Complete AZ-104 Azure Administrator study guide — identity, storage, compute, networking, and monitoring for Azure admins.
This guide works best as a loop: read a chapter, test yourself with practice questions, look up unfamiliar terms in the glossary, then move to the next chapter.
168 chapters covering every exam objective. Each chapter includes key concepts, exam tips, common traps, comparison tables, and a 5-question quiz at the end.
Start Chapter 1Free timed and untimed practice with instant feedback and full explanations. Pick 10–120 questions per session. Filter by domain to drill your weak areas.
Go to practice testEvery AZ-104term defined and searchable. Use it when a chapter mentions a concept you haven't seen before or want a quick refresher on.
Browse glossaryExam blueprint, domain weights, passing score, duration, cost, and registration links. Start here if you're new to this certification.
View exam guide41 chapters
VPN Gateway and ExpressRoute
Objective 4.4 · Networking
Azure Virtual Networks and Subnets
Objective 4.1 · Networking
Network Security Groups (NSG)
Objective 4.1
VNet Peering and Global VNet Peering
Objective 4.1
Azure Load Balancer
Objective 4.2 · Networking
Azure Application Gateway and WAF
Objective 4.2
Azure DNS and Private DNS Zones
Objective 4.3 · Networking
Azure Firewall
Objective 4.5 · Networking
Azure Bastion
Objective 4.5
User-Defined Routes (UDR) and Route Tables
Objective 4.1
Service Endpoints vs Private Endpoints
Objective 4.1
Azure Private Link Service
Objective 4.1
Application Security Groups (ASG)
Objective 4.1
Service Tags in NSG Rules
Objective 4.1
Cross-Subscription and Cross-Region VNet Peering
Objective 4.1
Subnet Delegation in Azure
Objective 4.1
IPv6 in Azure Virtual Networks
Objective 4.1
Azure NAT Gateway
Objective 4.1
Azure Front Door and CDN Profiles
Objective 4.2
Azure Traffic Manager Routing Methods
Objective 4.2
Azure CDN Profiles and Rules Engine
Objective 4.2
Public IP Address SKUs and Allocation Methods
Objective 4.2
Public IP Address Prefixes
Objective 4.2
Load Balancer Frontend, Backend, and Health Probe Rules
Objective 4.2
Application Gateway v2 Autoscaling
Objective 4.2
Application Gateway Ingress Controller for AKS
Objective 4.2
Azure DDoS Protection Standard
Objective 4.5
Web Application Firewall (WAF) Policies
Objective 4.5
Azure Firewall Premium Features
Objective 4.5
Azure Firewall Policy and Rule Collections
Objective 4.5
Azure Route Server
Objective 4.4
ExpressRoute Global Reach and FastPath
Objective 4.4
VPN Gateway BGP Configuration
Objective 4.4
Point-to-Site VPN Gateway
Objective 4.4
Azure Virtual WAN
Objective 4.4
Hub-and-Spoke Network Topology on Azure
Objective 4.4
Network Virtual Appliances (NVA)
Objective 4.5
Just-in-Time VM Access
Objective 4.5
Azure DNS Private Resolver
Objective 4.3
Azure Bastion Standard vs Developer SKU
Objective 4.5
Azure Connection Monitor v2
Objective 4.5
35 chapters
Dynamic Membership Groups
Objective 1.1 · Identity Governance
Privileged Identity Management (PIM)
Objective 1.1
Managed Identities for Azure Resources
Objective 1.1
Microsoft Entra ID Users and Groups
Objective 1.1
Azure RBAC Role Assignments
Objective 1.1
Azure AD Connect and Hybrid Identity
Objective 1.1
Azure Policy and Initiatives
Objective 1.2 · Identity Governance
Management Groups and Subscriptions
Objective 1.2
Resource Locks and Tag Governance
Objective 1.2
Azure Blueprints for Compliance
Objective 1.2
MFA and Passwordless Authentication in Entra
Objective 1.1
External Identities and B2B Collaboration
Objective 1.1
Access Reviews in Entra ID
Objective 1.1
Entitlement Management and Access Packages
Objective 1.1
Azure AD Application Proxy
Objective 1.1
Self-Service Password Reset (SSPR)
Objective 1.1
Azure AD Domain Services (AADDS)
Objective 1.1
Custom Domains in Entra ID
Objective 1.1
Administrative Units in Entra
Objective 1.1
App Registrations and Service Principals
Objective 1.1
Named Locations and Conditional Access Policies
Objective 1.1
Token Lifetime and Session Control Policies
Objective 1.1
Identity Protection Risk Policies
Objective 1.1
Custom RBAC Role Definitions
Objective 1.1
Cross-Tenant Synchronization
Objective 1.1
Emergency Access Break-Glass Accounts
Objective 1.1
Resource Tagging Strategy and Enforcement
Objective 1.2
Azure Cost Management and Budgets
Objective 1.2
Azure Lighthouse for Multi-Tenant Management
Objective 1.2
Azure Arc for Servers
Objective 1.2
Subscription Transfer and Resource Move Operations
Objective 1.2
Azure Policy Remediation Tasks
Objective 1.2
Azure Compliance Dashboard and Regulatory Standards
Objective 1.2
Deny Assignments and Resource Locks Deep Dive
Objective 1.2
Well-Architected Framework: Governance Pillar
Objective 1.2
24 chapters
Customer-Managed Keys (CMK) for Storage Encryption
