Four Azure services balance traffic, and two questions tell them apart: is it web traffic that needs layer 7, and is it regional or global? Each service on a 2x2 grid, plus three exam traps.
By Tony Rough
Azure has four services that all “balance traffic”: Azure Load Balancer, Application Gateway, Azure Front Door and Traffic Manager. Exam questions like to make them look interchangeable. They aren’t, and two questions sort them out.
Put the answers on a grid and each service gets its own square:
| Regional | Global | |
|---|---|---|
| Layer 7 (web) | Application Gateway | Front Door |
| Layer 4 / any protocol | Load Balancer | Traffic Manager (DNS) |
Load Balancer works at layer 4: TCP and UDP. It passes connections straight through to the virtual machines (or scale set instances) in its backend pool, which makes it fast, with very high throughput and very low latency. It can be public (internet-facing) or internal (a private frontend inside a virtual network).
What it can’t do is anything that needs to read the request: no URL-based routing, no TLS termination, no WAF.
Application Gateway is a reverse proxy. The client’s connection ends at the gateway, and the gateway opens its own connection to the backend. That lets it:
/api to one pool, /images to another) or by host name;It’s deployed into a virtual network in one region.
Front Door runs at Microsoft’s edge locations around the world. Users connect to the nearest edge, and Front Door carries the request over Microsoft’s network to the best healthy origin, in whichever region that is. It fails over between regions quickly, caches content like a CDN, and has its own WAF.
Traffic Manager never touches the traffic. It answers the DNS query with the address of the best endpoint (by priority, performance, weight, geography and so on), and the client then connects to that endpoint directly. So it works for any protocol, but:
For global layer 4 traffic there’s also a second option now: the cross-region tier of Azure Load Balancer.
| You need… | Choose |
|---|---|
| TCP or UDP inside one region | Load Balancer |
| A web app in one region, with path routing or a WAF | Application Gateway |
| A web app across regions, with edge acceleration or caching | Front Door |
| Any protocol across regions, steered by DNS | Traffic Manager |
Real designs often combine them, for example Front Door globally, Application Gateway regionally, and an internal Load Balancer in front of the database tier. Ask the two questions for each hop.
Load balancing gets three chapters in the AZ-700 study guide: Load Balancer and Traffic Manager (chapter 9), Application Gateway (chapter 10) and Front Door (chapter 11). It’s also in chapter 13 of the AZ-104 study guide and the networking chapter of the AZ-305 study guide. Facts checked against Microsoft Learn’s Load balancing options guide on 4 October 2026.
Both lock an Azure service down to your virtual network, but they work in completely different ways. How each one works, the on-premises trap, DNS, data exfiltration, and a five-second way to choose.
Six redundancy options, four acronyms and one trap that catches almost everyone. The two questions that pick the right Azure Storage option every time, plus the read-access trap and three more.
Azure has two separate role systems. Azure roles control resources; Microsoft Entra roles control the directory. Scopes and inheritance, Owner vs Contributor vs User Access Administrator, elevate access, and three traps.
Microsoft has pushed the retirement of Application Insights URL ping tests back to September 2028 and announced that Azure IoT Central retires in September 2029. Automatic zone placement for scale sets, and Microsoft Entra Kerberos for Azure NetApp Files, are now in preview.
Four Microsoft certification study guides are out, three more are on the way, and there's now a free glossary for the whole series. Here's what the books are, how they're different, and what's free on this site.