Exam AZ-104: Microsoft Azure Administrator Associate
Microsoft AZ-104 certification exam is the updated version of the AZ-103 exam. The AZ-104 exam is a new pathway to get certified as a Microsoft Azure Administrator. The exam is designed to measure the candidate’s skills as an Azure Administrator to implement, manage, and monitor identity in a cloud environment. The certification exam is the new version with newly loaded and updated features. Some of the top features include:
- Importance of identities
- Focus on the management of data
- New domain for backup and recovery
- Moving from virtual machines to compute resources
Who should take the exam?
Microsoft Azure Administrator Associate (AZ-104) exam is built to facilitate candidates planning a career as Azure Administrator. Some of the important details listed for candidates planning to take this exam includes –
- A minimum of six months of hands-on experience administering Azure.
- Strong understanding of core Azure services, Azure workloads, security, and governance.
- Experience in using PowerShell, the Command Line Interface, Azure Portal, and ARM templates.
AZ-104 Interview Questions
Get ready for the Az-104 interview with these practice questions and ace your interview.
Getting Started – Prerequisite Lessons for Azure Administrators
The AZ-104 prerequisites lessons for Azure Adminstrators include:
- Learn governance and Management in Azure
- Intro to Azure Virtual Machines
- Networking Fundamentals
- Network Security
- Using Azure CLI to control azure services
- Using Azure Powershell to automate azure tasks
- Intro to Azure Active Directory
- Intro to Docker Containers
- Intro to data storage in azure
- Learn data storage approach in azure
Learning Objectives
Microsoft being a dominant player constantly provides relevant and required documentation to meet the needs of all of today’s diverse learners and therefore, helping them to build a life in the world of cloud computing. As a result, the potential aspirants are easily able to locate the required detailed information along with the subtopics included in each domain.
The Microsoft AZ-104 certification exam focuses on five key areas:
- Manage Azure identities and governance
- Implement and manage storage
- Deploy and manage Azure compute resources
- Configure and manage virtual networking
- Monitor and back up Azure resources
Learning Path: AZ-104 Exam
The AZ-104 exam learning path helps candidates to implement, manage, and monitor identity, governance, storage, compute, and virtual networks in a cloud environment, plus provision, size, monitor, and adjust resources, when needed. The AZ-104 exam tests your knowledge across five different subject areas, and that’s how this learning path is structured
Exam Format
The Microsoft AZ-104 exam comprises 40-60 questions that need to be completed within a time span of 120 minutes. There are different types of questions present during the exam including case study, short answers, multiple-choice, mark review, drag, and drop, etc. The candidate has to score a minimum of 700 or more points in order to pass the exam. The AZ-104 exam fee is $165 USD. Also, the exam is only available in the English language.
How to schedule the exam?
Microsoft Azure Administrator Associate (AZ-104) has been built to tests and validates your expertise as an Azure Administrator. Candidates planning to take AZ-104 exam should also have a strong understanding of core Azure services, workloads, security, and governance.
Candidates can schedule their exam with the Pearson VUE.
Exam Detailed Course Outline
Now let’s start taking a detailed look at these modules. We will list the necessary and important links from the documentation where you can learn all the concepts required to pass the exam. Once you go through all the concepts, don’t forget to subscribe to our AZ-104 practice tests, since they are very necessary to keep your progress in check.
