
An independent study guide for Microsoft Certified: Azure Fundamentals · by Tony Rough
Know what each Azure service is for, and which one fits.
Publishing soon on Amazon in Kindle and paperback editions.
This independent study guide for the Microsoft Certified: Azure Fundamentals exam distils what AZ-900 really expects you to understand into clear definitions, comparisons and the traps that catch newcomers. It assumes no previous Azure experience and is written to the skills measured as of July 2026.
Nine chapters, each readable on its own and together covering all three AZ-900 skill areas:
Azure changes quickly. This edition reflects Microsoft's documentation as of October 2026, including recent changes such as retired storage account types, VPN gateway SKU consolidation and the move to Flex Consumption for Azure Functions.
This book contains no exam questions. It explains the knowledge the exam expects, so you can answer questions you have never seen and carry the same understanding into AZ-104, AZ-305 and real Azure work.
Written by Tony Rough, a cloud architect with more than twenty years in IT infrastructure who holds the Azure Solutions Architect Expert, Azure Administrator and Azure Security Engineer certifications.
Part of the Ultra Transcenders series from Distilled Press. An independent publication, not affiliated with, sponsored by or endorsed by Microsoft Corporation.
Every skill area in Microsoft's AZ-900 outline (as of July 20, 2026), and the chapters that cover it.
| Skill area | Weight | Chapters |
|---|---|---|
| Describe cloud concepts | 25–30% | 1, 2 |
| Describe Azure architecture and services | 35–40% | 3, 4, 5, 6, 7 |
| Describe Azure management and governance | 30–35% | 8, 9 |
Plus an appendix glossary of 300+ terms, each linked to Microsoft Learn, with the same terms explained free online for print readers.



Some sections of the book, free to read online:
Which security and management duties Microsoft owns, which you always keep, and which shift by service type.
What each cloud service type gives you, what you still manage, and typical use cases for each.
What sovereign regions are, who can use them, and how they differ from the public Azure regions.
How peering connects virtual networks within and across regions, and what traffic and transitivity rules apply.
How each storage redundancy option copies your data and which failures it protects against.
The three Zero Trust principles and how they change the traditional network-perimeter approach to security.
How resource locks prevent accidental deletion or change, how they inherit, and how they differ from RBAC and Policy.
What Azure Advisor recommends across its categories and how it fits alongside Service Health and Azure Monitor.