IT Practice Exams

AZ-900 · Describe Cloud Concepts · Updated August 7, 2026

Public, Private, and Hybrid Cloud Deployment Models in Azure

A cloud deployment model describes who owns the infrastructure and who else shares it. Public cloud is owned by a third-party provider and shared across many tenants over the internet. Private cloud is dedicated to a single organization, whether it sits in that organization’s own datacenter or is hosted by a third party on its behalf. Hybrid cloud combines the two, letting workloads and data move between a private environment and public cloud capacity as business needs demand. For how deployment models fit into the exam’s broader structure, see the full AZ-900 study guide for how this fits into all three exam domains.

What each deployment model actually means

Public cloud resources — compute, storage, networking — are owned and operated by a provider like Microsoft and made available to any customer who signs up, over the internet. Multiple organizations share the same underlying hardware, isolated from each other logically rather than physically. This multi-tenancy is exactly what makes public cloud cheap and fast to consume: you pay for a slice of shared capacity instead of buying dedicated equipment.

Private cloud flips that arrangement. Infrastructure is reserved exclusively for one organization and never shared with other tenants. The key detail students often miss: private cloud doesn’t have to mean “in our own building.” A third party can host dedicated, single-tenant infrastructure on an organization’s behalf — what matters isn’t the physical location, it’s that nobody else’s workloads run on that hardware.

Hybrid cloud joins the two together. An organization keeps some workloads on private or on-premises infrastructure while running others in the public cloud, with the ability to shift capacity or data between them as circumstances change. It isn’t a separate third type of infrastructure — it’s an architecture that deliberately spans both.

Public vs. private vs. hybrid cloud at a glance

Public cloudPrivate cloudHybrid cloud
Who owns the infrastructureThird-party providerThe organization, or a third party dedicating it exclusivelyBoth — split across environments
Shared with other tenantsYes, multi-tenantNo, single-tenantThe public portion is shared; the private portion isn’t
Upfront hardware costNoneOften significantReduced, but not eliminated
Typical driverSpeed, low cost, elastic scaleRegulatory control, dedicated hardware requirementsRegulated data kept local, elastic capacity used elsewhere

Why organizations choose hybrid cloud

Hybrid cloud almost always shows up for one of two reasons. The first is regulatory or data-residency pressure: an organization must keep certain data — patient records, classified information, payment data — on infrastructure it directly controls, while still wanting the cost and scale benefits of the public cloud for everything else. The second is a phased migration: rather than moving every workload to the cloud at once, an organization keeps an aging or tightly customized system running on its own hardware for now while shifting newer workloads, like a website or an analytics platform, to public cloud services.

A third common driver is bursting — keeping a baseline workload on infrastructure the organization controls, then temporarily using public cloud capacity to absorb a demand spike (a seasonal sales rush, a large live event) without buying and maintaining hardware sized for that peak year-round. None of these reasons make hybrid automatically cheaper or automatically compliant — the deployment model doesn’t remove the work of configuring governance correctly, it just gives you the option to keep sensitive workloads local while still using elastic public capacity elsewhere. Managing that split environment consistently is where Azure Arc comes in, extending Azure management to resources running outside Azure.

Matching workloads to the right deployment model

Most AZ-900 questions on this topic aren’t asking you to define the three models — they’re describing a business situation and asking which model fits. A few recurring shapes:

  • An organization with a strict data-residency or classified-data requirement, needing full control over physical infrastructure and no shared tenancy at all, points to private cloud.
  • A small team with little capital, unpredictable traffic, and no interest in owning hardware points to public cloud — nothing about the scenario requires dedicated infrastructure.
  • Any scenario that keeps one piece regulated or legacy on infrastructure the organization controls while using public cloud elasticity for another piece — a hospital’s patient records alongside its scheduling app, a bank’s account data alongside its intranet, a manufacturer’s ERP system alongside its website — points to hybrid cloud.

Once you can separate “must stay under our control” from “benefits from elastic public capacity” within a single scenario, hybrid cloud questions stop being tricky. It also pairs directly with how responsibility is divided once you pick a model — see the shared responsibility model for how that split changes depending on which service model you layer on top of your deployment choice. Deployment model and service model are chosen independently, too: once you’ve settled on public, private, or hybrid, the next question is usually which of IaaS, PaaS, or SaaS you’ll run within it.

How the AZ-900 exam tests this

  • The regulated-data-plus-elasticity scenario. An organization must keep specific data on infrastructure it fully controls but also wants public cloud capacity for another part of the workload. The answer is hybrid cloud; single-model answers (public alone, private alone) each satisfy only half the requirement.
  • The “no shared infrastructure, full control” scenario. A government agency or similarly strict organization requires dedicated hardware never shared with anyone else. The answer is private cloud, even when hybrid is offered as a distractor — hybrid’s public portion still involves shared infrastructure, which fails the “never shared” requirement.
  • The low-capital startup scenario. A small team wants to launch quickly with no hardware to buy and elastic scaling if the app takes off. The answer is public cloud; private and hybrid both imply some owned or dedicated infrastructure the startup doesn’t need or can’t afford.
  • The phased-migration scenario. An organization keeps a legacy system on-premises for now while moving newer workloads to the cloud, with a plan to migrate the legacy system later. This transitional state — running some things locally and some things in the public cloud simultaneously — is hybrid cloud, distinct from a completed migration to public cloud.

These four situational patterns cover the large majority of deployment-model questions; AZ-900 practice questions reinforce the pattern-matching until it’s second nature.

Quick reference

  • Public cloud: third-party owned, multi-tenant, no upfront hardware cost, fastest to launch.
  • Private cloud: dedicated to one organization, single-tenant, may be hosted on-premises or by a third party.
  • Hybrid cloud: combines public and private, with workloads and data able to move between them.
  • Private cloud location doesn’t have to be “in our building” — a third party can host dedicated, non-shared infrastructure.
  • Hybrid cloud’s two most common drivers: regulatory/data-residency requirements and phased migration.
  • No deployment model automatically guarantees compliance or the lowest cost — those still depend on how you configure and use it.
  • When a scenario splits requirements between “must stay controlled” and “benefits from elasticity,” that split is the hybrid cloud signal.
Choose your exam → Lifetime access
from $59, once