The Microsoft AZ-104 exam topics include:
Module 1: Manage Azure identities and governance (20-25%)
1.1 Manage Microsoft Entra users and groups
- Create users and groups (Microsoft Documentation: Add or delete users using Azure Active Directory)
- Manage user and group properties
- Manage licenses in Microsoft Entra ID
- Manage external users
- Configure self-service password reset (SSPR) (Microsoft Documentation: Tutorial: Enable users to unlock their account or reset passwords using Azure Active Directory self-service password reset)
1.2 Manage access to Azure resources
- Manage built-in Azure roles
- Assign roles at different scopes
- Interpret access assignments
1.3 Manage Azure subscriptions and governance
- Implementing and managing Azure policy (Microsoft Documentation: Create and manage policies to enforce compliance)
- Configuring resource locks (Microsoft Documentation: Lock resources to prevent unexpected changes)
- Apply and manage tags on resources (Microsoft Documentation: Use tags to organize your Azure resources and management hierarchy)
- Managing resource groups (Microsoft Documentation: Move resources to a new resource group or subscription)
- Managing subscriptions (Microsoft Documentation: Organize and manage multiple Azure subscriptions)
- Manage costs by using alerts, budgets, and Azure Advisor recommendations (Microsoft Documentation: Use cost alerts to monitor usage and spending)
- Configuring management groups (Microsoft Documentation: Create management groups for resource organization and management)
Module 2: Implement and manage storage (15-20%)
2.1 Configure access to storage
- Configure Azure Storage firewalls and virtual networks
- Create and use shared access signature (SAS) tokens
- Configure stored access policies
- Manage access keys (Microsoft Documentation: Manage storage account access keys)
- Configure identity-based access for Azure Files
2.2 Configure and manage storage accounts
- Create and configure storage accounts
- Configure Azure Storage redundancy (Microsoft Documentation: Azure Storage redundancy)
- Configure object replication (Microsoft Documentation: Configure object replication for block blobs)
- Configure storage account encryption
- Manage data by using Azure Storage Explorer and AzCopy (Microsoft Documentation: Get started with AzCopy)
2.3 Configure Azure files and Azure blob storage
- Create and configure a file share in Azure Storage (Microsoft Documentation: Create an Azure file share)
- Create and configure a container in Blob Storage
- Configure storage tiers (Microsoft Documentation: Hot, Cool, and Archive access tiers for blob data)
- Configure snapshots and soft delete for Azure Files
- Configure blob lifecycle management (Microsoft Documentation: Configure a lifecycle management policy)
- Configure blob versioning
Module 3: Deploy and manage Azure compute resources (20-25%)
3.1 Automate deployment of resources by using Azure Resource Manager (ARM) templates or Bicep files
- Interpret an Azure Resource Manager template or a Bicep file
- Modify an existing Azure Resource Manager template
- Modify an existing Bicep file
- Deploy resources by using an Azure Resource Manager template or a Bicep file
- Export a deployment as an Azure Resource Manager template or convert an Azure Resource Manager template to a Bicep file
3.2 Create and configure Virtual Machines
- Create a Virtual Machine (Microsoft Documentation: Create a Windows virtual machine)
- Configure Azure Disk Encryption (Microsoft Documentation: Create and encrypt a Windows virtual machine with the Azure portal)
- Move a virtual machine to another resource group, subscription, or region (Microsoft Documentation: Move a Windows VM to another Azure subscription or resource group)
- Manage virtual machines sizes (Microsoft Documentation: Sizes for virtual machines in Azure)
- Add virtual machines disks
- Deploy virtual machines to availability zones and availability sets
- Deploy and configure an Azure Virtual Machines scale sets (Microsoft Documentation: Create a virtual machine scale set in the Azure portal)
3.3 Provision and manage containers in the Azure portal
- Create and manage an Azure container registry
- Provision a container by using Azure Container Instances
- Provision a container by using Azure Container Apps
- Manage sizing and scaling for containers, including Azure Container Instances and Azure Container Apps
3.4 Create and configure Azure App Service
- Provision an App Service plan
- Configure scaling for an App Service plan
- Create an App Service (Microsoft Documentation: App Service overview)
- Configure certificates and Transport Layer Security (TLS) for an App Service
- Map an existing custom DNS name to an App Service
- Configure a backup for an App Service (Microsoft Documentation: Back up and restore your app in Azure App Service)
- Configuring networking settings for an App Service (Microsoft Documentation: Configuring the Network)
- Configure deployment slots for an App Service
Module 4: Implement and manage virtual networking (15–20%)
4.1 Configure and manage virtual networks in Azure
- Create and configure virtual networks and subnets (Microsoft Documentation: Azure Virtual Network)
- Create and configure virtual network peering (Microsoft Documentation: Virtual network peering)
- Configure public IP addresses
- Configure user-defined network routes (Microsoft Documentation: Virtual network traffic routing)
- Troubleshoot network connectivity
4.2 Configure secure access to virtual networks
- Create and configure network security groups (NSGs) and application security groups (Microsoft Documentation: Network security groups)
- Evaluate effective security rules in NSGs (Microsoft Documentation: Effective security rules view in Azure Network Watcher)
- Implement Azure Bastion (Microsoft Documentation: Azure Bastion)
- Configure service endpoints for Azure platform as a service (PaaS)
