Azure Services: A Tech Team Quick Reference Page Azure Services: A Tech Team Quick Reference A condensed, decision-focused guide to the major Azure service categories By Swedel F Menezes - Cloud Team A condensed, decision-focused guide to the major Azure service categories. For each service: what it is, primary use cases, and a one-line “when to choose it” rule. Use this as a quick reference when designing or reviewing an Azure architecture. Azure Reference Architecture — Layer Overview Layer Service(s) Role Edge / Ingress Azure Front Door Global HTTP load balancing, CDN, WAF & intelligent routing Web / API Compute App Service Managed PaaS for web apps, REST APIs and mobile backends Container Compute AKS (Kubernetes) Orchestrated containers, microservices, auto-scaling Serverless Compute Azure Functions Event-driven, short-lived tasks triggered by HTTP/queue/blob Relational Data Azure SQL Database Managed SQL Server — structured OLTP workloads NoSQL / Global Data Cosmos DB Multi-model, globally distributed, <10 ms latency Object Storage Blob Storage Unstructured data — media, backups, analytics staging Caching Azure Cache for Redis Sub-millisecond in-memory caching & session state Identity Microsoft Entra ID SSO, MFA, app registrations & managed identities Secrets Key Vault Centralised store for secrets, keys & TLS certificates Observability Azure Monitor + App Insights Full-stack metrics, logs, alerts & distributed tracing Security Posture Defender for Cloud CSPM scoring, threat detection & compliance dashboards 1. Compute Service What it is & key use cases When to choose it Virtual Machines (VMs) IaaS with full OS control. Lift-and-shift, legacy apps, custom OS, dev/test. You need full OS control or have compliance/legacy needs that block PaaS. App Service Managed PaaS for web apps & REST APIs. ASP.NET/Node/Python/Java, auto-scale, CI/CD. You want to focus on code, not infra, and don’t need container orchestration. Azure Kubernetes Service (AKS) Managed Kubernetes for containers. Microservices, auto-scaling, self-healing. You run multiple containers needing orchestration & service discovery. Container Instances (ACI) Serverless single containers. Batch jobs, CI tasks, quick tests. Simple isolated container tasks; use AKS if you need orchestration. Azure Functions Event-driven serverless compute. HTTP APIs, timers, queue/blob events. Short-lived, event-triggered work. Avoid for long-running (>10 min) jobs. 2. Storage Service What it is & key use cases When to choose it Blob Storage Object storage for unstructured data. Static sites, media, backups, analytics staging. Any binary/unstructured data. Hot/Cool/Archive tiers by access frequency. Azure Files Managed SMB/NFS file shares. Replace on-prem file servers, shared config. Apps that need a shared file system; use Blob for object storage. Data Lake Storage Gen2 Blob + hierarchical namespace for big data. ML data, ETL, Synapse/Databricks. Big-data workloads needing directory-level ACLs and hierarchy. 3. Networking Service What it is & key use cases When to choose it Virtual Network (VNet) Isolated private network — foundation of secure deployments. Always for production. Never expose resources without NSG rules. Load Balancer Layer 4 (TCP/UDP) balancing across VMs. HA, inbound NAT, internal LB. Non-HTTP VM workloads needing HA; use App Gateway for HTTP. Application Gateway Layer 7 (HTTP/S) LB with WAF, SSL termination, URL routing. HTTP/S apps needing WAF, SSL offload, or path-based routing (regional). Front Door Global HTTP LB with CDN, WAF, intelligent routing. Global apps needing low latency worldwide + edge CDN/failover. VPN Gateway Site-to-site / point-to-site VPN to on-prem. Hybrid cloud, remote access. Encrypted hybrid connectivity; use ExpressRoute for dedicated bandwidth. 