Skip to content
GetHandsOn.ai

AI-901 Study Guide


Module 1 of 835 min read

Introduction to AI and Azure

Start here. This chapter covers what AI actually is, the six core AI workloads tested in AI-901, the principles of responsible AI, what Microsoft Azure is, and how Microsoft Foundry brings it all together as the platform for building AI solutions.

These study notes summarise Microsoft Learn material for Exam AI-901. For the official skills measured, see the Microsoft Learn study guide for Exam AI-901.

On this pageShow

What Is Artificial Intelligence?

Artificial intelligence (AI) is software that imitates human-like behaviors such as understanding language, recognizing images, making decisions, and learning from data. Unlike traditional software that follows explicit instructions you write, AI systems learn patterns from large volumes of data and use those patterns to produce useful outputs.

Most modern AI is built on machine learning, where a model is trained on examples rather than hard-coded rules. Given enough quality data, the model learns to recognize patterns and generalize to new inputs it has never seen before.

This distinction matters for the exam: AI is not a single thing. It is a collection of capabilities, each suited to different problems. Microsoft's AI-901 certification is built around six of those capabilities, called workloads. Let's meet all six now so you have the full map before we explore each one in depth.


The Six Core AI Workloads

The AI-901 exam is organized around six core AI workloads. Each represents a distinct type of thing AI can do, and each has dedicated services in Microsoft Azure to support it. In this section you get a quick overview of all six. Every module after this one covers a single workload in full depth, so think of this as orientation before you start.

1. Generative AI and Agents

Generative AI creates new content, such as text, images, code, and audio, in response to natural language instructions called prompts. The models behind this capability are called large language models (LLMs), trained on vast amounts of text to understand and generate human-like language.

Small language models (SLMs) are more compact versions suited for specific tasks or environments where compute is limited (such as mobile devices).

AI agents take generative AI further. An agent is an application that can respond to questions and also take actions to complete a goal. An agent has three core components:

  • A model - the LLM that provides reasoning and language understanding
  • Instructions - a system prompt that defines the agent's role, constraints, and behavior
  • Tools - capabilities the agent can invoke, such as searching the web, querying a database, sending emails, or calling an API

Multiple agents can work together in multi-agent systems, where each agent specializes in a particular task and they collaborate to complete complex workflows. For example, an automated travel booking system might use one agent to search for available flights, a second agent to check hotel availability for the same dates, and a third agent to compare prices and generate a full itinerary summary for the user, all without a human involved in each step.

2. Natural Language Processing (NLP)

Natural language processing covers AI techniques that analyze and understand human language. NLP forms the foundation of generative AI but also powers more focused text analysis tasks:

  • Sentiment analysis - determining whether text expresses positive, negative, or neutral emotion. For example, an e-commerce platform like Amazon automatically tags customer reviews as positive or negative to surface product ratings at scale.
  • Named entity recognition (NER) - identifying and classifying entities in text such as people, organizations, and locations. For example, a flight booking chatbot extracts "London" and "next Tuesday" from a user's message so it knows where and when to search.
  • Language detection - identifying which language a piece of text is written in
  • Summarization - condensing long documents into key points
  • PII detection - identifying personally identifiable information like names, addresses, and phone numbers. For example, a hospital system automatically redacts patient names and ID numbers from documents before sharing them with external researchers.

3. Speech

AI speech capabilities enable machines to work with spoken language in two directions:

  • Speech recognition (speech-to-text) - transcribing spoken words into written text. For example, Microsoft Teams uses this to generate live captions during meetings, making conversations accessible to participants with hearing disabilities.
  • Speech synthesis (text-to-speech) - converting written text into natural-sounding spoken audio. For example, a virtual assistant reads your calendar reminders aloud, or an audiobook platform narrates articles without a human voice actor.

Real-time speech translation combines both: recognizing speech in one language and synthesizing the output in another. A presenter speaking English in a global call can be heard in French, German, or Japanese by other participants simultaneously.

