Microsoft Azure Administrator [AZ-104] Exam Guide (2026)
![Microsoft Azure Administrator [AZ-104] Exam Guide (2026)](/_next/image?url=https%3A%2F%2Fcdn.sanity.io%2Fimages%2F2oo9oqu3%2Fproduction%2F7d91b9e74eac6387b614d3b455a83c04bf4a4bfd-1600x789.png%3Frect%3D99%2C0%2C1403%2C789%26w%3D1200%26h%3D675&w=3840&q=75)
If you can say which scope a role assignment has to sit at before a helpdesk user can reset a password, why a delete lock on a storage account still lets someone wipe a container, and which redundancy option survives the loss of one datacenter without surviving the loss of a region, you are in the right exam.
AZ-104 is the exam behind Microsoft Certified: Azure Administrator Associate. The credential page marks it intermediate, Azure, administrator role, with a 12 month renewal frequency and a last updated date of 17 April 2026. The study guide publishes the matching skills outline under the heading Skills measured as of April 17, 2026. That outline is the whole scope of the sitting.
This guide is for people who will sit AZ-104 on that April 2026 blueprint. It covers who Microsoft expects to walk in, how the 100 minute sitting and the 700 pass mark actually work, exactly what the change log moved, and the three discriminators that decide most questions.
Who this exam is for
Take it if the daily job is already running someone else's Azure environment rather than designing a new one. The audience profile asks for subject matter expertise implementing, managing, and monitoring an organization's Azure environment across virtual networks, storage, compute, identity, security, and governance. Microsoft is explicit that the Azure administrator usually sits inside a larger team and coordinates with networking, security, database, application development, and DevOps roles. The exam is written for the person who executes the platform, not the person who signs off the architecture.
The prerequisite list is a gap check, and it is unusually concrete for a Microsoft outline. Familiarity with operating systems, networking, servers, and virtualization. Experience with PowerShell, the Azure CLI, the Azure portal, Azure Resource Manager templates or Bicep files, and Microsoft Entra ID. If four of those five tools are things you have only read about, the sitting will feel like a vocabulary test rather than a job test.
The compute area makes the point sharper than the audience profile does. It asks candidates to interpret an ARM template or a Bicep file, modify an existing ARM template, modify an existing Bicep file, and export a deployment as an ARM template or convert one to Bicep. Nothing on the outline asks for a template authored from an empty file. The skill being scored is reading infrastructure code that already exists and changing it without breaking the deployment.
Skip it if the goal is the language of the cloud rather than the operation of it. Service definitions, pricing models, and shared responsibility belong to AZ-900. Skip it if the work you actually want is designing the landing zone, because governance appears here as management groups, policy assignments, locks, and tags that an administrator applies, not as a hierarchy an architect invents.
Exam shape and how the score works
The April 2026 outline has five functional groups, and Microsoft publishes weight ranges rather than fixed percentages.
| Skill area | Weight | What gets tested |
|---|---|---|
| Manage Azure identities and governance | 20 to 25% | Entra users and groups, built-in roles at the right scope, Policy, locks, tags, resource groups, subscriptions, cost alerts and budgets, management groups |
| Implement and manage storage | 15 to 20% | Storage firewalls, SAS tokens and stored access policies, access keys, redundancy, object replication, encryption, Files and Blob, tiers, soft delete, versioning, lifecycle management |
| Deploy and manage Azure compute resources | 20 to 25% | ARM templates and Bicep, virtual machines, disks, zones and availability sets, scale sets, Container Registry, Container Instances, Container Apps, App Service |
| Implement and manage virtual networking | 15 to 20% | Virtual networks and subnets, peering, public IPs, user-defined routes, NSGs and ASGs, Bastion, service endpoints, private endpoints, Azure DNS, load balancers |
| Monitor and maintain Azure resources | 10 to 15% | Azure Monitor metrics, log settings, log queries, alert rules and action groups, Insights, Network Watcher, Recovery Services vault, Backup vault, backup policies, Site Recovery failover |
Do the arithmetic on those ranges before building a plan. The lower bounds total 80%. The upper bounds total 105%. The midpoints total 92.5%. No exact split exists to memorize, and the bands are the only ordering Microsoft gives you. Identities and governance ties with compute in the top band. Storage ties with networking in the middle band. Monitoring sits alone at the bottom. Any study plan that gives five equal weeks overweights monitoring and underweights governance.
The logistics come off the credential page. The sitting is 100 minutes, proctored, scheduled through Pearson VUE, and the page warns that the exam may have interactive components. Price depends on the country or region where the exam is proctored, so no single global figure is published. Languages are English, Chinese (Simplified), Korean, Japanese, French, Spanish, German, Portuguese (Brazil), Chinese (Traditional), and Italian. A failed attempt can be retaken 24 hours later, and the wait varies for later retakes.
