About the exam
AZ-104 Exam structure
Microsoft Azure Administrator AZ-104 prep with 601 original practice questions, skills-measured weighted mocks, Azure administration drills, flashcards, and topic recovery.
Issuer and path
Microsoft Azure Administrator AZ-104 Exam Prep is administered through Microsoft. Check official resources before booking, retesting, or relying on a stale requirement.
Manage Azure Identities and Governance
23 scored + 0 pretest
Microsoft Entra users and groups, licenses, external users, SSPR, RBAC roles and scopes, Azure Policy, locks, tags, resource groups, subscriptions, costs, and management groups.
Implement and Manage Storage
18 scored + 0 pretest
Storage account access, firewalls, virtual networks, SAS, stored access policies, keys, identity-based access, redundancy, replication, encryption, blobs, files, tiers, snapshots, soft delete, and lifecycle management.
Deploy and Manage Azure Compute Resources
24 scored + 0 pretest
ARM templates, Bicep, virtual machines, disks, availability zones and sets, scale sets, Azure Container Registry, Container Instances, Container Apps, App Service, certificates, scaling, networking, backups, and deployment slots.
Implement and Manage Virtual Networking
20 scored + 0 pretest
Virtual networks, subnets, peering, public IPs, user-defined routes, network connectivity troubleshooting, NSGs, ASGs, Azure Bastion, service endpoints, private endpoints, Azure DNS, and load balancing.
Monitor and Maintain Azure Resources
15 scored + 0 pretest
Azure Monitor metrics, logs, alerts, action groups, alert processing rules, VM/storage/network insights, Network Watcher, Connection Monitor, Recovery Services vaults, Backup vaults, backup policies, restore operations, Site Recovery, failover, and backup reporting.
Before you schedule
Confirm the exam is AZ-104, review the April 17, 2026 skills measured, check ID requirements, accommodations, language availability, renewal rules, and Microsoft exam policies.
Official Outline Coverage Map
Coverage is mapped to official outline item counts so content depth can be checked without hard-coding a single exam.
| Topic | Official outline items | Your questions | Your flashcards | Confidence |
|---|---|---|---|---|
| Microsoft Entra Users, Groups and Azure RBAC | 8 | 46 | 10 | Priority |
| Subscriptions, Azure Policy, Tags and Cost Controls | 8 | 46 | 10 | Priority |
| Management Groups, Resource Locks and Governance Hierarchy | 7 | 46 | 10 | Strong |
| Storage Account Security and Access | 6 | 36 | 10 | Priority |
| Storage Redundancy, Replication and Data Management | 6 | 36 | 10 | Priority |
| Azure Files, Blob Storage and Lifecycle Features | 6 | 36 | 10 | Strong |
| ARM, Bicep and Repeatable Resource Deployment | 6 | 36 | 10 | Priority |
| Virtual Machines, Disks, Scale and Availability | 8 | 40 | 10 | Priority |
| Containers and Azure App Service | 8 | 38 | 10 | Priority |
| Compute Networking, Backup and Operational Settings | 5 | 30 | 10 | Strong |
| Virtual Networks, Subnets, Routing and Peering | 7 | 40 | 10 | Priority |
| Secure Virtual Network Access | 7 | 41 | 10 | Priority |
| Azure DNS, Load Balancing and Network Troubleshooting | 6 | 40 | 10 | Strong |
| Azure Monitor, Logs, Alerts and Insights | 8 | 45 | 10 | Priority |
| Azure Backup, Restore and Site Recovery | 7 | 45 | 10 | Priority |
How to use this guide
How to study for AZ-104
Treat each AZ-104 item as an admin workflow: identify the scope, resource type, access boundary, deployment method, monitoring signal, or recovery requirement.
1. Identify scope and resource
Locate the relevant tenant, subscription, resource group, resource, subnet, vault, workspace, or identity.
2. Choose the admin control
Pick RBAC, Policy, lock, tag, template, endpoint, NSG, route, alert, or backup policy based on the job.
