{"id":25276,"date":"2026-10-05T07:42:51","date_gmt":"2026-10-05T07:42:51","guid":{"rendered":"https:\/\/www.examlabs.com\/certification\/?p=25276"},"modified":"2026-10-05T07:42:51","modified_gmt":"2026-10-05T07:42:51","slug":"microsoft-az-104-what-the-blueprint-covers","status":"publish","type":"post","link":"https:\/\/www.examlabs.com\/certification\/microsoft-az-104-what-the-blueprint-covers\/","title":{"rendered":"Microsoft AZ-104: What the Blueprint Covers"},"content":{"rendered":"<p>AZ-104 remains Microsoft\u2019s core administration exam for professionals who implement, manage, and monitor Azure environments. As of October 3, 2026, the live Microsoft study guide measures five connected skill areas: identities and governance, storage, compute, virtual networking, and monitoring and recovery. The English blueprint in use was updated on April 17, 2026, and Microsoft\u2019s certification page still positions the credential at the intermediate administrator level.<\/p>\n<p>That matters because the <a href=\"https:\/\/www.examlabs.com\/az-104-exam-dumps\">AZ-104 exam<\/a> is not a survey of every Azure service. It concentrates on the operational layer that keeps an environment usable, controlled, connected, observable, and recoverable. Candidates are expected to understand how Azure resources are deployed and changed, how access is assigned, how data is protected, how networking is secured, and how administrators diagnose problems after workloads are running.<\/p>\n<p>The blueprint also assumes real platform familiarity. Microsoft explicitly calls out operating systems, networking, servers, virtualization, PowerShell, Azure CLI, the Azure portal, Azure Resource Manager templates or Bicep files, and Microsoft Entra ID. A study plan that treats AZ-104 as a vocabulary exam will therefore miss the level of practical judgment the role requires.<\/p>\n<h3>Identity and governance define who can act and where rules apply<\/h3>\n<p>The first domain, worth 20\u201325%, combines Microsoft Entra administration with Azure authorization and resource governance. Candidates should be comfortable creating and managing users and groups, working with licenses and external users, configuring self-service password reset, and assigning built-in Azure roles at appropriate scopes. The key distinction is between identity and authorization: Entra ID represents users and groups, while Azure role assignments determine what those identities can do to Azure resources.<\/p>\n<p>Scope is one of the most important concepts in this domain. A role assignment at a management group can affect many subscriptions; an assignment at a resource group is narrower; an assignment at a single resource is narrower still. The same hierarchy shapes policy, tags, locks, and cost-management decisions. Understanding <a href=\"https:\/\/www.examlabs.com\/certification\/understanding-core-principles-of-azure-role-based-access-for-az-800-certification\">Azure role-based access control<\/a> helps candidates reason about least privilege rather than memorizing role names in isolation.<\/p>\n<p>Governance objectives include Azure Policy, resource locks, tags, resource groups, subscriptions, management groups, budgets, alerts, Azure Advisor recommendations, and cost controls. These tools solve different problems. Policy evaluates or enforces desired conditions. Locks help prevent accidental deletion or modification. Tags add management metadata. Budgets and alerts expose spending behavior. A strong candidate knows when each control should be used and when combining them provides layered governance.<\/p>\n<h3>Storage questions combine configuration, security, resilience, and data operations<\/h3>\n<p>Storage accounts are only the beginning of the 15\u201320% storage domain. Candidates must configure access through firewalls, virtual-network rules, shared access signatures, stored access policies, access keys, and identity-based access for Azure Files. The exam can therefore test both immediate configuration and the security consequences of a chosen access method.<\/p>\n<p>Redundancy, replication, encryption, lifecycle management, soft delete, snapshots, versions, and storage tiers add a second dimension. These features address different recovery, durability, cost, and operational requirements. A locally redundant account and a geo-redundant account do not provide the same failure protection. Blob lifecycle policies and access tiers change cost behavior over time. Soft delete and versioning protect against logical mistakes in ways redundancy alone does not.