That 100 minute figure is worth reading against Microsoft's own duration table. Fundamentals exams run 45 minutes. Associate and expert role-based exams without labs run 100 minutes with 120 minutes of seat time. Associate and expert role-based exams that may contain labs run 120 minutes with 140 minutes of seat time. AZ-104 is published at the 100 minute figure. Microsoft also states plainly that it does not publish a list of exams with labs, because labs can be pulled at any time for an outage or a bandwidth problem, and that the real exam time is confirmed at registration and on the launch screens. Plan for interactive components. Do not plan for a lab timer that Microsoft has not given you.
Scoring is the part most candidates get wrong. Technical exam scores are reported on a scale of 1 to 1,000 and 700 or greater passes. Microsoft says outright that the scaled score is not 70 percent of the points, because the passing standard reflects question difficulty. Multi-part questions usually award one point per correctly answered component, so all, some, or none of the points on a question are possible. There is no penalty for guessing. Some questions are unscored and used to collect data, and candidates are never told which, so every question deserves an answer.
The score report gives one overall number, a pass or fail status, and a bar chart per skill area. It does not give a numeric score per section, and Microsoft warns that the bars cannot be added up to reconstruct the result. A short bar in a small area can mean a handful of questions went wrong, and scoring zero in an area that carries only a few questions is documented as normal.
Two more details change how you prepare. Microsoft Learn is available in a split screen during role-based exams, covering everything on learn.microsoft.com except Q&A, practice assessments, and your profile, with no extra time added and no navigation outside the domain. Five minutes of break time are built into the clock, questions were removed to make room for it, and any question you have already seen is gone once the break starts. The credential itself renews every 12 months through a free, unproctored, open book assessment inside a six month window before expiry.
What changed on 17 April 2026
The study guide publishes a change log comparing the previous outline with the current one. The full table is short.
| Skill area prior to 17 April 2026 | Skill area as of 17 April 2026 | Change |
|---|---|---|
| Audience profile | Minor | |
| Implement and manage storage | Implement and manage storage | No change |
| Configure Azure Files and Azure Blob Storage | Configure Azure Files and Azure Blob Storage | Minor |
| Deploy and manage Azure compute resources | Deploy and manage Azure compute resources | No change |
| Create and configure virtual machines | Create and configure virtual machines | Minor |
| Provision and manage containers in the Azure portal | Provision and manage containers in the Azure portal | Minor |
| Implement and manage virtual networking | Implement and manage virtual networking | No change |
| Configure and manage virtual networks in Azure | Configure and manage virtual networks in Azure | Minor |
| Monitor and maintain Azure resources | Monitor and maintain Azure resources | No change |
| Monitor resources in Azure | Monitor resources in Azure | Minor |
Three things are true of that table, and each one changes what you should do with older study material.
Every functional group listed is marked No change. Nothing on the table is marked Major. The exam code did not move, the five areas did not move, and the published weight ranges are the ones above. AZ-104 material written against the previous outline is still structurally correct.
Every sub-area listed is marked Minor. The touched sub-areas are Azure Files and Blob Storage, virtual machines, containers in the portal, virtual networks, and monitoring. Those are exactly the places where Azure ships new capability fastest, so treat them as refresh work rather than relearning. Microsoft adds that most questions cover features that are generally available, and that preview features can appear when they are commonly used.
The table carries no row at all for Manage Azure identities and governance. Storage, compute, networking, and monitoring each appear. The joint-heaviest area is the one the change log leaves out entirely. Scope, roles, policy, locks, and tags behave on the current exam the way they behaved on the previous one, which makes that area the cheapest place to bank points and the least excusable place to lose them.
How a permission actually lands on a resource
Identities and governance is the joint-heaviest area, and most of its questions reduce to a single skill: naming the level at which a control applies, then naming the plane it applies on.

Azure RBAC has four scope levels: management group, subscription, resource group, and resource. They form a parent and child hierarchy, each level down is more specific, and lower levels inherit role permissions from higher levels. A role assigned at a management group reaches every subscription inside it. A role assigned at a resource reaches nothing else. When a stem describes a team that needs the same access across several subscriptions, the answer is almost always one assignment higher up the tree rather than several assignments lower down.
Management groups have hard shapes worth knowing. Every subscription inside one management group must trust the same Microsoft Entra tenant. A directory supports up to 10,000 management groups, the tree supports up to six levels of depth, and every directory has a single root management group holding all management groups and subscriptions. Global policy and global role assignments belong at that root.
