A focused AZ-104 study plan should be built around the current objective weighting and around the fact that Azure administration is a hands-on role. The April 17, 2026 blueprint assigns 20–25% to identities and governance, 15–20% to storage, 20–25% to compute, 15–20% to virtual networking, and 10–15% to monitoring and maintenance. Those percentages provide a useful time budget, but they do not remove the need for integrated practice.
The plan below assumes the candidate already understands basic operating systems, networking, servers, and virtualization—the background Microsoft lists for the role. If those foundations are weak, add preparation time before starting the exam-specific cycle. Azure CLI, PowerShell, the portal, ARM or Bicep, and Microsoft Entra ID should be present throughout the plan rather than saved for a single topic.
Use the AZ-104 exam blueprint as the final checklist. The schedule can be compressed or expanded, but the order should preserve prerequisites and repeated hands-on exposure.
Phase one: establish the Azure control model
Begin with tenants, subscriptions, management groups, resource groups, and resources. Learn how scope and inheritance work. Then add Microsoft Entra users and groups, licenses, external users, and self-service password reset. Practice built-in Azure roles and assign them at different scopes.
Bring governance into the same phase: Azure Policy, locks, tags, budgets, alerts, Advisor recommendations, and management groups. Do not study these as unrelated management features. They are the controls that shape how resources can be created, modified, organized, and paid for.
A strong checkpoint is being able to explain the difference among identity, authentication, authorization, policy, and lock behavior without referring to notes. Review Azure RBAC until role and scope decisions feel natural.
Phase two: use storage to practice layered access and data protection
Create storage accounts and configure redundancy, encryption, object replication where appropriate, Azure Files, blob containers, tiers, lifecycle management, snapshots, soft delete, and versioning. Move data with AzCopy and Azure Storage Explorer.
Then focus on access paths: keys, SAS tokens, stored access policies, identity-based access, firewalls, and virtual-network rules. For each method, write down who or what is trusted, how long access lasts, which operations are allowed, and whether network controls still apply.
This phase should end with recovery drills. Delete data and restore it using the protection feature you configured. Change a network rule and troubleshoot the resulting access failure. Storage is only 15–20% of the exam, but it teaches several patterns that reappear elsewhere.
Phase three: build the network before adding complex workloads
Create virtual networks, subnets, peering, public IPs, and user-defined routes. Add NSGs and application security groups. Explore effective rules. Configure or at least understand Bastion, service endpoints, private endpoints, Azure DNS, and internal versus public load balancers.
Spend at least as much time troubleshooting as configuring. Use Network Watcher and Connection Monitor. Break an NSG rule, route, name-resolution dependency, or health probe and trace the fault from source to destination.
A review of Azure virtual networks should leave you able to draw a packet path and mark where routing, filtering, DNS, and service-specific access controls apply.
Phase four: spend the largest hands-on block on compute
Compute shares the highest weighting, so give it a large practical block. Create and configure virtual machines, disks, sizes, zones, availability sets, and scale sets. Practice moving resources where supported. Use encryption-at-host concepts and understand the administrative implications of availability choices.
Introduce infrastructure as code by interpreting and modifying ARM or Bicep definitions. Deploy a known resource through a template, change a parameter, and fix at least one failed deployment. ARM templates should feel like another administration interface, not a foreign development task.
Then cover managed compute: Azure Container Registry, Container Instances, Container Apps, and App Service. Practice App Service plans, scaling, TLS, custom DNS names, backups, networking, and deployment slots. For containers, focus on image source, sizing, scaling, connectivity, and identity.
Phase five: make monitoring part of normal administration
At this point you should have enough resources to make monitoring useful. Use Azure Monitor to inspect metrics and logs from different resource types. Configure log settings, write simple queries, create alert rules, connect action groups, and explore Insights.
For each workload, answer four questions: What signals show normal health? What signal would reveal a common failure? What alert would be actionable? What additional tool would you use to narrow the problem? This keeps monitoring tied to operations rather than turning it into another service-definition chapter.
