Suggested study time: 50 minutes • Beginner level • Aligned with the AZ-900 cloud concepts domain
By João Ricardo Dutra••Complete original content
1. Azure Fundamentals and this chapter's role
Learning objectives
Define and identify the IT services that can be delivered over the Internet.
Explain how changes across on-premises, ,, and .
Distinguish public, private, hybrid, and environments and choose a model for a scenario.
Relate and to hybrid and environments.
Compare capital expenditure () and operational expenditure ().
Explain consumption, pay-as-you-go pricing, , and cloud capacity planning.
The four themes of the chapter: concept, responsibility, deployment, and economics.
How to study this chapter
On the first pass, focus on how the concepts connect. Next, use the diagrams and tables to compare models. During review, justify every decision: which cloud model fits, who operates each layer, and how consumption changes cost and capacity.
Microsoft Azure is a platform that supports solutions ranging from simple to complex. It can host web applications, run Azure Virtual Machines, provide remote storage and databases, centralize identities with Microsoft Entra ID, and deliver artificial intelligence and Internet of Things (IoT) capabilities.
Azure Fundamentals organizes an introduction to Azure into three conceptual learning paths and one hands-on exploration path. Together they cover cloud concepts, Azure architecture and services, and Azure management and governance. Guided lessons and knowledge checks reinforce the vocabulary.
The path serves newcomers, people who already use cloud services, and candidates for Exam AZ-900: Microsoft Azure Fundamentals. Previous technical experience is not required, although general IT knowledge makes the material easier to apply.
Exam AZ-900 domains and relative weights in the reference material.
Domain
Weight
Cloud-computing concepts
25–30%
Azure services and architecture
35–40%
Azure governance and management
30–35%
2. What means
delivers computing capacity through a network, usually the Internet. Instead of relying only on equipment installed in an organization's own datacenter, teams request provider resources and consume them as services.
Those services include familiar IT infrastructure such as virtual machines, storage, databases, and networking. The same platform can also provide specialized capabilities such as IoT, machine learning, and artificial intelligence.
The defining change is not simply storing information outside the company. turns capacity, software, and platforms into resources that can be provisioned, expanded, reduced, and retired on demand.
3. From infrastructure purchasing to on-demand provisioning
In a traditional datacenter, growth requires forecasting demand, buying hardware, preparing space, power, cooling, and networking, and then installing systems. That cycle can take weeks or months and continues to cost money when equipment is idle.
In the cloud, a team can create resources in minutes. A retailer expecting a seasonal traffic spike can add compute for the event and remove it after traffic returns to normal instead of keeping extra servers all year.
This model improves agility, shortens test cycles, and lets services run in regions closer to users. It also supports regional resilience without requiring the organization to build several physical datacenters.
4. The model
The model separates cloud-provider tasks from customer tasks. On-premises, the organization operates the entire stack: building, power, cooling, network, servers, operating systems, applications, identities, and data.
When Azure is used, Microsoft assumes responsibility for datacenter physical security, power, cooling, the physical network, and physical hosts. The remaining layers are divided according to the service that the customer selects.
does not mean that security has been fully outsourced. The provider protects the platform it offers; the customer protects how identities, data, configurations, and controlled resources are used.
The customer's operational share falls from on-premises to , but data and identities remain its responsibility.
5. Responsibilities that do not disappear in the cloud
Under every cloud service model, customers remain responsible for the information they store, the devices allowed to connect, and the accounts and identities of people, applications, and devices.
Customers also decide who gets access, which roles and policies apply, and how data is classified, retained, and protected. Microsoft runs an identity platform such as Microsoft Entra ID, while each organization manages its users, groups, permissions, and policies.
Microsoft always operates the physical datacenter, network, and hosts. Operating systems, network controls, applications, directory infrastructure, and logical infrastructure shift among the parties depending on ,, or .