Azure Policy answers a different question from RBAC, and Microsoft states the split directly. Policy evaluates state by examining properties on resources, and it enforces compliance without concern for who made the change or who had permission to make it. RBAC manages user actions at different scopes. Even when a person holds the permission to perform an action, Policy still blocks the create or update when the result would be non-compliant. Read a governance stem twice. If it describes a property that resources must or must not have, it is a policy question. If it describes a person who must or must not act, it is an RBAC question. Microsoft's own guidance is to start with an audit or auditIfNotExists effect and move to deny, modify, or deployIfNotExists once the impact is understood.
Resource locks are the third control and the one that traps people. Two types exist: Delete in the portal is CanNotDelete on the command line, and Read-only in the portal is ReadOnly on the command line. CanNotDelete allows read and modify but not delete. ReadOnly allows read only, which is close to restricting everyone to the Reader role. Locks inherit down from a parent scope to everything inside it including resources added later, and the most restrictive lock in the chain wins. A delete lock on one resource blocks the deletion of its entire resource group, because Azure will not do a partial delete.
Now the plane. Locks apply to control plane operations only. Control plane traffic goes to management.azure.com. Data plane traffic goes to the service endpoint itself. Microsoft says it plainly: a read-only lock or a cannot-delete lock on a storage account does not protect the blob, queue, table, or file data inside it. A File Shares Delete call is control plane and fails against the lock. A Delete Share call is data plane and succeeds. A stem that asks how to stop data from being deleted is asking about soft delete, versioning, or backup. It is not asking about a lock.
How storage redundancy gets picked
Storage is 15 to 20% and redundancy is the part of it that produces clean, answerable questions. The redundancy setting belongs to the storage account and is shared by every service in it, so resources with different requirements belong in separate accounts.

| Option | Primary region | Secondary region | Read from secondary | Durability over a year |
|---|---|---|---|---|
| LRS | Copies inside one datacenter | None | No | at least 11 nines |
| ZRS | Synchronous across three or more availability zones | None | No | at least 12 nines |
| GRS | LRS | Asynchronous copy, LRS there | No | at least 16 nines |
| GZRS | ZRS | Asynchronous copy, LRS there | No | at least 16 nines |
| RA-GRS | LRS | Asynchronous copy, LRS there | Yes | at least 16 nines |
| RA-GZRS | ZRS | Asynchronous copy, LRS there | Yes | at least 16 nines |
Read the failure the stem describes before reading the options. LRS replicates inside a single physical datacenter and protects against drive, server, and rack failures, and a fire or flood in that building can lose every replica. ZRS writes synchronously across three or more availability zones in the primary region and returns success only once every available zone has the write, so data stays readable and writable through the loss of a zone. Microsoft recommends ZRS in the primary region for high availability, and specifically for Azure Files, because clients do not have to remount when a zone drops.
The geo options differ from each other in one place only. GRS uses LRS in the primary region, GZRS uses ZRS in the primary region, and the secondary region is always LRS either way. The paired secondary is determined by the primary and cannot be changed. With plain GRS or GZRS the secondary is not readable or writable until a failover happens, and failover repoints DNS so the secondary endpoints become primary while data is inaccessible during the cut. Read access before an outage requires RA-GRS or RA-GZRS, where the secondary endpoint appends the suffix -secondary to the account name and the access keys are the same for both endpoints.
Two limits decide questions on their own. Azure Files does not support RA-GRS or RA-GZRS. The archive tier for Blob Storage works on LRS, GRS, and RA-GRS but not on ZRS, GZRS, or RA-GZRS. And the most useful sentence on the whole page is the one about what redundancy is not for. Deletions and overwrites apply to every copy at once, so redundancy protects against hardware failure and never against a bad delete.
How a private path to a PaaS service gets picked
Networking is 15 to 20%, and the private access question shows up in storage stems, App Service stems, and database stems as often as in networking ones.

A private endpoint is a network interface that takes a private IP address from your virtual network and brings one instance of a service into that network over Azure Private Link. The target service then sees traffic arriving from a private address inside the virtual network. DNS has to resolve the service host name to that private IP, which is the job private DNS zones do, and the public IP of the target can stay in place while the service firewall blocks it. The endpoint has to live in the same region and subscription as the virtual network, though the target resource can sit elsewhere. Only an endpoint in an Approved state passes traffic. On Azure Storage each subresource needs its own endpoint, so blob and file are two endpoints rather than one, and the storage account has to be general purpose v2.