4. Computer Vision

Computer vision enables AI to interpret and understand visual information from images and video. Key tasks include:

  • Image classification - identifying the primary subject of an image. For example, a manufacturing quality control system classifies each item on a production line as "pass" or "defect" by analysing a photo taken at the end of the line.
  • Object detection - identifying and locating multiple objects within an image, with bounding boxes around each one. For example, self-driving cars use object detection to simultaneously identify pedestrians, traffic lights, and other vehicles in real time.
  • Semantic segmentation - classifying each individual pixel in the image by the object it belongs to, providing a more precise map of what is where
  • Multimodal analysis - using models trained on both images and text to generate natural language descriptions of images, answer questions about visual content, or understand scenes in context

Modern vision models can also generate images from text descriptions using a process called diffusion, where the model starts from noise and progressively refines an image until it matches the prompt. For example, a product designer types a description of a new sneaker and the model generates several photorealistic mockups in seconds.

5. Information Extraction

Information extraction automates the process of pulling structured data from unstructured sources such as scanned forms, receipts, invoices, contracts, photographs, and even audio or video recordings. The process typically involves two stages:

  1. Optical character recognition (OCR) - a computer vision technique that identifies and reads text in an image
  2. Field mapping - AI that interprets the extracted text and maps individual values to meaningful data fields (for example, matching text on a receipt to "vendor name", "date", and "total amount")

A concrete example: a company receives thousands of paper supplier invoices each month. Instead of having staff manually key in each invoice, Azure Document Intelligence scans every document, automatically extracts the vendor name, invoice date, line items, and total amount, and feeds them directly into the accounting system, reducing processing time from days to minutes.

This capability is used in expense processing, document digitization, healthcare record management, and any workflow where paper-based or spoken information needs to enter a digital system automatically. Module 7 covers how this extends to audio recordings and video, extracting transcripts, speaker labels, and topics from meeting recordings or call center logs.

6. Responsible AI

Responsible AI is not a technical capability but a set of principles that guide how AI should be designed, built, and operated. Microsoft defines six principles:

PrincipleWhat It MeansReal-World Example
FairnessAI should treat all people equitably. Biased training data can produce discriminatory outputs.A facial recognition system trained mostly on lighter-skinned faces performs significantly worse on darker skin tones, a fairness failure that can cause real harm if used in security or law enforcement.
Reliability and SafetyAI models are probabilistic and can make mistakes. Systems must include safeguards proportional to the risk of errors.A medical diagnosis AI must flag its confidence level and always recommend a human doctor review the result, because an incorrect diagnosis carries serious consequences.
Privacy and SecurityTraining data and model outputs must protect personal information. Models must not expose sensitive data.A customer service chatbot should never surface another customer's order history, even if a clever prompt tries to extract it.
InclusivenessAI benefits should be accessible to everyone, not restricted to certain groups or abilities.A speech recognition system should work equally well for users with accents or speech impediments, not just for one dialect.
TransparencyUsers should understand what an AI system is, how it works, and what its limitations are.A bank's loan-decision AI must be able to explain why a loan was denied, "insufficient income relative to debt", rather than giving an unexplained rejection.
AccountabilityOrganizations that develop and deploy AI are responsible for its outcomes and must implement governance frameworks.If an AI hiring tool inadvertently screens out qualified candidates from a particular demographic, the company that deployed it is responsible for identifying and correcting the bias.

These six principles recur throughout the entire exam. They appear not just as a standalone topic but woven into every workload, you will be asked how fairness applies to computer vision, how reliability applies to speech recognition, and how accountability shapes how you deploy agents. Module 8 brings all of this together with detailed scenarios and the Azure tools that implement each principle in practice.

The rest of Module 1 covers three things that apply across all six workloads: the platform where everything gets built (Azure), the dedicated AI development environment within it (Foundry), and the practical tools for responsible and secure deployment. Modules 2 through 7 then go deep on each workload in turn, and Module 8 brings the responsible AI principles back together as a capstone.


