AZ-900 Azure Management and Governance: Domain 3 Study Notes 2026 October

Boost your AZ exam score with practice questions and detailed answer explanations. Track progress with instant feedback. 🎯

AZ-900 Azure Management and Governance: Domain 3 Study Notes 2026 October

Domain 3 Overview: Management and Governance

Azure Management and Governance is the largest domain on the AZ-900 exam, accounting for 30–35% of all questions. This domain tests your understanding of how Azure helps organizations control costs, enforce compliance, and maintain visibility across cloud resources.

Domain 3 is organized around three pillars:

  • Cost Management — Tools that help you estimate, track, and optimize Azure spending.
  • Governance — Services that enforce organizational rules, protect resources, and maintain compliance at scale.
  • Monitoring — Solutions that provide operational visibility, proactive recommendations, and service-health awareness.

Because this domain makes up roughly one-third of the exam, even a basic conceptual understanding of each tool can meaningfully improve your score. You are not expected to configure these services — only to understand what they do and when you would use them.

Before diving in, make sure you have already reviewed core Azure services and the broader AZ-900 study guide, since governance concepts build on foundational cloud knowledge.

Cost Management Tools in Detail

Pricing Calculator vs. TCO Calculator

The Azure Pricing Calculator is used before you deploy. You select Azure products, configure their expected usage (region, tier, hours per month), and receive a cost estimate. It is ideal for planning new workloads or comparing service tiers.

The Total Cost of Ownership (TCO) Calculator serves a different purpose: it helps you justify migration by comparing your current on-premises infrastructure costs against equivalent Azure costs over time. You input your existing servers, storage, networking, and labor costs, and the tool projects multi-year savings. On the exam, remember: Pricing Calculator = estimate Azure costs; TCO Calculator = compare cloud vs. on-prem.

Azure Cost Management

Once resources are running, Azure Cost Management (sometimes called Microsoft Cost Management) provides dashboards, budgets, and alerts to track actual spending. You can set budget thresholds that trigger email alerts when costs approach or exceed defined limits, and use cost-analysis views to break down spending by service, resource group, or time period.

Tags

Tags are name-value pairs you attach to Azure resources (e.g., Department: Finance or Environment: Production). Tags do not affect resource behavior, but they make it easy to filter cost reports and allocate charges to specific teams or projects. Tags are applied at the resource or resource-group level.

Governance Features in Detail

Azure Policy vs. Resource Locks

Azure Policy lets you define rules — called policy definitions — that Azure enforces across your subscriptions and resource groups. A policy might require all resources to have a specific tag, restrict deployment to certain regions, or mandate a minimum VM SKU. Policies can audit (report non-compliant resources) or deny (block non-compliant deployments). You can bundle multiple policies into an initiative (also called a policy set).

Resource Locks operate differently: they prevent changes or deletions regardless of the user's permissions. A CanNotDelete lock allows reads and modifications but blocks deletion. A ReadOnly lock prevents all writes — even authorized administrators cannot modify the resource without first removing the lock. Locks are applied at the resource, resource-group, or subscription level and cascade downward.

Key distinction for the exam: Azure Policy enforces what can be deployed or configured; Resource Locks protect existing resources from modification or deletion.

Microsoft Purview

Microsoft Purview is a unified data-governance platform. It discovers data across Azure, on-premises, and multi-cloud environments, classifies it (e.g., identifying personal data or financial records), and tracks data lineage. Purview supports compliance requirements such as GDPR by giving organizations a map of where sensitive data lives and how it flows.

Azure Blueprints

Azure Blueprints package together role assignments, policy assignments, ARM templates, and resource groups into a single reusable definition. When you deploy a blueprint to a subscription, Azure creates all the components consistently and maintains a tracked relationship between the blueprint and what was deployed — making it easy to audit or update governed environments. Blueprints are designed for repeatable, compliant environment setup at scale.

Monitoring Tools in Detail

Azure Advisor

Azure Advisor analyzes your Azure usage and configurations and provides personalized, actionable recommendations across five categories: Cost, Security, Reliability (formerly High Availability), Operational Excellence, and Performance. Advisor is proactive — it surfaces potential improvements before problems occur. For example, it might recommend resizing an underutilized VM or enabling soft delete on a storage account.

Azure Monitor

Azure Monitor is the central platform for collecting, analyzing, and acting on telemetry from Azure and on-premises environments. It ingests metrics (numerical time-series data like CPU usage) and logs (structured or unstructured event records). Key sub-features include Log Analytics (query logs with KQL), Application Insights (application performance monitoring), and Alerts (notifications triggered by metric thresholds or log conditions). Azure Monitor is reactive — it tells you what is happening or has happened.

