Microsoft AZ-104: What Matters Most

AZ-104 is one of the most practical Microsoft exams because it is built around the day-to-day work of administering Azure rather than around one narrow product. The current objectives, effective April 17, 2026, cover identity and governance, storage, compute, virtual networking, monitoring, backup, and recovery. That breadth is why candidates often underestimate the exam. Passing AZ-104 requires more than knowing where settings live in the portal; it requires understanding how Azure resources behave together when an administrator has to make a real operational decision.

The associated Azure Administrator credential is aimed at people who implement, manage, and monitor an organization’s Azure environment. Microsoft specifically expects familiarity with operating systems, networking, servers, virtualization, PowerShell, Azure CLI, the Azure portal, ARM or Bicep deployments, and Microsoft Entra ID. That combination should shape preparation from the start.

The exam is easiest to understand when the five measured areas are treated as connected administrative work. Identity determines who can manage a resource. Governance constrains what can be deployed. Networking determines reachability. Storage and compute host the workload. Monitoring shows whether it works. Backup and recovery determine how the organization responds when it does not.

Identity and governance are administrative foundations, not theory

Managing Azure identities and governance accounts for 20–25 percent of the current exam. Candidates need to work with users, groups, licenses, external identities, self-service password reset, Azure role assignments, subscriptions, management groups, tags, locks, budgets, and policy. These subjects are related because governance is how an administrator turns organizational rules into repeatable control.

Microsoft Entra ID and Azure RBAC deserve hands-on practice. A common mistake is to memorize built-in role names without understanding scope and inheritance. Candidates should be able to explain what changes when a role is assigned at a management group, subscription, resource group, or individual resource, and how that differs from Entra directory roles.

The same reasoning applies to Azure Policy. Know the difference between controlling who can perform an action and evaluating whether deployed resources comply with a desired state. Resource locks, policy, RBAC, tags, and management groups solve different governance problems, and scenario questions often depend on choosing the smallest mechanism that satisfies the requirement.

Storage questions reward precise knowledge of access and resilience

Implementing and managing storage accounts for 15–20 percent of AZ-104. The exam covers access controls, SAS tokens, stored access policies, access keys, identity-based access for Azure Files, firewalls, virtual networks, redundancy, replication, encryption, Blob Storage, Azure Files, lifecycle management, versions, snapshots, and soft delete.

Candidates should practice the tradeoffs behind Azure Storage redundancy rather than memorizing acronyms alone. Local, zone, geo, and geo-zone redundancy represent different durability and regional-failure choices. The right answer depends on recovery requirements, read access expectations, region support, and cost. Similar tradeoffs appear with storage tiers and lifecycle rules.

Access is equally important. A storage account can be secure at the identity layer and still exposed through network configuration, or private at the network layer while an application fails because it has no valid authorization method. Build test scenarios that combine identity, SAS, keys, firewalls, private access, and file-share permissions so those layers become intuitive.

Compute is about deployment, availability, scaling, and service choice

Azure compute is another 20–25 percent of the exam. The outline includes infrastructure-as-code deployment, virtual machines, disks, availability options, virtual machine scale sets, container registries, container instances, container apps, and App Service. The challenge is not knowing that these services exist; it is recognizing which operational model fits a requirement.

For virtual machines, candidates should be comfortable with sizing, disks, zones, availability sets, movement between resource groups or subscriptions, encryption, and scale. For application platforms, know the administrative differences between App Service, Container Instances, and Container Apps. A managed application platform reduces infrastructure administration, but it introduces its own networking, scaling, certificate, deployment-slot, and backup settings.

Infrastructure automation is also part of the administrator role. The exam expects candidates to interpret, modify, and deploy ARM templates or Bicep files. Even if most of your daily work is in the portal, repeatable administration depends on being able to recognize how a resource declaration maps to the environment you are managing.

Networking is where weak Azure fundamentals become visible quickly

Virtual networking represents 15–20 percent of the exam and frequently exposes gaps because a single connectivity problem can involve subnets, peering, routes, NSGs, DNS, public IPs, private endpoints, service endpoints, load balancers, Bastion, and application-level settings. Candidates should be able to troubleshoot the path a packet is expected to take rather than guessing which portal page contains the answer.