<\/p>\n<p>Hands-on familiarity with <a href=\"https:\/\/www.examlabs.com\/certification\/comprehensive-guide-to-azure-storage-features-setup-and-management\">Azure Storage<\/a> and <a href=\"https:\/\/www.examlabs.com\/certification\/what-is-azure-storage-explorer\">Azure Storage Explorer<\/a> is useful because the blueprint includes both service configuration and administrative data movement with tools such as Storage Explorer and AzCopy. Candidates should understand which settings live at the storage-account level and which belong to individual containers or file shares.<\/p>\n<h3>Compute is broader than virtual machines<\/h3>\n<p>Compute is another 20\u201325% domain, but AZ-104 no longer means \u201cVM administration\u201d alone. Virtual machines remain important: sizing, disks, availability zones and sets, encryption at host, moves between scopes or regions, and Virtual Machine Scale Sets are all in scope. Yet the same domain also expects candidates to understand infrastructure-as-code deployment, container services, and Azure App Service.<\/p>\n<p>ARM templates and Bicep matter because administrators increasingly manage environments through repeatable definitions rather than one-off portal clicks. The blueprint includes interpreting and modifying templates, deploying them, exporting deployments, and converting ARM templates to Bicep. The goal is not to become a full application developer; it is to understand how repeatable infrastructure deployment affects administration and change control. A focused review of <a href=\"https:\/\/www.examlabs.com\/certification\/enhancing-azure-deployments-with-arm-templates\">ARM template deployment<\/a> can reinforce that operational perspective.<\/p>\n<p>Container objectives include Azure Container Registry, Azure Container Instances, Azure Container Apps, and sizing or scaling decisions. App Service adds plans, scaling, TLS certificates, custom DNS names, backups, networking, and deployment slots. Candidates who only practice virtual-machine tasks will leave a substantial part of the current compute blueprint uncovered.<\/p>\n<h3>Networking joins connectivity, access control, name resolution, and traffic distribution<\/h3>\n<p>The 15\u201320% networking domain asks administrators to build and troubleshoot virtual networks, subnets, peering, public IP addresses, and user-defined routes. These are the foundations for service connectivity in Azure. The exam then layers security controls on top through network security groups, application security groups, Bastion, service endpoints, and private endpoints.<\/p>\n<p>It is useful to separate routing from filtering. Routes decide where traffic goes. Network security groups decide whether traffic is allowed. Private endpoints change how a platform service is reached by giving it private connectivity into a virtual network. Bastion changes how administrators connect to virtual machines without exposing the same management ports publicly. Studying <a href=\"https:\/\/www.examlabs.com\/certification\/step-by-step-guide-to-configuring-and-managing-virtual-networks\">Azure virtual networks<\/a> together with <a href=\"https:\/\/www.examlabs.com\/certification\/how-to-set-up-azure-network-security-groups\">network security groups<\/a> makes these relationships clearer.<\/p>\n<p>Name resolution and load balancing complete the domain. Candidates should understand Azure DNS, internal and public load balancers, and the troubleshooting process when traffic does not reach the expected backend. A configuration can be syntactically valid while still failing because of a route, probe, NSG rule, DNS record, or backend-health problem.<\/p>\n<h3>Monitoring and recovery turn configuration into an operational service<\/h3>\n<p>The smallest weighted domain, 10\u201315%, is easy to underestimate because it contains skills administrators use across every other area. Azure Monitor metrics and logs, alert rules, action groups, alert processing rules, Insights, Network Watcher, and Connection Monitor help administrators establish what is happening and why. The exam expects candidates to interpret signals rather than merely know the service names.<\/p>\n<p><a href=\"https:\/\/www.examlabs.com\/certification\/what-is-azure-monitoring-a-complete-guide\">Azure Monitor<\/a> should be viewed as part of a diagnostic workflow. Metrics can reveal capacity or performance changes. Logs can expose detailed events. Alerts convert conditions into actions. Insights provide workload-specific views. Network Watcher adds network-focused evidence. The administrator\u2019s job is to combine those signals until the fault domain becomes narrow enough to act.