Microsoft / Azure Azure Administrator Study Library
AZ-104
19 free articles on the concepts the AZ-104 exam tests, grouped by exam domain. Each one backs real questions in our practice exam.
Deploy and manage Azure compute resources
- ARM Templates vs Bicep: Why Bicep Is Now the Recommended Azure IaC Language ARM templates vs Bicep: how Bicep compiles to ARM JSON, Incremental vs Complete deployment modes, deployment stacks, and the what-if operation.
- Azure App Service Deployment Slots Explained: Swapping, Sticky Settings, and Swap with Preview How App Service slot swapping actually works, which settings stick to a slot vs swap with the app, swap with preview, and the tier requirement for slots.
- Azure Availability Sets vs Availability Zones: Fault and Update Domains, SLA How availability sets and availability zones protect Azure VMs differently, their SLA numbers, and how VM Scale Set orchestration modes relate to both.
- Azure Container Instances vs Container Apps vs AKS: Choosing the Right Container Compute When a single ACI container group is enough, when Container Apps' KEDA autoscaling and Dapr fit, and when AZ-104 wants full Kubernetes control (AKS).
- Azure VM Disk Encryption Options: Azure Disk Encryption vs Encryption at Host ADE, encryption at host, and confidential disk encryption compared. ADE retires September 2028, so here's what AZ-104 wants you to deploy instead.
Implement and manage storage
- Azure Blob Storage Access Tiers Compared: Hot, Cool, Cold, and Archive Compare Hot, Cool, Cold, and Archive tiers by cost, latency, minimum retention, and rehydration time, plus how lifecycle policies automate tiering.
- Azure Files vs Azure Blob Storage: Choosing File Shares vs Object Storage Azure Files vs Blob Storage: when you need an SMB/NFS share vs object storage, identity-based auth options, and how Azure File Sync fits hybrid setups.
- Azure Storage Redundancy Options Compared: LRS, ZRS, GRS, GZRS, and the RA- Variants LRS, ZRS, GRS, GZRS and their read-access variants compared: durability numbers, failover types, and how an administrator should choose between them.
- Shared Access Signatures (SAS) in Azure Storage: Account, Service, and User Delegation SAS Explained Account SAS vs service SAS vs user delegation SAS compared: what each can scope, stored access policies, and why Entra-signed SAS is now recommended.
Implement and manage virtual networking
- Azure Load Balancer vs Application Gateway vs Traffic Manager vs Front Door Compare Azure's four load-balancing services by OSI layer and scope, and see why Basic Load Balancer's Sept 2025 retirement changed the exam answer.
- Azure Virtual Network Peering Explained: Non-Transitive by Design How Azure VNet peering works, why it's non-transitive, gateway transit, global peering, and how a hub NVA with UDRs works around the limits.
- NSG vs Azure Firewall vs Azure Bastion: Layered Azure Network Security NSGs filter at the subnet/NIC, Azure Firewall centralizes threat-aware filtering, and Bastion removes public IPs from VMs entirely. How they layer.
Manage Azure identities and governance
- Azure Policy vs. Azure RBAC: Controlling Who Can Act vs. What State Resources Must Be In RBAC controls who can act at a scope. Policy controls what state resources must be in, no matter who created them. Effects and exemptions explained.
- Azure RBAC Built-In Roles Explained: Owner, Contributor, Reader, and Access Administrators What Owner, Contributor, Reader, User Access Administrator, and RBAC Administrator each grant, and how PIM eligible vs. active roles fit in.
- Azure Resource Locks Explained: CanNotDelete vs. ReadOnly, Inheritance, and Who Can Remove One CanNotDelete and ReadOnly locks compared: how inheritance works, the RBAC permission needed to remove one, and why ReadOnly can silently break VM resizing.
- Microsoft Azure Administrator (AZ-104) Study Guide: Format, Domains, Cost, and How to Pass Complete AZ-104 guide: exam format, passing score, and $165 fee, plus all five domains explained and a study plan mapped to every AZ-104 topic.
- The Azure Resource Hierarchy: Management Groups, Subscriptions, and Resource Groups How management groups, subscriptions, resource groups, and resources nest, how RBAC and Policy inherit down that chain, and where the tree ends.
Monitor and maintain Azure resources
- Azure Backup vs Azure Site Recovery: Data Protection vs Disaster Recovery Backup restores data to a point in time after loss or corruption. Site Recovery fails an entire workload over to another region. Learn when to use each.
- Azure Monitor Metrics vs Logs: Data Collection Rules and the Azure Monitor Agent Metrics are numeric time-series data; logs are queryable records in KQL. Learn the split, plus Data Collection Rules and why the legacy agent matters now.
Reading is step one — practicing is what passes the exam.
1,300 original AZ-104 questions, every answer explained, $59 once — no subscription.