Blog

AZ-104 study guide: domains, format and a 6-week plan

· 8 min read

AZ-104, Microsoft Azure Administrator, is the exam for the Microsoft Certified: Azure Administrator Associate certification. It tests whether you can run an organisation's Azure environment day to day: identities and governance, storage, compute, virtual networking, and monitoring and backup. You have 100 minutes, the exam is proctored and may include interactive components, and the passing score is 700.

Unlike AZ-900, it expects you to have done the work in the portal, the CLI and PowerShell, not just to recognise service names.

AZ-104 at a glance

ItemDetail
ProviderMicrosoft Azure
LevelAssociate (intermediate)
Questions40–60
Duration100 minutes
Passing score700 out of 1000
Exam feeUS$165 in the United States; the price varies by country or region
LanguagesEnglish, Chinese (Simplified), Chinese (Traditional), French, German, Italian, Japanese, Korean, Portuguese (Brazil), Spanish
DeliveryProctored, scheduled through Pearson VUE, online or at a test centre
Question formatsMultiple choice (single and multiple answer), yes/no statement series, drag and drop, hot area and case studies

Details as of September 2026 — confirm on the official exam page before booking.

Microsoft does not publish which exams contain labs, because labs can be removed at any time. Its exam-experience page gives 100 minutes for role-based exams without labs and 120 minutes for those that may contain them, and AZ-104 is currently listed at 100. The certification must be renewed every 12 months through a free, unproctored online assessment on Microsoft Learn.

Who this exam is for

Microsoft's audience profile describes an administrator with subject matter expertise in implementing, managing and monitoring an organisation's Azure environment, usually as part of a larger team that also includes networking, security, database, development and DevOps roles.

You should be familiar with operating systems, networking, servers and virtualisation, and have hands-on experience with PowerShell, the Azure CLI, the Azure portal, ARM templates or Bicep files, and Microsoft Entra ID. There is no prerequisite exam. If you have never used Azure, start with [AZ-900](/blog/az-900-study-guide) or at least a few weeks in a free subscription before you start this plan.

What the exam covers

The AZ-104 study guide lists the skills measured as of 17 April 2026 in five areas.

Manage Azure identities and governance (20–25%)

The first half is Microsoft Entra ID: creating users and groups, managing their properties and licences, inviting external users, and configuring self-service password reset. The second half is Azure access and governance: built-in roles, assigning them at management group, subscription, resource group and resource scope, and reading an access assignment to work out what someone can actually do.

Governance tasks cover Azure Policy, resource locks, tags, resource groups, subscriptions, management groups, and cost control with budgets, alerts and Azure Advisor. Expect questions that test inheritance: what a policy or lock at one scope does to resources below it.

Implement and manage storage (15–20%)

Access is a large part of this area: storage firewalls and virtual network rules, shared access signatures, stored access policies, access keys, and identity-based access for Azure Files. You also create and configure storage accounts, choose a redundancy option, set up object replication and encryption, and move data with Azure Storage Explorer and AzCopy.

The final task covers Azure Files shares and Blob Storage containers, access tiers, soft delete, Azure Files snapshots, lifecycle management and blob versioning.

Deploy and manage Azure compute resources (20–25%)

Four tasks. Infrastructure as code: reading, modifying and deploying ARM templates and Bicep files, exporting a deployment and converting a template to Bicep. Virtual machines: creating them, encryption at host, moving VMs between resource groups, subscriptions and regions, resizing, managing disks, availability zones and availability sets, and Virtual Machine Scale Sets.

Containers: Azure Container Registry, Azure Container Instances and Azure Container Apps, including sizing and scaling. App Service: plans and their scaling, certificates and TLS, custom domains, backup, networking and deployment slots. The judgement tested is usually which compute option or setting fits the stated constraint.

Implement and manage virtual networking (15–20%)

You create virtual networks and subnets, configure peering, public IP addresses and user-defined routes, and troubleshoot connectivity. Secure access covers network security groups and application security groups, evaluating effective security rules, Azure Bastion, and the difference between service endpoints and private endpoints for PaaS services.

The last task is Azure DNS and internal or public load balancers, including troubleshooting a load balancer that is not distributing traffic. Rule evaluation order and routing precedence are frequent sources of scenario questions.

Monitor and maintain Azure resources (10–15%)

Monitoring means interpreting Azure Monitor metrics, configuring diagnostic and log settings, querying logs, building alert rules, action groups and alert processing rules, using Azure Monitor Insights for VMs, storage and networks, and diagnosing with Network Watcher and Connection monitor.

Backup and recovery covers Recovery Services vaults and Azure Backup vaults, backup policies, backup and restore operations, Azure Site Recovery for Azure resources, failover to a secondary region, and backup reports and alerts. Knowing which vault type protects which workload is worth learning early.

A 6-week study plan

Identity, governance and compute together carry up to half the marks, so they get the most time. Do every week in a real subscription; AZ-104 rewards having clicked through the settings.