A service endpoint solves a narrower problem. It extends the virtual network to the service over the Azure backbone while the service keeps its public endpoint. Private addresses in the virtual network reach the service without an outbound public IP, and the service sees a private source address, which is what lets a service firewall allow one specific subnet. DNS entries stay as they are and keep resolving to public addresses. The line that decides between the two: a service endpoint applies to all instances of the target service, while a private endpoint targets one instance. A stem about stopping data from being written to some other tenant's storage account is a private endpoint stem.
Peering and Bastion round out the area. Virtual network peering joins virtual networks so they behave as one for connectivity, locally inside a region or globally across regions, with traffic staying on the Microsoft backbone and routing directly rather than through a gateway. Sending spoke traffic through an appliance or a VPN gateway in a hub is service chaining, and it requires user-defined routes whose next hop is the private IP of a virtual machine in the peered network or a virtual network gateway. A user-defined route cannot name an ExpressRoute gateway as the next hop for routing between virtual networks. Gateway transit lets a peered network use the other network's VPN or ExpressRoute gateway, and a network using a remote gateway cannot have one of its own, because a virtual network gets exactly one.
Azure Bastion is the managed answer to administrative access. It gives RDP and SSH over TLS on port 443, from the portal or a native client, and it reaches every VM in the virtual network by private IP, so those VMs need no public IP, no agent, and no special client software. Basic, Standard, and Premium need a dedicated AzureBastionSubnet and a public IP. Developer runs on shared infrastructure and needs no virtual network. Premium supports a private-only deployment with no public IP. Native client connections, Microsoft Entra ID authentication, file transfer, and shareable links need Standard or Premium.
How to study without wasting a month
Order the weeks by the weight bands, not by the order the areas are printed in.
Week 1. Identities and governance, the joint-heaviest area and the one the change log skipped. Build one management group tree. Put a subscription under it. Assign a built-in role at the management group and watch it reach the resource group. Assign a different one at the resource group and watch it stop there. Write one policy definition that denies a resource property, assign it at a scope, and confirm it blocks an owner. Apply a CanNotDelete lock and then try to delete the resource group. Then try the same thing through a data plane call and watch it go through. Finish with tags, a budget, and a cost alert, because those are on the same task statement.
Week 2. Compute, the other 20 to 25% area. Export an existing deployment as an ARM template. Convert it to Bicep. Change something in each and redeploy. Create a VM into an availability zone and another into an availability set, and be able to say which failure each one survives. Resize a VM, add and expand a disk, move a VM to a different resource group. Then push a container image into Azure Container Registry and run it twice, once through Container Instances and once through Container Apps. Close the week on App Service: a plan, scaling on the plan, a deployment slot, TLS with a custom domain.
Week 3. Storage and networking, the two middle-band areas, together. They share their hardest question. Build a storage account, set a firewall that denies public access, then reach it once through a service endpoint and once through a private endpoint, and watch what each does to DNS. Create a SAS token backed by a stored access policy and revoke it through the policy. Turn on soft delete, versioning, and a lifecycle rule. On the network side, peer two virtual networks, write a user-defined route through a hub, read the effective security rules on a network interface, and deploy Bastion into AzureBastionSubnet so a VM with no public IP is still reachable.
Week 4. Monitoring, the 10 to 15% area, and a full review. Monitoring is the smallest band, so give it days rather than a week. Set a metric alert with an action group. Turn on diagnostic settings and write one log query. Run Network Watcher against a connectivity problem you created on purpose. Create a Recovery Services vault and a Backup vault, note which workloads each one takes, run a backup and a restore, then configure Site Recovery and perform a failover. Spend the rest of the week rereading the study guide task statements and naming, for each bullet, the portal blade and the CLI command that does it.
Take the free practice assessment on the credential page and run the exam sandbox at least once before exam day. The sandbox exists so the question formats cost you nothing on the clock.
Traps that look like easy elimination
Associate items rarely give one plausible answer and three absurd ones. They give two controls that both sound correct and one detail that picks between them.
- A role assignment at a resource group does not reach a sibling resource group. Scope inheritance runs downward only.
- Policy governs what a resource looks like. RBAC governs who may act. A person with full permission still cannot create a non-compliant resource.
- A lock is a control plane guard. It does not stop data plane deletes. Blob and file data inside a locked storage account is still deletable.
- The most restrictive lock in an inheritance chain wins, and a delete lock on one resource blocks the deletion of the whole resource group.
- LRS survives a rack. ZRS survives a zone. Only a geo option survives a region. Adding nines does not change which failure domain is covered.
- GRS and GZRS do not give read access to the secondary. That is what the RA prefix is for. Azure Files does not support either RA option.
