AZ-900 Study Guide
Module 2 of 118 min read
Azure Architecture & Core Concepts
Explore how Azure is physically organized with Regions, Availability Zones, and Region Pairs, and understand the logical resource hierarchy.
These study notes summarise Microsoft Learn material for Exam AZ-900. For the official skills measured, see the Microsoft Learn study guide for Exam AZ-900.
On this pageShow
This module explains the physical and logical structure of Microsoft Azure. We'll cover how Azure's global infrastructure is organized into Geographies, Regions, and Availability Zones to provide resilience and low latency. You'll also learn the critical four-level hierarchy for managing all your Azure resources, from Management Groups down to individual services.
Azure Regions, Geographies, and Availability Zones
Azure's global footprint is built on a hierarchy of physical locations designed for high availability, low latency, and data residency.
Geographies
A geography is a discrete market, typically containing two or more Azure regions, that preserves data residency and compliance boundaries. Data in a geography (e.g., Europe) stays within that geography, which is critical for meeting regulatory requirements like GDPR.
Regions
An Azure region is a geographic area on the planet containing one or more data centers that are networked together with a low-latency network. When you deploy a resource like a virtual machine, you must choose a region for it.
- Azure has more global regions (60+) than any other cloud provider.
- Choosing the right region impacts latency to your users, service availability, cost, and data residency compliance.
Region Pairs
Most Azure regions are paired with another region within the same geography, at least 300 miles away. This pairing is designed for disaster recovery.
| Region Pair Benefit | What It Means for You |
|---|---|
| Staggered Updates | Microsoft updates one region in a pair at a time, preventing simultaneous outages from planned maintenance. |
| Priority Recovery | In the event of a broad outage, Microsoft prioritizes restoring at least one region in each pair. |
| Data Residency | Data replicated between paired regions (using GRS storage) remains within the same geography. |
Note
Region pairs are chosen by Microsoft; you cannot select your own pair. You can, however, choose to replicate data to the paired region using geo-redundant storage (GRS).
Availability Zones
Availability Zones (AZs) are physically separate data centers within a single Azure region. Each AZ has independent power, cooling, and networking. They are connected by a high-speed, private fiber-optic network.
In Plain English
Imagine a city with three separate electricity substations. If one substation fails, the others keep power running to the city. Availability Zones work the same way for your Azure applications, protecting you from a single data center failure.
| Resilience Concept | Scope | Protects Against | Example |
|---|---|---|---|
| Availability Zone | Within one region | Single data center failure (power, cooling, hardware) | Deploying VMs across Zone 1, 2, and 3 in the East US region. |
| Region Pair | Between two regions | A full regional outage (natural disaster, major network failure) | Replicating data from East US to its paired region, West US. |
Sovereign Regions
Some Azure regions are physically and logically isolated from the main public cloud to meet strict government or compliance requirements.
- Azure Government (US): Operated by screened US personnel for US federal, state, and local governments.
- Azure China 21Vianet: A physically separate instance of Azure in China, operated by a local partner (21Vianet).
Exam Tip
Sovereign regions are not part of standard Azure. Access is restricted, often requires separate subscriptions, and they may be operated by third parties rather than Microsoft directly.
Azure Resource Hierarchy
Every resource you create in Azure exists within a four-level management hierarchy. This structure is fundamental to organizing, billing, and securing your environment. Policies and access controls applied at a higher level are inherited by the levels below.
| Level | Name | Think of It As... | Key Rule |
|---|---|---|---|
| 1. Top Level | Management Groups | A folder for your subscriptions | Optional. Used by large organizations to apply policies and access control across multiple subscriptions. |
| 2. Billing/Access | Subscriptions | A billing and access control boundary | Required for creating any resources. A subscription is tied to a single payment method and a single Microsoft Entra ID tenant. |
| 3. Logical Container | Resource Groups | A folder for related resources | Required. Every resource must exist in one, and only one, resource group. Used to group resources with a common lifecycle (e.g., all resources for a single application). |
| 4. Individual Service | Resources | The actual Azure services you use | The individual instances of services like VMs, Storage Accounts, or databases. |
Exam Tip
A resource can only belong to ONE resource group. Resource groups CANNOT be nested inside each other. A subscription can only belong to ONE management group. These are common exam traps.
Official exam information from Microsoft
- Study guide for Exam AZ-900: Microsoft Azure Fundamentals (skills measured, weights and passing score), and the Microsoft Certified: Azure Fundamentals certification page.