The identities and governance domain and the compute domain are the two heaviest on AZ-104, at 20-25% of the exam each, and the whole test runs 100 minutes across five domains. Take the free AZ-104 assessment before you study anything, and sort the questions you get wrong into missing facts and confusions between two plausible tools. Then work the five domains in order for six weeks of about 8 to 10 hours a week, in proportion to the weights, and count a weak area as fixed only when a fresh retest says so.
What the exam measures, as of April 17, 2026
Microsoft's official AZ-104 study guide lists five skills domains, with weights for the skills measured as of April 17, 2026:
- Manage Azure identities and governance: 20-25%
- Implement and manage storage: 15-20%
- Deploy and manage Azure compute resources: 20-25%
- Implement and manage virtual networking: 15-20%
- Monitor and maintain Azure resources: 10-15%
The two 20-25% domains anchor the plan, and the lightest domain shares its week with mixed review. Format facts that shape the plan:
- A score of 700 or greater passes. Technical exam scores are reported on a scale of 1 to 1,000, and 700 is a scaled score, so it may not equal 70% of the points (exam scoring and score reports).
- You have 100 minutes, and the exam is proctored. If you fail, you can retake it 24 hours after the first attempt, and the wait varies for later retakes. You book through Pearson Vue (certification page, last updated April 17, 2026). At 100 minutes, a timed mixed run matters in the final week.
- The study guide links a free Microsoft Practice Assessment for the style and wording of the questions, and an exam sandbox where you can explore the exam environment.
- Most questions cover features that are in general availability, and the exam may include commonly used Preview features.
- The change log marks the April 17, 2026 version as minor changes to the audience profile and to five objectives across storage, compute, networking, and monitoring. Identity and governance carries no change rows, so notes written before that date may list slightly different items.
The audience profile expects familiarity with operating systems, networking, servers, and virtualization, and experience with PowerShell, Azure CLI, the Azure portal, ARM templates or Bicep files, and Microsoft Entra ID. If that list already describes your day job, you need a sequence and a retest method, and the plan below is built for that.
First action: take the free assessment and split the wrong answers
Take the free AZ-104 assessment without looking anything up. It needs no card, and it returns a Readiness Report that scores the attempt on a 1 to 1,000 scale, lists your top gaps, and previews a targeted repair. Set the score aside. The job of this step is a list of the decisions that cost you points.
Put each wrong answer in one of two piles. A missing fact (a name, a limit, a default) takes minutes to fix. A confusion between two plausible tools, such as a role assignment versus a policy or Backup versus Site Recovery, takes practice, because the next question words the same choice differently. That second pile decides where your extra hours go.
Six weeks, in this order
This plan assumes about 8 to 10 hours a week. Weeks follow the weights, and the lightest domain shares its week with mixed review.
- Week 1: identities and governance (20-25%). Done when you can say which resources an RBAC assignment, a policy, or a lock affects, without opening the portal.
- Week 2: storage (15-20%). Done when you can choose an access method and a redundancy option for a stated requirement.
- Week 3: compute (20-25%). Done when you can keep environment values out of the template and choose between VMs, containers, and App Service for a described workload.
- Week 4: virtual networking (15-20%). Done when you can trace a blocked connection through routes, NSGs, peering, and DNS.
- Week 5: monitoring, backup, and recovery (10-15%), plus mixed review. Done when you can choose between metrics, logs, and alerts, and between Backup and Site Recovery.
- Week 6: mixed timed practice and retests. Done when a fresh timed mix produces no new gaps from your list.
Identities and governance comes first because its scope decisions, who can act on which resources and where, show up in storage, compute, and networking questions too. Networking follows compute because a VM in front of you is what you test an NSG or a route against. If you are already strong in a domain, cut its week to two or three days and give the time to your weakest heavy domain. If networking is your weakest, start it earlier and give it more than a week. Its objectives span virtual networks, routes, NSGs, and name resolution at once.
Identities and governance (20-25%): name the scope before the tool
The domain's objectives split into two tools and a set of scopes. RBAC covers the built-in roles, assigning roles at different scopes, and interpreting access assignments. Governance covers Azure Policy, resource locks, tags, resource groups, subscriptions, and management groups, plus cost alerts and budgets. The exam cue for the tool is in the stem's wording. If a stem says a user cannot create or change something, suspect RBAC. If it says resources must carry a tag or stay in a region, suspect Policy. When the requirement is to prevent deletion or modification, the lock objective is the candidate answer. Scope is the second half of the decision. The objectives ask you to assign roles at different scopes and to read an assignment back, so practice stating which scope the stem assigns before you name what it allows.
The Microsoft Entra half covers users and groups: creating users and groups, managing properties and licenses, external users, and self-service password reset. Read the order of failure in the stem. If sign-in itself fails, the question is about the identity object, its state, or its license, and the answer lives in that half of the domain.
Practice by reading a scenario and naming the tool and the scope before you look at the options.
Storage (15-20%): work out which layer grants the access
Storage questions reward knowing where a permission is decided. The access objectives list the methods side by side: storage firewalls and virtual networks, shared access signature (SAS) tokens, stored access policies, access keys, and identity-based access for Azure Files. The stem's wording picks the method. A delegation to someone who should not hold a long-term credential points to a SAS token. A requirement to allow network access only from a specific virtual network points to the firewall setting. A requirement that only specific identities reach a file share points to identity-based access for Azure Files.
