Microsoft Azure Administration AZ-104: Skills Measured
Microsoft Azure Administration AZ-104: Skills Measured
Microsoft Azure Administration AZ-104: Skills Measured
Azure Administration
AZ-104
Microsoft Azure is a cloud computing platform and infrastructure for building, deploying and managing applications and
services through a global network of Microsoft-managed datacentres. It provides both Platform-as-a-Service (PaaS) and
Infrastructure-as-a-Service (IaaS).
Course Overview
This course teaches IT Professionals how to manage their Azure subscriptions, create and scale virtual machines,
implement storage solutions, configure virtual networking, back up and share data, connect Azure and on-premises sites,
manage network traffic, implement Azure Active Directory, secure identities, and monitor your solution.
The exam guide below shows the changes that were implemented on November 24, 2020.
Skills Measured
NOTE: The bullets that appear below each of the skills measured are intended to illustrate how we are
assessing that skill. This list is not definitive or exhaustive.
NOTE: In most cases, exams do NOT cover preview features, and some features will only be added to an exam
when they are GA (General Availability).
1 . Manage Azure identities and governance (15-20%) • NOT: selecting an container solution architecture or
product; container registry settings
1.1 Manage Azure AD objects
3.5 Create and configure Web Apps
• create users and groups
• create and configure App Service
• manage user and group properties
• create and configure App Service Plans
• manage device settings
• NOT: Azure Functions; Logic Apps; Event Grid
• perform bulk user updates
• manage guest accounts 2. Configure and manage virtual networking (30-35%)
• configure Azure AD Join 4.1 Implement and manage virtual networking
• configure self-service password reset • create and configure VNET peering
• NOT: Azure AD Connect; PIM • configure private and public IP addresses, network
1.2 Manage role-based access control (RBAC) routes, network interface, subnets,and virtual network
• create a custom role 4.2 Configure name resolution
• provide access to Azure resources by assigning roles • configure Azure DNS
o subscriptions. o resource groups • configure custom DNS settings
o resources (VM, disk, etc.) • configure a private or public DNS zone
• interpret access assignments 4.3 Secure access to virtual networks
• manage multiple directories • create security rules
1.3 Manage subscriptions and governance • associate an NSG to a subnet or network interface
• configure Azure policies • evaluate effective security rules
• configure resource locks • deploy and configure Azure Firewall
• apply tags • deploy and configure Azure Bastion Service
• create and manage resource groups • NOT: Implement Application Security Groups; DDoS
o move resources o remove RGs 4.4 Configure load balancing
• manage subscriptions • configure Application Gateway
• configure Cost Management • configure an internal load balancer
• configure management groups • configure load balancing rules
2 . Implement and manage storage (10-15%) • configure a public load balancer
2.1 Manage storage accounts • troubleshoot load balancing
• configure network access to storage accounts • NOT: Traffic Manager and FrontDoor and PrivateLink
• create and configure storage accounts 4.5 Monitor and troubleshoot virtual networking
• generate shared access signature • monitor on-premises connectivity
• manage access keys • use Network Performance Monitor
• implement Azure storage replication • use Network Watcher
4.6 Integrate an on-premises network with an Azure virtual network
• configure Azure AD Authentication for a storage account
• troubleshoot external networking
2.2 Manage data in Azure Storage
• troubleshoot virtual network connectivity
• export from Azure job
• import into Azure job • create and configure Azure VPN Gateway
• install and use Azure Storage Explorer • create and configure VPNs
• copy data by using AZCopy • configure ExpressRoute
2.3 Configure Azure files and Azure blob storage • configure Azure Virtual WAN
• create an Azure file share 5.0 Monitor and back up Azure resources (10-15%)
• create and configure Azure File Sync service 5.1 Monitor resources by using Azure Monitor
• configure Azure blob storage • configure and interpret metrics
• configure storage tiers for Azure blobs o analyze metrics across subscriptions
3 . Deploy and manage Azure compute resources (25-30%) • configure Log Analytics
3.1 Configure VMs for high availability and scalability o implement a Log Analytics workspace
• configure high availability o configure diagnostic settings
• deploy and configure scale sets • query and analyze logs
3.2 Automate deployment and configuration of VMs o create a query
• modify Azure Resource Manager (ARM) template o save a query to the dashboard
• configure VHD template o interpret graphs
• deploy from template • set up alerts and actions
• save a deployment as an ARM template o create and test alerts. o create action groups
• automate configuration management by using custom script extensions o view alerts in Azure Monitor
3.3 Create and configure VMs o analyze alerts across subscriptions
• configure Azure Disk Encryption • configure Application Insights
• move VMs from one resource group to another • NOT: Network monitoring
• manage VM sizes 5.2 Implement backup and recovery
• add data discs • configure and review backup reports
• perform backup and restore operations by using Azure Backup Service
• configure networking
• redeploy VMs • create a Recovery Services Vault
3.4 Create and configure containers o use soft delete to recover Azure VMs
• create and configure Azure Kubernetes Service (AKS) • create and configure backup policy
• perform site-to-site recovery by using Azure Site Recovery
• create and configure Azure Container Instances (ACI)
• NOT: SQL or HANA