Every Exam PrepFREE EXAM PREP
Ask AI
STUDY GUIDE · AZ-104

Microsoft Certified: Azure Administrator Associate (Exam AZ-104) Study Guide

Verified against the official content outline 6 sections
Written by Every Exam Prep Editorial TeamSource and review policyPublished July 18, 2026
Time limit
1h 40m
Passing score
700/1000
Governing body
Microsoft

The Microsoft Certified: Azure Administrator Associate credential, earned by passing Exam AZ-104, validates the hands-on skills needed to implement, manage, and monitor an organization's Microsoft Azure environment. It is one of Microsoft's most widely pursued cloud certifications and serves as a practical benchmark for professionals who configure, secure, and maintain cloud infrastructure day to day.

AZ-104 is designed for Azure administrators who manage cloud services spanning compute, storage, networking, and identity. Typical candidates already have some experience with Azure and are comfortable using the Azure portal, Azure PowerShell, Azure CLI, and Azure Resource Manager templates to carry out administrative tasks.

Who Should Take This Exam

  • IT professionals moving from on-premises administration into cloud operations
  • Systems administrators responsible for provisioning and maintaining Azure resources
  • Support engineers who monitor, troubleshoot, and optimize Azure workloads
  • Anyone building a foundation toward more advanced Azure role-based certifications

Earning AZ-104 signals to employers that a candidate can be trusted with core cloud administration duties: managing virtual machines, configuring storage accounts, securing identities, and keeping networks running smoothly. For many IT careers, it functions as a stepping stone toward specialist certifications in security, networking, or solutions architecture, and it remains one of the most requested Azure credentials in job postings for cloud administrator and cloud support roles.

Exam AZ-104 is a proctored exam that may include interactive components such as drag-and-drop and case study scenarios, in addition to traditional multiple-choice and multiple-select questions. Candidates are given 100 minutes to complete the exam, which is enough time to work through the question set carefully if time is managed well.

Scoring uses a scaled range from 1 to 1,000, and a candidate needs a score of 700 or greater to pass. There is no penalty for guessing, so candidates should answer every question rather than leaving any blank. After completing the exam, candidates receive a score report showing an overall numeric score, pass/fail status, and a bar chart breaking down performance by skill area, which is useful for identifying weak domains if a retake is needed.

Scheduling and Delivery

  • Exams are scheduled and delivered through Pearson VUE, either at a testing center or via online proctoring
  • The exam is offered in English, Chinese (Simplified), Korean, Japanese, French, Spanish, German, Portuguese (Brazil), Chinese (Traditional), and Italian
  • Candidates whose preferred language is unavailable can request an additional 30 minutes to complete the exam
  • Exam pricing is based on the country or region in which the exam is proctored, so cost varies by location

If a candidate does not pass on the first attempt, a retake is allowed 24 hours after the initial attempt, giving time to review weak areas before trying again.

Exam AZ-104 measures skills across five functional groups, each weighted differently in the final score. Understanding these weightings helps candidates allocate study time to the areas that matter most.

Manage Azure Identities and Governance (20-25%)

This domain covers Microsoft Entra ID (formerly Azure AD) objects, role-based access control, subscriptions, and governance tools like Azure Policy and resource locks. Administrators are expected to know how to manage users, groups, and permissions securely.

Deploy and Manage Azure Compute Resources (20-25%)

This is the largest domain alongside identities and governance, covering virtual machines, containers, and App Service. Candidates should be comfortable configuring VM availability, scaling, and deploying resources via templates.

Implement and Manage Storage (15-20%)

This domain focuses on storage accounts, blob storage lifecycle management, Azure Files, and configuring storage security and redundancy options.

Implement and Manage Virtual Networking (15-20%)

Networking skills include virtual networks, subnets, network security groups, load balancing, and connectivity between on-premises and Azure resources.

Monitor and Maintain Azure Resources (10-15%)

The smallest domain covers Azure Monitor, backup and recovery configuration, and using diagnostic tools to keep resources healthy over time.

  • Manage Azure identities and governance — 20-25%
  • Deploy and manage Azure compute resources — 20-25%
  • Implement and manage storage — 15-20%
  • Implement and manage virtual networking — 15-20%
  • Monitor and maintain Azure resources — 10-15%

Most candidates spend six to eight weeks preparing for AZ-104, depending on prior Azure experience. A structured, domain-by-domain approach tends to work better than passive reading, since the exam emphasizes practical administration skills.

