Azure Networking Across AZ-104, AZ-700 and AZ-305

Azure networking appears in AZ-104, AZ-700, and AZ-305, but each exam looks at the network from a different job role. AZ-104 asks the administrator to implement and manage virtual networking. AZ-700 asks the network engineer to design and implement Azure networking as a specialty. AZ-305 asks the solutions architect to choose networking patterns as part of a broader solution architecture. The technologies overlap; the decision depth and responsibility change.

This makes networking a useful connective topic. You can study the same VNet, VPN, load balancer, Private Link, or routing scenario three times and ask three different questions: can I operate it, can I engineer it deeply, and is it the right architecture?

AZ-104 treats networking as one administrator domain

The current AZ-104 exam allocates 15–20% to virtual networking. Administrators configure VNets/subnets, peering, public IPs, user-defined routes, NSGs, DNS, load balancing, and connectivity, then monitor/troubleshoot the resources as part of a wider Azure environment.

The Azure Administrator must be competent in networking, but the exam balances it with identity/governance, storage, compute, and monitoring.

AZ-700 makes networking the entire role

The Azure Network Engineer exam is devoted to networking design and implementation across core infrastructure, connectivity services, application delivery, private access, and network security. Its current July 27 blueprint expects much deeper knowledge of routing, VPN/ExpressRoute/Virtual WAN, load balancing, Front Door/Application Gateway, Private Link, Firewall, and related operations.

An AZ-700 network engineer owns the network as a service rather than one part of general administration.

AZ-305 uses networking as an architecture dependency

AZ-305’s infrastructure-design domain asks the architect to choose topologies, connectivity, load balancing, name resolution, security boundaries, and network integration as part of an entire application or enterprise design.

The architect may not configure every route personally, but should know enough to understand failure domains, operational complexity, latency, security, cost, and organizational ownership.

VNet and subnet skills progress from creation to strategy

AZ-104 creates and configures VNets/subnets and related policies. AZ-700 goes deeper into routing architecture, address planning, Virtual Network Manager, Route Server, NAT Gateway, SD-WAN/Virtual WAN, and network security. AZ-305 asks how many networks/regions/hubs are appropriate and how the topology supports the solution.

The same address plan becomes more strategic as the role moves upward.

Hybrid connectivity changes by role

An administrator needs to understand VPN gateways, connections, and basic ExpressRoute or hybrid dependencies. A network engineer designs resilient VPN/ExpressRoute/Virtual WAN paths, routing, BGP, failover, and monitoring. An architect decides which connectivity model best meets security, bandwidth, latency, resiliency, and cost requirements.

A networking-solutions perspective helps connect implementation with architecture.

Application delivery is specialty depth in AZ-700

Load Balancer, Traffic Manager, Application Gateway, Front Door, WAF, and global/regional traffic patterns receive much more attention in AZ-700. AZ-104 needs enough knowledge to deploy or manage common services, while AZ-305 needs enough to select an application-delivery architecture.

The network engineer is the role most likely to be responsible for the detailed health-probe, routing, and security behavior.

Private access illustrates the same progression

AZ-104 may configure service endpoints/private endpoints and storage/network restrictions. AZ-700 designs private access at scale, including Private Link, DNS integration, service endpoints, routing, and security architecture. AZ-305 decides whether public, private, hub-and-spoke, or other access patterns satisfy enterprise requirements.

Implementation teaches the hidden dependencies that make architecture realistic.

Network security broadens beyond NSGs

AZ-104 covers NSGs and basic network protection within the administrator role. AZ-700 goes much deeper into Azure Firewall, Firewall Manager, WAF, DDoS, Bastion, segmentation, routing security, and identity-aware access patterns. AZ-305 integrates network security with the whole solution’s Zero Trust and governance design.

The technologies are shared, but the exam perspective changes from configure → engineer → justify.

Troubleshooting depth is greatest in AZ-700

AZ-104 administrators troubleshoot common VNet, DNS, routing, and connectivity problems. AZ-700 expects a more disciplined network-engineering approach using Network Watcher, flow/connection evidence, route analysis, service metrics, and complex hybrid or application-delivery paths.

AZ-305 uses those operational realities to choose designs that are supportable and observable.

Use the three exams as layers, not duplicates

If you administer Azure broadly, networking is one major AZ-104 skill. If networking is your primary technical specialty, AZ-700 adds the depth. If you design complete Azure solutions, AZ-305 adds architectural trade-offs on top of enough administration/networking knowledge to make credible decisions.

Address planning is a good example of depth. AZ-104 needs to create subnets and avoid obvious overlap. AZ-700 needs to plan address spaces across hubs, spokes, regions, hybrid networks, and growth. AZ-305 must decide how address strategy supports acquisitions, hybrid connectivity, security zones, and future architecture without creating expensive renumbering.

Routing shows the same progression. AZ-104 configures route tables and diagnoses effective routes. AZ-700 works with Route Server, BGP, forced tunneling, Virtual WAN, VPN/ExpressRoute propagation, and complex route domains. AZ-305 decides which topology/routing architecture best balances scale, reliability, operational ownership, and security.

