Baseline & tools
Build an Azure map before memorizing services.
Mastery map
Rate each skill from 1 to 5. Anything at 3 or below becomes your short list for a lab, flashcards, and the linked Microsoft Learn path.
Focus next
Use an honest rating—this map is a planner, not a scorecard.
Deep-dive topics: Management groups, locks, tags, budgets and Advisor · External users, licenses and SSPR
Deep-dive topics: Azure Files identity-based access · Object replication, lifecycle, versioning and transfer tools
Deep-dive topics: Bicep conversion and deployment export · VM moves, encryption at host, VMSS, ACR and Container Apps
Deep-dive topics: Service endpoints versus private endpoints · ASGs, Bastion and Connection Monitor
Deep-dive topics: KQL logs, action groups and processing rules · Recovery Services versus Backup vaults and Site Recovery
Administrator Associate prep
A practical AZ-104 field guide with current weighted objectives, original scenario practice, tenant-ready labs, and rapid comparison notes.
Your runway
Spend time where the exam spends time: identity/governance and compute. Each session ends with a decision, an Azure action and a short recall loop.
Build an Azure map before memorizing services.
Learn the controls people most often blend together.
Choose access, durability and protection independently.
Select the platform by workload shape, not familiarity.
Trace traffic instead of guessing at services.
Choose a data or recovery mechanism that answers one question.
Connect objectives into one small operating environment.
Convert misses into targeted improvement, not random question volume.
Arrive rested with key distinctions ready at speed.
Quick notes
Use these facts and scenario cues to identify the right scope, control, or service before opening a lab or answering a question.
Scenario cueIf the action creates, changes, assigns, or deploys an Azure resource, start with the control plane and the target scope.
Do not confuseA resource group is a lifecycle container, not a regional container. Its resources can live in different regions.
Try it in AzureExplain why a developer can be Contributor in one resource group but unable to list another.
Recall lineScope → plane → control → evidence.
Open the related Microsoft Learn pathThe blueprint
These weights match Microsoft’s skills-measured guide as of April 17, 2026. Use them to choose your next study hour, then confirm changes against the official outline.
Entra users/groups, RBAC scopes, Policy, locks, tags, subscriptions, budgets and management groups.
Storage access, SAS and policies, redundancy, Azure Files, Blob protection, lifecycle and transfer tools.
Bicep/ARM, VM operations, disks, availability, scale sets, containers and App Service.
VNets, peering, NSGs, ASGs, UDRs, Bastion, private access, DNS, load balancing and troubleshooting.
Metrics, logs, alerts, Insights, Network Watcher, Backup, Site Recovery and recovery testing.
Decision lens
Use your tenant
The exercises use small, reversible resources. Check pricing, quotas and regional availability before creating anything; delete temporary resources at the end.
Practice a least-privileged assignment and interpret where it takes effect.
Use guardrails without confusing what each one controls.
Make a private container recoverable and grant a short limited handoff.
Compare a shared file system with object storage and map its recovery tools.
Move from clicking resources to understanding a declarative deployment.
Separate VM configuration, capacity and availability design.
Build a small network and prove why a flow is allowed or denied.
Connect a PaaS resource through a private address and validate resolution.
Choose Layer 4 distribution and avoid exposing VM management ports.
Make a small workload observable with a believable recovery plan.
Decision maps
Follow each visual as a scenario. The arrows show a responsibility or traffic path, so you can identify what a question is actually asking you to configure or troubleshoot.
Scenario: secure a production project
A new finance workload needs access, standards, protection, and cost ownership. Each control answers a different question.
Scenario prompt: A finance reader needs visibility, a developer needs narrow write access, and public IPs are not allowed. Which controls solve each requirement?
Scenario: private app reaches storage
An internal app must reach a storage account without using the public endpoint. Diagnose the path in this order.
Scenario prompt: The service name resolves publicly after the private endpoint is created. Which component is missing, and why would an NSG rule not fix the name resolution?
Scenario: slow VM and recovery requirement
Monitoring tells you what is happening. Recovery mechanisms determine what you can restore or fail over.
