Microsoft AZ-104: Skills Candidates Struggle With
AZ-104 feels difficult less because any single Azure service is unusually obscure and more because administrators must understand how many services interact. The current AZ-104 objectives cover identity and governance, storage, compute, networking, monitoring, backup, and recovery. Candidates often study those areas separately, then struggle when a question crosses two or three of them.
The exam is designed for the Azure Administrator job. That means a candidate must move from requirement to configuration to diagnosis. Knowing that a service exists is not enough; you need to predict how Azure will behave when roles, policy, routes, DNS, storage authorization, availability, and monitoring controls overlap.
The hardest skills are therefore the ones that expose weak mental models. Improving them usually requires small targeted labs, not more passive reading.
Candidates frequently mix up authorization and governance. Azure Policy and Azure RBAC can both affect whether an operation succeeds, but for different reasons. RBAC asks whether the identity is allowed to perform the action at the relevant scope. Policy asks whether the resulting resource configuration is permitted or compliant.
Practice assigning roles at management-group, subscription, resource-group, and resource levels. Then apply a policy that blocks or audits a setting. When an operation fails, identify which mechanism caused the failure before changing anything. This discipline prevents the common exam mistake of solving a policy problem by granting more permissions.
A storage client may need valid identity, sufficient data-plane permissions, an allowed network route, the correct endpoint, and a storage configuration that supports the requested operation. SAS tokens, account keys, Microsoft Entra authorization, firewalls, private endpoints, encryption, and redundancy all solve different parts of the problem.
Resilience choices add another layer. Azure Storage redundancy is easier when tied to failure scenarios rather than acronyms. Ask which failures must be survived, whether read access to a secondary region is required, and what recovery expectations justify the cost.
Virtual machines, scale sets, App Service, Container Instances, and Container Apps can all run workloads, but they place different operational responsibilities on the administrator. Candidates who memorize configuration steps without understanding those boundaries can choose a technically possible service that does not fit the requirement.
Build the same small workload in two different compute models and compare networking, scaling, identity, storage, certificates, logging, patching, and deployment. Then practice ARM or Bicep so the infrastructure can be reproduced. The exam often rewards the option that meets the operational requirement with the least unnecessary management.
Azure networking is one of the most common weak areas because a single connection can depend on address ranges, subnets, peering, user-defined routes, NSGs, DNS, public IPs, load balancers, private endpoints, and service configuration. Study virtual network peering as one part of a complete path.
When a connection fails, ask the same questions in order: what address is the client using, how is the name resolved, what route is selected, which security rules apply, what endpoint receives the traffic, and is the target service listening? This method is more reliable than jumping between portal blades hoping to find a red warning.
Metrics, logs, alerts, action groups, diagnostic settings, resource insights, and Network Watcher are related but not interchangeable. Practice Azure Monitor alerts and action groups with a real condition, then verify what data triggered the alert and what happened next.
Ask whether the requirement is to collect telemetry, query historical events, detect a threshold, notify a team, launch automation, or troubleshoot network behavior. Once the desired outcome is clear, the correct monitoring component becomes much easier to select.
Many candidates know the words backup, snapshot, vault, and Site Recovery but do not connect them to the required recovery outcome. Build examples around accidental deletion, workload corruption, virtual-machine failure, and regional outage. Decide what must be restored, how quickly, and to what point in time.
Then test the restore process. A backup configuration that has never been restored is only half learned. Scenario questions often distinguish between protecting data, recovering a workload, and orchestrating failover. The right answer depends on the business failure being addressed.
Microsoft expects familiarity with PowerShell, Azure CLI, and ARM or Bicep. Candidates do not need to memorize every command, but they should be able to read a command and identify the resource, scope, parameter, and effect. The same applies to declarative deployment files.
Take resources you created through the portal and recreate them with code. Change one parameter and predict the result. This closes the gap between “I know where to click” and “I understand the Azure object being configured.” It also makes deployment and troubleshooting questions easier because the resource model becomes explicit.
Another recurring weakness is understanding resource movement and dependency. Practice moving resources between resource groups or subscriptions where supported and identify what must remain unchanged, what permissions are required, and which dependent resources can prevent the move. These questions test the Azure resource model rather than any one service.
Name resolution deserves specific attention because candidates often treat DNS as an invisible background service. Build a private endpoint or peered-network scenario and verify which DNS name the client resolves, which address is returned, and whether that address is reachable. A route can be correct while the name resolves to the wrong endpoint, producing a failure that looks like a network-security problem.
Availability concepts are another trap. Availability sets, zones, scale sets, load balancing, backups, and disaster recovery all improve resilience in different ways. Ask whether the requirement is surviving host failure, datacenter failure, traffic growth, application failure, accidental deletion, or regional outage. Choosing the right mechanism becomes easier once the failure boundary is explicit.
Candidates also underestimate governance under time pressure. Tags, locks, budgets, management groups, policy, and RBAC can appear together in one scenario. Translate the business requirement into the type of control needed: organization, cost visibility, prevention of deletion, compliance enforcement, or authorization. Then choose the narrowest Azure mechanism that satisfies it.
Finally, practice reading questions without assuming every detail matters equally. Azure scenarios often include realistic but irrelevant context. Identify the required outcome, existing constraint, and prohibited change first. Only then evaluate services. This reduces the tendency to pick an answer because it mentions the most familiar Azure feature.
A user may lack access because of RBAC, a deployment may fail because of policy, a storage account may be unreachable because of networking, or an application may appear healthy while monitoring and backup requirements are missing. Mixed scenarios are hard only when each domain exists as a separate memory silo.
Use AZ-700 and AZ-305 as markers for deeper networking and architecture study, not as substitutes for the broad AZ-104 foundation. The administrator exam expects you to see how the parts of Azure fit together before you specialize.
The best final practice is to build one environment and intentionally create failures across identity, governance, storage, compute, networking, and monitoring. Diagnose each failure with evidence. Candidates who can explain why Azure behaved as it did are far less likely to be surprised by scenario wording on exam day.
Subscription and management-group structure can also trip up candidates because the effect is indirect. A policy or role assigned above the resource group may explain behavior that is not visible from the resource itself. Practice moving upward through the hierarchy when a local configuration appears correct but the outcome still does not make sense. Effective access and inherited governance are often the missing clue.
Storage and networking create a similar hidden-dependency problem with service endpoints and private endpoints. Learn what changes in name resolution, routing, and public exposure when private connectivity is introduced. Test from two clients in different networks so you can see why one succeeds and the other fails. The exam rewards candidates who understand the path rather than memorizing which checkbox creates the endpoint.
Finally, make restoration part of every destructive lab. Delete a blob, break a VM, change a configuration, or remove a resource and then recover it using the protection you configured earlier. This reinforces that administration is not only deployment and uptime; it includes recoverability. The hardest AZ-104 questions often become easier when you think in terms of the full lifecycle of the resource.
Use effective configuration views whenever Azure provides them. Effective routes, effective security rules, inherited role assignments, policy compliance, and diagnostic data can reveal the final state after several layers combine. These views teach an important administrator habit: troubleshoot the configuration Azure is actually enforcing, not only the settings you remember creating.
This effective-state mindset is especially valuable during timed questions: inspect inheritance, dependencies, and the enforced result before assuming the visible local setting tells the whole story.