- Configure private endpoints for Azure PaaS(Microsoft Documentation: private endpoint)
4.3 Configure name resolution and load balancing
- Configure Azure DNS
- Configure an internal or public load balancer (Microsoft Documentation: Create an internal load balancer)
- Troubleshoot load balancing (Microsoft Documentation: Troubleshoot Azure Load Balancer)
Module 5: Monitor and Maintain Azure resources (10-15%)
5.1 Monitor resources in Azure
- Interpret metrics in Azure Monitor (Microsoft Documentation: Metrics in Azure Monitor)
- Configure log settings in Azure Monitor (Microsoft Documentation: Azure Monitor Logs overview)
- Query and analyze logs in Azure Monitor(Microsoft Documentation: Get started with log queries in Azure Monitor)
- Set up alert rules, action groups, and alert processing rules in Azure Monitor (Microsoft Documentation: Create, view, and manage metric alerts using Azure Monitor)
- Configure and interpret monitoring of virtual machines, storage accounts, and networks by using Azure Monitor Insights (Microsoft Documentation: VM insights)
- Use Azure Network Watcher and Connection Monitor
5.2 Implement backup and recovery
- Create a Recovery Services vault (Microsoft Documentation: Create and configure a Recovery Services vault)
- Create Azure backup vault (Microsoft Documentation: Backup vaults overview)
- Create and configure backup policy
- Perform backup and restore operations by using Azure Backup (Microsoft Documentation: restore Azure VM data in Azure portal)
- Configure Azure Site Recovery for Azure resources (Microsoft Documentation: Azure to Azure disaster recovery architecture)
- Perform failover to a secondary region by using Site Recovery (Microsoft Documentation: Failover Azure VMs to a secondary region)
- Configure and interpret reports and alerts for backups (Microsoft Documentation: Configure Azure Backup reports)
Exam Policies
Microsoft is solely responsible to provide exam policies with a view to enabling the candidates to plan and manage a positive outcome. Microsoft Certification exam policies are an appropriate blend of all the exam-related details, accompanying the before and after exam procedures. These exam policies are the inclusion of certain rules that need to be followed during the exam time or at testing centres.
For More Queries Visit : Microsoft Azure AZ-104 Exam FAQs
Microsoft Azure AZ-104 Study Guide
Learning Resource 1: Review the exam objectives
When you begin your preparation journey, it becomes essential to review all exam objectives. Doing so will provide you with a clear idea about all the different topics and skills that you need to be proficient in. Also, reviewing the exam objectives will leave no space for confusion in your head and you can focus on your preparation. Exam objectives can help you strengthen the modules and the respective subtopics for the Microsoft Azure AZ-104 exam.
Learning Resource 2: Instructor Led Training
Achieving Microsoft certification is not a breeze. It takes moxie of determination and proper training. Saying so, we mean instructor-led training. Instructor-led training is basically an online training course that helps potential candidates gain a basic understanding of the skills that are required for the exam. Besides this, there are lab scenario questions provided in the course that can add support and exhibit the structure of various application scenarios. So, getting better AZ-104 training instructor-led can be very beneficial.
Expand your certification portfolio with Microsoft Azure Administrator Associate (AZ-104). Apply for Online Course and earn yourself a digital badge.
Learning Resource 3: Online Forums
Joining online forums is a great idea to boost your preparation process as they help you meet different people who are on the same road as you. They provide you an advantage to ask your queries immediately and receive the response in a prompt manner. Online forums are generally headed by industry experts or certified professionals. But the idea to join an online forum is completely subjective. There is no such compulsion for the same.
Learning Resource 4: Books
Books are the most important ingredient while you prepare for your certification exam. While preparing for the exam, questions may haunt you. However, you get away with this fear by books. There are some excellent books ruling the market for years that you can use or refer to study for the AZ-104 exam. This particular step is possibly the most important step to offer you. However, the AZ-104 book that can be useful includes:
- Exam Ref AZ-104 Microsoft Azure Administrator Book by Harshul Patel and Scott Hoag
Learning Resource 5: Practice Tests
The evolution of practice tests from pen and paper to online mode has done nothing but added more relevancy to the concept of practice tests. They are the oldest yet the most effective tools to increase your efficiency as well as confidence. For the AZ-104 exam, practice tests are highly important to find out your core strengths and iron out your weaknesses. They are formed to provide you a scenario of the exam hall before you appear for the actual exam.
Get ready to Practice and Prepare for Microsoft Azure Administrator Associate (AZ-104) Exam Now!
Microsoft Azure Administrator Associate (AZ-104) Online Tutorial
Testprep Training offers Online Tutorials to assist you in your preparation for Exam AZ-104: Microsoft Azure Administrator Associate. The online tutorial has been built to help you acquire the required knowledge of the domain areas and structure the learning path to support your preparation. The online tutorial covers the learning objectives including –
- Manage Azure identities and governance
- Implement and manage storage
- Deploy and manage Azure compute resources
- Configure and manage virtual networking
- Monitor and back up Azure resources
It is suggested that you have general knowledge of IT architecture. So lets dig deeper and train ourselves with all the required skills set.
