Microsoft Azure Services and Architecture Questions

Microsoft Azure's core service catalog and architectural patterns: Virtual Machines, managed Kubernetes (AKS), App Service and Azure Functions, Storage accounts and managed disks, Azure SQL and Cosmos DB, VNets with hybrid connectivity and global load balancing, Microsoft Entra ID and RBAC, and Key Vault secrets and encryption. Covers Azure service selection, infrastructure as code (ARM, Bicep, Terraform), observability with Azure Monitor and Kusto queries, cost governance and Azure Policy, the Azure Well-Architected design principles, and hybrid management via Azure Arc, common in enterprise Azure estates. For provider-agnostic trade-offs, see the cross-cloud entries.

MediumTechnical
76 practiced

An enterprise wants to migrate hundreds of VMs and databases to Azure. Compare lift-and-shift (IaaS) to re-platforming (PaaS) and refactoring. Discuss migration effort, downtime, cost, operational benefits, and propose a phased migration roadmap with pilot, migration waves, validation, and rollback plans. Also cover tools (Azure Migrate, Database Migration Service) you would use.

HardSystem Design
69 practiced

Propose a cost-optimized architecture for a batch data processing pipeline that ingests 10 TB/day with a 6-hour SLA. Compare using Azure Batch (spot VMs), AKS with scale-to-zero nodes, Databricks with spot workers, and serverless orchestration. Discuss throughput, checkpointing, handling spot preemptions, and operational overhead for each choice.

MediumTechnical
79 practiced

You're designing compute for a latency-sensitive transactional service. Describe the selection process for Azure VM sizes including considerations for vCPU, memory ratio, local/ephemeral disk availability, managed disk IOPS and throughput, network bandwidth, and cost. Explain how you'd validate sizing with benchmarks and telemetry.

MediumTechnical
97 practiced

Describe how to use Azure Policy to enforce resource-level constraints such as requiring an enforced 'cost-center' tag, permitted VM SKUs, and encryption at rest. Provide an example policy effect (Audit, Deny, DeployIfNotExists) for tagging and explain how to remediate existing non-compliant resources without breaking production.

MediumTechnical
57 practiced

Write a Terraform (HCL) snippet that creates a user-assigned Managed Identity in Azure, assigns it the 'Reader' built-in role on a specific resource group, and configures the remote backend to use Azure Storage with locking enabled. Assume azurerm provider; show the key resource blocks and backend configuration.

Unlock Full Question Bank

Get access to all Microsoft Azure Services and Architecture interview questions and detailed answers.

Sign in to Continue

Join thousands of developers preparing for their dream job.