Weeks 1-2: Identities and Governance

Start with the largest-weighted domains. Set up a free or trial Azure subscription and practice creating users and groups in Microsoft Entra ID, assigning RBAC roles, and applying Azure Policy and resource locks. This foundation supports everything else in the exam.

Weeks 3-4: Compute Resources

Move into virtual machines: create VMs from images, configure availability sets and scale sets, and deploy an App Service instance. Practice using both the Azure portal and command-line tools so you're comfortable regardless of how a question is framed.

Week 5: Storage and Networking

Configure storage accounts, blob lifecycle rules, and Azure Files shares. Then build a virtual network with subnets, network security groups, and a basic load balancer. These two domains combined carry substantial weight, so don't compress them too tightly.

Week 6: Monitoring and Review

Set up Azure Monitor alerts and configure a backup policy. Spend the remaining time taking practice questions across all domains, reviewing weak areas identified by score breakdowns, and revisiting flashcards for terminology you keep missing.

  • Rotate between hands-on labs and review sessions rather than studying one domain exclusively
  • Re-test weaker domains in the final week rather than assuming early review was enough
  • Build a short glossary of Azure-specific terms as you go — networking and identity domains are especially jargon-heavy

Walking into the AZ-104 exam prepared means managing both your technical knowledge and your time. With 100 minutes to complete the exam, pacing matters — don't let one difficult case study question consume time you need for the rest of the exam.

Before the Exam

  • Confirm your identification and testing environment requirements ahead of time if testing online through Pearson VUE
  • Review your weakest domains one final time the night before rather than cramming new material
  • Get sufficient rest — cloud administration questions often require careful reading, not just memorization

During the Exam

  • Answer every question, since there is no penalty for guessing and no points are deducted for incorrect answers
  • Flag uncertain questions and return to them if time allows, rather than getting stuck
  • Read scenario-based questions carefully — the correct answer often depends on a specific constraint mentioned in the setup
  • Watch for questions that test similar-sounding services or settings; Azure has several features with overlapping names

Common Mistakes to Avoid

Many candidates underestimate the networking and storage domains because they feel less intuitive than compute. Others skip hands-on practice entirely and rely on video courses alone, which leaves gaps when questions ask about specific portal navigation or CLI syntax. Since the certification requires renewal, treat the exam as the start of ongoing familiarity with Azure rather than a one-time hurdle.

Preparing for AZ-104 doesn't require expensive bootcamps alone — free study resources on this site can reinforce the same material through different formats, which helps information stick.

Practice Questions

Scenario-style practice questions mirror the case-study format the real exam uses, letting you rehearse reading a constraint-heavy prompt and identifying the single best answer among plausible-looking distractors. Working through practice sets by domain also helps surface which of the five functional groups needs more attention before exam day.

Flashcards

Flashcards are well suited to the terminology-heavy parts of AZ-104, such as distinguishing between similarly named services, storage redundancy options, or networking components. Short, repeated review sessions using flashcards can help lock in details that are easy to blank on under time pressure.

Glossary

A glossary of Azure-specific terms is useful for quickly looking up a service or concept encountered while working through labs or practice questions, without having to search through longer documentation. Building familiarity with exact terminology also helps when questions hinge on subtle wording differences between similar Azure features.

Combining hands-on labs in an actual Azure subscription with these free resources gives a well-rounded preparation approach: labs build muscle memory, while practice questions, flashcards, and the glossary reinforce recall and fill in conceptual gaps.

AZ-104 flashcards

30 cards on the highest-yield terms and rules. Grading uses spaced repetition and saves in this browser.

Card 1 of 300 mastered
Say the answer out loud before flipping.
Browse all 30 cards
  1. What is the renewal assessment like compared to the original AZ-104 exam?

    It is shorter, unproctored, and open book, and can be completed online within a six-month renewal window before expiration.

  2. What is a resource group in Azure?

    A logical container that holds related resources for an Azure solution, used as the primary unit for applying access control, tags, and lifecycle management (deploy, update, delete together).

  3. What are the five functional domains measured by Exam AZ-104?

    Manage Azure identities and governance; implement and manage storage; deploy and manage Azure compute resources; implement and manage virtual networking; and monitor and maintain Azure resources.

  4. How long do candidates have to complete Exam AZ-104?

    100 minutes, with an additional 30 minutes available if the candidate's preferred language is not offered for the exam.

  5. What is the passing score for AZ-104?

    700 or greater on a scale of 1 to 1,000.

  6. Is there a penalty for guessing on AZ-104?

    No. No points are deducted for incorrect answers, so candidates should answer every question rather than leave it blank.