Domain 1 – Manage Azure identities and governance (15-20%)
1.1 Manage Azure AD objects
- Learn to create users and groups using Azure Directory
- Managing User Profile and Group Information
- Manage device Settings using Azure Portal
- Bulk user Updates in Active Directory
- Adding guest accounts in Azure Portal
- Steps to configure Azure AD Join
- Enable User to Configure self-service Password Reset
1.2 Manage role-based access control (RBAC)
- Creating a custom role using PowerShell
- Role Assignment using Azure Portal
- Understand Azure Deny assignments
- Creating and Managing Multiple Directories
1.3 Manage subscriptions and governance
- Create and Manage Azure Policy
- Using Resource Locks
- Apply tags to organize Azure resources
- Creating and Managing Resource Groups
- Manage Azure Subscriptions
- Azure Cost Management and Billing
- Creating Management Groups
2. Implement and manage storage (10-15%)
2.1 Manage storage accounts
- Configuring Azure Virtual Network Access
- Creating an Azure storage accounts
- Grant access using Shared Access Signature (SAS)
- Managing your Storage Account access keys
- Process of Azure storage replication
- Configure Azure AD Authentication for a storage account
2.2 Manage data in Azure Storage
- Import/Export Services to Export Data from Azure Blob Storage
- Learn about Microsoft Azure Storage Explorer
- Overview of AZCopy
2.3 Configure Azure files and Azure blob storage
- Creating an Azure file share
- Deployment of Azure File Sync
- Overview: Upload, download, and file block blobs using the Azure portal
- Azure Blob storage: hot, cool, and archive access tiers
3. Deploy and manage Azure compute resources (25-30%)
3.1 Configure VMs for high availability and scalability
3.2 Automate deployment and configuration of VMs
- Update an Azure Resource Manager template
- Creating a Windows VM from a specialized disk by using PowerShell
- Creating a Windows VM from a Resource Manager template
- Downloading the template for a VM
- Automate configuration management by using custom script extensions
3.3 Create and configure VMs
- Creating and encrypting a Windows virtual machine with the Azure portal
- Moving Windows VM to another Azure subscription or resource group
- VMs size in Azure
- Attach a data disk to a Windows VM with PowerShell
- Vnet and VM in Azure
- Creating an Azure Bastion
3.4 Create and configure containers
3.5 Create and configure Web Apps
Domain 4 – Configure and manage virtual networking (30-35%)
4.1 Implement and manage virtual networking
- Create and configure VNET peering
- Create, change, or delete a public IP address
4.2 Configure name resolution
- Creating an Azure DNS zone and record using the Azure portal
- Using Azure DNS to implement custom domain settings
- Hosting domain in Azure DNS
4.3 Secure access to virtual networks
- Create security rules
- Associate an NSG to a subnet or network interface
- View effective security rules
- Deploy and configure Azure Firewall
- Deploy and configure Azure Bastion Service
- NOT: Implement Application Security Groups; DDoS
4.4 Configure load balancing
- Direct web traffic with Azure Application Gateway
- Create an internal load balancer to load balance VMs
- Create outbound rule configuration
- Create a public load balancer to load balance VMs
- Troubleshoot Azure Load Balancer
- NOT: Traffic Manager and FrontDoor and PrivateLink
4.5 Monitor and troubleshoot virtual networking
- Monitoring On-Premise Active Directory via Azure AD Connect Health
- Network Performance Monitor solution in Azure
- Create an Azure Network Watcher instance
- Troubleshooting an Azure site-to-site VPN connection
- Diagnose a communication problem between networks
4.6 Integrate an on-premises network with an Azure virtual network
- Create and manage a VPN gateway using Azure portal
- Create a Site-to-Site connection in the Azure portal
- Create and modify an ExpressRoute circuit
- Connect a VPN Gateway (virtual network gateway) to Virtual WAN
Domain 5 – Monitor and back up Azure resources (10-15%)
5.1 Monitor resources by using Azure Monitor
- Azure Monitor Metrics overview
- Create a Log Analytics workspace and Manage access to log data
- Log Queries and Analytics
- Create, view, and manage metric alerts using Azure Monitor
- Configure Application Insights
5.2 Implement backup and recovery
- Configure Azure Backup reports
- Perform backup and restore operations by using Azure Backup Service
- Create and configure a Recovery Services vault
- az backup policy
- Prepare Azure resources for Hyper-V disaster recovery