Practice creating networks and then connecting them with virtual network peering. Add route tables and security groups. Compare service endpoints with private endpoints. Use effective-security-rule views and connectivity tools. The objective is to recognize whether a failure is caused by addressing, name resolution, routing, filtering, service configuration, or an unavailable target.

Load balancing and DNS should be studied the same way. Do not memorize “internal” and “public” as isolated labels. Understand which clients need to reach the workload, where the frontend address lives, how health determines backend selection, and how name resolution maps the client to the correct endpoint.

Monitoring matters because administrators are judged by what they can detect and recover

Monitoring and maintenance account for 10–15 percent, but the skills connect to every other domain. Administrators must interpret metrics, collect logs, query data, configure alerts and action groups, use resource insights, work with Network Watcher, and implement backup and disaster-recovery controls. A resource is not operationally complete merely because deployment succeeded.

Azure Monitor alerts and action groups are a good hands-on starting point. Create a meaningful condition, route the alert, and then ask what signal would identify a real failure in a VM, storage account, or network. Practice distinguishing metrics from logs and learning when a query is required instead of a simple threshold.

Backup and recovery need equally practical treatment. Know the purpose of Recovery Services vaults and Backup vaults, policy configuration, restore operations, Site Recovery, failover, and alerting. Scenario questions often test whether the proposed control meets the actual recovery requirement rather than whether the candidate recognizes the service name.

The exam rewards cross-domain reasoning more than isolated memorization

Many administrative incidents cross several objective areas. A web application may be healthy but inaccessible because a private endpoint is wrong. A deployment may fail because a policy denies the requested configuration. A user may see a resource but be unable to modify it because the role assignment is scoped differently. A VM may run correctly but violate the organization’s backup requirement. These are cross-domain problems.

The best study labs therefore combine features. Build a resource group, apply policy and tags, assign roles, deploy storage and compute, configure networking, enable monitoring, and add backup. Then change one setting and diagnose the resulting behavior. This teaches the dependency graph that the exam is actually assessing.

Command-line practice also matters. You do not need to memorize every Azure CLI or PowerShell parameter, but you should be comfortable reading commands, recognizing the resource being manipulated, and using automation to inspect or change an environment. Administrators who know only the portal tend to struggle when the exam presents the same concept in another interface.

AZ-104 sits between fundamentals and specialist or architecture work

AZ-104 is often paired conceptually with AZ-305, but the two exams serve different responsibilities. AZ-104 is implementation and administration; AZ-305 is solution architecture. A strong administrator knows how a resource behaves and how to operate it. An architect must decide which resource pattern should be used and how the wider design meets business and technical requirements.

Administrators who specialize in connectivity may move toward AZ-700, while people responsible for Azure Virtual Desktop can go deeper with AZ-140. Those exams should be treated as depth in a particular area, not as substitutes for the broad operational foundation AZ-104 validates.

That makes AZ-104 useful even for people who eventually become architects, security engineers, or platform engineers. Knowing how Azure behaves under real administrative pressure improves later design decisions because the person understands the operational consequences of those designs.

Focus preparation on tasks you can perform without a script

A strong final review is based on actions, not chapter titles. Can you assign access at the correct scope? Can you explain why a policy evaluates a resource as noncompliant? Can you choose storage redundancy from a recovery requirement? Can you diagnose a blocked connection? Can you deploy and scale compute? Can you build an alert that catches a meaningful failure? Can you restore data or explain a failover plan?

Use the official objective list as a checklist and mark each line according to what you can actually perform. For weaker areas, build a small lab and deliberately break it. Recovery from mistakes is especially valuable because AZ-104 is fundamentally an operations exam. Administrators spend much of their time understanding why a system is not behaving as expected.

What matters most is therefore not one high-weight domain or one memorized command. It is the ability to connect identity, governance, storage, compute, networking, monitoring, and recovery into a coherent administrative model. When those relationships make sense, the exam becomes far less about recalling isolated Azure features and much more about applying the judgment expected from an Azure administrator.

img