AZ-104 Exam Domains
The current English AZ-104 study guide lists skills measured as of April 17, 2026.
- Its five weighted domains are Manage identities and governance (20-25%), Implement and manage storage (15-20%), Deploy and manage compute resources (20-25%), Implement and manage virtual networking (15-20%), and Monitor and maintain Azure resources (10-15%).
- The ranges guide coverage; they do not reveal an exact question count or guarantee each exam’s composition.
On this page9 sections
- Start with the current study guide
- 1. Manage identities and governance: 20-25%
- 2. Implement and manage storage: 15-20%
- 3. Deploy and manage compute resources: 20-25%
- 4. Implement and manage virtual networking: 15-20%
- 5. Monitor and maintain resources: 10-15%
- How the domains connect
- Turn weights into a study plan
- What the weights cannot tell you
Start with the current study guide
Microsoft’s AZ-104 study guide is the authoritative public map of the current exam skills. The current English version is marked skills measured as of April 17, 2026. Use that date when comparing books, courses, or notes. An older resource may still teach durable Azure concepts, but its task list or terminology may not match the active outline. The guide organizes the objectives into five domains with approximate weight ranges.
| Domain | Approximate weight |
|---|---|
| Manage identities and governance | 20-25% |
| Implement and manage storage | 15-20% |
| Deploy and manage compute resources | 20-25% |
| Implement and manage virtual networking | 15-20% |
| Monitor and maintain Azure resources | 10-15% |
A range describes a blueprint allocation, not a fixed count. The exact number of questions varies, and Microsoft does not publish a guaranteed item count for AZ-104. Do not calculate an exact number of questions by multiplying a range by a presumed exam length. Use weights to prioritize time while covering every task.
1. Manage identities and governance: 20-25%
This domain brings together identity administration and control over Azure resources. The tasks include managing Microsoft Entra users and groups, handling external identities, assigning Azure roles, managing subscriptions and governance, and applying policies or resource locks. The shared idea is that administrators must establish who can act, what actions are permitted, and where those permissions apply.
For role-based access control, reason about three components: the security principal, the role definition, and the scope. A user, group, service principal, or managed identity is the principal. The role defines permitted actions. The scope determines which resources inherit the grant. A subscription-wide assignment is broader than a resource-group assignment; an assignment at a resource can be narrower still. Least privilege means granting only the actions and scope needed for the task.
Do not confuse Azure RBAC with Azure Policy. RBAC controls who can perform management actions. Policy evaluates or constrains resource configurations. A lock helps protect a resource from deletion or modification, depending on its type and scope. Tags add metadata for organizing or reporting resources; they do not grant access. A scenario may mention all these controls, but select the one that addresses the requested outcome.
Worked example: a support engineer needs permission to restart virtual machines in one resource group. A subscription-level Owner role grants far more than the task requires. Identify the principal, find an appropriate role with the required action, and assign it at the resource-group scope if that scope matches the work. If the task also asks to prevent accidental deletion, evaluate a lock separately. Permission and protection solve different problems.
2. Implement and manage storage: 15-20%
Storage objectives cover storage accounts and data services, access, redundancy, protection, and management. Candidates should understand how requirements drive choices: which type of data is stored, how clients connect, what availability or durability is required, and what recovery options are needed. Storage decisions affect performance, access, cost, and the consequences of a regional or local failure.
Learn the difference between management-plane permissions and data-plane permissions. An administrator may be able to create a storage account but not read blobs, or may be able to access data without changing account configuration. Role names and scopes matter. If an application needs blob data, consider its identity and the appropriate data role instead of granting broad resource management rights.
Redundancy choices should be tied to the failure scenario. Locally redundant storage keeps copies within a primary region, while zone or geo options add resilience across specified failure boundaries. Higher redundancy may add cost and does not remove the need to understand recovery objectives or access. Backup is a separate protection mechanism from replication: replication helps maintain availability across certain failures, while backup supports recovery from deletion, corruption, or retention needs according to the service and policy.
Worked example: a business needs data to remain available after a datacenter-zone failure but has no requirement to survive a regional outage. The administrator should identify the required availability boundary and choose a suitable zone-resilient option where supported. Selecting geo-redundancy automatically because it sounds safest may add cost and complexity beyond the requirement. If the scenario requires recovery from accidental deletion, add an appropriate data-protection control rather than assuming replication is a backup.
3. Deploy and manage compute resources: 20-25%
This domain includes deploying and administering compute such as virtual machines and related services. Tasks can involve selecting images and sizes, configuring disks and availability, managing extensions or configuration, scaling, and automating deployment. The goal is not to memorize every SKU. Understand how workload needs such as operating system, memory, performance, availability, and maintenance shape the choice.
Virtual-machine administration connects compute to storage, networking, and identity. A VM needs a network interface and address configuration, disks for operating system and data, and an access approach. It may need availability options, backup, monitoring, and controlled administrative access. A choice that works in isolation can fail the scenario if it creates an unreachable machine or grants broad permissions.