Azure Service Health

Azure Service Health communicates the health of the Azure platform itself — not your individual resources. It has three components: Azure Status (global outage map), Service Health (personalized alerts for the regions and services you use), and Resource Health (health of your specific resources). If an Azure data center has an outage affecting your region, Service Health is where you learn about it and receive updates.

For a complete picture of exam topics, see the complete AZ-900 guide and review all domains in the Microsoft Certified Azure Fundamentals overview.

You can continue preparing with the az 900 practice test, which includes answer explanations for every question.

Azure Cost Management dashboard showing budget alerts and spending analysis
  • ✓Explain the difference between the Pricing Calculator and the TCO Calculator.
  • ✓Describe what Azure Cost Management does and how budget alerts work.
  • ✓Explain how resource tags are used for cost allocation.
  • ✓Distinguish between Azure Policy (rule enforcement) and Resource Locks (change protection).
  • ✓Know the two lock types: CanNotDelete and ReadOnly.
  • ✓Describe what Microsoft Purview does and why organizations use it.
  • ✓Explain the five recommendation categories in Azure Advisor.
  • ✓Differentiate Azure Monitor (telemetry platform) from Azure Service Health (platform health).
Azure Policy and Resource Locks governance diagram showing rule enforcement hierarchy
✅Pros
  • +Industry-recognized credential boosts your resume
  • +Higher earning potential (10-20% salary increase on average)
  • +Demonstrates commitment to professional development
  • +Opens doors to advanced career opportunities
❌Cons
  • −Exam preparation requires significant time investment (4-8 weeks)
  • −Certification fees can be $100-$400+
  • −May require continuing education to maintain
  • −Some employers may not require certification

Sample AZ-900 Practice Questions

Try these questions from our free AZ-900 practice tests. The correct answer and an explanation follow each question.

  1. Which Azure service category includes tools like Azure DevOps, Azure Monitor, and Azure Automation for managing and operating Azure deployments?

    • A. Azure management and governance tools
    • B. Azure compute services
    • C. Azure networking services
    • D. Azure identity services

Answer: A. Azure management and governance tools

Azure management and governance tools include services for monitoring, automating, and governing Azure deployments, such as Azure Monitor, Azure Automation, Azure Policy, and Azure DevOps.

  • A company plans to move all of its resources and data to Azure. Only Platform as a Service (PaaS) solutions must be used in Azure, according to the migration plan specified. John has been asked to set up an Azure environment that complies with the migration plan's requirements. John proposes setting up Azure SQL databases and an Azure App Service. Does the proposed remedy satisfy the demand?

    • A. Elasticity
    • B. High availability
    • C. Load balancing
    • D. High latency
  • Answer: A. Elasticity

    Azure SQL databases and Azure App Service are both examples of Platform as a Service (PaaS) solutions. A key characteristic and benefit of PaaS offerings is elasticity, which means they can automatically scale resources up or down based on demand. This inherent ability to adapt to varying workloads without manual intervention directly satisfies the requirement for using PaaS solutions in the migration plan.

  • How do resource tags primarily assist with cost management and governance in Azure?

    • A. By automatically encrypting resource data
    • B. By preventing resources from being deployed in certain regions
    • C. By enforcing network security rules
    • D. By allowing costs to be grouped and allocated to specific departments or projects
  • Answer: D. By allowing costs to be grouped and allocated to specific departments or projects

    Resource tags are key-value pairs that act as metadata to organize resources. For cost management, they are crucial for grouping billing data, allowing you to filter and analyze costs by categories such as department, project, or environment. This enables cost allocation and showback/chargeback within an organization. Tags do not provide encryption, location restrictions, or network security.

  • An organization wants a unified security management system that provides security posture recommendations and threat protection for their workloads running in Azure, on-premises, and in other clouds. Which Azure service provides these capabilities?

    • A. Azure Monitor
    • B. Microsoft Sentinel
    • C. Microsoft Defender for Cloud
    • D. Azure Firewall
  • Answer: C. Microsoft Defender for Cloud

    Microsoft Defender for Cloud is a solution for cloud security posture management (CSPM) and cloud workload protection (CWPP). It identifies weaknesses across cloud configurations, helps strengthen the security posture, and protects workloads in multi-cloud and hybrid environments from threats.

    Take the full AZ-900 practice test

    About the Author

    Dr. Lisa Patel
    Dr. Lisa PatelEdD, MA Education, Certified Test Prep Specialist

    Educational Psychologist & Academic Test Preparation Expert

    Columbia University Teachers College

    Dr. Lisa Patel holds a Doctorate in Education from Columbia University Teachers College and has spent 17 years researching standardized test design and academic assessment. She has developed preparation programs for SAT, ACT, GRE, LSAT, UCAT, and numerous professional licensing exams, helping students of all backgrounds achieve their target scores.

    Join the Discussion

    Connect with other students preparing for this exam. Share tips, ask questions, and get advice from people who have been there.

    View discussion (9 replies)