Microsoft Azure Interview Questions
Comprehensive Azure interview questions covering cloud fundamentals, compute, storage, networking, security, serverless, and DevOps on Azure.
Azure is Microsoft's cloud computing platform providing over 200 products and services including compute, storage, networking, databases, AI, analytics, and DevOps tools. It allows organisations to build, deploy, and manage applications globally through Microsoft-managed data centres.
IaaS (Infrastructure as a Service) provides virtualised compute, storage, and networking (e.g., Azure VMs). PaaS (Platform as a Service) provides a managed platform for development without managing infrastructure (e.g., Azure App Service). SaaS (Software as a Service) delivers fully managed software (e.g., Microsoft 365).
A Resource Group is a logical container that holds related Azure resources for an application. It simplifies management, access control, billing, and lifecycle operations — deleting a resource group deletes all its resources.
Azure VMs are on-demand, scalable computing resources in the cloud. They provide IaaS, giving full control over the OS, software, and configuration. They support Windows and Linux and can be scaled using VM Scale Sets.
Azure App Service is a PaaS offering for hosting web apps, REST APIs, and mobile backends. It supports .NET, Node.js, Java, Python, and PHP, with built-in scaling, CI/CD, custom domains, and SSL.
Azure Blob Storage is a massively scalable object storage service for unstructured data — images, videos, documents, backups, and logs. It offers three access tiers: Hot (frequent access), Cool (infrequent access), and Archive (rare access).
Azure SQL Database is a fully managed PaaS database for single databases with hyperscale options. SQL Managed Instance provides near-100% compatibility with SQL Server on-premises, ideal for lift-and-shift migrations that require SQL Agent, linked servers, or CLR.
Azure Active Directory (now Microsoft Entra ID) is a cloud-based identity and access management service. It provides SSO, MFA, conditional access, and integration with thousands of SaaS applications and on-premises systems.
Azure Functions is a serverless compute service that runs event-driven code without managing infrastructure. Functions scale automatically and you pay only for execution time. Triggers include HTTP, timers, queues, blobs, and Event Grid.
AKS is a managed Kubernetes container orchestration service. It simplifies deployment, scaling, and management of containerised applications, with Azure handling the Kubernetes control plane, upgrades, and patching.
Azure DevOps is a suite of development tools including Azure Repos (Git), Azure Pipelines (CI/CD), Azure Boards (work tracking), Azure Test Plans, and Azure Artifacts (package management) for end-to-end DevOps workflows.
Azure Service Bus is a fully managed enterprise message broker that decouples applications and services. It supports queues (point-to-point) and topics (publish-subscribe), with features like sessions, dead-letter queues, and transactions.
Azure API Management is a gateway for publishing, securing, throttling, and monitoring APIs. It provides a developer portal, rate limiting, caching, authentication, and transformation policies to manage APIs at scale.
Azure Queue Storage is simple, low-cost, and suitable for large-volume message queuing with basic ordering. Service Bus is enterprise-grade with advanced features like topics, sessions, dead-lettering, transactions, and guaranteed message ordering.
Azure Monitor collects and analyses telemetry from Azure resources, VMs, and applications. Application Insights is a feature of Azure Monitor for application performance monitoring (APM), tracking requests, exceptions, dependencies, and user behaviour in web apps.
Azure Key Vault is a cloud service for securely storing and accessing secrets (API keys, passwords), certificates, and cryptographic keys. It integrates with other Azure services and controls access via Azure RBAC and access policies.
Azure Load Balancer operates at Layer 4 (TCP/UDP), distributing traffic based on IP and port. Application Gateway operates at Layer 7 (HTTP/HTTPS) with URL-based routing, SSL termination, WAF, and cookie-based session affinity.
Role-Based Access Control (RBAC) in Azure assigns roles to users, groups, or service principals at different scopes (subscription, resource group, or resource). Built-in roles include Owner, Contributor, and Reader.
Managed Identity provides an automatically managed identity in Azure AD for Azure services, eliminating the need to store credentials. System-assigned identities are tied to a resource's lifecycle; user-assigned identities are standalone and reusable.
IaC allows Azure resources to be defined and provisioned through code. Azure supports ARM templates, Bicep (a DSL for ARM), and third-party tools like Terraform and Pulumi to automate infrastructure provisioning consistently and repeatably.
Availability Sets protect VMs from hardware failures within a data centre using fault domains and update domains. Availability Zones are physically separate data centres within a region, protecting against data centre-level failures with higher SLAs.
Azure Content Delivery Network (CDN) caches static content at edge locations worldwide, reducing latency for users by serving content from the nearest point of presence rather than the origin server.
Azure Logic Apps is a low-code integration platform for automating workflows and integrating applications, data, services, and systems. It provides hundreds of connectors for SaaS and enterprise systems.
Cosmos DB is a globally distributed, multi-model NoSQL database with guaranteed single-digit millisecond latency, multi-region writes, and support for multiple APIs (SQL, MongoDB, Cassandra, Gremlin, Table).
The Azure Well-Architected Framework is a set of guiding principles across five pillars: Reliability, Security, Cost Optimisation, Operational Excellence, and Performance Efficiency, helping architects build robust Azure solutions.
Preparing for AZ-900, AZ-204, or AZ-305? Check out our Azure training.