6. How responsibility changes across ,, and
supplies virtualized infrastructure and leaves the largest customer responsibility of the three service types. With Azure Virtual Machines, Microsoft operates physical infrastructure and virtualization, while the customer maintains the guest operating system, updates, applications, network configuration, and data.
sits in the middle. In a managed product such as Azure SQL Database, Microsoft maintains the database platform and underlying infrastructure; the customer still owns ingested data, identities, authorization, and customer-controlled configuration.
supplies a ready-to-use application and moves more operations to the provider. Customers still manage their data, users, devices, tenant settings, and access policies. More abstraction reduces direct technical maintenance, but it does not remove governance responsibility.
The customer's operational share falls from on-premises to , but data and identities remain its responsibility.
Environment
Data and identities
Applications
Operating system and logical network
Physical infrastructure
On-premises
Customer
Customer
Customer
Customer
Customer
Customer
Customer
Microsoft
Customer
Customer
Shared
Microsoft
Customer
Shared
Microsoft
Microsoft
7. Deployment models: public, private, and hybrid
A is built and operated by a provider that offers services to different customers. Resources are obtained on demand without every customer owning the physical datacenter.
A serves one organization. It can run in the organization's datacenter or in dedicated third-party facilities. It offers extensive control over resources and security but requires more investment, maintenance, and capacity planning.
A connects public and private environments. An organization decides where each workload runs and may use public-cloud resources for temporary peaks, integration, or specific security, compliance, and location requirements.
Deployment models and Azure technologies that help connect and manage environments.
8. Choosing a cloud model
commonly fits when fast provisioning, , and avoiding an initial datacenter purchase matter most. Customers pay for what they consume but do not control the complete physical infrastructure.
fits scenarios that demand dedicated resources and maximum control. In return, the organization buys, updates, and maintains hardware and funds capacity before using it.
provides the greatest placement flexibility. It works when applications and data must remain in different locations, but that freedom adds integration, connectivity, identity, observability, and governance across environments.
Deployment models and Azure technologies that help connect and manage environments.
Model
Main benefit
Main responsibility or trade-off
Public
Fast provisioning, , and no initial datacenter purchase.
Less control over physical infrastructure.
Private
Dedicated resources and extensive control.
The organization purchases, maintains, and updates hardware.
Hybrid
Flexible workload placement across public and private environments.
Integration and governance become more complex.
Services from multiple public providers.
Policy, cost, and security must be coordinated across platforms.
9. : more than one public provider
means using two or more public-cloud providers. A business might combine differentiated capabilities, meet geographic needs, or migrate gradually from one provider to another.
It is not a synonym for : hybrid combines public and private clouds; combines multiple public providers and may or may not include private infrastructure. Both require coordinated identities, policy, cost, inventory, and security across environments.
10. for hybrid and management
extends Azure management capabilities to servers, Kubernetes clusters, and other resources that run outside Azure. It provides a consistent control plane across on-premises, hybrid, and environments.
Teams can use to organize inventory, apply policy, and observe distributed resources without claiming that everything has physically moved into Azure. It reduces operational fragmentation across locations and providers.
11.
runs VMware-based workloads in a deployed in Azure. It provides a path to extend or migrate VMware environments while using Azure integration and scale.
The service helps organizations that already rely on VMware skills, tooling, and applications. Planning is still required for networking, identity, data, continuity, cost, and the remaining operational responsibilities.
12. The consumption-based model
In a consumption-based model, an organization uses IT resources while they are needed and releases capacity afterward. Billing follows service metrics such as time, storage, transactions, or provisioned capacity.
The model avoids buying all datacenter hardware in advance and reduces the risk of holding large amounts of unused capacity. It also lets teams add resources as demand grows and remove them as demand falls.
Pay-as-you-go does not automatically mean inexpensive. Forgotten resources, overprovisioning, and data transfer can create waste. Savings depend on monitoring, budgets, automation, and disciplined shutdown practices.
13. and
, or capital expenditure, is upfront investment in physical assets such as servers, network equipment, datacenter space, power, and cooling. The asset is purchased before it produces value and must be sized for uncertain future demand.
, or operational expenditure, is ongoing spending on services over time. Because cloud services are charged as they are consumed, cloud spending is commonly treated as an operating expense.
Moving from to replaces part of the upfront commitment with variability. That improves adaptability but requires continuous forecasting, limits, alerts, and workload-level cost analysis.
