Microsoft Azure Certification Paths by Role

Microsoft’s Azure certification landscape makes more sense when it is read as a set of job-role routes rather than a ladder that everyone must climb in the same order. AZ-900 is the broad fundamentals starting point. AZ-104 is the administrator route. AZ-700 focuses on Azure networking, while AZ-305 belongs to the solutions-architecture path. Azure Virtual Desktop, Windows Server, DevOps, and cloud security each add their own specialist or advanced direction.

The important 2026 update is that several familiar Azure codes no longer represent current registration targets. AZ-500 retired on August 31, 2026 and Microsoft replaced the Azure Security Engineer Associate route with SC-500, Cloud and AI Security Engineer Associate. AZ-800 and AZ-801 retired on September 30, 2026; the current Windows Server Administrator Associate route now centers on AZ-802. A useful Azure path therefore has to separate active exams from legacy pages that still appear in search results.

There is also no universal requirement to begin with a fundamentals exam. AZ-900 is useful for people who need the vocabulary and service model before role-based study, but experienced administrators, network engineers, architects, security engineers, and DevOps practitioners can start with the credential that matches the work they already perform. The best route is role-first, then skill-gap driven.

Azure Fundamentals is orientation, not a gate

AZ-900 validates foundational understanding of cloud concepts, core Azure architecture and services, and Azure management and governance. That makes it valuable for people entering Azure from support, infrastructure, development, data, security, project management, or nontechnical stakeholder roles. The exam helps candidates learn how subscriptions, regions, resource groups, compute, storage, networking, identity, governance, pricing, monitoring, and shared responsibility fit together.

Its value is conceptual coverage rather than administration depth. A candidate can explain why availability zones matter without being expected to design a production failover topology, or describe Azure networking without building a complex hybrid routing environment. That boundary is useful: fundamentals should give enough context to understand later role-based decisions without pretending to validate operational expertise.

For candidates who want a broad view of the Microsoft credential ecosystem before specializing, Microsoft certifications provide the wider frame. AZ-900 is one starting point inside that system, not a mandatory prerequisite for the associate and expert routes that follow.

AZ-104 is the core route for operating Azure

AZ-104 is built around implementing, managing, and monitoring Azure environments. The administrator has to work across identity and governance, storage, compute, virtual networking, and monitoring and maintenance. That breadth is what makes the certification such a strong operational foundation: administrators see the consequences of design choices after resources are deployed and real users, workloads, permissions, budgets, alerts, and failures enter the picture.

Hands-on administration requires more than knowing product names. You need to reason about scope and inheritance for access, storage security, virtual-machine availability, network address spaces, DNS, load balancing, private access, backup, policy, alerts, and the difference between a configuration that is technically valid and one that is maintainable. Azure monitoring matters because observability connects almost every operational domain and gives administrators evidence when those domains interact badly.

AZ-104 is also the formal prerequisite certification for Microsoft Certified: Azure Solutions Architect Expert. That does not mean every architect must perform day-to-day administration forever, but it reflects an important principle: architecture decisions are stronger when the designer understands how Azure resources are actually operated.

Architecture, networking, and security split the platform into different decision levels

AZ-305 asks a different class of question from AZ-104. Instead of primarily configuring resources, the solutions architect translates business and technical requirements into designs for identity, governance, monitoring, storage, continuity, and infrastructure. The architect weighs cost, resilience, security, operational complexity, existing skills, recovery objectives, data constraints, and long-term change.

AZ-700 narrows deeply into network engineering. Its current scope covers core network infrastructure, hybrid connectivity, application delivery, private access, network security, monitoring, resiliency, and troubleshooting. Candidates who work with hubs and spokes, VPN and ExpressRoute, load balancing, private endpoints, routing, name resolution, firewall integration, and connectivity diagnostics are operating in a more specialized network role than the general Azure administrator.

Security now has an important transition. AZ-500 remains historically relevant, but it is retired. The active replacement is SC-500, which expands the security-engineer remit across identity, networking, storage, databases, compute, security posture, and AI workloads. That change should shape any current Azure learning plan.

Azure Virtual Desktop is a specialist route inside the administration family

AZ-140 serves administrators who design, implement, manage, and maintain Azure Virtual Desktop experiences and remote applications. It sits close to AZ-104 because the work depends on compute, networking, identity, storage, resiliency, monitoring, scripting, and automation. The difference is that those platform skills are applied to desktop delivery and end-user experience.

