AZ-104 to AZ-305: Administration to Architecture

AZ-104 and AZ-305 are tightly related, but they assess different levels of Azure responsibility. AZ-104 validates the administrator who implements, manages, secures, and monitors Azure resources. AZ-305 validates the solutions architect who turns business and technical requirements into designs for identity, governance, monitoring, storage, business continuity, and infrastructure. The important current detail is that Microsoft Certified: Azure Solutions Architect Expert requires an active Azure Administrator Associate certification plus AZ-305.

You can think of AZ-104 as learning how Azure behaves under your hands and AZ-305 as learning how to choose and justify the architecture before implementation. Administration experience feeds architecture because design decisions are better when you understand operational consequences.

AZ-104 owns implementation and day-to-day state

The current Azure Administrator role covers identities and governance, storage, compute, virtual networking, and monitoring/maintenance. Administrators create users and groups, assign RBAC, apply policy, deploy VMs or containers, configure storage access, build VNets, and troubleshoot resources.

An Azure Administrator should be comfortable with the portal, PowerShell, Azure CLI, ARM/Bicep, and Entra ID. The exam asks “can you configure and operate this environment?”

AZ-305 owns the design decision

The Azure Solutions Architect role is responsible for designs across compute, network, storage, monitoring, security, governance, data, and continuity. The current AZ-305 domains are design identity/governance/monitoring, data storage, business continuity, and infrastructure.

An AZ-305 architecture question is more likely to ask which pattern best satisfies scale, security, recovery, latency, cost, and governance requirements than how to click through a deployment wizard.

Identity progresses from assignment to architecture

In AZ-104, you manage Entra users/groups, subscriptions, Azure roles, policy, locks, tags, and management groups. In AZ-305, the same concepts become design decisions: how should identity boundaries, administrative scopes, governance hierarchy, and monitoring be structured across an enterprise?

The administrator learns what happens when a role is assigned at subscription scope; the architect decides whether subscription scope is appropriate in the first place.

Storage progresses from configuration to service selection

AZ-104 expects you to configure storage accounts, access, redundancy, lifecycle, file shares, and related controls. AZ-305 asks you to choose the data-store and redundancy/replication pattern that meets consistency, performance, availability, security, and cost needs.

Operational knowledge matters because an architect who has never configured storage may underestimate network restrictions, identity, replication, lifecycle, or recovery complexity.

Compute progresses from deployment to topology

Administrators deploy and manage VMs, availability options, containers, and app-service resources. Architects decide how applications should be partitioned across VMs, containers, serverless or managed services and how those components scale or recover.

The design answer must consider the whole application rather than one resource. A VM that can be configured successfully is not automatically the right architecture.

Networking is where the progression becomes obvious

AZ-104 covers VNet/subnet configuration, peering, routing, NSGs, DNS, load balancing, connectivity, and troubleshooting at administrator depth. AZ-305 expects an architect to choose network topology, connectivity model, security boundaries, name-resolution approach, ingress/egress pattern, and regional design from business requirements.

Hands-on troubleshooting in AZ-104 teaches which architectural shortcuts later become operational pain.

Monitoring moves from alert configuration to observability design

An administrator configures Azure Monitor, alerts, log collection, backup, and resource health. An architect decides what telemetry the solution needs, how logs and metrics flow, which operational teams consume them, and how monitoring supports availability/security objectives.

Good architecture includes observability before the first incident rather than adding monitoring after deployment.

Business continuity makes architecture broader

AZ-104 includes backup and resource-level availability, but AZ-305 expands the question to RTO/RPO, zone and region failure, application dependency, replication, disaster recovery, and continuity across entire solutions. This is where local administration knowledge must be combined with business impact.

An architect designs recovery for a service, not just for one VM or database.

AZ-104 is a certification prerequisite, not an exam prerequisite

Microsoft’s current Azure Solutions Architect Expert page requires the Azure Administrator Associate certification as a prerequisite and lists AZ-305 as the required exam. You may sit AZ-305 without first taking AZ-104, but you do not earn the Solutions Architect Expert certification until the prerequisite certification is active.

This distinction matters because the sequence is not merely study advice; it is part of the credential requirements.

The strongest progression is operate, then justify

Use AZ-104 experience to build operational intuition, then shift your study questions from “how do I configure this?” to “why is this the right design given competing requirements?” Practice architecture trade-offs using scenarios where several Azure services could work but one best fits resilience, governance, security, cost, and operations.

