AZ-400 study guide: domains, format and a 6-week plan
· 8 min read
AZ-400, Designing and Implementing Microsoft DevOps Solutions, is the exam for the Microsoft Certified: DevOps Engineer Expert certification. It tests whether you can design and run the delivery system around an application, from work tracking and source control to pipelines, security and monitoring, across GitHub and Azure DevOps. You have 100 minutes for 40 to 60 questions, and the passing score is 700 out of 1000.
Half the exam is one domain, build and release pipelines. If you have only used one of GitHub Actions or Azure Pipelines, the other is where your preparation time will go.
AZ-400 at a glance
| Item | Detail |
|---|---|
| Provider | Microsoft Azure |
| Level | Expert |
| Questions | 40–60 |
| Duration | 100 minutes |
| Passing score | 700 / 1000 |
| Exam fee | US$165; the price varies by country or region |
| Languages | English, Japanese, Chinese (Simplified), Korean, German, French, Spanish, Portuguese (Brazil), Chinese (Traditional), Italian |
| Delivery | Proctored, scheduled through Pearson VUE, online or at a test centre in most cases |
| Question formats | Single and multiple choice, yes/no statement sets, drag and drop, hot area and case studies |
| Prerequisite | Azure Administrator Associate or Azure Developer Associate (see below) |
Details as of September 2026 — confirm on the official exam page before booking.
Who this exam is for
Microsoft describes the DevOps engineer as a developer or infrastructure administrator who also works with people, processes and products to deliver value continuously, alongside developers, SREs, Azure administrators and security engineers. Microsoft expects experience of both administering and developing in Azure, with strong skills in at least one, and experience implementing both GitHub and Azure DevOps solutions.
That last point matters: almost every objective names both platforms, and questions often ask which one, or which combination, fits a scenario.
The prerequisite
To earn the certification, you must pass AZ-400 and hold at least one of Microsoft Certified: Azure Administrator Associate or Microsoft Certified: Azure Developer Associate. Microsoft has since retired the Azure Developer Associate certification and its renewal assessment, so for most new candidates the practical route is the Azure Administrator Associate through AZ-104. See our [AZ-104 study guide](/blog/az-104-study-guide). If you already hold the Developer Associate, check your eligibility in your Microsoft Learn profile before you book.
Renewal
The certification expires annually unless renewed. Renewal is free: a short, unproctored, open-book assessment on Microsoft Learn, taken in the six-month window before expiry.
What the exam covers
The AZ-400 study guide lists skills measured as of 27 July 2026 in five domains. Localised versions are updated roughly eight weeks after English, so check which version you will sit.
Design and implement processes and communications (10–15%)
This domain covers how work flows and how the team sees it: GitHub Flow, feedback through notifications and GitHub Issues, and tracking that links GitHub projects, Azure Boards and repositories for traceability. You choose metrics and dashboards for each stage, including cycle time, lead time and time to recovery. The last task is documentation and integration: wikis with Markdown and Mermaid, release notes, documentation generated from Git history, webhooks, Azure Boards with GitHub, and Microsoft Teams integration.
The judgement tested is which metric answers a stated question, and which integration removes manual steps.
Design and implement a source control strategy (10–15%)
Branching covers trunk-based, feature branch and release branch strategies, with pull request workflows enforced through branch policies or branch protection rules. Repository management covers Git LFS and git-fat, scaling with Scalar, permissions, tags, recovering data with Git commands and removing data that should never have been committed.
Expect scenarios where a team's release cadence or size points to one branching model, and questions about what really removes a leaked secret from history rather than hiding it in a new commit.
Design and implement build and release pipelines (50–55%)
The core of the exam, in six tasks.
- Package management: GitHub Packages versus Azure Artifacts, feeds and views, upstream sources, and versioning with SemVer or CalVer for packages and pipeline artifacts.
- Testing strategy: quality and release gates for security and governance, the balance of local, unit, integration and load tests, running tests in pipelines and publishing results, and code coverage.
- Pipelines: choosing GitHub Actions or Azure Pipelines, runner and agent infrastructure, connecting GitHub repositories to Azure Pipelines, triggers, YAML, multi-stage pipelines and parallelism, self-hosted runners or agents, templates and variable groups, and checks and approvals on YAML environments.
- Deployments: blue-green, canary, ring, feature flags and A/B testing; ordering dependent deployments; minimising downtime with rolling deployments and slot swaps; hotfix paths; Azure App Configuration Feature Manager; and deployments that include containers and database changes.
- Infrastructure as code: configuration management, an IaC strategy with automated testing and deployment, desired state with Bicep, Azure Resource Manager and Azure Machine Configuration, and Azure Deployment Environments for self-service.
- Maintaining pipelines: failure rate, duration and flaky tests; cost and concurrency; retention; and migrating classic pipelines to YAML.
Most questions are design choices under constraints: the cheapest agent that reaches a private network, or the deployment pattern that limits blast radius.
