StudyToCert

All certifications / Azure Fundamentals / Lessons

Microsoft Certified: Azure Fundamentals AZ-900 · Domain 1: Describe cloud concepts

What cloud computing is, and the shared responsibility model across on-premises, IaaS, PaaS and SaaS

▶ Watch the overview video

Last reviewed September 30, 2026 · Leer en español

Cloud computing is the delivery of computing services, such as servers, storage, databases, networking, analytics and software, over the internet from a provider's datacenters. Instead of buying and running your own hardware, you rent capacity from a provider like Microsoft Azure, create it in minutes, and pay only for what you use. The provider owns the buildings, power, cooling and physical machines; you get virtual resources on top of them. For the Microsoft Azure Fundamentals exam (AZ-900), this is the starting point for everything else: the benefits of the cloud, the service types and the pricing all follow from the idea that someone else runs the physical layer.

On-premown DCIaaSEC2, VMPaaSRDS, App SvcSaaSM365Data and accessYouYouYouYouApplicationsYouYouYouProviderRuntimeYouYouProviderProviderOperating systemYouYouProviderProviderVirtualizationYouProviderProviderProviderServers, storageYouProviderProviderProviderNetworkingYouProviderProviderProviderDatacenterYouProviderProviderProviderYou: security in the cloudProvider: of the cloudYour data, identities and access are always yours
Shared responsibility model: on-premises, IaaS, PaaS and SaaS

Moving to the cloud does not mean handing over all responsibility. The shared responsibility model describes which tasks belong to the cloud provider and which stay with you, the customer. The split depends on the service type you choose. Picture a stack of layers from the bottom up: physical datacenter, physical network, physical hosts, operating system, network controls, applications, identity and directory infrastructure, accounts and identities, devices, and finally information and data. In an on-premises datacenter you own every layer, from the locks on the doors to the backups of your data.

With infrastructure as a service (IaaS), such as Azure virtual machines, Microsoft takes over the physical layers: the datacenter, the physical network and the physical hosts, including the hypervisor that runs your virtual machines. You still manage the guest operating system and its patches, the applications, network controls such as the firewall and network security group rules you configure, identities and data. With platform as a service (PaaS), such as Azure App Service or Azure SQL Database, Microsoft also runs the operating system and runtime, so you focus on your application code, its configuration and your data. With software as a service (SaaS), such as Microsoft 365, Microsoft runs the whole application, and you mainly configure its settings and manage who uses it.

Some responsibilities never move to the provider, whichever service type you pick. You always own your information and data, the devices (laptops and phones) that connect to the service, and the accounts and identities that sign in. If an employee's password is stolen, or someone shares sensitive files publicly, that is the customer's problem in every model. Likewise, some responsibilities always belong to the provider once you are in the cloud: the physical hosts, the physical network and the physical datacenter. The layers in between, such as the operating system, network controls, applications and identity infrastructure, shift from you toward Microsoft as you move from IaaS to PaaS to SaaS, and in PaaS several of them are shared, because Microsoft provides the controls and you configure them.

A helpful way to remember the model is that the line between 'provider manages' and 'you manage' moves up the stack as you go from on-premises to IaaS to PaaS to SaaS. The more the provider manages, the less control you have and the less operational work you do. That is a trade-off rather than a ranking: a team that needs a custom kernel setting wants IaaS, while a team that just wants email wants SaaS.

Consider a worked example. A retailer runs three workloads: a legacy inventory application on an Azure VM, a new ordering website on App Service, and staff email in Microsoft 365. A critical Windows security update is released. For the VM, the retailer's own administrators must apply it to the guest OS, for example with Azure Update Manager or inside the machine. For App Service, Microsoft patches the underlying OS and the retailer does nothing at that layer. For Microsoft 365, Microsoft patches everything. The next week, a sales manager falls for a phishing email and gives away a password. In all three workloads, protecting that account, for instance by requiring multifactor authentication, is the retailer's job.

Common mistakes: believing that moving to the cloud makes the provider responsible for data breaches caused by weak passwords or oversharing; assuming Microsoft patches the operating system inside an IaaS virtual machine; and thinking SaaS means you have no responsibilities at all. Another trap is treating 'the cloud' as a single model, when the split is different for every service you use.

Exam questions are usually worded as 'who is responsible for' a named task in a named service type. 'Physical security of the datacenter', 'physical hosts' or 'the hypervisor' is always Microsoft. 'Patching the operating system of a virtual machine' is the customer in IaaS. 'Information and data', 'devices', 'accounts and identities' is always the customer. If the scenario says the customer wants the least management effort, look for SaaS; if it says the most control, look for IaaS or on-premises.

Key terms

Cloud computing
Delivering computing services such as servers, storage, databases and software over the internet on demand.
Shared responsibility model
The division of security and management tasks between the cloud provider and the customer, which depends on the service type.
Infrastructure as a service (IaaS)
A service type where the provider runs the physical infrastructure and you manage the operating system and everything above it.
Platform as a service (PaaS)
A service type where the provider also manages the operating system and runtime, and you manage your application and data.
Software as a service (SaaS)
A complete application run by the provider that you configure and use, such as Microsoft 365.
On-premises
Infrastructure you own and run in your own datacenter, where you are responsible for every layer.
Hypervisor
The software on a physical host that runs virtual machines; in Azure it is always Microsoft's responsibility.
Real-world example

A clinic moves its scheduling server to an Azure VM and assumes Microsoft now handles security. Months later an audit finds the guest OS unpatched and several staff accounts without multifactor authentication. The auditor explains the shared responsibility model: Microsoft secures the physical hosts and datacenter, but in IaaS the clinic still patches the operating system, and in every model it protects its own accounts and patient data.

Exam tip: Physical hosts, physical network, the datacenter and the hypervisor are always Microsoft's. Data, devices, accounts and identities are always yours. The guest OS is yours in IaaS and Microsoft's in PaaS and SaaS.

Check yourself

In IaaS, who applies security patches to the virtual machine's operating system?

The customer, because in IaaS Microsoft manages only the physical layers and the hypervisor, not the guest OS.

Name the responsibilities that stay with the customer in every service type.

Information and data, devices (endpoints), and accounts and identities, because only the customer controls what is stored and who signs in.

Which service type gives the customer the least management responsibility?

SaaS, because the provider runs the infrastructure, platform and application; the customer mainly configures it and manages users and data.

Why does moving from IaaS to PaaS reduce patching work?

In PaaS Microsoft manages the operating system and runtime, so the customer no longer patches them and focuses on the application and data.

Study Azure Fundamentals for free
A week-by-week plan with every lesson, quizzes, checkpoint tests, a practice exam and hands-on labs.
Open the Azure Fundamentals study plan