The shared responsibility model is one of the ideas the AZ-900 comes back to again and again — and if it feels slippery right now, you are in good company. Almost everyone finds it fuzzy until they see it as a single picture. So start with the diagram above: a stack of seven layers, from the physical datacenter at the bottom to access management at the top, with three columns showing who owns each layer under IaaS, PaaS, and SaaS. Once that picture is in your head, most exam questions on this topic become a matter of pointing at the right layer.
The line moves — but only in the middle
Here is the whole model in one sentence: the more managed the service, the more of the stack Microsoft takes over — starting from the bottom. In IaaS (think Azure Virtual Machines) Microsoft owns the physical datacenter and the host and network infrastructure, while you own the operating system and everything above it. Move to PaaS (Azure App Service) and the operating system slides over to Microsoft too — you just bring your application and data. Move to SaaS (Microsoft 365) and the application itself becomes Microsoft’s, leaving you a thin, important strip at the top.
The key insight is that the boundary only ever moves through the middle of the stack. The bottom is always Microsoft’s. And the top — the highlighted band in the diagram — is always yours.
The four things that never leave your side
No matter which model you choose, four responsibilities stay with the customer: your data, your identities, your accounts, and access management. Learn these four words cold, because they answer a surprising share of the questions on this topic.
- Data — you decide what is sensitive and who may read it. Microsoft secures the platform and hands you encryption and labels, but it never classifies your data for you.
- Identities and accounts — you create users, you disable them when people leave, you decide how they authenticate.
- Access management — you assign who may do what, and you enforce controls like multi-factor authentication.
This is why a question about switching on MFA in Microsoft 365 — a fully managed SaaS product — still lands on the customer. The application is Microsoft’s; the identity in front of it is yours.
Reading the layers Microsoft always owns
Just as the top never moves, the bottom never moves either. The physical datacenter — the building, the badge readers, the servers, the cabling — is Microsoft’s in every single model, IaaS included. This trips people up, because “full control of the operating system” in IaaS sounds like full control of everything. It is not: you manage the software from the OS up, never the hardware it runs on. The same goes for the host and physical network infrastructure. Watch for questions that hide two layers behind one word — “network” can mean the physical switches (always Microsoft) or your Network Security Group rules (always you).
Practise pointing at the right layer
Work through the seven questions below, and for each one, ask yourself which layer of the diagram it is really testing, and whether that layer is in the fixed top, the fixed bottom, or the moving middle. Read every explanation past the correct answer — the “Why not the others:” line is where this topic actually clicks, because the distractors are built from the exact confusions the exam wants to catch. The real test mixes multiple-choice, true/false, and drag-and-drop formats; our samples are standard multiple-choice, but the reasoning is identical. Get the layers straight here, and shared responsibility turns into one of the calmest, most predictable topics on your AZ-900.
Updated for AZ-900 (July 2026). The sample questions above are our own work
in the style of the exam — not real exam items. The exam itself is set and marked
by the certification body.