3. Apply least exposure
Prefer scoped permissions, private access, protected storage, repeatable deployment, and controlled management paths.
4. Verify operations
Confirm with effective rules, routes, metrics, logs, alerts, backup status, restore tests, or failover validation.
Microsoft Entra Users, Groups and Azure RBAC
Identity questions test users, groups, properties, licenses, external users, SSPR, built-in Azure roles, role assignments, scopes, and interpreting access.
Key rules
Rule 1
Microsoft Entra Users, Groups and Azure RBAC questions reward operational Azure administration judgment rather than simple service-name recall.
Exam cue: Identify the Azure scope: tenant, management group, subscription, resource group, resource, subnet, or identity.
Rule 2
The best answer identifies the scope, resource type, access path, deployment method, monitoring signal, and recovery requirement.
Exam cue: Match the tool to the administrative task: manage access, deploy, secure, monitor, back up, or troubleshoot.
Rule 3
Eliminate answers that confuse RBAC with policy, public access with private access, monitoring with backup, or templates with manual changes.
Exam cue: Prefer least privilege, repeatable deployment, protected storage, private networking, and validated recovery.
Common traps
Using Azure Policy when the question asks who is allowed to perform an action.
Prevention: Avoid answers that confuse RBAC with Policy, tags with network controls, dashboards with backup, or public exposure with secure private access.
Opening public access when private endpoints, service endpoints, or NSGs meet the requirement.
Prevention: Avoid answers that confuse RBAC with Policy, tags with network controls, dashboards with backup, or public exposure with secure private access.
Assuming backup exists before checking vault, policy, retention, and restore validation.
Prevention: Avoid answers that confuse RBAC with Policy, tags with network controls, dashboards with backup, or public exposure with secure private access.
Memory anchors
Microsoft Entra User
A Microsoft Entra user represents an identity that can authenticate to tenant resources.
Group
A group simplifies assignment of access, licenses, or management to multiple users.
License Assignment
License assignment enables users to access specific Microsoft cloud services.
External User
External users support collaboration with identities outside the tenant.
SSPR
Self-service password reset lets users reset passwords after meeting configured verification requirements.
Azure RBAC
Azure role-based access control assigns permissions to Azure resources using roles and scopes.
Built In Role
A built-in role provides predefined Azure management permissions.
Role Scope
Role scope controls whether permissions apply at management group, subscription, resource group, or resource level.
Access Assignment
An access assignment combines principal, role, and scope.
Least Privilege
Least privilege grants only the access needed for the approved task.
Next best moves
Quick check-up
Use a short quiz to confirm the rule pattern is actually sticking.
Check-up Questions
A new support department needs 40 cloud-only identities with a common usage location and department value. Which approach minimizes repetitive portal work?
A dynamic Microsoft Entra group should include every user whose Department property equals Finance. A transferred employee remains in the group. What should the administrator do?
Answer all questions to submit.
Next step personalized recommendations
Open another topic next
Official resources
Verify the details with the official sources
Use these links for eligibility, scheduling, handbook rules, and issuer updates. Our guide helps you study; official sources tell you what the testing partner currently requires.
FAQ
Common AZ-104 questions
Is this the official Microsoft AZ-104 exam?
No. These are original practice questions aligned to Microsoft's public AZ-104 study guide. They are not copied from secure exam material.
Which skills-measured version is this aligned to?
This content is aligned to the Microsoft Learn AZ-104 study guide that lists skills measured as of April 17, 2026.
What domains are covered?
The bank covers Azure identities and governance, storage, compute, virtual networking, and monitoring and maintenance.
What should I study first?
Start with Microsoft Entra ID, Azure RBAC, subscriptions, Policy, storage access, ARM/Bicep, VMs, VNets, NSGs, Azure Monitor, and backup.
How should I use the 601 questions?
Use topic drills for weak admin workflows, section drills for each skills group, then 100-question weighted mocks.