Scenario prompt: CPU is high, the app is still available, and regional DR is required. Which services collect evidence, alert operations, restore data, and prepare the workload to fail over?
Decision tables
Read from the requirement column first. The best answer usually matches the stated boundary without adding unrelated capability.
What question are you actually answering?
| Option | Choose it when | Administrator cue |
|---|---|---|
| RBAC | Who can perform an Azure action? | Role assignment at the narrowest useful scope |
| Azure Policy | Which configurations are allowed or required? | Assign a definition or initiative and review compliance |
| Resource lock | How do I prevent accidental management change? | CanNotDelete or ReadOnly at the protected scope |
| Tags / budgets | Who owns this cost and when should we notice spend? | Resource metadata and cost notifications |
Separate access, durability and recovery.
| Option | Choose it when | Administrator cue |
|---|---|---|
| Blob Storage | Object data, media or unstructured content | Containers, tiers, lifecycle, versioning and soft delete |
| Azure Files | Managed SMB/NFS file-system workload | File shares, identity access, snapshots and soft delete |
| SAS / stored policy | Time-bounded delegated Storage access | Limit permissions; use policy-backed service SAS when central revocation matters |
| LRS / ZRS / GRS | A local, zonal or regional resilience requirement | Choose the failure boundary first |
Pick the operating model before the product name.
| Option | Choose it when | Administrator cue |
|---|---|---|
| Virtual machine | You need operating-system control | Size, disks, extensions, availability and lifecycle operations |
| VM Scale Set | A scalable fleet of similar VMs | Instance model, autoscale and load distribution |
| Availability set / zones | Protection from hardware/update or zone failure | Availability placement; not capacity scaling |
| ACI / Container Apps / App Service | A single container, managed container app or managed web app | Operational abstraction, scaling and networking requirements |
Name → route → filter → endpoint.
| Option | Choose it when | Administrator cue |
|---|---|---|
| Private DNS | What address should a service name resolve to? | Link the correct private zone to the VNet |
| User-defined route | Where should the packet go next? | Route table and next-hop type |
| NSG / ASG | Which flows are permitted or denied? | Rule priority, direction and effective rules |
| Private / service endpoint | How does a VNet reach PaaS? | Private IP versus public endpoint with VNet identity |
Which layer and reach determine the answer?
| Option | Choose it when | Administrator cue |
|---|---|---|
| Load Balancer | TCP/UDP Layer 4 distribution | Public or internal frontend, health probe, rule and backend pool |
| Application Gateway | HTTP/S Layer 7 routing and web-aware features | Listener, routing rule, backend and optional WAF |
| Front Door | Global HTTP/S entry and acceleration | Global routing, edge presence and web delivery needs |
| Traffic Manager | DNS-based endpoint selection | Priority, weighted, performance or geographic DNS routing |
Is this evidence, notification, restore or failover?
| Option | Choose it when | Administrator cue |
|---|---|---|
| Metrics | Numeric condition over time | Charts and near-real-time threshold alerts |
| Logs / Activity Log | Detailed events or management history | KQL analysis versus subscription-level change evidence |
| Azure Backup | Return data or workload to a recovery point | Vault, policy, restore point and restore test |
| Azure Site Recovery | Continue workload in another region after disaster | Replication, failover and failback planning |
Original question set
Each round draws 18 original scenarios from a broader, validated study bank. Do them closed-book first, then use every explanation to repair the underlying concept. This is preparation material—not an exam brain dump.
Question 1
Question 2
Question 3
Question 4
Question 5
Question 6
Question 7
Question 8
Question 9
Question 10
Question 11
Question 12
Question 13
Question 14
Question 15
Question 16
Question 17
Question 18
Validated active recall
Built from your imported cards, then reduced to stable concepts checked against Microsoft’s current learning paths. Say the answer before revealing it; use the linked path only when you need a deeper rebuild.
Final review
Use this as a final pass, not an extra study session. Verify appointment and identification requirements in your own booking confirmation.
Sources & attribution
Microsoft updates certification objectives periodically. Before final practice, verify the skills outline and take the official practice assessment through Microsoft Learn.