Fixed capacity needs early forecasts; keeps provisioned resources closer to actual demand.
Model
How spending occurs
Examples
Watch point
Upfront asset purchase
Servers, networking, and datacenter space
Risk of idle or insufficient capacity
Recurring expense based on service and use
Cloud compute and storage consumption
Risk of variable spending without governance
14. Capacity planning: datacenter and cloud
In a traditional datacenter, overestimating demand creates idle hardware; underestimating it creates shortages and degraded performance until additional equipment is purchased and installed.
In the cloud, teams keep provisioned capacity closer to actual demand. They can scale out for peaks and scale in afterward. shortens response time, but it depends on suitable architecture, service limits, and automation.
Capacity planning still matters. It combines performance, scaling rules, quotas, budgets, and consumption telemetry instead of focusing only on hardware purchasing.
Fixed capacity needs early forecasts; keeps provisioned resources closer to actual demand.
15. Cloud pricing and business focus
Cloud providers commonly offer pay-as-you-go pricing. It helps plan operating costs, use infrastructure more efficiently, and adjust capacity to workload demand.
Because Microsoft maintains Azure power, cooling, hardware, and physical networking, teams can spend more time on applications and business outcomes. They still need to choose sizes, regions, and services deliberately.
Official material also presents Azure account options, including pay-as-you-go and free offers with their own terms. Always review the current Azure page before assuming duration, credit, or eligibility.
16. Review scenarios
The scenarios below revisit the module assessment with new wording. The goal is to recognize each idea instead of memorizing a sentence.
When defending an answer, look for three clues: how the service is delivered, which environments are involved, and which layer still depends on the customer.
Scenario
Answer
Reasoning
A company needs compute and databases over the Internet without building another datacenter.
The concept covers multiple computing services delivered over a network, not only websites or storage.
An organization keeps a dedicated cloud and uses a public provider for demand peaks.
The scenario connects private and public resources.
A team wants the model where it manages a virtual machine's operating system, application, and data.
Among ,, and , leaves the most technical responsibility with the customer.
17. Chapter recap
delivers computing resources over a network and turns capacity into an on-demand service.
Customers always retain responsibility for their data, identities, devices, and access decisions. Microsoft always operates Azure datacenters, physical networking, and physical hosts.
Public, private, hybrid, and environments solve different needs. helps manage distributed resources, while supports VMware workloads in Azure.
Consumption and align capacity with demand. Shifting from to reduces upfront investment but makes ongoing cost management essential.
Define cloud by how services are delivered, not only by where data is located.
Map responsibility to abstraction: on-premises > > > for the customer.
Distinguish public, private, hybrid, and deployment before selecting technology.
Connect and consumption to the balance among demand, performance, and cost.
Use the CSV and official documentation to preserve localized Microsoft product names.
18. Explore with Copilot Chat
Use Copilot Chat as a review partner, not as a replacement for official documentation. Ask it to explain comparisons, and then validate the response against this chapter's diagrams and references.
Create one business application example and assign every layer across on-premises, ,, and .
Compare public, private, hybrid, and and recommend an option for three organizations with different constraints.
Build a financial comparison of and for a seasonal workload moving to consumption-based billing.
19. Essential glossary
This glossary consolidates terms that appear in introductory AZ-900 questions and in real cloud-adoption decisions.
Term
Definition
Delivery of computing services over a network with on-demand provisioning and consumption.
Division of security and operations tasks between provider and customer.
Infrastructure as a service; virtualized resources with more customer administration.
Platform as a service; abstracts infrastructure and operating systems for applications.
Software as a service; provides a ready-to-use application.
Provider services available to multiple customers.
A cloud environment dedicated to one organization.
Integration of public and environments.
Use of services from two or more public-cloud providers.
Azure management technologies for resources across hybrid and environments.
A service for VMware workloads in a deployed in Azure.
Capital expenditure used to acquire assets in advance.
Recurring operational expenditure associated with service use.
The ability to increase or decrease resources in response to demand.
20. Official references
The references below point to Microsoft Learn and official documentation. They also confirm product naming and help you track changes published after this chapter.