What Is Microsoft Azure?

You now know what the six AI workloads are. The natural next question is: where do you actually build them? The AI-901 exam is specifically about AI on Microsoft Azure, Microsoft's cloud computing platform and the environment where every service covered in this guide lives.

This is important to understand from the start: AI-901 is not a purely conceptual exam. It tests whether you know which Azure service implements each workload, how those services connect to each other, and how they are configured and secured. That means understanding Azure itself is essential, not just the AI theory.

Microsoft Azure is one of the world's leading cloud computing platforms. Instead of buying and maintaining physical servers, you rent computing resources over the internet and pay for what you use. For AI specifically, Azure provides the infrastructure, the storage, the networking, and the managed AI services that together turn an idea into a running application.

Every workload you just read about maps to one or more Azure services:

WorkloadKey Azure Service(s)
Generative AI and AgentsMicrosoft Foundry (model catalog, agent builder)
Natural Language ProcessingAzure AI Language
SpeechAzure AI Speech
Computer VisionAzure AI Vision
Information ExtractionAzure Document Intelligence, Azure Content Understanding
Safety and MonitoringAzure AI Content Safety, Foundry evaluators

How Azure Is Organized

Before you start provisioning AI services, you need to understand how Azure structures everything. Resources live inside a hierarchy of five levels:

  1. Azure Tenant - your organization's top-level identity in Azure, managed through Microsoft Entra ID (formerly Azure Active Directory). Think of it as your company's account with Microsoft - everything else exists within it.
  2. Management Group - a container for organizing multiple subscriptions together within a tenant. It allows you to apply governance policies (like Azure Policy and RBAC) across subscriptions at scale. Every tenant has a root management group, and you can nest child management groups beneath it.
  3. Subscription - a billing and access boundary linked to a payment method, with quotas and access controls. An organization can have multiple subscriptions.
  4. Resource Group - a logical folder that groups related Azure resources together for easier management, billing, and access control.
  5. Resource - any individual Azure service you create, such as a storage account, database, virtual machine or AI service.

You manage all of this through the Azure portal, a web-based interface for creating, configuring, and monitoring everything in your Azure environment.

Knowing this hierarchy matters for the exam because questions about access control, cost management, and deployment all reference it.

Now that you understand how Azure is organized, let's look at the specific environment Microsoft built for AI development within it.


Microsoft Foundry: Azure's AI Development Platform

Azure is your cloud infrastructure. Microsoft Foundry is the specialized workspace Microsoft built within Azure specifically for AI. Instead of navigating dozens of separate Azure services to build an AI application, Foundry brings everything you need into one unified environment.

Think of Azure as a city with many districts. Foundry is the AI district: a place where models are deployed, agents are assembled, data is connected, and applications are tested and shipped. When the exam refers to building, deploying, or evaluating AI on Azure, it almost always means working within Foundry.

Foundry has four main components:

Models

Foundry's model catalog gives you access to thousands of AI models from a wide range of providers, including Microsoft, OpenAI (GPT family), Anthropic (Claude), Mistral, Meta (Llama), DeepSeek, and many more.

Models in Foundry can be deployed with two billing types:

  • Standard deployments - pay-as-you-go per token. Shared capacity, suitable for development and variable workloads.
  • Provisioned deployments - reserved capacity for consistent throughput at high volume.

Foundry organizes everything into two resource levels:

  • Foundry resource - the parent Azure resource (created in your subscription) that provides the cloud infrastructure and shared endpoint for your AI services.
  • Foundry project - a dedicated workspace within a Foundry resource where you deploy models, build agents, connect data sources, and manage assets for a specific AI application.

Agents

The Foundry Agent Builder is where you create AI agents without writing custom orchestration code. You define the agent's instructions (a system prompt), connect tools (such as Bing search, your own APIs, or Azure AI Search), and choose the underlying model. Foundry handles the conversation loop and tool invocations automatically.

