AZ-104 cheat sheet

Updated September 28, 2026

Last-minute reference for AZ-104. Identity and compute are the largest areas; monitoring and backup is the smallest.

Exam facts

Duration100 minutes
Passing score700 / 1000
PriceSet per country or region; shown at booking
Languages10
RenewalFree, every 12 months

Skill areas

AreaWeight
Manage Azure identities and governance20–25%
Deploy and manage Azure compute resources20–25%
Implement and manage storage15–20%
Implement and manage virtual networking15–20%
Monitor and maintain Azure resources10–15%

Requirement to answer

RequirementAnswer
Group membership follows a user attributeDynamic membership group
Manage resources but not grant accessContributor
Grant access but not manage resourcesUser Access Administrator
Reset passwords, no resource accessEntra role, not an Azure role
Block resources without a tagAzure Policy, Deny effect
Fix existing non-compliant resourcesRemediation task
Prevent deletion, allow changesCanNotDelete lock
One assignment for many subscriptionsManagement group
Revoke a group of SAS tokensStored access policy
SAS without the account keyUser delegation SAS
Survive a datacenter failure (storage)ZRS or GZRS
Read during a regional outageRA-GRS or RA-GZRS
Recover overwritten blobsVersioning
Recover deleted blobsSoft delete
Move blobs to cheaper tiers by ageLifecycle management
Survive a datacenter failure (VMs)Availability zones
Release with instant rollback on App ServiceDeployment slot + swap
Simple short-lived containerContainer Instances
RDP without public IPsAzure Bastion
PaaS on a private IP, reachable on-premisesPrivate endpoint
Force traffic through an applianceRoute table, next hop virtual appliance
Silence alerts during maintenanceAlert processing rule
Who deleted a resourceActivity log
VM backupsRecovery Services vault
Disk and blob backupsBackup vault
Run VMs in another region after an outageSite Recovery

Numbers worth knowing

Reserved addresses per subnet5
Bastion subnetNamed AzureBastionSubnet, /26 or larger
NSG rule priorities100–4096, lowest number first
Minimum tier daysCool 30, cold 90, archive 180
App Service autoscale and slotsStandard tier or higher

Traps

  • Peering is not transitive. Spokes do not talk through a hub without a gateway or appliance.
  • Traffic must pass both NSGs when subnet and NIC each have one.
  • Tags do not inherit from resource groups without a policy.
  • Locks apply to Owners too. A ReadOnly lock can block key listing on a storage account.
  • Budgets alert; they do not stop resources.
  • Complete deployment mode deletes resources not in the template.
  • Entra roles and Azure roles are separate. Global Administrator does not mean subscription access.
  • Archive blobs must be rehydrated before they can be read.

Night-before checklist

  • Name the five areas and which are largest
  • Least-privilege role and scope for any requirement, cold
  • Service endpoint versus private endpoint, in one sentence each
  • Check ID and proctoring rules; see exam day

Take the 20-question practice test and check your weakest area.