Review Network Watcher and Connection Monitor again in this phase so networking and monitoring reinforce one another.
Phase six: add backup, restore, and continuity
Create vaults, configure policies, protect test resources, and perform restores. Study Azure Backup alongside Site Recovery so you can explain the difference between recovery points and replicated failover. Include reports and alerts because the blueprint expects administrators to monitor protection, not only configure it.
Compare backup and Site Recovery with storage redundancy, availability zones, and scale. Write a one-sentence failure model for each. If you cannot explain what type of failure a feature addresses, the concept is not yet exam-ready.
This phase should be shorter than compute but highly practical. Recovery tasks are memorable when performed and easily confused when only read about.
Schedule at least one no-notes administration session before the final review. Create a resource group, storage account, virtual network, VM or managed workload, role assignment, monitoring alert, and protection setting using only the official objective list as a prompt. The goal is not speed. It is to discover which tasks still depend on step-by-step instructions. Those tasks belong back in the study queue before practice questions consume the remaining time.
Phase seven: convert domain knowledge into mixed scenarios
Stop doing single-domain exercises. Build scenarios where several controls interact. A VM needs access to a storage account over restricted networking. A load-balanced application becomes partially unavailable. A deployment is blocked by policy. A user can manage a resource but not its data. A workload must survive a regional event. Diagnose each requirement from first principles.
For every scenario, classify the issue: identity, authorization, governance, storage, compute, network, monitoring, or recovery. Then identify scope and evidence. This habit is more important than memorizing answer patterns.
Use mistakes to update the study plan. If multiple wrong answers involve networking, return to routes and NSGs. If storage access questions fail, revisit the separation among authentication, authorization, and network reachability. The plan should react to evidence rather than follow a calendar blindly.
Phase eight: use the blueprint for final gap analysis
In the last review, read the current Microsoft objectives line by line. Mark each as strong, adequate, or weak. Strong means you can perform or explain the task without prompts. Adequate means you can recognize the correct approach but may need documentation for exact syntax. Weak means the objective still causes confusion or depends on memorized steps.
Allocate remaining time according to both weakness and weighting. A weak 20–25% domain deserves urgent work, but a completely unfamiliar 10–15% recovery objective can still cost points. Do not chase topics outside the blueprint merely because they are interesting or newly announced.
The Azure Administrator Associate is a role credential. Final review should therefore prioritize decisions and operational outcomes, not product trivia.
Budget review time by evidence, not by comfort
As the plan advances, keep a simple scorecard for each objective group. Track whether you have configured the feature, troubleshot it, and explained the reason for choosing it over an alternative. A domain can feel familiar because you have read it repeatedly while still being weak in real decisions. The scorecard exposes that gap.
Use exam weighting as a multiplier rather than as the only priority. A weak compute objective matters because compute carries 20–25%, but a completely unpracticed backup task also deserves attention even though monitoring and maintenance is the smallest domain. The practical question is how much uncertainty remains and how often that uncertainty is likely to appear across scenarios.
Reserve the last review block for mixed failures: policy blocking deployment, NSGs blocking storage, managed identities lacking data access, health probes removing a backend, alerts missing because telemetry is not configured, or restores failing because the wrong protection method was chosen. These scenarios reveal whether the domains are genuinely connected in your mental model.
Keep a compact exam notebook built around contrasts
Your final notes should contain contrasts that prevent common errors: RBAC versus Policy; route versus NSG; redundancy versus backup; backup versus Site Recovery; availability versus scaling; metrics versus logs; keys versus SAS versus identity-based access; public endpoints versus private endpoints. These comparisons compress large parts of the syllabus.
Add only the commands, properties, or service details you repeatedly forget. Avoid rewriting documentation into a giant notebook that cannot be reviewed. A focused plan works because it removes low-value material as preparation advances.
Across Microsoft certifications, later credentials may specialize in networking, architecture, identity, data, or DevOps. AZ-104 preparation is strongest when it produces a reusable operational foundation rather than a short-lived collection of exam facts.