the steps.
- Idempotent
- Producing the same result no matter how many times a deployment is run.
- Configuration drift
- Environments that should match gradually becoming different through manual changes.
- Azure Advisor
- A free service that gives personalized best-practice recommendations for your Azure resources.
- Advisor categories
- Reliability, security, performance, operational excellence and cost.
- Advisor score
- A percentage showing how well your resources follow Advisor's recommendations.
- Azure status
- A public page showing widespread Azure outages across all regions.
- Service Health
- A personalized portal view of issues, planned maintenance and advisories for the services and regions you use.
- Resource Health
- A view of the current and past health of an individual resource and whether a platform event caused a problem.
- Health advisory
- A Service Health notice about changes that may require action, such as a feature retirement.
- Azure Monitor
- The platform for collecting, analyzing and acting on telemetry from Azure, on-premises and other clouds.
- Metrics
- Numeric values sampled at regular intervals, ideal for charts and fast alerts.
- Logs
- Detailed event records with rich properties, stored in a Log Analytics workspace.
- Log Analytics
- The portal tool for querying log data with Kusto Query Language (KQL).
- Alert rule
- A definition of the scope, condition and severity that triggers an alert.
- Application Insights
- An Azure Monitor feature for application performance monitoring of live web apps.
- Activity log
- A subscription-level log of management operations, showing who did what and when.
Study Azure Fundamentals for free
Lessons, quizzes, exam simulations and hands-on labs.
Open the Azure Fundamentals study planLessons, quizzes, exam simulations and hands-on labs.