AZ-104 study plan: pass in 4 weeks

Updated September 28, 2026

Four weeks is realistic for AZ-104 if you already work with Azure or another cloud and study 8–10 hours a week. Cover the five domains in an order that builds on itself: identity and governance first, because every later lab needs roles and resource groups; then storage; then compute, the largest block; then networking and monitoring together in the last week. Without any cloud or server administration experience, double the timeline.

Before you start

  • Read the official skills outline once, end to end. It is two pages and lists every objective.
  • Create a free or pay-as-you-go Azure subscription and set a budget alert on day one. That is itself an exam objective, and it protects you from a forgotten VM.
  • Install the Azure CLI and Azure PowerShell, or use Cloud Shell. Do each lab at least once in the portal and once from the command line.
  • Take the free Microsoft practice assessment cold. The score does not matter yet; the per-domain breakdown does.

Week 1: identities and governance (20–25%)

Goal: control who can do what, where, and at what cost.

  • Microsoft Entra ID: create users and groups, dynamic versus assigned membership, group-based licensing, guest users through B2B, and self-service password reset.
  • Azure RBAC: Owner, Contributor, Reader and User Access Administrator; the difference between Entra roles and Azure roles; assigning at management group, subscription, resource group and resource scope; reading effective access on the IAM blade.
  • Governance: Azure Policy definitions, initiatives, assignments and remediation; resource locks (CanNotDelete and ReadOnly); tags and why they do not inherit by default; management groups; moving resources between resource groups and subscriptions.
  • Cost: budgets, cost alerts and Azure Advisor recommendations.

Lab: a management group with two subscriptions or resource groups, a policy that requires a costCenter tag, a delete lock on production, and a guest user with Reader on one resource group only.

Week 2: storage (15–20%)

Goal: create a storage account you would trust with real data.

  • Accounts and redundancy: LRS, ZRS, GRS, RA-GRS, GZRS and RA-GZRS; which conversions are possible; account kinds and performance tiers.
  • Access: access keys and rotation, account and service SAS, user delegation SAS, stored access policies, storage firewalls and virtual network rules, and identity-based access for Azure Files.
  • Blob Storage: containers, hot, cool, cold and archive tiers, rehydration, lifecycle management rules, soft delete, versioning and object replication.
  • Azure Files: file shares, snapshots and soft delete.
  • Tools: AzCopy and Azure Storage Explorer; encryption with Microsoft-managed and customer-managed keys.

Lab: an account with a lifecycle rule that moves blobs to cool after 30 days, a SAS tied to a stored access policy that you then revoke, and a file share mounted on a VM.

Week 3: compute (20–25%)

Goal: deploy the same workload three ways and automate it.

  • ARM and Bicep: read a template, change a parameter, deploy it, export a resource group as a template and decompile it to Bicep.
  • Virtual machines: sizes and resizing, managed disks and disk types, encryption at host, availability sets versus availability zones, moving a VM to another resource group, subscription or region.
  • Scale sets: autoscale rules, instance counts and upgrade policy.
  • Containers: Azure Container Registry, Azure Container Instances and Azure Container Apps, including sizing and scaling.
  • App Service: plans and scaling, custom domains, TLS certificates, backup, networking settings and deployment slots with swap.

Lab: a Bicep file that deploys a VM into an availability zone, then the same small web app on App Service with a staging slot, and in Container Apps.

Week 4: networking (15–20%), monitoring (10–15%) and review

Goal: make the resources from weeks 1–3 reachable, secure and observable.

  • Virtual networks: address spaces and subnets, peering and its non-transitive nature, public IP SKUs, user-defined routes and connectivity troubleshooting.
  • Secure access: NSGs and application security groups, effective security rules, Azure Bastion, service endpoints versus private endpoints.
  • Name resolution and load balancing: Azure DNS public and private zones, public and internal load balancers, health probes, and load balancer troubleshooting.
  • Azure Monitor: metrics, diagnostic settings, Log Analytics and KQL basics, alert rules, action groups and alert processing rules, VM, storage and network insights, Network Watcher and Connection monitor.
  • Backup and recovery: Recovery Services vault versus Backup vault, backup policies, restores, Site Recovery replication and failover, backup reports and alerts.

Review: take the free 20-question practice test mid-week, then repeat the official practice assessment. Spend the remaining days on the lowest-scoring domain, using its guide in this section.

If you already administer Azure

Compress weeks 1 and 3. Most working administrators know RBAC and VMs well. Spend the saved time on the objectives people rarely touch at work: stored access policies, object replication, Bicep decompilation, alert processing rules, Backup vaults and Site Recovery failover.

How to know you are ready

  • You can say, without looking it up, which scope a role assignment needs for a given requirement.
  • You can read an NSG rule list and say whether a given packet is allowed.
  • You can read an ARM template or Bicep file and say what it deploys and what a changed parameter will do.
  • You score 80% or more on realistic practice questions twice in a row, on different question sets.

Then book it. See the exam format for the mechanics and the exam day guide for the day itself.