Microsoft AZ-700: Current Exam Scope

AZ-700 is the current Microsoft exam for the Azure Network Engineer Associate role. The live English skills measured are dated July 27, 2026, so candidates should use the current guide rather than older blueprints that may omit newer networking, monitoring or security details. The current AZ-700 assessment allows 100 minutes and requires a score of 700 or greater to pass.

Microsoft describes the target candidate as a network engineer who plans, implements and manages core Azure network infrastructure, hybrid connectivity, application delivery services, private access to Azure services and network security. The role also includes performance, resiliency, scale, monitoring and connectivity troubleshooting, which makes this much more hands-on than AZ-900.

Core networking infrastructure is 25–30%

The largest foundational domain begins with IP addressing and segmentation. Candidates should be able to plan address spaces, create VNets, design subnets for gateways, private endpoints, service endpoints, firewalls, Application Gateway, VNet-integrated services and Azure Bastion, and choose shared versus dedicated subnets where appropriate.

The current outline also includes public IP prefixes, custom/bring-your-own IP prefixes and associating public addresses to resources. Address design is not an isolated arithmetic exercise; it affects routing, connectivity, security and future scale.

DNS and name resolution are explicit design skills

The blueprint includes VNet DNS settings, public DNS zones, private DNS zones, linking private zones to VNets and Azure DNS Private Resolver. Candidates should understand which names must resolve from Azure, from on-premises and across private-endpoint architectures.

A DNS failure can look like an application or private-link failure even when routing and security rules are correct, so name resolution belongs in every troubleshooting model.

VNet routing now includes several Azure-native services

Current objectives cover service chaining and gateway transit, VNet peering, Azure Virtual Network Manager, user-defined routes, route tables, forced tunneling, Azure Route Server and Azure NAT Gateway. Candidates are expected to diagnose routing issues, not merely configure routes.

A VNet-peering foundation is useful because peering, gateway transit and route propagation often determine whether large Azure networks behave as intended.

Monitoring is part of the core domain

The current guide explicitly includes Network Watcher, Azure Monitor for Networks, DDoS protection and Defender for Cloud network-security recommendations, including Secure Score, attack-path analysis and Cloud Security Explorer. Monitoring therefore begins in the blueprint’s first domain rather than being treated as a final optional skill.

A Network Watcher mindset helps candidates connect diagnostics with routing, NSG flow, reachability and health rather than relying on configuration screenshots alone.

Connectivity services account for 20–25%

This domain covers site-to-site VPN, point-to-site VPN, ExpressRoute and Azure Virtual WAN. For site-to-site VPN, candidates should choose gateway SKUs, policy- versus route-based models, local network gateways, IPsec/IKE policy, high availability and troubleshooting. Azure Extended Network also appears in the current guide.

Point-to-site topics include tunnel type, authentication method, RADIUS, Microsoft Entra ID, VPN client configuration, Always On VPN requirements and Azure Network Adapter requirements.

ExpressRoute is a deep professional topic

AZ-700 covers ExpressRoute connectivity models, SKUs/tiers, cross-region connectivity, redundancy/disaster recovery, Global Reach, FastPath, ExpressRoute Direct, private/Microsoft peering, gateways, route advertisement, encryption over ExpressRoute, Bidirectional Forwarding Detection and troubleshooting.

The role is expected to choose and operate private hybrid connectivity, not just know that ExpressRoute exists.

Application delivery is 15–20%

Candidates must design and implement Azure Load Balancer and Traffic Manager, including public/internal and regional/cross-region load-balancer choices, Gateway Load Balancer, NAT/outbound rules and traffic distribution. The domain also covers Application Gateway and Azure Front Door.

A Load Balancer comparison is valuable because Layer 4 balancing, DNS-based global routing, Layer 7 gateway behavior and global edge delivery solve different problems.

Application Gateway and Front Door add Layer 7 behavior

Application Gateway objectives include backend pools, health probes, listeners, routing rules, HTTP settings, TLS and rewrite rules. Front Door includes origins, endpoints, TLS termination/end-to-end TLS, caching, acceleration, rules, redirects/rewrites and Private Link origin protection.

The exam expects candidates to map application-delivery requirements to the right service before configuring it.

Private access is 10–15%

This domain covers Private Link services, private endpoints, DNS integration, on-premises access to Private Link and service endpoints with service-endpoint policies. The central distinction is whether a service is reached through a private IP/private-link model or remains on a service public endpoint with subnet identity extended through service endpoints.

Private connectivity designs frequently fail because DNS or routing is not planned together with the endpoint.

Network security is 15–20%

The final domain covers NSGs/ASGs, inbound/outbound rules, virtual network flow logs, IP flow verification, Bastion administration, Virtual Network Manager security, Azure Firewall/Firewall Manager, secure Virtual WAN hubs and Web Application Firewall on Front Door or Application Gateway.

The July 27, 2026 update retains the same five high-level skill areas but makes several current implementation details more explicit. Core networking now emphasizes current subnet requirements, IP prefixes, Azure Virtual Network Manager, Route Server, NAT Gateway and modern monitoring integrations. Final preparation should therefore use the live guide rather than an older AZ-700 outline that stops at basic VNet peering and VPN.

