AZ-900 Microsoft Azure Fundamentals Exam
Start here! Get your feet wet with the Microsoft cloud and begin your journey to earning your Microsoft Certified: Azure Fundamentals certification!
Gauge your current knowledge

Gauge your current knowledge

Start here! Get your feet wet with the Microsoft cloud and begin your journey to earning your Microsoft Certified: Azure Fundamentals certification!
Gauge your current knowledge

Gauge your current knowledge

Azure datacenters are physical facilities operated by Microsoft across multiple global regions, and they form the core of Azure's cloud platform. These facilities comply with industry security standards such as ISO/IEC 27001:2013 and NIST SP 800-53, with dedicated operations staff ensuring 24x7 continuity for all services. Microsoft implements multiple layers of security including physical security to protect hardware in restricted facilities, network architecture that uses segmentation and firewalls to prevent unauthorized access, and real-time monitoring to detect and respond to threats. Data protection is enforced through encryption both at rest and in transit, maintaining data confidentiality for customers. Customers can specify data residency to keep information within specific regions, supporting regulatory requirements like the CJIS Security Policy for U.S. law enforcement. The shared responsibility model means Microsoft secures the underlying infrastructure while customers manage security for their own workloads and data, with tools like Microsoft Defender for Cloud helping organizations monitor and maintain compliance.
Azure datacenters serve as the building blocks of the cloud service, with these physical facilities globally dispersed and connected by experienced Microsoft staff. Azure organizes these datacenters into regions, which are geographic boundaries defining a set of datacenters connected by a high-speed, low-latency network. Users can deploy resources closer to their customers by selecting specific regions, which reduces latency and improves performance, though not all services are available in every region. Within each region, Availability Zones provide resilience by physically separating datacenters, each with independent power, cooling, and networking, so that if one zone fails, workloads can fail over to another zone. Azure's global backbone network connects all regions and zones using private fiber-optic cables including undersea links, ensuring high-bandwidth, low-latency connectivity between regions. Services like Azure Peering Service establish efficient connections between on-premises networks and Azure's backbone, while Azure Traffic Manager uses DNS-based load balancing to route user traffic to the nearest or healthiest endpoints.
High availability means services remain operational during failures, while redundancy involves having extra resources ready as alternatives when components fail. Azure divides infrastructure into fault domains and update domains to protect against hardware and software disruptions, with fault domains providing physical isolation to limit the impact of server or network failures, and update domains ensuring maintenance operations occur in staggered groups to avoid simultaneous downtime. Azure uses multiple datacenters within a single region for redundancy, often pairing them with another region for disaster recovery where data is synchronously or asynchronously replicated between paired regions. Azure DNS hosts zones on multiple name servers across different datacenters, providing automatic fault tolerance and failover for DNS resolution. Azure Traffic Manager enhances availability through DNS-based load balancing that includes automatic failover directing queries to healthy endpoints, global load balancing routing traffic based on performance or priority, and monitoring that detects outages and triggers reroutes.
Azure datacenters are the backbone of Microsoft's cloud services, providing the infrastructure needed to deliver scalable and reliable cloud solutions. The physical structure includes servers, storage devices, and networking equipment that work together to deliver cloud services efficiently, with layout optimized for performance and scalability. Advanced security measures protect data and applications through physical security like surveillance and access controls, combined with logical security such as encryption and firewalls. The logical structure supports seamless integration using virtual networks, load balancers, and identity management systems that facilitate communication and control within the cloud environment. These components work together to provide a cohesive operational framework focused on high availability, security, and scalability.
Azure datacenters are built with a strong focus on energy efficiency and sustainability to support global cloud services. Microsoft invests in renewable energy sources through power purchase agreements and on-site installations, partnering with wind and solar farms to match energy consumption with clean energy production and reduce reliance on fossil fuels. Efficient cooling methods include free-air cooling systems using outside air when conditions allow, and liquid cooling with advanced heat exchange techniques in hotter climates that lower energy required for temperature control. Datacenter buildings are constructed to be modular, allowing quick expansion without major environmental disruption, and incorporate water conservation measures such as reclaiming and reusing water in cooling towers. Additional sustainable practices include using energy-efficient hardware that uses less power per computing unit, smart building materials that improve insulation and reduce thermal loss, and site selection prioritizing locations with access to renewable energy resources.