AZ-104 cheat sheet
Last-minute reference for AZ-104. Identity and compute are the largest areas; monitoring and backup is the smallest.
Exam facts
| Duration | 100 minutes |
| Passing score | 700 / 1000 |
| Price | Set per country or region; shown at booking |
| Languages | 10 |
| Renewal | Free, every 12 months |
Skill areas
| Area | Weight |
|---|---|
| Manage Azure identities and governance | 20–25% |
| Deploy and manage Azure compute resources | 20–25% |
| Implement and manage storage | 15–20% |
| Implement and manage virtual networking | 15–20% |
| Monitor and maintain Azure resources | 10–15% |
Requirement to answer
| Requirement | Answer |
|---|---|
| Group membership follows a user attribute | Dynamic membership group |
| Manage resources but not grant access | Contributor |
| Grant access but not manage resources | User Access Administrator |
| Reset passwords, no resource access | Entra role, not an Azure role |
| Block resources without a tag | Azure Policy, Deny effect |
| Fix existing non-compliant resources | Remediation task |
| Prevent deletion, allow changes | CanNotDelete lock |
| One assignment for many subscriptions | Management group |
| Revoke a group of SAS tokens | Stored access policy |
| SAS without the account key | User delegation SAS |
| Survive a datacenter failure (storage) | ZRS or GZRS |
| Read during a regional outage | RA-GRS or RA-GZRS |
| Recover overwritten blobs | Versioning |
| Recover deleted blobs | Soft delete |
| Move blobs to cheaper tiers by age | Lifecycle management |
| Survive a datacenter failure (VMs) | Availability zones |
| Release with instant rollback on App Service | Deployment slot + swap |
| Simple short-lived container | Container Instances |
| RDP without public IPs | Azure Bastion |
| PaaS on a private IP, reachable on-premises | Private endpoint |
| Force traffic through an appliance | Route table, next hop virtual appliance |
| Silence alerts during maintenance | Alert processing rule |
| Who deleted a resource | Activity log |
| VM backups | Recovery Services vault |
| Disk and blob backups | Backup vault |
| Run VMs in another region after an outage | Site Recovery |
Numbers worth knowing
| Reserved addresses per subnet | 5 |
| Bastion subnet | Named AzureBastionSubnet, /26 or larger |
| NSG rule priorities | 100–4096, lowest number first |
| Minimum tier days | Cool 30, cold 90, archive 180 |
| App Service autoscale and slots | Standard tier or higher |
Traps
- Peering is not transitive. Spokes do not talk through a hub without a gateway or appliance.
- Traffic must pass both NSGs when subnet and NIC each have one.
- Tags do not inherit from resource groups without a policy.
- Locks apply to Owners too. A ReadOnly lock can block key listing on a storage account.
- Budgets alert; they do not stop resources.
- Complete deployment mode deletes resources not in the template.
- Entra roles and Azure roles are separate. Global Administrator does not mean subscription access.
- Archive blobs must be rehydrated before they can be read.
Night-before checklist
- Name the five areas and which are largest
- Least-privilege role and scope for any requirement, cold
- Service endpoint versus private endpoint, in one sentence each
- Check ID and proctoring rules; see exam day
Take the 20-question practice test and check your weakest area.