The second half of the domain is account configuration: creating and configuring storage accounts, redundancy, object replication, encryption, and data management with Storage Explorer and AzCopy. The data-protection objectives split by data type. Soft delete applies to blobs and to Azure Files, versioning and lifecycle management apply to blobs, and snapshots apply to Azure Files. When the stem says data must survive a zone or region failure, the decision is about copies, so look at the redundancy objectives. When it says data must survive accidental deletion or overwrite, the decision is about protection, so look at versioning, soft delete, and snapshots.
Practice by matching each access objective to the stem wording that selects it, and each protection objective to the data type it applies to.
Compute (20-25%): the template stays the same between environments
Compute spans templates, virtual machines, containers, and App Service, and the template objectives turn on one split, structure versus values. The objectives ask you to interpret and modify ARM templates and Bicep files, to deploy with them, and to export a deployment as a template or convert one to Bicep. Structure lives in the template, and values that vary between environments belong in a Bicep parameter file, a .bicepparam file that holds the values and passes them to the Bicep file (Bicep parameter files). The docs describe them for exactly this case, values that vary by subscription, environment, or region. The second cue is scope. A deployment runs at the scope where the target resources live, so a stem that creates resources in one resource group points to a resource group deployment. The tempting wrong move is to run from the broadest scope that can see the resources. The scope follows the target resources, not the visibility.
The rest of the domain is the services. The VM objectives cover creating and configuring virtual machines, encryption at host, moving a VM to another resource group, subscription, or region, sizes, disks, availability zones and sets, and scale sets. The container objectives name a container registry, Container Instances, and Container Apps, with sizing and scaling across them. The App Service objectives center on the plan behind the app, scaling, certificates and TLS, custom DNS names, backup, networking, and deployment slots.
When you read a deployment scenario, say where each changing value lives and at which scope the deployment runs before you look at the options.
Virtual networking (15-20%): trace the packet before you pick a fix
When a question describes blocked traffic, trace the path in order: source, destination, name resolution, route, security rule. The outline backs the order. Virtual networks, peering, public IP addresses, and user-defined routes come first, then NSGs, application security groups, Bastion, service endpoints, and private endpoints, then Azure DNS and load balancers. Pick the first point on the path where the stem says something is wrong, and answer there.
NSG questions add one rule you must know cold. NSG rules are processed in priority order, with lower numbers processed before higher numbers, and once traffic matches a rule, processing stops (NSG overview). An allow added at 300 does nothing if a deny at 200 matches the same traffic first, because the deny is reached first. The fix is a narrower allow at a lower number. The troubleshooting objectives ask you to work through connectivity and load balancing, so the tracing order above is the method the questions expect.
With a blocked-connection scenario, walk the five steps out loud and name what you would check at each step.
Monitoring and recovery (10-15%): protect the running system first
The domain has two halves. The first is monitoring. The objectives split by the kind of data: metrics, logs, and alerts with action groups, plus Azure Monitor Insights for virtual machines, storage accounts, and networks, and Network Watcher with Connection Monitor for network diagnostics. Read the job in the stem. A number over time is a metric. A record you query is a log. A notification or action that fires when a condition is met is an alert.
The second half is backup and recovery: Recovery Services vaults, Backup vaults, backup policies, restore operations, and Site Recovery with failover to a secondary region. Recovery questions hinge on what must not change while you recover. Read the stem for words like "must remain" or "validate before", and eliminate any option that touches the running system first. The tool choice has a cue in the objective wording itself: Site Recovery questions name a secondary region or a failover, and backup questions name a recovery point or a restore. The reports and alerts objectives mean the stem can also ask where backup health shows up, not just how a restore works.
Because it is the lightest domain at 10-15%, this week shares time with mixed review.
A weak area is fixed when a fresh retest says so
Rereading an explanation teaches you that one answer. It does not teach you whether you will spot the same problem in a new stem. So at the end of each week, check the domain again with questions you have not seen, and count it as fixed only when the confusion does not come back.
The CramHQ AZ-104 course is built around that loop. Start with the free assessment. It needs no card, and it returns a Readiness Report that scores the attempt on a 1 to 1,000 scale, lists your top gaps, and previews a targeted repair. The course page includes free practice questions with explanations. The paid course, $34.99 with 12 months of access, adds the Pass Plan, full practice tests, and a timed final simulation.
The readiness call: book or fix one domain
In the final week, take a fresh mixed set of practice questions with the timer on, and Microsoft's free Practice Assessment, which the study guide links. Count only the questions you have not seen before, and note which domain the wrong answers come from. If they spread thinly across the domains, book the exam through Pearson Vue. If one domain holds most of them, give it two more days and retest before you book. Use the exam sandbox the study guide links so the exam interface is not new on the day.
If this is a step in a longer path, the CramHQ AZ-104 course lists AZ-900 and AZ-305 as the related exams, and its path copy frames the move: administrator readiness is a strong bridge into Azure architecture, with fundamentals available for quick reinforcement.