  7. Who administers AZ-104 exam proctoring?

    Pearson VUE, and the exam may include interactive, performance-based components in addition to multiple-choice items.

  8. How soon can a candidate retake AZ-104 after a failed attempt?

    24 hours after the first attempt.

  9. What does the AZ-104 score report include?

    An overall numeric score, a pass/fail result, and a bar chart showing performance broken down by skill area (domain).

  10. How often must the Azure Administrator Associate certification be renewed, and what does renewal cost?

    Renewal is required every 12 months, and renewal itself is free.

  11. What is Azure Role-Based Access Control (RBAC)?

    An authorization system built on Azure Resource Manager that grants fine-grained access to Azure resources by assigning roles (collections of permissions) to users, groups, service principals, or managed identities at a management group, subscription, resource group, or resource scope.

  12. What is the Azure resource hierarchy from top to bottom?

    Management groups, then subscriptions, then resource groups, then individual resources.

  13. What is an Azure Policy used for?

    To enforce organizational rules and effects (such as deny, audit, or append) on resource properties during creation and update, ensuring compliance with standards like naming conventions or allowed regions, distinct from RBAC which controls who can act.

  14. What is the difference between Azure AD (Microsoft Entra ID) users and groups for access management?

    Users are individual identities; groups aggregate users (or other groups) so administrators can assign roles and permissions once to the group rather than to each user individually.

  15. What is a Network Security Group (NSG) in Azure?

    A set of inbound and outbound security rules that filter network traffic by source/destination IP, port, and protocol, applied to subnets or individual network interfaces.

  16. What is Azure Virtual Network (VNet) peering?

    A mechanism that connects two virtual networks so resources in each can communicate directly using private IP addresses, without traversing the public internet, and (by default) without transitive routing through a peered network.

  17. What is the purpose of an Azure Load Balancer versus Application Gateway?

    Azure Load Balancer operates at Layer 4 (TCP/UDP) distributing traffic across VMs based on network-level rules, while Application Gateway is a Layer 7 web traffic load balancer that can route based on URL path/host and provides features like SSL termination and a web application firewall.

  18. What is a public IP address SKU consideration in Azure (Basic vs Standard)?

    Standard SKU public IPs are secure by default (require an explicit NSG rule to allow traffic) and support availability zones, while Basic SKU is open by default and does not support zone redundancy.

  19. What is Azure Storage account redundancy: LRS vs GRS?

    Locally Redundant Storage (LRS) replicates data three times within a single datacenter/region, while Geo-Redundant Storage (GRS) additionally replicates asynchronously to a secondary, geographically distant region for disaster recovery.

  20. What are the main Azure Blob storage access tiers?

    Hot (frequently accessed, higher storage cost/lower access cost), Cool (infrequently accessed, lower storage cost/higher access cost, minimum retention expectations), and Archive (rarely accessed, lowest storage cost, offline and requires rehydration before access).

  21. What is Azure File Sync used for?

    It centralizes an organization's file shares in Azure Files while keeping the flexibility, performance, and compatibility of an on-premises file server through caching (cloud tiering) on a Windows Server endpoint.

  22. What is a Shared Access Signature (SAS) in Azure Storage?

    A URI that grants delegated, time-limited access to specific storage resources with defined permissions, without sharing the account's access keys.

  23. What is an Azure Availability Set?

    A logical grouping of VMs within a datacenter that spreads them across fault domains (separate power/network) and update domains (separate maintenance windows) to reduce the chance of correlated downtime.

  24. What is an Azure Availability Zone?

    A physically separate location within an Azure region, each with independent power, cooling, and networking, used to protect applications and data from datacenter-level failures with higher resiliency than availability sets alone.

  25. What is a VM Scale Set?

    An Azure compute resource that lets you deploy and manage a group of identical, load-balanced VMs, with the ability to automatically increase or decrease the number of instances based on demand or a defined schedule.

  26. What is Azure Update Manager (formerly Update Management) used for?

    To assess and manage OS updates for Windows and Linux VMs across Azure, on-premises, and other clouds, allowing scheduled and controlled patch deployment.

  27. What is Azure Monitor and how do metrics differ from logs?

    Azure Monitor is the platform for collecting, analyzing, and acting on telemetry; metrics are lightweight numerical time-series values (e.g., CPU percentage) good for near-real-time alerting, while logs are structured event records queried with Kusto Query Language (KQL) for deeper analysis.

  28. What is the purpose of Azure Backup?

    A managed service that centrally protects and restores data for VMs, files, folders, and other workloads by taking scheduled backups stored in a Recovery Services vault.