Foundry Tools

Foundry Tools are the supporting capabilities that make AI applications production-ready:

  • Playground - test models and prompts interactively before writing any code
  • Prompt flow - build and visualize multi-step AI workflows
  • Evaluation - test model outputs for quality, safety, and relevance using automated evaluators
  • Fine-tuning - adapt a model to your specific domain using your own training data

Foundry IQ is Foundry's implementation of retrieval-augmented generation (RAG), a technique where the model retrieves relevant information from your own data sources before generating a response. This ensures responses are grounded in your organization's documents rather than relying solely on the model's training knowledge.

Foundry IQ connects to Azure AI Search to index and query documents, product catalogs, knowledge bases, and other structured or unstructured data.

Foundry makes building powerful AI accessible. With that power, however, comes responsibility. Security is where that starts. Let's look at how to protect what you build.


Securing AI Applications on Azure

Deploying an AI application on Azure means putting a real service on the internet. That service processes user data, calls external APIs, and may produce outputs that influence real decisions. Proper security is not optional, it is a prerequisite for production.

Security for Azure AI applications has three layers: identity and access management, secrets management, and hosting and scaling.

Exam focus: AI-901 directly tests API key vs. managed identity (Entra ID) authentication and recognising Azure Key Vault as the secrets management service. The detailed Entra ID and Key Vault workflows and the hosting/scaling section (AKS, App Service) are real-world context - useful to read once, but not tested as AI-901 exam objectives.

Identity and Access Management with Microsoft Entra ID

Microsoft Entra ID (formerly Azure Active Directory) is Azure's identity platform. Every person, application, and service that accesses Azure resources must authenticate through Entra ID.

For AI applications, this means:

  • Users authenticate through Entra ID before accessing your application
  • Applications use managed identities (not hardcoded credentials) to authenticate to Azure services
  • Role-Based Access Control (RBAC) determines what each identity is permitted to do

RBAC assigns roles at the resource, resource group, or subscription level. Common roles for AI applications include Reader (view only), Contributor (create and manage resources), and specific roles like Azure AI Developer (for Foundry operations). The principle of least privilege applies: each identity should have only the permissions it needs, nothing more.

API Keys and Azure Key Vault

Many Azure AI services authenticate via API keys, secret strings that grant access to a service endpoint. These keys must be protected carefully.

A common real-world mistake: a developer accidentally pushes an API key into a public GitHub repository. Within minutes, automated bots scan the repo, find the key, and begin making requests against the service, racking up costs or exposing sensitive data. Azure Key Vault exists specifically to prevent this.

Azure Key Vault is the Azure service for storing and managing secrets, certificates, and cryptographic keys. The correct workflow for API key management is:

  1. Store the API key as a secret in Key Vault
  2. Grant the AI application access to Key Vault via its managed identity
  3. At runtime, the application retrieves the key from Key Vault and uses it to authenticate requests to the model endpoint
  4. The key is never written to a config file or environment variable in plain text

This pattern ensures that secrets are auditable, rotatable, and protected from accidental exposure in code repositories.

Hosting and Scaling AI Applications

Background context only: AKS and App Service are Azure infrastructure services covered in AZ-900 and AZ-204. They are included here so you understand how AI applications reach production, but AI-901 does not test them directly.

AI applications deployed to production need reliable, scalable hosting. Two common Azure services for this are:

  • Azure Kubernetes Service (AKS) - orchestrates containerized workloads, automatically managing multiple instances of your application as demand changes
  • Azure App Service - a managed platform for hosting web applications and APIs without managing the underlying servers

Both support auto-scaling: automatically adding or removing compute instances based on traffic, CPU usage, or request volume. This matters for AI applications, which can have highly variable usage patterns, a customer service chatbot might receive 10 requests per minute at 3am and 10,000 at 9am.

Scaling out (horizontal scaling) adds more instances of the application. Scaling up (vertical scaling) moves to a larger compute size. For most AI applications, scaling out is preferred because it provides resilience, if one instance fails, others continue to serve traffic.

There is also the question of rate limits. Azure AI services are governed by tokens per minute (TPM) quotas. If your application exceeds its quota, requests are throttled with a 429 error. You can request quota increases through the Azure portal or design your application with retry logic and backoff to handle throttling gracefully.

Securing your infrastructure protects the application itself. But there is another dimension of responsible AI that deserves its own section: what about the content your AI actually generates?


Responsible AI in Practice: Content Safety

Microsoft's six responsible AI principles tell you what to aim for. Content safety tools are what you reach for in Foundry to actually enforce them in a running application.

When you deploy a model in Foundry, your application is processing real user inputs and generating real outputs. Without safeguards, a generative AI application can produce harmful, biased, or inappropriate content, not because the model is defective, but because language models are designed to be helpful and will follow instructions, including harmful ones. Content safety is how you prevent that.

Content Filters

Content filters in Foundry act as a safety layer that inspects both inputs (what users send to the model) and outputs (what the model generates) for potentially harmful content. They prevent AI applications from producing or processing:

  • Hate speech and discriminatory content
  • Sexual content
  • Violent or graphic content
  • Content that encourages self-harm
  • Content related to weapons or illegal activity

In Microsoft Foundry, content filtering is applied by default to all deployed models. The filters evaluate content across multiple categories and severity levels, and you can configure thresholds based on your application's needs. For example, a medical information application may need stricter filters than a creative writing tool.

Safety Evaluators in Foundry

Beyond content filters on live traffic, Foundry also provides safety evaluators in its evaluation framework. These are components you use during development and testing to scan model outputs for harmful content, bias, unfairness, and other safety issues before the application goes to production.

Safety evaluators detect and flag:

  • Hateful or unfair content targeting specific groups
  • Sexually explicit or violent content
  • Self-harm-related content
  • Hallucinations and factual inaccuracies
  • Jailbreak vulnerabilities (where carefully crafted prompts bypass safety instructions). For example, a user might phrase a request to make the model ignore its instructions and reveal its system prompt, a safety evaluator catches this class of attack before the app goes live.

Running safety evaluators as part of your development workflow is how responsible AI principles get applied in practice, before users ever interact with your application.

The Responsible AI Lifecycle

Content safety tools fit into a broader responsible AI lifecycle that spans the entire development process:

PhaseResponsible AI Activity
DesignDefine fairness requirements; identify affected groups; document intended use
DevelopmentUse diverse, representative training data; apply bias detection; document model limitations
TestingRun safety evaluators; red-team the application; test edge cases
DeploymentConfigure content filters; apply least-privilege access
OperationMonitor outputs; audit for unexpected behaviors; maintain human oversight

The key exam insight: content filters address the reliability and safety and fairness principles at the output level. But responsible AI also requires privacy protections (how data is stored), inclusiveness (does the interface work for all users?), transparency (are users told they are using AI?), and accountability (who is responsible when something goes wrong?).



Using Azure AI Services

Throughout this guide, specific services appear for each workload: Azure AI Vision for computer vision, Azure AI Speech for speech, Azure AI Language for NLP, and so on. Before you start building with any of them, you need to understand what these services actually are in Azure terms, how you provision them, and how your application connects to them.

Resource Types: Multi-Service vs Single-Service

Azure AI Services come in two forms:

A multi-service resource (called Azure AI Services) is a single Azure resource that gives you access to a broad set of AI capabilities under one endpoint and one set of API keys. If your application needs to use language, vision, and speech capabilities together, a multi-service resource is more convenient to manage.

Single-service resources are dedicated resources for a specific capability, such as a standalone Azure AI Vision resource or a standalone Azure AI Language resource. These are useful when you want to isolate billing, apply different access controls, or work only with one service.

For the exam, you need to know that both options exist and when each makes sense. A single-service resource gives you finer-grained control; a multi-service resource simplifies management.

