AZ-104 Exam Blueprint: Azure Administrator Skills

Map the current AZ-104 domains to practical Azure administration tasks, including Bicep, containers, networking, monitoring, and recovery.

Use IT Mastery topic drills to find weak areas, then compare them with this map. Mark each area can do, needs documentation, or needs practice. A remembered service name is less useful than being able to interpret its settings and verify the result.

Current scope and weights

Official source checked: September 11, 2026. Microsoft’s AZ-104 study guide lists skills effective April 17, 2026. These are the official domain ranges; the practice tasks below are our summaries.

DomainWeightPractical focus
Identities and governance20–25%User lifecycle, licensing, scoped access, policy, resource organization, and cost controls.
Storage15–20%Secure access, account configuration, data transfer, retention, and recovery.
Compute20–25%Infrastructure definitions, VMs, containers, and App Service operations.
Virtual networking15–20%Addressing, peering, routes, traffic filtering, DNS, and load balancing.
Monitoring and maintenance10–15%Telemetry, queries, alerts, backups, and regional recovery.

Bicep is a language for describing Azure resources declaratively. Reading and modifying Bicep is part of preparation, alongside ARM templates, the Azure portal, Azure CLI, and PowerShell. It is more than optional terminology to recognize.

What to practise in each domain

Identities and governance

  • Manage users, groups, guest invitations, licenses, and self-service password reset.
  • Interpret a role assignment’s principal, permissions, and scope, including inherited access.
  • Distinguish Microsoft Entra directory administration from Azure resource administration.
  • Work with policy effects and remediation, resource locks, tags, management groups, and supported resource moves.
  • Interpret budget thresholds and Azure Advisor recommendations without assuming that a budget automatically stops spending.

Useful evidence: an access-assignment table, a policy result, or a resource hierarchy. Explain which scope or permission changes the outcome.

Storage

  • Separate the network path from authentication and authorization when a request fails.
  • Select and manage shared access signatures (SAS), keys, and identity-based file access.
  • Compare redundancy with object replication and recovery features; they address different failures.
  • Choose account settings, encryption, transfer tools, access tiers, and lifecycle rules for a stated workload.
  • Recover blobs, versions, containers, file shares, or individual files using the applicable protection settings.

Useful evidence: an access policy, transfer log, lifecycle rule, or recovery-point timeline. Check the account and feature configuration before applying a general rule.

Compute

  • Read and modify ARM templates or Bicep; inspect parameters, dependencies, deployment scope, and what-if output.
  • Provision and resize VMs, manage disks and moves, and configure encryption at host.
  • Compare availability arrangements and configure Virtual Machine Scale Sets.
  • Work with Container Registry, Container Instances, and Container Apps, including image access, resource sizing, revisions, and scaling.
  • Configure App Service plans, domains, TLS, networking, backups, and deployment slots.

Useful evidence: a short configuration, deployment error, resource dependency diagram, or application setting. Identify the smallest complete change that satisfies the requirement.

Virtual networking

  • Read address ranges and effective routes; determine connectivity from the connections actually shown.
  • Evaluate network security group (NSG) rules at subnet and network-interface scopes.
  • Configure Bastion, service endpoints, private endpoints, and the corresponding DNS path.
  • Configure public or private DNS and diagnose Standard Load Balancer rules, probes, and backend access.

Useful evidence: a topology, route table, DNS result, or probe status. A line between resources must have a defined meaning; it does not prove every kind of access.

Monitoring and maintenance

  • Distinguish platform telemetry from guest collection and inspect the destination and collection period.
  • Read Kusto Query Language (KQL) filters and aggregations; relate results to the supplied time window.
  • Separate alert conditions, action groups, and alert processing rules.
  • Use Insights, Network Watcher, and Connection monitor evidence for the relevant investigation.
  • Match a workload to its vault and policy, restore the required data, and distinguish backup from Site Recovery failover.

Useful evidence: a metric chart, query result, backup schedule, or replication status. Check what was collected or protected before the incident.

Turn the map into your next session

Choose one uncertain task and a short app drill. For each mistake, record the deciding fact and the configuration or command you need to inspect again. Return to mixed practice after correcting that gap.

The study plan organizes this cycle. The scenario guide shows how to read code, tables, and diagram evidence. Use Microsoft’s detailed outline to resolve scope questions; this page is a practice aid rather than a replacement for it.