Objective 2.3 · Storage
Azure Storage Accounts
Objective 2.1 · Storage
Azure Files and Azure File Sync
Objective 2.2 · Storage
Securing Azure Storage (SAS, Keys, Firewall)
Objective 2.3
AzCopy and Storage Explorer
Objective 2.4 · Storage
Storage Redundancy: LRS, ZRS, GRS, GZRS Compared
Objective 2.1
Blob Versioning and Soft Delete
Objective 2.1
Azure Blob Object Replication
Objective 2.1
Blob Lifecycle Management Policies
Objective 2.1
Immutable Blob Storage: Legal Hold and Time-Based Retention
Objective 2.1
Azure Data Lake Storage Gen2
Objective 2.2
Azure Import/Export Service and Data Box
Objective 2.2
Azure NetApp Files
Objective 2.2
Premium File Shares and NFS
Objective 2.2
Azure Queue and Table Storage
Objective 2.2
Storage Account Failover and RA-GZRS
Objective 2.3
Private Endpoints for Azure Storage
Objective 2.3
SAS Token Types: Account, Service, User Delegation
Objective 2.3
Storage Firewall and Virtual Network Rules
Objective 2.3
Blob Storage Events with Event Grid
Objective 2.4
Azure File Share Backup via Recovery Vault
Objective 2.4
Managing Blob Access Tiers at Scale
Objective 2.4
Azure Blob Storage Access Tiers
Objective 2.1
Static Website Hosting on Azure Blob
Objective 2.2
42 chapters
Generalizing and Capturing VM Images
Objective 3.1 · Compute
Azure Virtual Machine Deployment
Objective 3.1
VM Availability Sets and Zones
Objective 3.1
Azure Virtual Machine Scale Sets
Objective 3.1
Azure App Service Plans and Web Apps
Objective 3.2 · Compute
Azure Container Instances and AKS Basics
Objective 3.3 · Compute
Azure Functions for Administrators
Objective 3.3
ARM Templates and Bicep
Objective 3.4 · Compute
VM Extensions: Custom Script, DSC, Diagnostics
Objective 3.1
Azure Managed Disk Types: HDD, SSD, Premium, Ultra
Objective 3.1
Disk Snapshots and Custom VM Images
Objective 3.1
Azure Compute Gallery and Image Versioning
Objective 3.1
Azure Spot VMs and Eviction Policy
Objective 3.1
Reserved Instances and Savings Plans
Objective 3.1
VM Boot Diagnostics and Serial Console
Objective 3.1
Azure Disk Encryption: BitLocker and dm-crypt
Objective 3.1
Azure Dedicated Hosts
Objective 3.1
Proximity Placement Groups
Objective 3.1
Linux VMs on Azure: cloud-init and Extensions
Objective 3.1
VM Run Command and Invoke Script
Objective 3.1
Ephemeral OS Disks for VMs and AKS
Objective 3.1
Azure Update Management Center
Objective 3.1
Azure Automanage for VMs
Objective 3.1
Azure Batch for HPC Workloads
Objective 3.1
Azure VMware Solution (AVS)
Objective 3.1
App Service Deployment Slots and Swapping
Objective 3.2
App Service Autoscaling Rules
Objective 3.2
App Service Custom Domains and TLS Certificates
Objective 3.2
App Service VNet Integration
Objective 3.2
Azure Container Registry (ACR)
Objective 3.3
AKS Node Pools and Cluster Upgrades
Objective 3.3
AKS Networking: Azure CNI vs Kubenet
Objective 3.3
AKS Scaling: HPA, KEDA, Cluster Autoscaler
Objective 3.3
AKS RBAC and Workload Identity
Objective 3.3
AKS Monitoring: Container Insights and Prometheus
Objective 3.3
Azure Container Apps vs AKS vs ACI
Objective 3.3
Azure Logic Apps Workflows
Objective 3.3
Bicep and ARM Template Advanced Patterns
Objective 3.4
Azure Template Specs
Objective 3.4
Azure Deployment Stacks
Objective 3.4
What-If Analysis for ARM Deployments
Objective 3.4
Azure Resource Graph Queries
Objective 3.4
26 chapters
Azure Monitor and Log Analytics
Objective 5.1 · Monitoring
Azure Alerts and Action Groups
Objective 5.1
Azure Backup and Recovery Services Vault
Objective 5.2 · Monitoring
Azure Site Recovery
Objective 5.2
Cost Management and Billing Analysis
Objective 5.3 · Monitoring
Azure Network Watcher
Objective 5.4 · Monitoring
Log Analytics Workspace Design and Data Retention
Objective 5.1
KQL Queries for Azure Monitoring
Objective 5.1
Azure Monitor Workbooks
Objective 5.1
Azure Dashboards and Shared Dashboards
Objective 5.1
Azure Metrics Explorer
Objective 5.1
Diagnostic Settings and Log Routing
Objective 5.1
Activity Log and Change History
Objective 5.1
Resource Health and Azure Service Health
Objective 5.1
Azure Advisor Recommendations
Objective 5.1
Change Tracking and Inventory
Objective 5.1
Azure Automation Runbooks
Objective 5.1
Azure Arc Monitoring for Hybrid VMs
Objective 5.1
Container Insights for AKS
Objective 5.1
VM Insights and Dependency Agent
Objective 5.1
Log Alerts vs Metric Alerts vs Activity Log Alerts
Objective 5.1
Autoscale Profiles and Schedule Rules
Objective 5.1
Data Collection Rules (DCR) and Azure Monitor Agent
Objective 5.1
Azure Site Recovery Monitoring and Reporting
Objective 5.2
Cost Alerts and Budget Thresholds
Objective 5.3
Application Change Analysis
Objective 5.4
Free AZ-104 practice questions with full explanations. Test what you learn chapter by chapter.
AZ-104 Practice Questions