AZ-104 study plan: pass in 4 weeks
Four weeks is realistic for AZ-104 if you already work with Azure or another cloud and study 8–10 hours a week. Cover the five domains in an order that builds on itself: identity and governance first, because every later lab needs roles and resource groups; then storage; then compute, the largest block; then networking and monitoring together in the last week. Without any cloud or server administration experience, double the timeline.
Before you start
- Read the official skills outline once, end to end. It is two pages and lists every objective.
- Create a free or pay-as-you-go Azure subscription and set a budget alert on day one. That is itself an exam objective, and it protects you from a forgotten VM.
- Install the Azure CLI and Azure PowerShell, or use Cloud Shell. Do each lab at least once in the portal and once from the command line.
- Take the free Microsoft practice assessment cold. The score does not matter yet; the per-domain breakdown does.
Week 1: identities and governance (20–25%)
Goal: control who can do what, where, and at what cost.
- Microsoft Entra ID: create users and groups, dynamic versus assigned membership, group-based licensing, guest users through B2B, and self-service password reset.
- Azure RBAC: Owner, Contributor, Reader and User Access Administrator; the difference between Entra roles and Azure roles; assigning at management group, subscription, resource group and resource scope; reading effective access on the IAM blade.
- Governance: Azure Policy definitions, initiatives, assignments and remediation; resource locks (CanNotDelete and ReadOnly); tags and why they do not inherit by default; management groups; moving resources between resource groups and subscriptions.
- Cost: budgets, cost alerts and Azure Advisor recommendations.
Lab: a management group with two subscriptions or resource groups, a policy that requires a costCenter tag, a delete lock on production, and a guest user with Reader on one resource group only.
Week 2: storage (15–20%)
Goal: create a storage account you would trust with real data.
- Accounts and redundancy: LRS, ZRS, GRS, RA-GRS, GZRS and RA-GZRS; which conversions are possible; account kinds and performance tiers.
- Access: access keys and rotation, account and service SAS, user delegation SAS, stored access policies, storage firewalls and virtual network rules, and identity-based access for Azure Files.
- Blob Storage: containers, hot, cool, cold and archive tiers, rehydration, lifecycle management rules, soft delete, versioning and object replication.
- Azure Files: file shares, snapshots and soft delete.
- Tools: AzCopy and Azure Storage Explorer; encryption with Microsoft-managed and customer-managed keys.
Lab: an account with a lifecycle rule that moves blobs to cool after 30 days, a SAS tied to a stored access policy that you then revoke, and a file share mounted on a VM.
Week 3: compute (20–25%)
Goal: deploy the same workload three ways and automate it.
- ARM and Bicep: read a template, change a parameter, deploy it, export a resource group as a template and decompile it to Bicep.
- Virtual machines: sizes and resizing, managed disks and disk types, encryption at host, availability sets versus availability zones, moving a VM to another resource group, subscription or region.
- Scale sets: autoscale rules, instance counts and upgrade policy.
- Containers: Azure Container Registry, Azure Container Instances and Azure Container Apps, including sizing and scaling.
- App Service: plans and scaling, custom domains, TLS certificates, backup, networking settings and deployment slots with swap.
Lab: a Bicep file that deploys a VM into an availability zone, then the same small web app on App Service with a staging slot, and in Container Apps.
Week 4: networking (15–20%), monitoring (10–15%) and review
Goal: make the resources from weeks 1–3 reachable, secure and observable.
- Virtual networks: address spaces and subnets, peering and its non-transitive nature, public IP SKUs, user-defined routes and connectivity troubleshooting.
- Secure access: NSGs and application security groups, effective security rules, Azure Bastion, service endpoints versus private endpoints.
- Name resolution and load balancing: Azure DNS public and private zones, public and internal load balancers, health probes, and load balancer troubleshooting.
- Azure Monitor: metrics, diagnostic settings, Log Analytics and KQL basics, alert rules, action groups and alert processing rules, VM, storage and network insights, Network Watcher and Connection monitor.
- Backup and recovery: Recovery Services vault versus Backup vault, backup policies, restores, Site Recovery replication and failover, backup reports and alerts.
Review: take the free 20-question practice test mid-week, then repeat the official practice assessment. Spend the remaining days on the lowest-scoring domain, using its guide in this section.
If you already administer Azure
Compress weeks 1 and 3. Most working administrators know RBAC and VMs well. Spend the saved time on the objectives people rarely touch at work: stored access policies, object replication, Bicep decompilation, alert processing rules, Backup vaults and Site Recovery failover.
How to know you are ready
- You can say, without looking it up, which scope a role assignment needs for a given requirement.
- You can read an NSG rule list and say whether a given packet is allowed.
- You can read an ARM template or Bicep file and say what it deploys and what a changed parameter will do.
- You score 80% or more on realistic practice questions twice in a row, on different question sets.
Then book it. See the exam format for the mechanics and the exam day guide for the day itself.