Skip to content
GetHandsOn.ai

AZ-900 Study Guide


Module 10 of 118 min read

Glossary of Key Terms

An alphabetical list of essential AZ-900 terminology and their definitions, from ARM and Availability Sets to VNet and Zero Trust.

These study notes summarise Microsoft Learn material for Exam AZ-900. For the official skills measured, see the Microsoft Learn study guide for Exam AZ-900.

This glossary provides definitions for the key terms and acronyms you'll encounter when working with Azure and preparing for the AZ-900 exam. The terms are listed alphabetically for quick reference.

Application Insights: An Application Performance Management (APM) service within Azure Monitor for monitoring live web applications.

ARM (Azure Resource Manager): The management and deployment service for Azure. It's the consistent management layer for all Azure operations.

ARM Template: A JSON file that declaratively defines the infrastructure and configuration for your project (Infrastructure as Code).

Authentication (AuthN): The process of verifying a user's identity to prove they are who they say they are.

Authorization (AuthZ): The process of determining what an authenticated user is permitted to do.

Autoscaling: The process of automatically adding or removing resources (like VMs) based on performance metrics or a schedule.

Availability Set: A logical grouping of VMs within a data center that protects against hardware failures by spreading them across fault and update domains.

Availability Zone (AZ): A physically separate data center with independent power, cooling, and networking within a single Azure region.

AVD (Azure Virtual Desktop): A cloud-hosted desktop virtualization service that delivers a Windows desktop experience to any device.

Azure Arc: A service that extends Azure management capabilities to on-premises, multi-cloud, and edge resources.

Azure Advisor: A free, personalized consultant that analyzes your Azure usage and provides recommendations to optimize your environment.

Azure Bastion: A fully managed PaaS service that provides secure and smooth RDP/SSH access to your VMs directly through the Azure portal without needing a public IP on the VM.

Azure Blueprint: A governance tool for packaging and deploying a consistent set of resources, policies, and RBAC assignments.

Azure CLI: A cross-platform command-line tool for managing Azure resources.

Azure Data Box: A physical, rugged appliance shipped by Microsoft for transferring large amounts of data to Azure offline.

Azure DNS: A hosting service for DNS domains that provides name resolution using Microsoft's global infrastructure.

Azure Firewall: A managed, cloud-based network security service that protects your Azure Virtual Network resources.

Azure Functions: A serverless compute service that allows you to run event-triggered code without provisioning or managing infrastructure.

Azure Key Vault: A service for securely storing and accessing secrets, such as API keys, passwords, and certificates.

Azure Monitor: The unified platform for collecting, analyzing, and acting on telemetry data from your Azure and on-premises environments.

Azure Policy: A service for creating, assigning, and managing policies that enforce rules and standards for your Azure resources.

Azure PowerShell: A set of command-line modules for managing Azure resources from a PowerShell interface.

Blob Storage: An object storage solution for the cloud, optimized for storing massive amounts of unstructured data.

CapEx (Capital Expenditure): The upfront spending of money on physical infrastructure.

Conditional Access: An intelligent policy engine in Microsoft Entra ID that enforces organizational access controls based on real-time signals.

DDoS Protection: A service that protects Azure resources from Distributed Denial of Service attacks.

Defense in Depth: A security strategy that uses multiple layers of defensive controls to protect assets.

ExpressRoute: A service that lets you create private, dedicated connections between your on-premises datacenters and the Microsoft cloud.

Fault Domain (FD): A group of resources that share a common power source and network switch, typically a server rack. Part of an Availability Set.

File Storage: Fully managed file shares in the cloud that are accessible via the standard Server Message Block (SMB) and Network File System (NFS) protocols.

General Availability (GA): The final stage in a service's lifecycle, indicating it is fully supported, has an SLA, and is ready for production use.

GRS (Geo-Redundant Storage): A storage redundancy option that replicates your data to a secondary region hundreds of miles away from the primary region.

IaaS (Infrastructure as a Service): A cloud computing model where the provider manages the physical infrastructure, and the customer manages the operating system, applications, and data.

Initiative (Policy Initiative): A collection of Azure Policy definitions that are grouped together towards a common goal.

Load Balancer: A service that distributes incoming network traffic across a group of backend resources or servers.

Log Analytics Workspace: The primary Azure Monitor tool for writing and running log queries against data collected from various sources.

LRS (Locally Redundant Storage): A storage redundancy option that stores three copies of your data within a single data center.

Management Group: A container that helps you manage access, policy, and compliance for multiple subscriptions.

Microsoft Entra ID: Microsoft's cloud-based identity and access management service.

MFA (Multi-Factor Authentication): A security process that requires users to provide two or more verification factors to gain access to a resource.

NSG (Network Security Group): A resource that contains a list of security rules that allow or deny network traffic to resources connected to Azure VNets.

OpEx (Operational Expenditure): The ongoing cost for running a business or a service, such as pay-as-you-go cloud services.

PaaS (Platform as a Service): A cloud computing model where the provider manages the platform (including OS and hardware), and the customer manages their applications and data.

Private Endpoint: A network interface that uses a private IP address from your virtual network to connect privately and securely to an Azure PaaS service.

Public Preview: A stage in a service's lifecycle where it is available to all Azure customers to evaluate. It typically does not have an SLA and is not recommended for production.

RBAC (Role-Based Access Control): A system for managing who has what permissions to which Azure resources.

Region: A specific geographical location in the world that contains at least one Azure data center.

Resource Group: A logical container into which Azure resources like web apps, databases, and a storage account are deployed and managed.

Resource Lock: A feature that prevents resources from being accidentally deleted or modified. Locks override RBAC permissions.

SaaS (Software as a Service): A cloud computing model where software is licensed on a subscription basis and is centrally hosted.

SLA (Service Level Agreement): A formal, financially backed commitment from Microsoft regarding the uptime and availability of a specific service.

Subscription: A logical unit of Azure services that is linked to an Azure account. It serves as a boundary for billing and management.

Tags: Metadata key-value pairs that you apply to Azure resources to logically organize them and track costs.

Update Domain (UD): A group of resources that can be updated and rebooted at the same time. Part of an Availability Set.

VM (Virtual Machine): A software emulation of a physical computer. An IaaS offering in Azure.

VNet (Virtual Network): The fundamental building block for your private network in Azure, enabling resources to securely communicate with each other, the internet, and on-premises networks.

VNet Peering: A mechanism that connects two virtual networks in the same or different regions, allowing them to communicate over the Microsoft backbone network.

VPN Gateway: A specific type of virtual network gateway that is used to send encrypted traffic between an Azure virtual network and an on-premises location over the public Internet.

ZRS (Zone-Redundant Storage): A storage redundancy option that replicates your data synchronously across three Azure Availability Zones in the primary region.

Zero Trust: A security model that assumes breach and verifies each request as though it originates from an untrusted network.

Official exam information from Microsoft

Get the full AZ-900 study guide as a PDF, freeAll 11 modules in one printable file. Enter your email on the guide page and it is yours.

Keep going

Get the full AZ-900 guide as a PDFEvery module in one file. Free after you enter your email.
Practice AZ-900 questionsExam-style questions with explanations, free to start.
AZ-900 guide overviewAll modules, pick what to read next.