That specialization introduces its own operational concerns: host pools, session hosts, application groups, profile containers, image management, user assignments, identity integration, security, monitoring, scaling, and client experience. A candidate who only studies generic Azure administration can understand the foundation while still lacking the desktop-specific decisions that make a real deployment stable.

Azure Virtual Desktop architecture brings host pools, identity, networking, profile storage, application delivery, scaling, and monitoring into one design problem. Administrators who understand those relationships can judge more accurately whether AZ-140 matches the responsibilities they are taking on.

Windows Server administration moved from AZ-800/AZ-801 to AZ-802

Hybrid Windows Server used to require the AZ-800 and AZ-801 pair. Both exams retired on September 30, 2026. The current Windows Server Administrator Associate path uses AZ-802, which validates administration across on-premises, cloud, and hybrid environments with identity, security, networking, storage, monitoring, virtual machines, Azure Arc, and modern Windows Server operations.

This matters because an Azure certification map can become misleading quickly if it treats old exam codes as current routes. AZ-801 is still useful as a historical reference for advanced hybrid services, but a new candidate should not build a registration plan around it. The current question is whether Windows Server is central to the job, and if so, whether AZ-802 better represents the environment being administered.

Hybrid administration is also a reminder that Azure skills do not begin and end inside the public cloud. Identity, DNS, networking, update management, monitoring, virtual machines, security, storage, and migration often span data centers and Azure services.

AZ-400 is the route for delivery systems rather than resource administration alone

AZ-400 targets DevOps engineers who design and implement processes, source control, build and release pipelines, security and compliance controls, instrumentation, feedback, and collaboration. It assumes experience in both development and Azure administration, because delivery systems sit between application code and the platform on which that code runs.

Azure DevOps connects those mechanics through a working model in which source control, pipelines, automation, instrumentation, security, and team feedback form one continuous delivery system rather than isolated tools.

Administrators who increasingly automate deployment may find AZ-400 a natural expansion. Developers who already build delivery pipelines may instead need more Azure infrastructure depth before the platform side of the exam feels intuitive.

Choose the next exam by the decisions you are expected to make

A role-based plan also prevents a common mistake: treating every Azure exam as another rung on one universal ladder. An engineer who spends most of the week troubleshooting virtual networks may gain more from deep networking study than from moving immediately toward architecture. A platform administrator who is taking ownership of governance, storage, compute, and monitoring may need broader AZ-104 depth before specializing. Someone moving into design reviews needs the ability to justify choices against requirements, which is where the AZ-305 path becomes more relevant. The sequence should follow the work that is becoming part of the job, not the desire to collect the largest number of badges.

The same principle applies to specialist areas. Azure Virtual Desktop administrators need to reason about host pools, session hosts, user profiles, identity, networking, application delivery, and monitoring as one operating system for end-user computing. Hybrid Windows Server administrators need a different mix of identity, migration, security, high availability, and Azure-connected management. DevOps engineers work across source control, pipelines, infrastructure as code, release controls, observability, and feedback loops. These areas overlap with core Azure administration, but the center of responsibility is different enough that a specialist route can be more useful than another broad exam.

Candidates should also separate historical familiarity from current registration decisions. Older Azure exam codes still appear in job descriptions, study notes, and internal training plans, so understanding what they represented can be useful. That does not make a retired exam the right target today. A current plan should use the live credential that now owns the role, while older codes are treated as context for people who earned them or for organizations updating legacy skills matrices. That distinction keeps a certification plan aligned with the platform Microsoft is actually supporting now.

A practical route can be built from responsibility. If your work is broad cloud operation, start with AZ-104. If you primarily design infrastructure and trade-offs, build toward AZ-305. If connectivity is your domain, AZ-700 is the specialist route. If you secure cloud and AI workloads, SC-500 is now the current security-engineer path. If you deliver virtual desktops, AZ-140 is the specialist credential. If you administer Windows Server across hybrid environments, use AZ-802. If your responsibility is delivery automation and DevOps systems, AZ-400 is the relevant advanced direction.

The strongest study plans also develop supporting concepts rather than treating each code as an isolated syllabus. Networking candidates benefit from a solid understanding of Azure virtual networking; architecture candidates should understand cost, monitoring, identity, security, and operational consequences; administrators should learn automation and governance as part of normal operations.

Microsoft changes credential names and retires exams as roles evolve. The durable strategy is therefore to anchor your path to the work: operate, design, connect, secure, deliver, or specialize. Exam codes are important, but the role boundary tells you why the credential exists.