The current AZ-104 blueprint is implementation-heavy by design. Its domains cover identities/governance, storage, compute, networking, and monitoring. That breadth exposes administrators to the dependencies architects later need to reason about: a storage choice affects networking, an identity choice affects automation, and a compute choice affects availability and cost.

AZ-305’s current architecture role explicitly expects advanced experience with IT operations, networking, virtualization, identity, security, business continuity, disaster recovery, data platforms, and governance. Microsoft also says candidates should have experience with Azure administration, development, and DevOps processes. This is why practical administrator experience maps naturally into architecture work.

Governance illustrates the progression well. AZ-104 applies tags, locks, policy, management groups, and role assignments. AZ-305 asks how the management-group/subscription hierarchy, policy strategy, cost boundaries, and monitoring responsibilities should be designed for an enterprise. The architect needs to predict the operational effect of those controls before implementation.

Compute shows the same transition. An administrator creates availability sets/zones, VM scale sets, App Service, containers, or related resources. The architect chooses the hosting pattern by considering workload shape, scale, deployment model, resiliency, security, observability, and team ownership. The correct answer can involve a service the architect will never configure personally.

Storage design in AZ-305 also depends on administrator intuition. Redundancy, network access, identity, lifecycle, encryption, performance tiers, and backup/recovery are not abstract boxes; they have real configuration and cost implications that an AZ-104 practitioner is more likely to have encountered.

Networking experience is especially valuable because architecture diagrams can hide operational detail. Hub-and-spoke, peering, private endpoints, DNS, route tables, NAT, load balancers, VPN/ExpressRoute, and firewalls all introduce dependencies. An architect who has troubleshot those paths is better equipped to design a topology that teams can actually operate.

Monitoring also changes from resource to system. AZ-104 might create alert rules or diagnostic settings for individual resources. AZ-305 asks which signals should be centralized, how operations teams receive them, how the solution supports incident response, and whether monitoring survives the same failure modes as the application.

Business continuity expands the scope again. Administrators know how to back up VMs, configure availability, and restore resources. Architects must combine multiple services into an application RTO/RPO plan and decide whether zone redundancy, region failover, replication, or backup is needed for each dependency.

The formal prerequisite also encourages this progression. Azure Administrator Associate must be active for the Solutions Architect Expert certification. That requirement does not mean every AZ-305 topic is covered by AZ-104; it means Microsoft expects architecture certification to build on proven operational Azure competence.

A productive transition study plan uses the same environment twice. First configure it as an administrator. Then, without changing anything, write an architecture review explaining which decisions you would keep, which would not scale, what the failure domains are, and what governance or cost assumptions were implicit. That exercise converts procedural skill into design judgment.

Cost management is another place where administration experience improves architecture. AZ-104 administrators see budgets, Advisor recommendations, storage tiers, VM sizing, and idle resources directly. AZ-305 architects need to predict how design choices change recurring cost, data transfer, resiliency cost, and operational staffing. A design that is technically elegant but financially unsustainable is not a good architecture.

Security progresses similarly. AZ-104 configures RBAC, policy, network controls, storage restrictions, and resource security within an environment. AZ-305 integrates security requirements across identity, network, data, compute, monitoring, and governance and must decide where controls belong without creating unnecessary complexity. Administrator experience reveals which policies are easy to operate and which create constant exceptions.

Migration and modernization also benefit from the progression. An administrator understands the actual configuration and dependencies of existing workloads. An architect decides whether the target should remain VM-based, move to containers or PaaS, change its data platform, or be redesigned for resilience. Without operational understanding, migration architecture can overlook DNS, identity, backup, or monitoring dependencies.

The best AZ-305 preparation after AZ-104 is therefore not to forget the administrator perspective. Keep asking what the implementation team must configure, what the operations team must monitor, what the security team must approve, and what the business expects during failure. Architecture quality improves when design decisions remain grounded in operational reality.

One final way to bridge the exams is to review every architecture decision through an operator handoff. For each proposed service, write who will deploy it, who will monitor it, how access is governed, what failure evidence exists, and how the service is recovered. If the design cannot answer those questions, it is not yet operationally complete. That handoff mindset is where AZ-104 experience becomes especially valuable to AZ-305 study.

For final review, pick one Azure solution and write two answers: the AZ-104 answer describing the concrete configuration and troubleshooting steps, and the AZ-305 answer describing why that configuration is the right architecture. If both answers read the same, the distinction between administration and architecture still needs work.

Within the wider Microsoft certification path, AZ-104 to AZ-305 is a meaningful progression because administration knowledge becomes the evidence base for architecture judgment—not because every administrator must become an architect.