DNS is often underestimated. AZ-104 configures Azure DNS/private DNS and troubleshoots name resolution. AZ-700 needs deeper hybrid DNS and Private Link resolution knowledge. AZ-305 decides how authoritative and recursive DNS, private zones, hybrid resolvers, and application naming should be structured across the solution.

Hybrid networking is where administration experience becomes especially useful to architects. BGP advertisement, asymmetric routing, gateway SKU/throughput, ExpressRoute locations, VPN redundancy, and DNS forwarding can turn a clean high-level diagram into a difficult implementation. AZ-700 provides the deepest technical treatment of those dependencies.

Load balancing also changes scope. AZ-104 configures a load balancer or application gateway. AZ-700 compares regional and global delivery, Layer 4 versus Layer 7, health probes, session persistence, WAF, Front Door, Traffic Manager, and cross-region behavior. AZ-305 selects the pattern as one part of application architecture.

Network security requires the same layered thinking. An NSG protects traffic near subnets/NICs, Azure Firewall centralizes inspection/NAT, WAF protects HTTP applications, DDoS protection addresses availability attacks, and Private Link reduces public exposure. The network engineer needs the most implementation detail; the architect needs the most trade-off context.

Operational ownership matters too. AZ-104 might manage a small VNet directly. AZ-700 often deals with centralized network teams, shared hubs, multiple subscriptions, Network Manager, policy, and standardized routing/security. AZ-305 decides whether that centralization fits the organization’s operating model and separation of duties.

Monitoring grows from resource checks to service assurance. AZ-104 uses Network Watcher, metrics, logs, and connection diagnostics. AZ-700 integrates flow logs, topology, route evidence, VPN/ExpressRoute health, load-balancer health, and security logs into a network-operations practice. AZ-305 requires enough observability design to ensure the architecture can be supported after handoff.

Cost is another role divider. Administrators need to understand resource cost and avoid accidental waste. Network engineers model data-transfer, gateway, firewall, NAT, cross-region, and connectivity-service costs. Architects weigh those costs against resilience, performance, security, and organizational complexity at solution level.

If you study all three, reuse one enterprise scenario. Configure it at AZ-104 depth, redesign its network at AZ-700 depth, then present architectural alternatives at AZ-305 depth. This creates progression without repeating the same flashcards and reveals which facts are operational versus architectural.

The exams are therefore best viewed as concentric responsibilities. AZ-104 keeps the Azure environment running, AZ-700 makes the network robust and scalable, and AZ-305 makes networking one intentional component of a complete Azure solution. Overlap is a feature because real projects require all three perspectives.

Private DNS is a good example of why the exams are not duplicates. AZ-104 configures zones and links and fixes common resolution problems. AZ-700 designs hybrid name-resolution flows around Private Link and on-premises resolvers. AZ-305 decides where DNS responsibility belongs and how the architecture avoids split-brain, latency, or ownership problems across regions and subscriptions.

Virtual Network Manager is another specialty-to-architecture bridge. AZ-700 can require detailed knowledge of connectivity configurations, security admin rules, and network groups. AZ-305 needs to understand when centralized network management provides governance value in a large estate. AZ-104 may interact with the resulting configuration operationally without owning the enterprise design.

Disaster recovery also changes the networking question. Administrators ensure secondary-region resources have correct routes and security. Network engineers design redundant hybrid links, global ingress, DNS or accelerator failover, and recoverable hubs. Architects decide which failure domains the business must survive and whether the extra network complexity is justified.

Automation depth grows with specialization too. AZ-104 uses ARM/Bicep, CLI, or PowerShell to deploy resources. AZ-700 may automate standardized VNets, route tables, firewall policy, private endpoints, or DNS at scale. AZ-305 focuses on whether the automated network pattern is the right reusable architecture and how teams consume it safely.

For someone deciding between certifications, choose AZ-700 when networking is the principal engineering skill you want to prove. Choose AZ-104 when you need broad Azure operations with competent networking. Choose AZ-305 when you already understand Azure operations and need to demonstrate end-to-end design judgment. The same service names should not obscure those role differences.

A strong cross-exam lab uses one hub-and-spoke environment. Configure the VNet, peering, routes, DNS, and security at AZ-104 depth; redesign connectivity, private access, application delivery, and observability at AZ-700 depth; then justify the topology, regional strategy, failure domains, governance, and cost at AZ-305 depth. Reusing one network shows exactly how the same Azure services support three different professional responsibilities.

In final preparation, label every networking fact as configuration, engineering, or architecture. “Create an NSG rule” is administrative; “design a segmented, observable rule strategy across many networks” is network engineering; “decide where segmentation belongs in the overall solution and operating model” is architecture. That classification keeps overlapping objectives from feeling repetitive.

Within the Microsoft certification path, the overlap is intentional: the same network must be operated, engineered, and architected by different roles working together.