- Redundancy is not backup. A delete replicates to every copy. Soft delete, versioning, and Azure Backup are the controls for that.
- A service endpoint covers every instance of a service. A private endpoint covers one instance and needs a private DNS record to be useful.
- NSG rules run from the lowest priority number upward, processing stops at the first match, and default rules sit at the highest numbers so custom rules always run first. NSGs are stateful, so a reply to an allowed flow needs no second rule.
- Peered virtual networks route directly. Traffic only passes through a hub appliance when a user-defined route sends it there.
- An availability set is a redundancy grouping inside one datacenter footprint. Availability zones are physically separate locations with their own power, cooling, and network.
- A Recovery Services vault and a Backup vault are two different resources on this outline, and the skills list names them as two separate tasks.
If deleting the scenario still lets you pick the answer from the service name, the question is easier than the live exam.
How this maps to CloudFluently
Start with the official material. The Microsoft Certified: Azure Administrator Associate credential page carries the logistics, the practice assessment, and the exam sandbox. The study guide for Exam AZ-104 carries the task statements, the weight ranges, and the change log quoted above. Exam duration and exam experience explains the 100 minute timer, the built-in break, and the Microsoft Learn split screen. Exam scoring and score reports explains the 700 scaled pass mark and why the bar chart cannot be added up. Microsoft Certification renewal explains the annual free assessment.
AZ-104 sits on top of Azure fundamentals, and that ground is already live here. The identities and governance area assumes subscriptions, resource groups, Entra ID, and the Azure pricing and cost model are already reflexes, which is the AZ-900 Azure Fundamentals study notes and the AZ-900 Azure Fundamentals practice exam sets. The Azure Fundamentals roadmap sequences that ground, and the AZ-900 exam guide is the companion page to this one.
Two adjacent fundamentals tracks pay off on specific AZ-104 task statements. Storage accounts, redundancy, and the relational and non-relational services behind them are covered in the DP-900 Azure Data Fundamentals study notes and the DP-900 Azure Data Fundamentals practice exam sets. Workload and platform vocabulary that shows up in compute and monitoring stems is covered in the AI-900 Azure AI Fundamentals study notes and the AI-900 Azure AI Fundamentals practice exam sets.
Work those until the fundamentals are automatic, then use this page and the official study guide for the administrator-only skills: scope and inheritance, Policy against RBAC, the control plane and data plane split, redundancy by failure domain, and service endpoints against private endpoints.
Frequently Asked Questions
What is the passing score for AZ-104? 700 or greater on a scale of 1 to 1,000. Microsoft states that this is a scaled score and is not the same as 70 percent of the points, because the standard reflects the difficulty of the questions asked.
How long is the exam and how many questions are there? The credential page gives 100 minutes. Microsoft does not publish a question count for any individual exam, and says most certification exams typically contain between 40 and 60 questions.
Does AZ-104 have labs? Microsoft does not publish a list of exams with labs, because labs can be removed at any time for outages or bandwidth issues. The exam page says the exam may have interactive components. The published 100 minute duration matches Microsoft's row for associate role-based exams without labs, while exams that may contain labs are listed at 120 minutes. The exam time is confirmed at registration and on the launch screens.
What changed on 17 April 2026? Every functional group on the change log is marked No change, and every listed sub-area is marked Minor. The touched sub-areas are Azure Files and Blob Storage, virtual machines, containers in the portal, virtual networks, and monitoring. The change log carries no row for Manage Azure identities and governance.
Which skill area is heaviest? Manage Azure identities and governance and Deploy and manage Azure compute resources share the top band at 20 to 25% each. Implement and manage storage and Implement and manage virtual networking sit at 15 to 20%. Monitor and maintain Azure resources is lowest at 10 to 15%.
Why do the percentages not add up to 100? Because Microsoft publishes ranges. The lower bounds total 80% and the upper bounds total 105%. Use the bands to order study time and stop looking for an exact split.
Can I use Microsoft Learn during the exam? Yes. Role-based exams give a split screen covering learn.microsoft.com, minus Q&A, practice assessments, and your profile. No extra time is added, the clock keeps running, and navigation to other domains is blocked.
How long does the certification last? The renewal frequency is 12 months. Renewal is free, online, unproctored, open book, and shorter than the original exam, and the eligibility window opens six months before expiry.
Can I retake it if I fail? Yes, 24 hours after the first attempt. Waiting periods for later retakes vary.
Where is the official outline? The study guide for Exam AZ-104. Use Microsoft for the task statements and the weight ranges. Use this page for what changed, what the discriminators are, and how to sequence the study.