<\/p>\n<p>Backup and recovery are equally concrete. The blueprint includes Recovery Services vaults, Backup vaults, policies, restore operations, Azure Site Recovery, regional failover, and backup reporting. <a href=\"https:\/\/www.examlabs.com\/certification\/unveiling-the-lesser-known-facets-of-azure-backup\">Azure Backup<\/a> protects recoverable copies; Site Recovery addresses continuity through replicated workloads and failover. Candidates should not collapse those into one generic \u201cdisaster recovery\u201d concept.<\/p>\n<h3>The blueprint rewards relationships more than isolated facts<\/h3>\n<p>AZ-104 becomes easier to understand when the five domains are connected. An administrator may create a storage account, grant a managed identity access to it, restrict network access, deploy an application that uses the storage, monitor the application, and protect the underlying resources with backup or recovery policies. A scenario can therefore cross several blueprint headings without being unusual.<\/p>\n<p>The same is true for governance. A subscription can inherit policy from a management group, contain resource groups with role assignments and locks, host virtual networks that control reachability, and generate cost or health alerts. The exam\u2019s structure separates those skills so candidates can study them; real operations reconnect them.<\/p>\n<p>The <a href=\"https:\/\/www.examlabs.com\/microsoft-certified-azure-administrator-associate-certification-dumps\">Azure Administrator Associate<\/a> credential is built around that operational breadth. It is not intended to prove deep specialization in security, networking, architecture, or DevOps. It proves that a candidate can administer the common platform layer well enough to work effectively with specialists in those areas.<\/p>\n<p>One useful boundary check is to ask whether a service is part of administration or a deeper specialty. AZ-104 expects administrators to configure and operate the Azure platform, but it does not require architect-level design across every service or specialist depth in database, security, or network engineering. That distinction keeps preparation efficient: learn enough of each measured service to deploy, secure, monitor, troubleshoot, and recover it, while using the official objective bullets to prevent adjacent Azure topics from expanding the syllabus without limit.<\/p>\n<h3>Use the April 2026 blueprint as the boundary for preparation<\/h3>\n<p>The most reliable preparation method is to map every lab, note, and practice scenario back to the current study guide. Azure changes constantly, but the exam has a defined boundary. A useful new service that does not appear in the blueprint may still improve professional knowledge, yet it should not displace time needed for the explicitly measured skills.<\/p>\n<p>For October 2026 candidates, that boundary is the April 17 skills-measured version. Microsoft notes that exam questions usually focus on generally available features, though commonly used preview features can appear. That is another reason to learn operational principles instead of memorizing portal screenshots that may change.<\/p>\n<p>Across the broader <a href=\"https:\/\/www.examlabs.com\/microsoft-certification-exams\">Microsoft certification<\/a> portfolio, AZ-104 remains the administration foundation for several directions. Mastering this blueprint gives candidates a durable map of Azure operations: identity and governance decide who can act, storage and compute host workloads, networking connects them, and monitoring plus recovery keeps the environment serviceable after deployment.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>AZ-104 remains Microsoft\u2019s core administration exam for professionals who implement, manage, and monitor Azure environments. As of October 3, 2026, the live Microsoft study guide measures five connected skill areas: identities and governance, storage, compute, virtual networking, and monitoring and recovery. The English blueprint in use was updated on April 17, 2026, and Microsoft\u2019s certification [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[1648,1647],"tags":[],"_links":{"self":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/25276"}],"collection":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/comments?post=25276"}],"version-history":[{"count":1,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/25276\/revisions"}],"predecessor-version":[{"id":25277,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/25276\/revisions\/25277"}],"wp:attachment":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/media?parent=25276"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/categories?post=25276"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/tags?post=25276"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}