Understanding Azure architecture is an essential task for the AZ-900 exam. Azure divides into physical infrastructure (where the servers are) and logical structure (how resources are grouped and managed). The nationwide logistics network and company filing system analogies make everything clear at once.
The Full Structure at a Glance
Azure's entire infrastructure breaks into two dimensions.
The physical dimension addresses "where in the world are Azure's servers." Data centers, regions, availability zones, and region pairs all belong here.
The logical dimension addresses "how Azure resources are grouped and managed." Resources, resource groups, subscriptions, and management groups all belong here.
Physical Infrastructure — The Nationwide Logistics Network Analogy
Imagine a large parcel delivery company running logistics centers in multiple cities across the country. Independent centers operate in Seoul, Busan, Daegu, and Incheon. If one city's center has a problem, the others keep running normally. Azure regions are exactly those logistics centers.
Data Centers
Everything in Azure starts with physical data centers. A data center is a building filled with actual servers, network equipment, and storage. Azure operates hundreds of data centers worldwide. Each data center has independent power supplies, cooling systems, and network connections. For security, the public cannot visit, and exact locations are not disclosed.
Regions
A region is a collection of multiple data centers located within the same geographic area. Azure operates more than 60 regions worldwide — more than any other cloud provider.
Sample Region List
| Area | Region Name | |------|------------| | South Korea | Korea Central (Seoul), Korea South (Busan) | | United States | East US (Virginia), West US (California), Central US (Iowa) | | Europe | North Europe (Ireland), West Europe (Netherlands) | | Asia | East Asia (Hong Kong), Southeast Asia (Singapore) | | Japan | Japan East (Tokyo), Japan West (Osaka) |
What to Consider When Choosing a Region
Latency: Choosing the region closest to end users speeds up response times. For a service targeting Korean users, Korea Central is the best choice. Data Sovereignty: Some national laws require certain types of data to be stored only within the country. For example, the EU's GDPR may require European citizens' data to remain within Europe. Service Availability: Not every Azure service is available in every region. When using a specific service, you must choose a region that supports it. Cost: Prices can differ by region. East US is typically among the least expensive. Compliance: Certain industries (finance, healthcare) may have regulations requiring the use of data centers in specific locations.
Availability Zones
Now think of a single logistics center (region) that operates multiple independent buildings. Building A, B, and C each have independent wiring, cooling, and internet connections. If Building A catches fire, Buildings B and C continue operating. That is an Availability Zone.
An Availability Zone is a physically separate data center inside a single region. Each zone has its own independent power supply, cooling system, and networking, so one zone going completely down does not affect the others. A region typically has three availability zones.
How to Use Availability Zones
Zone-redundant services: Azure automatically replicates data or applications across multiple zones. Azure Storage's ZRS (Zone-Redundant Storage) is the prime example. Zonal services: You directly place resources in a specific zone. Placing one VM in each of zones 1, 2, and 3, for instance, ensures the service continues even if one zone goes down.
Region Pairs
Think of twin logistics centers. The Seoul center and the Busan center are officially paired. If a large-scale disaster (earthquake, flood) hits Seoul, the Busan center automatically takes over the service. Both centers constantly monitor each other's status. That is a region pair.
Key Region Pairs
| Region 1 | Region 2 | |---------|---------| | Korea Central (Seoul) | Korea South (Busan) | | East US | West US | | North Europe | West Europe | | East Asia | Southeast Asia | | Japan East | Japan West |
Important Characteristics of Region Pairs
The two regions are at least 300 km apart within the same geographic area (same country or adjacent countries). A large-scale disaster triggers automatic failover from one region to the other. When Azure rolls out platform updates, it never updates both regions in a pair at the same time. It updates one first, and only updates the other if the first succeeds. This prevents total service outages during updates. Data replication stays within the same country or adjacent countries, respecting data sovereignty regulations.
Availability Zones vs. Region Pairs
| | Availability Zones | Region Pairs | |--|-------------------|-------------| | Scope | Within the same region | Different regions (hundreds of km apart) | | Distance | A few km | At least 300 km | | Protects against | Single data center failure | Disasters affecting an entire region | | Typical count | 3 per region | 1 pair per region | | Active status | Both zones active simultaneously | One in standby, activates on failure |
Sovereign Regions
These are special-purpose regions physically and logically isolated from standard Azure commercial regions. They exist to meet specific government or regulatory requirements.
Azure Government: Reserved exclusively for US federal, state, and local government agencies and their partners. Accessible only from within the United States; completely inaccessible with a standard Azure account. Complies with US government FedRAMP and DoD security standards. Azure China: An isolated environment operating entirely within China, as required by Chinese law. Operated by 21Vianet, not Microsoft.
On the exam, whenever "a special Azure environment for a specific country's government agencies" is mentioned, a sovereign region is the answer.
Logical Structure — The Company Filing System Analogy
If physical infrastructure is "where Azure servers are," logical structure is "how Azure resources are managed." The way a company organizes paper filing systems makes this easy to understand.
A Resource is one sheet of paper. One VM, one database, one network — each is one resource.
A Resource Group is a file folder. Related documents go into one folder. For example, a "web project" folder holds the web server VM, the database, and the load balancer.
A Subscription is a file drawer. One drawer produces one invoice. Using different drawers per department keeps departmental costs separate.
A Management Group is the entire filing cabinet. Multiple drawers (subscriptions) are grouped into one cabinet, and the same security policy is applied to all of them at once.
!The Azure resource hierarchy
Full Hierarchy
Resource Groups
A resource group is a container that bundles related Azure resources together as a single management unit. Every Azure resource must belong to exactly one resource group.
Important Characteristics of Resource Groups
Every Azure resource can belong to exactly one resource group — it cannot be in two groups at the same time. Deleting a resource group deletes all resources inside it. This is a powerful feature, but misusing it can cause data loss. The resource group itself incurs no cost. Only the resources inside it generate charges. Resources in one resource group can freely communicate with resources in another resource group. Resources can be moved to a different resource group (though some resource types have move restrictions). Tags can be applied to resource groups to track costs or categorize resources.
Common Resource Group Organization Patterns
By project: "ProjectA-Dev", "ProjectA-Prod" By environment: "Dev-ResourceGroup", "Test-ResourceGroup", "Prod-ResourceGroup" By department: "Marketing-ResourceGroup", "Engineering-ResourceGroup" By lifecycle: Group resources that will be deleted together at the same time
Subscriptions
A subscription is the contractual and billing unit for using Azure services. Every Azure resource must belong to exactly one subscription. Subscriptions also serve as access control boundaries.
Key Roles of a Subscription
Billing boundary: A separate invoice is generated for each subscription. Separating subscriptions by department gives precise visibility into each department's cloud costs. Access control boundary: Azure RBAC (Role-Based Access Control) can be applied at the subscription level. Teams that should be isolated from each other use separate subscriptions. Resource limits: Each subscription has resource creation limits. For example, a subscription defaults to a maximum of 20,000 VMs. If a limit is reached, you can create a new subscription or request a limit increase.