Address-space planning deserves more attention than it often gets because Azure networking services consume or depend on specific subnets. GatewaySubnet, AzureFirewallSubnet, ApplicationGatewaySubnet and delegated/service-integrated subnets can impose sizing or exclusivity rules. Poor early address design can force disruptive rework when the environment later adds private endpoints, firewalls or hybrid gateways.

Public IP prefixes and custom IP prefixes are now directly in scope. Public IP prefixes let organizations reserve contiguous Azure public addresses for predictable assignment, while Custom IP address prefixes support bringing an organization’s owned address ranges into Azure under supported conditions. Both are planning topics as much as configuration topics.

Subnet delegation is another design concept that links platform services with the network. Delegation grants selected Azure services explicit permissions to create service-specific resources in a subnet. Candidates should understand why some managed services require a delegated or dedicated subnet rather than treating every subnet as interchangeable.

Azure Virtual Network Manager belongs in core networking because large estates need centralized connectivity and security administration. Network groups, connectivity configurations and security-admin rules can help manage many VNets consistently. The engineer still needs to understand ordinary peering, routing and NSG behavior underneath the centralized model.

Azure Route Server adds dynamic-routing integration between Azure and network virtual appliances. The current exam expects candidates to know where BGP-based exchange can reduce manual UDR management and how route propagation interacts with gateways and NVAs. It is not a replacement for every route table.

Azure NAT Gateway solves predictable, scalable outbound connectivity for supported subnet workloads. It should be distinguished from inbound NAT rules on Load Balancer, DNAT on Azure Firewall and ordinary public-IP attachment. The common clue is outbound SNAT for many private resources without individual public IP addresses.

Network monitoring has become more security-aware in the current guide. In addition to Network Watcher and Azure Monitor for Networks, candidates should evaluate Defender for Cloud Secure Score recommendations, attack-path analysis and Cloud Security Explorer for network-resource context. These tools help connect configuration state with security exposure.

Site-to-site VPN design should include high availability. Active-active gateway configurations, redundant on-premises devices and multiple tunnels can reduce dependence on one path. Gateway SKU selection affects throughput, features, zone redundancy and scale, so “create a VPN gateway” is rarely a complete design answer.

Point-to-site VPN emphasizes user/client access rather than site connectivity. Authentication choices include certificates, RADIUS and Microsoft Entra ID depending on tunnel and requirements. Candidates should also understand client-profile distribution and why Always On VPN or Azure Network Adapter scenarios have additional dependencies.

ExpressRoute design should begin with business requirements for private connectivity, bandwidth, resilience and geography. Global Reach connects certain on-premises locations through Microsoft’s network, FastPath can optimize the data path, ExpressRoute Direct provides high-capacity direct connectivity, and BFD can improve failure detection. Each feature solves a different requirement.

ExpressRoute peering is another high-value distinction. Azure private peering is used for private Azure virtual-network connectivity, while Microsoft peering provides access to supported Microsoft public services through ExpressRoute. Route advertisement and filtering are central to making either model work safely.

Azure Virtual WAN aggregates branch, VPN, ExpressRoute and VNet connectivity around managed virtual hubs. The blueprint expects candidates to choose SKUs, gateway scale units, routing and third-party NVA integration. The design question is often whether centralized managed transit provides simpler scale than manually meshing gateways and VNets.

Application-delivery questions frequently turn on layer and scope. Azure Load Balancer is Layer 4 and can be internal or public; Traffic Manager is DNS-based and global; Application Gateway is regional Layer 7 for HTTP/S; Front Door is global edge/application delivery. Gateway Load Balancer inserts supported NVAs transparently into traffic flows.

Application Gateway requires candidates to understand backend pools, health probes, listeners, routing rules, HTTP settings, TLS and rewrite behavior. A backend can be reachable at the network layer yet unhealthy from the gateway’s perspective if the probe or application response does not match expectations.

Front Door adds global origins, endpoints, caching, traffic acceleration, rule sets, redirects and Private Link origin protection. It is especially useful for internet-facing global applications that need edge routing, acceleration or WAF integration. It should not be confused with ordinary regional Load Balancer.

Private Link and service endpoints are intentionally separate objectives because they create different security models. A private endpoint gives a supported service a private IP presence in the VNet, while a service endpoint keeps the service on its public endpoint but extends the subnet identity/trust relationship to that service.

Private-endpoint DNS is one of the most common practical failure points. Creating the endpoint alone is not enough if clients continue resolving the public service name to a public address. Private DNS zones, links and hybrid resolver paths must be designed together with the network route.

NSGs remain a foundational distributed control. Rule priority, direction, stateful behavior, service/address matching and subnet-versus-NIC association all matter. ASGs simplify grouping application tiers without hardcoding every IP address into rules.

Azure Firewall and Firewall Manager provide centralized network-security capabilities that complement NSGs. Firewall policy, network/application rules, DNAT and secure-hub architectures can govern traffic across larger environments. WAF remains separate because it protects HTTP application traffic at Layer 7 on Application Gateway or Front Door.

Overall, the current exam is built around design plus implementation plus diagnosis. A candidate who knows what each service is called but cannot explain effective routes, DNS dependencies, health probes, VPN negotiation, private-endpoint resolution or rule precedence will struggle with professional networking scenarios.

An NSG foundation and WAF context help distinguish network-layer filtering from application-layer web protection. Within the broader Microsoft certification path, AZ-700 is a practical architecture-and-operations exam where design choices and troubleshooting evidence carry more weight than product definitions alone.