Week 1: identity and access. Create users and groups in Entra ID, invite a guest, assign licences and turn on self-service password reset. Assign built-in roles at several scopes, then check effective access for a user and explain it in writing.

Week 2: governance and cost. Build a small management group hierarchy, assign a policy and a policy initiative, add a resource lock and tags, and move a resource between groups. Set a budget with an alert and read the Advisor recommendations for your subscription.

Week 3: storage. Create accounts with different redundancy settings, generate a SAS and a stored access policy, restrict an account to a virtual network, and copy data with AzCopy. Configure lifecycle rules, soft delete, versioning and an Azure Files share with snapshots.

Week 4: compute. Deploy a VM from a Bicep file, then modify and redeploy it. Resize it, add a disk, and deploy a scale set across availability zones. Push an image to Container Registry and run it on Container Instances and Container Apps. Create an App Service with a deployment slot and a custom domain.

Week 5: networking and monitoring. Build two peered virtual networks with a user-defined route, NSGs with application security groups, Bastion, and a private endpoint to storage. Put a load balancer in front of two VMs. Then send logs to a Log Analytics workspace, write a few queries, create an alert with an action group, and back up and restore a VM.

Week 6: mocks and repair. Take a full-length timed mock, review every explanation (including the ones you got right), and spend two or three days on the weakest area. Take a second mock at the end of the week. The [study plan template](/blog/cloud-certification-study-plan-template) shows how to adapt this schedule.

Common traps

  • Mixing up Entra roles and Azure roles. Entra roles control the directory; Azure RBAC roles control resources. Scenario questions often hinge on which one is needed.
  • Forgetting scope inheritance. Role assignments, policies and locks flow down from management groups and subscriptions. A read-only lock on a resource group affects everything inside it.
  • Service endpoints versus private endpoints. Both restrict access to PaaS services, but only a private endpoint gives the service a private IP address in your virtual network.
  • Misreading NSG rules. Rules are processed by priority, lowest number first, and subnet and NIC rules both apply. Work through the effective rules rather than guessing.
  • Choosing the wrong vault. Recovery Services vaults and Azure Backup vaults protect different workloads. Check the current Azure Backup documentation rather than older course notes.
  • Over-relying on Microsoft Learn in the exam. Role-based exams let you open Microsoft Learn, but no extra time is added and the clock keeps running. It helps with one lookup, not a dozen.
  • Case study pacing. Case studies are long. Read the requirements first, then the background, and remember that once you take a break you cannot return to questions you have already seen.

How to practise

CertifyCloudx has original AZ-104 practice questions organised by the exam's five skill areas, each explained option by option. You can work through domain papers of up to 25 questions (60 minutes per 25), take full-length timed mock exams with the real exam's 100-minute limit, and practise case studies alongside single-answer, multiple-answer, drag-and-drop and hot area questions.

Start with the [AZ-104 practice questions](/certifications/azure-administrator-az-104). The free plan includes practice sets for every certification, up to 10 questions a day, with no card required. For getting the most from each attempt, see [how to use practice exams effectively](/blog/how-to-use-practice-exams-effectively).

Frequently asked questions

How much experience do I need for AZ-104?

Microsoft expects familiarity with operating systems, networking, servers and virtualisation, plus hands-on experience with PowerShell, the Azure CLI, the portal, ARM templates or Bicep, and Microsoft Entra ID. Real administration work, or a disciplined lab routine like the plan above, makes the difference.

Do I need AZ-900 before AZ-104?

No. There is no prerequisite exam for the Azure Administrator Associate certification. AZ-900 is useful if Azure is new to you, but many candidates with some cloud or infrastructure background go straight to AZ-104.

Does AZ-104 include labs?

Microsoft does not publish a list of exams with labs, because labs can be withdrawn at any time. AZ-104 is currently listed at 100 minutes, which matches Microsoft's timing for role-based exams without labs, but the exam page says you may have interactive components. Check the overview screens when you launch the exam.

How long is the AZ-104 certification valid?

The certification must be renewed every 12 months. Renewal is free: you pass an unproctored, open-book online assessment on Microsoft Learn during the six-month window before the certification expires, and you can retake that assessment as often as you need before the expiry date.

What happens if I fail AZ-104?

Microsoft allows a retake 24 hours after a first failed attempt. Waiting periods for later retakes are longer and are set out in Microsoft's exam retake policy.

What comes after AZ-104?

The Azure Solutions Architect Expert certification, whose exam is AZ-305, is the most common next step for administrators moving towards design work. Our [AZ-305 study guide](/blog/az-305-study-guide) covers that exam.

CertifyCloudx is independent and not affiliated with Microsoft. Microsoft Certified: Azure Administrator Associate is a trademark of its owner. All CertifyCloudx practice questions are original.

Practise for this exam
Microsoft Certified: Azure Administrator Associate (AZ-104)
See practice papers
AZ-104 study guide: domains, format and a 6-week plan · CertifyCloudx