4. Databases Service What it is & key use cases When to choose it Azure SQL Database Managed relational PaaS (SQL Server engine). Web/enterprise OLTP, migrations. Structured relational data. Elastic Pool for many DBs, MI for full compat. Cosmos DB Globally distributed multi-model NoSQL. IoT, catalogs, gaming, multi-region writes. You need <10ms global latency, flexible schema, or active-active replication. Azure Cache for Redis Managed in-memory cache. Session state, query caching, leaderboards, pub/sub. App has repetitive expensive queries or needs sub-millisecond responses. Synapse Analytics Unified data warehouse + big data analytics. ETL/ELT, BI, Power BI/ML. Large-scale analytical workloads; use Azure SQL for operational OLTP. 5. AI & Machine Learning Service What it is & key use cases When to choose it Azure Machine Learning End-to-end ML platform. Custom models, AutoML, MLOps, monitoring/retraining. Building custom models; use AI Services for pre-built capabilities. Azure AI Services Pre-built AI APIs — Vision, Speech, Language, Decision. OCR, sentiment, STT/TTS. You need AI features fast via REST without training custom models. Azure OpenAI Service OpenAI models (GPT, DALL-E, Whisper, embeddings) in Azure. Chatbots, summarization, code, semantic search. You need enterprise security, private networking, compliance & data residency. 6. DevOps & Monitoring Service What it is & key use cases When to choose it Azure DevOps Boards, Repos, Pipelines, Test Plans, Artifacts. CI/CD, agile, source control. End-to-end DevOps lifecycle integrated with the Azure ecosystem. Key Vault Secure store for secrets, keys, certificates. Connection strings, TLS certs, CMK. Always — never hardcode credentials. Access via managed identity. Monitor & App Insights Full-stack observability — metrics, logs, alerts, APM, distributed tracing. Enable on every app/Function from day one; retro-fitting is harder. 7. Security & Identity Service What it is & key use cases When to choose it Microsoft Entra ID Cloud identity & access (IAM). SSO, MFA, app registrations, managed identities. Always for authentication; use managed identities for service-to-service auth. Defender for Cloud CSPM + workload protection. Posture scoring, threat detection, compliance. Enable on all production subscriptions for a unified security view. Microsoft Sentinel Cloud-native SIEM + SOAR. Event aggregation, AI analytics, automated response. Centralized security monitoring across Azure + on-prem + multi-cloud. 8. Integration & Messaging Service What it is & key use cases When to choose it Service Bus Enterprise broker — queues & topics (pub/sub). Decoupling, dead-lettering, ordering. Reliable, ordered, transactional messaging; use Event Hubs for streaming. Event Hubs Big-data event streaming (millions/sec). IoT telemetry, logs, click-streams. High-volume event ingestion feeding analytics pipelines. Logic Apps Low-code workflow automation, 400+ connectors. B2B, approvals, SaaS integration. Integration workflows across SaaS/enterprise; use Functions for custom code. API Management (APIM) Full-lifecycle API gateway. Publish, secure, throttle, version, dev portal. Exposing APIs externally or across teams with governance & observability. 9. Analytics Service What it is & key use cases When to choose it Azure Databricks Spark-based analytics platform. Large ETL, ML at scale, streaming, lakehouse. Complex big-data processing with Spark; integrates with ADLS Gen2 & Synapse. Data Factory (ADF) Cloud-scale ETL/ELT integration. Pipeline orchestration, 90+ connectors. The orchestration layer of your data platform; moving data on-prem ↔ cloud. Service Selection Decision Tree What kind of workload?   Run application code Event-driven → Functions Web app / API → App Service Containers at scale → AKS Full OS control → VMs Store / query data Relational / OLTP → Azure SQL Global NoSQL → Cosmos DB Files / blobs → Blob Storage Analytics / DW → Synapse Connect / process events Reliable queue → Service Bus High-volume stream → Event Hubs Low-code workflow → Logic Apps Publish APIs → API Management Always add: Entra ID (identity) • Key Vault (secrets) • Monitor + App Insights (observability) Figure 2 — Decision tree mapping a workload type to the recommended Azure service. Service Selection Quick Reference Need Service Host a web app App Service Run containers at scale AKS Simple container task ACI Serverless function Azure Functions Relational DB Azure SQL Database NoSQL / Global DB Cosmos DB Cache Azure Cache for Redis Data warehouse Synapse Analytics Big data processing Databricks ETL orchestration Data Factory Store files/blobs Blob Storage Shared file system Azure Files Pre-built AI APIs Azure AI Services Custom ML models Azure ML LLM / GPT Azure OpenAI Message queue Service Bus Event streaming Event Hubs API gateway API Management Secrets management Key Vault Identity / SSO Microsoft Entra ID Security posture Defender for Cloud SIEM Microsoft Sentinel Monitoring / APM Azure Monitor + App Insights