AZ-900 Azure Management and Governance: Domain 3 Study Notes 2026 October
Boost your AZ exam score with practice questions and detailed answer explanations. Track progress with instant feedback. 🎯

Domain 3 Overview: Management and Governance
Azure Management and Governance is the largest domain on the AZ-900 exam, accounting for 30–35% of all questions. This domain tests your understanding of how Azure helps organizations control costs, enforce compliance, and maintain visibility across cloud resources.
Domain 3 is organized around three pillars:
- Cost Management — Tools that help you estimate, track, and optimize Azure spending.
- Governance — Services that enforce organizational rules, protect resources, and maintain compliance at scale.
- Monitoring — Solutions that provide operational visibility, proactive recommendations, and service-health awareness.
Because this domain makes up roughly one-third of the exam, even a basic conceptual understanding of each tool can meaningfully improve your score. You are not expected to configure these services — only to understand what they do and when you would use them.
Before diving in, make sure you have already reviewed core Azure services and the broader AZ-900 study guide, since governance concepts build on foundational cloud knowledge.
Cost Management Tools in Detail
Pricing Calculator vs. TCO Calculator
The Azure Pricing Calculator is used before you deploy. You select Azure products, configure their expected usage (region, tier, hours per month), and receive a cost estimate. It is ideal for planning new workloads or comparing service tiers.
The Total Cost of Ownership (TCO) Calculator serves a different purpose: it helps you justify migration by comparing your current on-premises infrastructure costs against equivalent Azure costs over time. You input your existing servers, storage, networking, and labor costs, and the tool projects multi-year savings. On the exam, remember: Pricing Calculator = estimate Azure costs; TCO Calculator = compare cloud vs. on-prem.
Azure Cost Management
Once resources are running, Azure Cost Management (sometimes called Microsoft Cost Management) provides dashboards, budgets, and alerts to track actual spending. You can set budget thresholds that trigger email alerts when costs approach or exceed defined limits, and use cost-analysis views to break down spending by service, resource group, or time period.
Tags
Tags are name-value pairs you attach to Azure resources (e.g., Department: Finance or Environment: Production). Tags do not affect resource behavior, but they make it easy to filter cost reports and allocate charges to specific teams or projects. Tags are applied at the resource or resource-group level.
Governance Features in Detail
Azure Policy vs. Resource Locks
Azure Policy lets you define rules — called policy definitions — that Azure enforces across your subscriptions and resource groups. A policy might require all resources to have a specific tag, restrict deployment to certain regions, or mandate a minimum VM SKU. Policies can audit (report non-compliant resources) or deny (block non-compliant deployments). You can bundle multiple policies into an initiative (also called a policy set).
Resource Locks operate differently: they prevent changes or deletions regardless of the user's permissions. A CanNotDelete lock allows reads and modifications but blocks deletion. A ReadOnly lock prevents all writes — even authorized administrators cannot modify the resource without first removing the lock. Locks are applied at the resource, resource-group, or subscription level and cascade downward.
Key distinction for the exam: Azure Policy enforces what can be deployed or configured; Resource Locks protect existing resources from modification or deletion.
Microsoft Purview
Microsoft Purview is a unified data-governance platform. It discovers data across Azure, on-premises, and multi-cloud environments, classifies it (e.g., identifying personal data or financial records), and tracks data lineage. Purview supports compliance requirements such as GDPR by giving organizations a map of where sensitive data lives and how it flows.
Azure Blueprints
Azure Blueprints package together role assignments, policy assignments, ARM templates, and resource groups into a single reusable definition. When you deploy a blueprint to a subscription, Azure creates all the components consistently and maintains a tracked relationship between the blueprint and what was deployed — making it easy to audit or update governed environments. Blueprints are designed for repeatable, compliant environment setup at scale.
Monitoring Tools in Detail
Azure Advisor
Azure Advisor analyzes your Azure usage and configurations and provides personalized, actionable recommendations across five categories: Cost, Security, Reliability (formerly High Availability), Operational Excellence, and Performance. Advisor is proactive — it surfaces potential improvements before problems occur. For example, it might recommend resizing an underutilized VM or enabling soft delete on a storage account.
Azure Monitor
Azure Monitor is the central platform for collecting, analyzing, and acting on telemetry from Azure and on-premises environments. It ingests metrics (numerical time-series data like CPU usage) and logs (structured or unstructured event records). Key sub-features include Log Analytics (query logs with KQL), Application Insights (application performance monitoring), and Alerts (notifications triggered by metric thresholds or log conditions). Azure Monitor is reactive — it tells you what is happening or has happened.
Azure Service Health
Azure Service Health communicates the health of the Azure platform itself — not your individual resources. It has three components: Azure Status (global outage map), Service Health (personalized alerts for the regions and services you use), and Resource Health (health of your specific resources). If an Azure data center has an outage affecting your region, Service Health is where you learn about it and receive updates.
For a complete picture of exam topics, see the complete AZ-900 guide and review all domains in the Microsoft Certified Azure Fundamentals overview.
You can continue preparing with the az 900 practice test, which includes answer explanations for every question.

- ✓Explain the difference between the Pricing Calculator and the TCO Calculator.
- ✓Describe what Azure Cost Management does and how budget alerts work.
- ✓Explain how resource tags are used for cost allocation.
- ✓Distinguish between Azure Policy (rule enforcement) and Resource Locks (change protection).
- ✓Know the two lock types: CanNotDelete and ReadOnly.
- ✓Describe what Microsoft Purview does and why organizations use it.
- ✓Explain the five recommendation categories in Azure Advisor.
- ✓Differentiate Azure Monitor (telemetry platform) from Azure Service Health (platform health).

- +Industry-recognized credential boosts your resume
- +Higher earning potential (10-20% salary increase on average)
- +Demonstrates commitment to professional development
- +Opens doors to advanced career opportunities
- −Exam preparation requires significant time investment (4-8 weeks)
- −Certification fees can be $100-$400+
- −May require continuing education to maintain
- −Some employers may not require certification
Sample AZ-900 Practice Questions
Try these questions from our free AZ-900 practice tests. The correct answer and an explanation follow each question.
Which Azure service category includes tools like Azure DevOps, Azure Monitor, and Azure Automation for managing and operating Azure deployments?
- A. Azure management and governance tools
- B. Azure compute services
- C. Azure networking services
- D. Azure identity services
Answer: A. Azure management and governance tools
Azure management and governance tools include services for monitoring, automating, and governing Azure deployments, such as Azure Monitor, Azure Automation, Azure Policy, and Azure DevOps.
A company plans to move all of its resources and data to Azure. Only Platform as a Service (PaaS) solutions must be used in Azure, according to the migration plan specified. John has been asked to set up an Azure environment that complies with the migration plan's requirements. John proposes setting up Azure SQL databases and an Azure App Service. Does the proposed remedy satisfy the demand?
- A. Elasticity
- B. High availability
- C. Load balancing
- D. High latency
Answer: A. Elasticity
Azure SQL databases and Azure App Service are both examples of Platform as a Service (PaaS) solutions. A key characteristic and benefit of PaaS offerings is elasticity, which means they can automatically scale resources up or down based on demand. This inherent ability to adapt to varying workloads without manual intervention directly satisfies the requirement for using PaaS solutions in the migration plan.
How do resource tags primarily assist with cost management and governance in Azure?
- A. By automatically encrypting resource data
- B. By preventing resources from being deployed in certain regions
- C. By enforcing network security rules
- D. By allowing costs to be grouped and allocated to specific departments or projects
Answer: D. By allowing costs to be grouped and allocated to specific departments or projects
Resource tags are key-value pairs that act as metadata to organize resources. For cost management, they are crucial for grouping billing data, allowing you to filter and analyze costs by categories such as department, project, or environment. This enables cost allocation and showback/chargeback within an organization. Tags do not provide encryption, location restrictions, or network security.
An organization wants a unified security management system that provides security posture recommendations and threat protection for their workloads running in Azure, on-premises, and in other clouds. Which Azure service provides these capabilities?
- A. Azure Monitor
- B. Microsoft Sentinel
- C. Microsoft Defender for Cloud
- D. Azure Firewall
Answer: C. Microsoft Defender for Cloud
Microsoft Defender for Cloud is a solution for cloud security posture management (CSPM) and cloud workload protection (CWPP). It identifies weaknesses across cloud configurations, helps strengthen the security posture, and protects workloads in multi-cloud and hybrid environments from threats.
About the Author

Educational Psychologist & Academic Test Preparation Expert
Columbia University Teachers CollegeDr. Lisa Patel holds a Doctorate in Education from Columbia University Teachers College and has spent 17 years researching standardized test design and academic assessment. She has developed preparation programs for SAT, ACT, GRE, LSAT, UCAT, and numerous professional licensing exams, helping students of all backgrounds achieve their target scores.
Join the Discussion
Connect with other students preparing for this exam. Share tips, ask questions, and get advice from people who have been there.
View discussion (9 replies)