  29. What is Azure Site Recovery used for?

    Disaster recovery that replicates workloads (VMs, physical servers) running in a primary location to a secondary location, and orchestrates failover and failback if an outage occurs.

  30. What is the difference between a service principal and a managed identity?

    A service principal is an identity created for an application or service to access Azure resources, typically requiring credential management; a managed identity is an automatically managed identity in Microsoft Entra ID tied to an Azure resource that eliminates the need to store credentials in code.

AZ-104 glossary

24 terms the AZ-104 tests, defined in plain English.

Application Gateway
A Layer 7 (application-layer) web traffic load balancer that supports URL-based routing, SSL/TLS termination, and an integrated web application firewall.
Availability Set
A grouping mechanism for VMs within a single datacenter that distributes instances across fault domains and update domains to minimize simultaneous outages.
Availability Zone
A physically distinct location with independent power, cooling, and networking within an Azure region, used to provide higher fault tolerance than availability sets alone.
Azure Load Balancer
A Layer 4 (transport-layer) service that distributes inbound network traffic across a pool of healthy VM instances to improve availability and scalability.
Azure Monitor
The umbrella platform for collecting, analyzing, and responding to telemetry (metrics and logs) from Azure resources, applications, and infrastructure.
Azure Policy
A governance service that evaluates resources against defined rules and enforces compliance, such as denying non-compliant deployments or auditing existing resources.
Azure Resource Manager (ARM)
The deployment and management service for Azure that provides a consistent management layer, enabling resources to be created, updated, and deleted through templates, the portal, CLI, or PowerShell.
Azure Storage Account
A container that provides a unique namespace for Azure Storage data objects, including blobs, files, queues, and tables, with configurable performance and redundancy settings.
Blob Storage
Azure's object storage service optimized for storing massive amounts of unstructured data such as documents, images, and backups, organized into containers.
Kusto Query Language (KQL)
The read-only query language used to search, filter, and analyze log data stored in Azure Monitor Logs and Log Analytics workspaces.
Managed Identity
An identity automatically managed by Microsoft Entra ID and tied to an Azure resource, allowing that resource to authenticate to other Azure services without storing credentials.
Management Group
A container above subscriptions in the Azure hierarchy used to apply governance conditions like policies and RBAC across multiple subscriptions at once.
Microsoft Entra ID (Azure AD)
Microsoft's cloud-based identity and access management service, used to authenticate and authorize users and applications and to manage groups, roles, and conditional access.
Network Security Group (NSG)
A firewall-like resource containing inbound and outbound security rules that allow or deny network traffic to resources based on source, destination, port, and protocol.
Recovery Services Vault
A storage entity in Azure used to hold backup data and recovery points for Azure Backup and Azure Site Recovery operations.
Redundancy (LRS/ZRS/GRS)
The replication strategy for a storage account: Locally Redundant Storage (LRS) copies data within one datacenter, Zone-Redundant Storage (ZRS) copies across availability zones in a region, and Geo-Redundant Storage (GRS) copies to a secondary, distant region.
Resource Group
A logical container for grouping related Azure resources that share the same lifecycle, used as the primary scope for applying RBAC, policies, and tags.
Role-Based Access Control (RBAC)
An Azure authorization model that grants permissions to identities by assigning built-in or custom roles at a specific scope (management group, subscription, resource group, or resource).
Shared Access Signature (SAS)
A time-limited, permission-scoped URI that grants delegated access to specific Azure Storage resources without exposing the storage account's full access keys.
Subnet
A range of IP addresses within a virtual network used to segment and organize resources, and to apply network security groups and route tables.
Subscription
A billing and access-management boundary in Azure that contains resource groups and resources, and is the level at which usage is metered and invoiced.
Virtual Machine Scale Set (VMSS)
An Azure resource for deploying and centrally managing a set of identical, auto-scaling VMs behind a load balancer.
Virtual Network (VNet)
An isolated, logically segmented network in Azure that enables secure communication between Azure resources, the internet, and on-premises networks.
VNet Peering
A connection method that links two virtual networks to enable private, low-latency traffic between them using the Azure backbone network rather than the public internet.

Sources

  1. 1.Study guide for Exam AZ-104: Microsoft Azure AdministratorMicrosoft (accessed Jul 18, 2026)
  2. 2.Microsoft Certified: Azure Administrator Associate — Certification pageMicrosoft (accessed Jul 18, 2026)
  3. 3.Exam scoring and score reportsMicrosoft (accessed Jul 18, 2026)

Official sources

Primary documents used to verify the exam details shown on this page.

Last verified against the official exam content outline: