⭐ Trusted by 700+ Buyers  ·  4.7★ Star Seller on Etsy  ·  $9.99/exam  ·  Grab it now →
Home › Microsoft › AZ-104 study guide

Microsoft Azure Administrator (AZ-104) Practice Test & Study Guide

Everything you need to plan your AZ-104 prep: the exam format, what each domain covers, a week-by-week study plan, original practice questions, and what thousands of study-group comments reveal about where candidates slip up.

Last updated · By the NotJustExam team

About the Microsoft Azure Administrator Associate (AZ-104) exam

The AZ-104 exam earns the Microsoft Certified: Azure Administrator Associate credential. It validates that you can implement, manage, and monitor an organization's Microsoft Azure environment day to day — identities and governance, storage, compute, virtual networking, and ongoing operations. In practice it is the certification for the person who keeps Azure running, not the architect who designs it from scratch.

It is aimed at working IT professionals who already administer cloud workloads: people comfortable in the Azure portal, Azure CLI, PowerShell, Azure Resource Manager templates, and the broader Azure operations toolset. Microsoft suggests at least six months of hands-on Azure administration experience before sitting the exam.

AZ-104 matters because it is one of the most widely recognized role-based Azure credentials and a common prerequisite-in-spirit for higher-level tracks such as the Azure Solutions Architect path. For many administrators it is the certification a hiring manager actually looks for.

Microsoft Azure Administrator Associate (AZ-104) exam format at a glance

Figures below are accurate to the best of our knowledge as of 2026; always verify on the official Microsoft Learn page before booking.

AttributeDetail
Exam codeAZ-104
Number of questionsTypically 40–60 (varies per delivery)
Question typesMultiple choice, multiple response, drag-and-drop, hot area, case studies; labs may appear
DurationRoughly 100–120 minutes of seat time (verify on official page)
Passing score700 out of 1000 (scaled, not a raw percentage)
CostAbout USD $165 (regional pricing and taxes vary)
LanguagesEnglish plus several others including Japanese, Chinese, Korean, German, French, Spanish
DeliveryOnline proctored or at a Pearson VUE test center
ValidityOne year; renew free online before expiry

Microsoft Azure Administrator Associate (AZ-104) domains & what they cover

The exam is organized into five skill areas. Approximate weightings as of 2026 (confirm on the official page, as Microsoft adjusts them periodically):

  • Manage Azure identities and governance (20–25%) — Microsoft Entra ID users and groups, role-based access control, subscriptions, management groups, resource locks, tags, and policy. This is the access-and-guardrails layer of Azure.
  • Implement and manage storage (15–20%) — storage accounts, blob and file shares, access tiers, shared access signatures, and securing and replicating data. Expect questions on choosing the right redundancy and access model.
  • Deploy and manage Azure compute resources (20–25%) — virtual machines, availability sets and scale sets, ARM/Bicep templates, containers, and Azure App Service. The heaviest hands-on area for most candidates.
  • Implement and manage virtual networking (15–20%) — virtual networks, subnets, network security groups, peering, DNS, load balancing, and connectivity. Networking trips up administrators who only used defaults.
  • Monitor and maintain Azure resources (10–15%) — Azure Monitor, alerts, Log Analytics, Network Watcher, and backup and recovery. The smallest domain, but easy points if you have actually configured monitoring.

How hard is Microsoft Azure Administrator Associate (AZ-104)?

AZ-104 is moderately hard. It is not the toughest Azure exam, but it is demanding for anyone who has only clicked through the portal a few times. The difficulty comes from breadth: you are expected to know networking, storage, identity, compute, and monitoring well enough to answer scenario questions that combine several of them.

Common sticking points are network security group rule evaluation, the difference between storage redundancy options, RBAC scope inheritance, and reading case-study scenarios under time pressure. The drag-and-drop ordering and hot-area questions also punish guesswork. A candidate with genuine hands-on experience typically needs four to eight weeks of focused study; someone newer to Azure should plan for two to three months and build a free-tier sandbox.

How to prepare for Microsoft Azure Administrator Associate (AZ-104): a study plan

A phased approach works well:

  1. Weeks 1–2 — Identity, governance, storage. Work through Microsoft Learn modules for Entra ID, RBAC, subscriptions, policy, and storage accounts. Create users, assign roles, and build a storage account with each redundancy option in your own subscription.
  2. Weeks 3–4 — Compute. Deploy VMs from the portal, CLI, and an ARM/Bicep template. Configure scale sets, availability, and App Service. This is the largest and most practical domain — do it by hand, not just by reading.
  3. Weeks 5–6 — Networking and monitoring. Build VNets, subnets, NSGs, peering, and a load balancer; then wire up Azure Monitor, alerts, and a backup. Networking rewards repetition.
  4. Final week — Practice and review. Take timed practice questions, then study every miss until you understand why the right answer is right and the others are wrong.

Use practice questions diagnostically, not as a memorization shortcut. The goal is to expose gaps so you can return to the portal and actually perform the task. Treat any question you got right by luck as a question you got wrong.

Microsoft Azure Administrator Associate (AZ-104) FAQ

How much does the AZ-104 exam cost?

It is approximately USD $165 in the United States as of 2026, with regional pricing, currency, and taxes varying. Confirm the current price on the official Microsoft page when you register.

What score do I need to pass?

You need 700 on a scale of 100 to 1000. This is a scaled score, so it does not translate directly to "70% of questions correct."

Are there prerequisites?

There are no mandatory prerequisites, but Microsoft recommends at least six months of hands-on Azure administration experience and familiarity with the portal, CLI, PowerShell, and ARM templates.

How long is the certification valid, and how do I renew?

The Azure Administrator Associate credential is valid for one year. You renew it for free through an online assessment on Microsoft Learn, available in the six months before it expires — no re-exam fee required.

