All certifications / Azure Administrator / Lessons
Azure Administrator AZ-104 lessons
Study Azure Administrator for free
A week-by-week plan with every lesson, quizzes, checkpoint tests, a practice exam and hands-on labs.
Open the Azure Administrator study planA week-by-week plan with every lesson, quizzes, checkpoint tests, a practice exam and hands-on labs.
Domain 1: Manage Azure identities and governance
- Microsoft Entra users and groups: create, bulk create, security vs Microsoft 365 groups, assigned vs dynamic membership
- User and group properties, licenses (including group-based licensing), external (B2B guest) users and self-service password reset
- Azure RBAC: built-in roles (Owner, Contributor, Reader, User Access Administrator), assigning roles at different scopes and interpreting access
- Entra roles vs Azure RBAC roles, and data-plane roles such as Storage Blob Data Reader
- Azure Policy: definitions, initiatives, assignments, scopes and exclusions, effects (Deny, Audit, Modify, DeployIfNotExists) and remediation tasks
- Resource locks: CanNotDelete vs ReadOnly, inheritance and who can remove them
- Tags: applying tags, why tags are not inherited, and enforcing or inheriting tags with policy
- Resource groups: create, move resources between groups and subscriptions
- Subscriptions and management groups: hierarchy, inheritance of policy and RBAC
- Cost management: cost analysis, budgets and budget alerts, Azure Advisor cost recommendations, reservations
Domain 2: Implement and manage storage
- Storage account types and redundancy: LRS, ZRS, GRS, RA-GRS, GZRS and RA-GZRS
- Storage firewalls and virtual network rules, trusted Microsoft services, private endpoints for storage
- Shared access signatures: account, service and user delegation SAS; stored access policies; access keys and key rotation
- Identity-based access for Azure Files (AD DS, Entra Domain Services, Entra Kerberos) with share-level RBAC and NTFS permissions
- Encryption: Microsoft-managed vs customer-managed keys in Key Vault, infrastructure encryption, encryption scopes
- Object replication, and data movement with AzCopy and Azure Storage Explorer
- Blob containers and access tiers: Hot, Cool, Cold and Archive; rehydration from Archive
- Lifecycle management policies that tier or delete blobs by age
- Data protection: blob and container soft delete, versioning, snapshots, change feed
- Azure Files: create and configure file shares, snapshots, soft delete, and SMB port 445 considerations
Domain 3: Deploy and manage Azure compute resources
- ARM templates and Bicep files: interpret and modify, deploy, export a deployment as a template, convert ARM JSON to Bicep
- Deployment modes (incremental vs complete) and deploying with `az deployment group create` or `New-AzResourceGroupDeployment`
- Create virtual machines: images, sizes, OS and data disks, disk types (Standard HDD to Ultra), encryption at host and Azure Disk Encryption
- Resize VMs, move VMs between resource groups, subscriptions and regions, manage disks
- Availability sets (fault and update domains) vs availability zones and their SLAs
- Virtual Machine Scale Sets: orchestration modes, autoscale rules, scale-in
- Azure Container Registry tiers and image management
- Azure Container Instances (container groups, restart policies) and Azure Container Apps (revisions, ingress, scale rules)
- App Service plans: tiers, scaling up vs scaling out, autoscale
- App Service: TLS certificates, custom DNS names, backups, networking (VNet integration, private endpoints) and deployment slots
Domain 4: Implement and manage virtual networking
- Virtual networks and subnets: address space planning, the 5 reserved IPs per subnet
- Virtual network peering: non-transitive, gateway transit and use remote gateways, global peering
- Public IP addresses: Standard SKU, static allocation, zones
- User-defined routes: route tables, next hop types (virtual appliance, virtual network gateway, internet, none) and forced tunneling
- Network security groups and application security groups: rule priority, default rules, subnet vs NIC association, effective security rules
- Azure Bastion: AzureBastionSubnet, SKUs, browser and native client access
- Service endpoints vs private endpoints, and private DNS zones for private link
- Azure DNS: public zones, delegation, record sets, alias records; private DNS zones with auto-registration
- Azure Load Balancer: public vs internal, Standard SKU, backend pools, health probes, load-balancing and inbound NAT rules
- Troubleshooting connectivity with Network Watcher: IP flow verify, next hop, connection troubleshoot, effective routes
Domain 5: Monitor and maintain Azure resources
- Azure Monitor metrics vs logs, and diagnostic settings that send resource logs to a Log Analytics workspace
- Querying logs with basic KQL (where, summarize, project, render)
- Alert rules (metric, log search, activity log), action groups and alert processing rules
- Azure Monitor insights: VM insights, storage and network insights, Azure Monitor Agent and data collection rules
- Network Watcher and Connection Monitor
- Recovery Services vault vs Backup vault and what each protects
- Backup policies (standard and enhanced), on-demand backup, soft delete and cross-region restore
- Restoring VMs, disks and individual files
- Azure Site Recovery: replication to a secondary region, test failover, failover, commit and failback
- Backup reports and alerts