Use deployment tools to reduce inconsistent configuration. Templates or infrastructure as code can define resources repeatably, while the portal can help with inspection and one-off administration. For exam reasoning, know what a deployment method controls and how to inspect failures. A deployment succeeding does not itself confirm that permissions, network reachability, monitoring, or backup are correct.
Worked example: a test workload needs a VM that can be recreated from a known image and should not be exposed directly to the public internet. The administrator should choose a compatible image and size, place the VM on a private network, use controlled access, and validate connectivity through the intended management path. If availability is required, select an appropriate availability approach. A public IP may simplify access, but it contradicts the stated exposure constraint.
4. Implement and manage virtual networking: 15-20%
Networking work includes configuring virtual networks and subnets, name resolution, routing, network security, and connectivity between resources or networks. The key is to trace how traffic moves. Identify source and destination, address range, route, filtering rules, name resolution, and service endpoint or private connectivity behavior. A connection failure can be caused by any one of these layers.
Network security groups filter traffic according to rules and are associated with subnets or network interfaces. They do not grant an identity permission to create or manage a resource. Routes influence traffic paths; DNS translates names; private endpoints provide private connectivity to supported services under the relevant network and name-resolution configuration. Learn the purpose and limits of each component rather than treating all networking features as interchangeable security controls.
Worked example: an application resolves a storage account’s public name but the organization wants service access through a private endpoint. The administrator must consider the endpoint, network reachability, and private DNS resolution so the name used by the application maps to the private address. Creating the endpoint alone may not complete the design. A network security group rule may further restrict traffic, but it cannot repair incorrect name resolution.
5. Monitor and maintain resources: 10-15%
This domain includes monitoring resources, responding to alerts, backup and recovery, and maintenance. Azure Monitor supports metrics, logs, and alerts. Service Health reports Azure service issues and planned maintenance relevant to subscriptions. Advisor provides recommendations. Backup and recovery services protect workloads according to their configuration. Understand what question each tool answers and what action it can take.
A monitoring design starts with a signal and an operational response. Decide what condition matters, how it is measured, who receives an alert, and what action follows. A notification does not prevent a failure. An alert that is too sensitive can create noise, while a missing signal can hide a meaningful problem. Backup is useful only if scope, retention, and restore procedures meet the requirement. A backup job reporting success is not the same as proving that a restore works.
Worked example: users report that a service in one region is unavailable. The administrator should determine whether the issue is a platform incident, a workload fault, or a local configuration problem. Service Health helps identify relevant Azure incidents and maintenance; Azure Monitor helps inspect resource and application signals. Both may be needed. Choosing the right diagnostic tool depends on whether the question is about Azure service status or telemetry from the candidate’s own deployment.
How the domains connect
Real administration tasks often cross domains. Deploying a VM requires compute, network configuration, identity, and monitoring. Protecting a storage account may involve access, networking, backup, and governance. A case study can combine these needs. Learn the domain labels, but also practice integrating them. When a scenario asks for a secure and recoverable application, list the identities, resource scope, network path, storage protection, monitoring, and recovery requirement before choosing a service.
A useful reasoning sequence is: identify the business outcome; note constraints such as cost, scope, availability, or least privilege; map the task to the appropriate Azure control; then verify its dependencies. If the proposal grants broad access, exposes a private service, or confuses monitoring with prevention, test it against the requirement again. This method makes domain knowledge transferable to new wording.
Turn weights into a study plan
Use the ranges to allocate study effort, not to skip the smallest domain. Identity and compute have the largest upper ranges, so gaps there can affect substantial portions of the assessment. Storage and networking also deserve dedicated practice, and monitoring still represents a meaningful share. Start with a diagnostic across all five, then spend additional time where your errors and practical weaknesses are concentrated.
For each study-guide task, mark whether you can explain it, perform it, and solve a variation. A task is not mastered just because you watched a video or recognize the portal blade. Write a short scenario with different constraints and decide what changes. For example, change the access scope, recovery objective, or network exposure and see whether your answer also changes. This checks understanding rather than memorization.
Keep source dates visible in your notes. Microsoft updates its exam guides, and localized versions may lag behind the current English guide. If your preparation material uses an older task list, compare it with the April 17, 2026 version and study additions or changed topics. The exam outline can change without changing the credential’s name, so currentness matters.
What the weights cannot tell you
The domain weights do not disclose exact question counts, the number of case studies, whether labs will appear, the raw score cutoff by domain, or the format of each item. They are a coverage guide. Microsoft’s general question range is variable, and role-based timing can depend on lab inclusion. Do not turn approximate ranges into an invented mock blueprint. Build broad capability using the official tasks and prepare to apply them in different formats.
Common questions
What are the AZ-104 domains?
Identity and governance; storage; compute; virtual networking; monitoring and maintenance.
When was the AZ-104 outline last updated?
Microsoft’s current English guide is marked skills measured as of April 17, 2026.
Which AZ-104 domain is largest?
Identity and governance and compute each carry a 20-25% range; use the official guide for the full current weights.
Do domain weights reveal question counts?
No. They are approximate blueprint weights, and Microsoft does not publish a fixed AZ-104 item count.