Develop a security and compliance plan (10–15%)
Authentication comes first: Microsoft Entra service principals versus managed identities, GitHub Apps, GITHUB_TOKEN and personal access tokens, Azure DevOps service connections, and permissions and access levels on both platforms. Sensitive information covers Azure Key Vault, secretless authentication with workload identity federation (OpenID Connect), secure files, and stopping secrets leaking. Scanning covers dependency, code, secret and licence scanning, Microsoft Defender for Cloud DevOps security, GitHub Advanced Security on both platforms, CodeQL and Dependabot alerts.
Implement an instrumentation strategy (5–10%)
The smallest domain. You connect Azure Monitor and Azure Monitor Logs to DevOps tools, collect telemetry with Application Insights, VM insights and Container insights, use GitHub insights, and alert on pipeline events. Analysis covers infrastructure indicators, application telemetry, distributed tracing in Application Insights, and basic KQL queries.
A 6-week study plan
Pipelines carry over half the marks, so they get three of the six weeks. Work in a GitHub organisation and an Azure DevOps organisation connected to a low-cost Azure subscription.
Week 1: process and source control. Set up Azure Boards linked to a GitHub repository, and a GitHub project. Create a dashboard with lead and cycle time. Configure branch policies in Azure Repos and branch protection rules in GitHub, then practise recovering a deleted branch and purging a file from history.
Week 2: packages and testing. Publish a package to Azure Artifacts with an upstream source and a view, then to GitHub Packages. Build a pipeline that runs unit tests, publishes results and code coverage, and fails below a threshold.
Week 3: pipelines. Write the same build in GitHub Actions and multi-stage Azure Pipelines YAML. Add templates, variable groups, a self-hosted agent, and an environment with an approval and a check. Migrate one classic pipeline to YAML.
Week 4: deployments and IaC. Deploy a web app with slot swaps, then a container with a canary rollout. Add a feature flag through Azure App Configuration. Deploy the infrastructure with Bicep from the pipeline, and try Azure Deployment Environments.
Week 5: security and monitoring. Replace a stored secret with workload identity federation in both platforms, pull a secret from Key Vault, and enable code, secret and dependency scanning. Wire Application Insights into the app, raise an alert from a failed pipeline, and write a handful of KQL queries.
Week 6: mocks and repair. Take a full-length timed mock, review every explanation, spend two days on the weakest domain, then take a second mock. Need longer? Adapt our [study plan template](/blog/cloud-certification-study-plan-template).
Common traps
- Knowing only one platform. Questions contrast similar features: branch protection rules and branch policies,
GITHUB_TOKENand service connections. Learn both. - Picking a secret when secretless exists. When a scenario asks for the most secure way to authenticate a pipeline to Azure, workload identity federation or a managed identity usually beats a stored credential.
- Confusing deployment patterns. Blue-green, canary, ring and feature flags reduce risk in different ways. Read what the scenario is trying to limit: downtime, exposed users or rollback time.
- Classic pipeline habits. The exam is YAML-first. Know where classic concepts such as task groups still appear and how they map to templates.
- Over-using Microsoft Learn in the exam. Role-based exams give access to Microsoft Learn, but no extra time is added. It helps with one lookup, not many.
- Case study pacing. Read the requirements before the background, and remember that after a break you cannot return to questions you have already seen.
How to practise
CertifyCloudx has original AZ-400 practice questions organised by the five domains, each with an explanation for every option. You can work through domain papers of up to 25 questions (60 minutes per 25), take full-length timed mock exams at the real 100-minute limit, and practise case studies alongside single-choice, multiple-choice, drag-and-drop and hot area formats. The free plan includes practice sets for every certification, up to 10 questions a day, with no card needed.
Start with the [AZ-400 practice questions](/certifications/azure-devops-engineer-expert-az-400). See [how to use practice exams effectively](/blog/how-to-use-practice-exams-effectively) for reviewing mocks, and the [DOP-C02 study guide](/blog/dop-c02-study-guide) for the AWS equivalent.
Frequently asked questions
Do I need AZ-104 before AZ-400?
To be awarded DevOps Engineer Expert you need AZ-400 plus the Azure Administrator Associate or the Azure Developer Associate. The Developer Associate has been retired, so most new candidates will earn the Administrator Associate through AZ-104.
How long does AZ-400 preparation take?
Six weeks suits someone who already runs pipelines at work. If you have used only one of GitHub or Azure DevOps, or little infrastructure as code, allow eight to ten weeks.
Is AZ-400 more about GitHub or Azure DevOps?
Both. The skills list names them side by side in almost every task, and many questions ask you to choose between them or combine them, such as running Azure Pipelines against a GitHub repository.
What happens if I fail?
Microsoft's retake policy lets you retake after 24 hours following a first failure, then after 14 days for later attempts, with no more than five attempts in 12 months. Each retake is paid.
How do I keep the certification current?
Pass the free online renewal assessment on Microsoft Learn in the six-month window before expiry. A pass extends the certification by a year.
Are CertifyCloudx questions taken from the real exam?
No. Every question is original, written against Microsoft's published skills list. No published question uses live or recalled exam content.
CertifyCloudx is independent and not affiliated with Microsoft. Microsoft Certified: DevOps Engineer Expert is a trademark of its owner. All CertifyCloudx practice questions are original.