Provisioning an Azure AI Service

You provision Azure AI services the same way you provision any Azure resource: through the Azure portal at portal.azure.com, using the Azure CLI, or using an Infrastructure-as-Code tool like Bicep or Terraform.

The key choices during provisioning are:

  • Resource group: which logical container this resource belongs to
  • Region: which Azure data center hosts the service. Not every model or feature is available in every region.
  • Pricing tier: most services offer a Free tier (F0) with limited calls per minute (typically 20 transactions per minute or per second), and a Standard tier (S0) with higher limits billed per usage. For production applications, you almost always need the Standard tier.

Endpoints and API Keys

Once a resource is provisioned, Azure generates two things automatically:

An endpoint: a URL that your application sends requests to. It looks something like https://your-resource-name.cognitiveservices.azure.com/. Every API call you make goes to this endpoint.

API keys: two secret keys (Azure provides two so you can rotate them without downtime) that authenticate your requests. You include one of these keys in the header of every API call.

The correct way to handle API keys in production is the pattern covered in the security section earlier: store them in Azure Key Vault and retrieve them at runtime using a managed identity, never hardcoding them in your application code.

Entra ID Authentication

As an alternative to API key authentication, Azure AI services also support authentication via Microsoft Entra ID tokens. Applications that run on Azure infrastructure (App Service, Azure Kubernetes Service, Azure Functions) can use a managed identity to authenticate directly without any stored secret. The application requests a short-lived token from Entra ID and presents it with each API call. This is the recommended approach for production because there is no secret to rotate or accidentally expose.

What This Means for the Exam

The exam tests whether you know how applications connect to Azure AI services. The key facts to have ready are: every Azure AI service has an endpoint and API keys; the endpoint is the URL your application calls; the keys authenticate requests; for production workloads you use Azure Key Vault or managed identity to avoid hardcoding secrets; and the region you choose determines feature availability and latency.

๐Ÿ”’ Hands-On Lab - Lab 1: Set Up Meridian's AI Foundation You now understand what Foundry is and how Azure AI services are structured. In Lab 1 you create a real Foundry project, use the portal to deploy your first language model, and configure it with a system prompt - all in a live Azure environment. Already enrolled? Labs are launching shortly - stay tuned!. New here? Get the AI-901 Lab Bundle โ†’

Key Takeaways for the Exam

  • AI is software that learns from data to perform tasks that would normally require human intelligence.
  • The six core AI workloads in AI-901 are: generative AI and agents, NLP, speech, computer vision, information extraction, and responsible AI.
  • Responsible AI has six principles: fairness, reliability and safety, privacy and security, inclusiveness, transparency, and accountability.
  • Azure organizes resources as: tenant > subscription > resource group > resource.
  • Microsoft Foundry is the unified AI development platform within Azure, it includes the model catalog, agent builder, Foundry Tools (playground, evaluation, fine-tuning), and Foundry IQ (RAG).
  • The difference between a Foundry resource and a Foundry project: a Foundry resource is the parent Azure resource that provides the shared infrastructure; a Foundry project is the workspace within it where you build, deploy, and manage a specific AI application.
  • Microsoft Entra ID manages identity and access; RBAC controls what each identity can do; Azure Key Vault stores secrets.
  • Content filters apply responsible AI principles to live traffic; safety evaluators apply them during testing and development.
  • Every Azure AI service has an endpoint (URL) and API keys. Multi-service resources bundle multiple capabilities; single-service resources are dedicated to one. Free tier (F0) is for development; Standard tier (S0) is for production.

Official exam information from Microsoft

Get the full AI-901 study guide as a PDF, freeAll 8 modules in one printable file. Enter your email on the guide page and it is yours.

Keep going

Get the full AI-901 guide as a PDFEvery module in one file. Free after you enter your email.
Practice AI-901 questionsExam-style questions with explanations, free to start.
Hands-on AI-901 labsApply this in a real Azure environment.
AI-901 guide overviewAll modules, pick what to read next.