What is the retake policy if I fail?

You can retake after a short waiting period (commonly 24 hours after a first attempt, with longer waits for subsequent attempts), and each attempt requires paying the exam fee again. Check the current Microsoft exam retake policy before rebooking.

Is AZ-104 worth it?

For administrators working with or moving to Azure, yes — it is among the most recognized role-based Azure credentials and a strong signal for cloud-operations roles, as well as a sensible step before architect-level certifications.

Free AZ-104 practice questions

5 original questions written for NotJustExam from the public AZ-104 exam objectives and independently answer-checked. Try answering before you open the explanation.

Question 1

A company needs its storage account data to remain available for read access even during a complete outage of the primary Azure region. Which redundancy option should be configured?

  1. Locally redundant storage (LRS)
  2. Read-access geo-redundant storage (RA-GRS)
  3. Zone-redundant storage (ZRS)
  4. Geo-redundant storage (GRS)
Show answer & explanation

Answer: B. RA-GRS replicates data to a secondary region and additionally allows read access to that secondary region's data even while the primary region is down. Plain GRS also replicates to a secondary region but does not allow read access to it unless a failover is triggered, which is the detail that trips up candidates.

Source: official documentation

Question 2

Which Azure feature automatically increases or decreases the number of identical virtual machine instances in response to demand or a defined schedule?

  1. Availability set
  2. Azure Batch
  3. Proximity placement group
  4. Virtual machine scale set with autoscale
Show answer & explanation

Answer: D. Virtual machine scale sets support autoscale rules that add or remove identical VM instances based on metrics or a schedule, providing elasticity. An availability set only spreads a fixed number of VMs across fault domains for resiliency and does not change instance count automatically.

Source: official documentation

Question 3

If no custom rules are added, what traffic do a Network Security Group's default rules allow?

  1. All inbound traffic from the internet
  2. All outbound traffic to the internet and traffic within the same virtual network, while denying inbound traffic from the internet
  3. All inbound and outbound traffic unconditionally
  4. No traffic at all until explicitly configured
Show answer & explanation

Answer: B. NSGs ship with default rules that allow outbound internet access and intra-VNet traffic while denying inbound traffic from the internet unless a custom allow rule is added. This default-deny-inbound posture is often mistaken for blocking all traffic, including outbound.

Source: official documentation

Question 4

An administrator wants to write a custom query against collected log data from multiple Azure resources to identify unusual sign-in patterns. Which component and query language should be used?

  1. Azure Monitor Metrics with PromQL
  2. Network Watcher with NSG flow logs only
  3. Log Analytics workspace with Kusto Query Language (KQL)
  4. Azure Advisor recommendations
Show answer & explanation

Answer: C. Log Analytics workspaces store log data that is queried using KQL, which supports the kind of complex analysis needed to spot anomalous sign-in patterns across resources. Azure Monitor Metrics stores lightweight numerical time-series data and is not the right store for this kind of log-based investigation.

Source: official documentation

Question 5

An administrator wants to grant a third-party application temporary, limited access to a specific container in a storage account without sharing the storage account key. What should be used?

  1. An Azure AD conditional access policy
  2. A resource lock
  3. A shared access signature (SAS) token
  4. A management certificate
Show answer & explanation

Answer: C. A SAS token grants delegated, time-limited access with specific permissions to storage resources without exposing the account key. Conditional access policies instead control sign-in conditions for Azure AD identities and are not used to delegate access to storage containers.

Source: official documentation

What 12,579 study-group comments reveal about AZ-104

We summarised the public study-group discussion behind every question in our AZ-104 bank and compared it with an independent AI review. Where they disagree, a posted answer key alone is not enough to trust — which is why every question in the full bank shows the community vote, a discussion summary and a reasoned explanation side by side.

602practice questions reviewed
12,579study-group comments summarised from Q2 2020 – Q2 2025
6%of questions where the answer commonly posted online is disputed
20%of single-answer questions where the community vote is split

The AZ-104 traps that come up most

  • VNet peering does not extend transitively — If VNet A is peered with VNet B, and VNet B is peered with VNet C, resources in VNet A cannot reach VNet C through that chain. Direct peering or a hub-and-spoke design with routing is required for that connectivity.
  • Some VM actions require the VM to be stopped first — Certain configuration changes, such as attaching a network interface or resizing to some VM sizes, are only available while the virtual machine is stopped and deallocated, not merely stopped or running.
  • A vault holding backup data blocks its own deletion — A Recovery Services vault cannot be deleted while it still contains backup items, even if those items are in a soft-deleted state; the backup data must be removed first before the vault or its resource group can be deleted.
  • Legacy classic administrator roles have been retired — Older subscription-level roles such as Service Administrator and Co-Administrator are being phased out in favor of Azure RBAC. Access should be managed by assigning built-in or custom roles through Access control (IAM).
  • Metrics alone cannot show packet-level traffic detail — Azure Monitor's metrics and alerts report aggregated performance data, not the contents of network traffic. Diagnosing connectivity at the packet level requires Network Watcher tools such as packet capture or NSG flow logs.

Inside the full AZ-104 practice bank

  • 598 practice questions in an interactive web app, plus a printable PDF
  • The community-voted answer and a summary of the study-group discussion for each question
  • A step-by-step AI explanation of why the right answer is right — and why the others are not
  • One-time $9.99, lifetime access, no subscription

More certification study guides

Independent study material. NotJustExam is not affiliated with, endorsed by, or sponsored by any certification body; all certification names, trademarks and exam codes belong to their owners and are used for descriptive purposes only. The sample questions on this page are original items written for NotJustExam from the publicly available exam objectives. Exam facts change — always confirm details on the official exam page before you register.