AZ-104: Azure administration in production
Learn Azure administration through access, governance, storage, deployment, networking, and operational recovery decisions.
Objectives and progression
Seven original modules develop Azure administration decisions through 35 questions and five fictional production cases. Every question maps to one of five official domains and explains its alternatives. The path follows the April 17, 2026 objectives with technical documentation consulted in September. The internal assessment reuses 26 bank decisions. This first pass does not replace practical experience or exhaustively cover all syllabus tasks. Exercises require no Azure subscription, resource creation, or real data.
Audience: Azure administrators, production engineers, and technical managers coordinating changes and recovery.
Prerequisites: Azure fundamentals, networking, operating systems, and basic declarative-configuration reading.
230 estimated study minutes
- Interpret effective access and governance controls.
- Make storage and data-protection configuration decisions.
- Assess deployment and capacity-change effects.
- Diagnose networking and prepare observability and recovery.
Modules
- Identities and effective access
- Governance, protection, and costs
- Storage, delegation, and recovery
- Declarative deployments and virtual machines
- Availability, scale, and releases
- Networks and layered diagnosis
- Observability and operational recovery
Continue learning
References and version
AZ-104; skills measured 2026-04-17
- Azure Administrator Associate · 2026-09-29
- AZ-104 study guide · 2026-09-29
- Microsoft exam scoring · 2026-09-29
- Microsoft exam experience · 2026-09-29
- Azure RBAC overview · 2026-09-29
- Azure and Microsoft Entra roles · 2026-09-29
- Managed identities · 2026-09-29
- Azure Policy · 2026-09-29
- Policy remediation · 2026-09-29
- Resource locks · 2026-09-29
- Azure budgets · 2026-09-29
- Shared access signatures · 2026-09-29
- Storage redundancy · 2026-09-29
- Storage private endpoints · 2026-09-29
- Blob access tiers · 2026-09-29
- Blob versioning · 2026-09-29
- AzCopy user authorization · 2026-09-29
- Bicep what-if · 2026-09-29
- ARM deployment modes · 2026-09-29
- Bicep parameters · 2026-09-29
- VM states and billing · 2026-09-29
- VM availability options · 2026-09-29
- VM Scale Sets autoscale · 2026-09-29
- App Service deployment slots · 2026-09-29
- Container Apps revisions · 2026-09-29
- NSG rules · 2026-09-29
- NSG evaluation · 2026-09-29
- Azure Bastion · 2026-09-29
- VNet peering · 2026-09-29
- Private endpoint DNS · 2026-09-29
- Virtual network routing · 2026-09-29
- Load Balancer health probes · 2026-09-29
- Azure Activity Log · 2026-09-29
- Diagnostic settings · 2026-09-29
- Azure Monitor Agent · 2026-09-29
- Data collection rules · 2026-09-29
- Azure Monitor alerts · 2026-09-29
- Alert processing rules · 2026-09-29
- Restore Azure virtual machines · 2026-09-29
- Site Recovery drill · 2026-09-29
What you will explore
0 / 7Identities and effective access
Relate principal, role, and scope to the actual task.
Governance, protection, and costs
Apply distinct controls to configuration, deletion, and spending.
Storage, delegation, and recovery
Coordinate authorization, network paths, and version protection.
Declarative deployments and virtual machines
Interpret a change’s effect before executing it.
Availability, scale, and releases
Combine capacity and version control for predictable changes.
Networks and layered diagnosis
Follow DNS, routing, filters, and backend health.
Observability and operational recovery
Produce evidence helping RUN detect, diagnose, and recover.