AZ-900 Study Guide
Module 3 of 1111 min read
Azure Compute & Networking
Discover how to run applications using Virtual Machines, Containers, and PaaS services, and how to connect them securely with Virtual Networks.
These study notes summarise Microsoft Learn material for Exam AZ-900. For the official skills measured, see the Microsoft Learn study guide for Exam AZ-900.
On this pageShow
This module covers the core services for running your applications (compute) and connecting them securely (networking). We'll explore fundamental compute options like Virtual Machines and their high-availability features, as well as more abstract options like Containers and App Service. You will also learn about Virtual Networks, how to connect them to each other and your on-premises environment, and how to secure access to your services.
Azure Compute Services
Azure offers a spectrum of compute services, from IaaS where you have full control, to PaaS and serverless where you focus only on your code.
Azure Virtual Machines (VMs)
A Virtual Machine is a software-based computer that runs inside Azure's physical servers. It's an IaaS offering that gives you total control over the operating system and installed software, just like a physical machine.
| VM Feature | Details |
|---|---|
| Operating Systems | Windows Server, Windows Desktop, Ubuntu, Red Hat, SUSE, and many more from the Azure Marketplace. |
| Sizes | Dozens of options optimized for different workloads, from small dev/test machines to massive high-performance computing instances. |
| Connection | Remote Desktop Protocol (RDP) for Windows, SSH for Linux, or securely via Azure Bastion. |
| Use Cases | Web servers, databases, development environments, and migrating legacy applications from on-premises ("lift and shift"). |
Availability Sets: An Availability Set protects against failures within a single data center by spreading your VMs across different physical hardware. It provides a 99.95% SLA.
- Fault Domain (FD): A group of VMs that share a common power source and network switch (think of it as a rack of servers). Spreading VMs across FDs protects against a rack-level failure.
- Update Domain (UD): A group of VMs that may be rebooted at the same time for planned maintenance. Spreading VMs across UDs ensures part of your application remains running during updates.
Virtual Machine Scale Sets (VMSS): A VMSS lets you create and manage a group of identical, load-balanced VMs. The number of VMs can automatically increase or decrease in response to demand or a defined schedule, a feature known as autoscaling.
Azure Virtual Desktop (AVD): AVD is a cloud-based desktop and app virtualization service. It delivers a full Windows 10 or 11 desktop experience, running in Azure, to any device. It's ideal for enabling remote work and secure, centralized desktop management.
Compute Options Compared
| Option | Best Described As | You Manage | Scales How | Best For |
|---|---|---|---|---|
| Virtual Machines | A full computer in the cloud | OS, software, configuration | Manually or via Scale Sets | Maximum control, legacy apps |
| Containers | A lightweight, packaged app | App code and its dependencies | Faster and lighter than VMs | Microservices, modern app architectures |
| Azure App Service | A managed web hosting platform (PaaS) | Just your code | Built-in auto-scale | Web apps and REST APIs |
| Azure Functions | Event-driven code execution (Serverless) | Only the function code | Fully automatic, pay-per-execution | Small, event-triggered tasks and automation |
Azure Networking Services
Azure networking services provide secure connectivity between Azure resources, from your on-premises network to Azure, and to and from the internet.
Virtual Networks (VNets)
A Virtual Network (VNet) is your own isolated, private network in the Azure cloud. It allows your Azure resources to communicate securely with each other, the internet, and your on-premises networks.
- Subnets: VNets are segmented into one or more subnets. A subnet is a range of IP addresses within the VNet where you can place groups of related resources (e.g., a web tier and a data tier).
- VNet Peering: This connects two VNets, making them appear as one for connectivity purposes. Traffic between peered VNets uses Microsoft's private backbone network, never traversing the public internet.
In Plain English
Think of a VNet as a private office building and a subnet as a floor inside it. VNet peering is like building a private skybridge between two office buildings: people can move freely between them without ever stepping onto the public street.
Connecting to On-Premises Networks
You can extend your on-premises network to Azure using two primary methods:
| Option | Connection Type | Goes Over Internet? | Speed / Reliability | Best For |
|---|---|---|---|---|
| Azure VPN Gateway | Encrypted site-to-site VPN tunnel | Yes (encrypted) | Good, but subject to internet variability | General-purpose hybrid connectivity, dev/test, smaller workloads. |
| Azure ExpressRoute | Private, dedicated fiber circuit | No | Highly reliable, low latency, up to 100 Gbps | Mission-critical workloads, large data transfers, regulated data. |
In Plain English
ExpressRoute is like having a private, dedicated highway directly from your data center to Azure. A VPN Gateway is like using the public highway but inside a secure, armored car: you're still sharing the road with other traffic.
Filtering Network Traffic
Network Security Groups (NSGs): An NSG is a basic stateful firewall that filters network traffic to and from Azure resources in a VNet. You create inbound and outbound security rules to allow or deny traffic based on source/destination IP address, port, and protocol.
In Plain English
An NSG is the bouncer at the door of your network. Each rule is a guest list entry: "allow port 443 from anywhere" or "deny port 22 except from the office IP". Rules are checked in priority order, lowest number first.
DNS and Endpoint Security
- Azure DNS: A hosting service for DNS domains that provides name resolution using Microsoft's global infrastructure. It supports both public domains (for the internet) and private DNS zones (for name resolution within your VNets).
- Public and Private Endpoints:
- Public Endpoint: An IP address and DNS name for an Azure service that is accessible from the public internet.
- Private Endpoint: Creates a network interface with a private IP address inside your VNet for an Azure PaaS service (like Azure Storage or SQL Database). This allows you to connect to the service without its traffic ever leaving the Microsoft network, dramatically improving security.
Official exam information from Microsoft
- Study guide for Exam AZ-900: Microsoft Azure Fundamentals (skills measured, weights and passing score), and the Microsoft Certified: Azure Fundamentals certification page.