
Prepare for the azure administrator az-104 exam by covering identities and governance, storage, compute resources, virtual networks, and monitoring with recovery services and backup vaults, plus role-based access control.
Create and manage users and groups in Azure Active Directory, understanding cloud versus hybrid scenarios. Explore default permissions, member versus guest roles, and static and dynamic group memberships.
Explore how licensing in Azure Active Directory controls user access through licenses, groups, and three admin centers; learn license levels, assignment methods, and admin roles for Azure Active Directory licensing.
Explore azure active directory administrative units as containers to group users and devices. Understand limitations: no nesting, no automatic user inheritance, and licensing for admins under role-based access control.
Learn to identify and manage user and group properties in Azure Active Directory, edit user and group profiles in the portal, and apply RBAC basics for AZ-104 success.
Identify and manage device settings and identities in Azure Active Directory. Learn how to view device status, manage ownership and enrollment (domain-joined, Azure AD joined, hybrid), and access BitLocker keys.
Perform bulk updates in Azure Active Directory, including bulk create, delete, and invite external guests, using official CSV templates downloaded from the portal.
Discover how to manage guest accounts in Azure Active Directory, covering external identities, B2B collaboration, and invitation, onboarding, and permission practices for guest users.
Learn how to enable and configure self-service password reset in Azure Active Directory, including policy settings, authentication methods, and registration, with hybrid on-premises integration via Azure AD Connect.
Learn how Azure role-based access control uses built-in and custom roles to grant only the needed permissions to users or groups, with scope and just-in-time ABAC considerations.
Interpret access assignments and view role definitions across subscriptions and resources, using portal, powershell, cloud shell, and rest api to export data in csv or json.
Learn how Azure policy measures resource compliance, defines and groups business rules into definitions and initiatives, and uses dashboards and remediation to enforce governance at scale.
Configure resource locks in Azure to prevent deletions or modifications at subscription, resource group, or resource levels; learn portal and PowerShell usage and the inheritance rules.
Apply and manage resource tags as metadata using key-value pairs to describe and organize Azure resources, resource groups, and subscriptions, with creation and updates via portal or PowerShell.
Explore resource groups as containers for related resources and learn to manage them with the portal, including exporting templates, tagging, access control, and moving resources across subscriptions and regions.
Master Azure subscriptions and costs by creating budgets, setting alerts, and using cost management tools and the pricing calculator to forecast spending.
Learn how Azure management groups organize subscriptions in a tenant directory to apply policies, RBAC, and compliance across subscriptions and resources.
Create and configure Azure storage accounts, choosing standard general purpose v2 or premium blob options. Learn to manage endpoints, networking, redundancy, and security via portal, PowerShell, and ARM templates.
Learn how shared access signature tokens grant limited, time-bound access to Azure blob storage resources, covering user delegation SAS, service SAS, and account SAS, with permissions and expiry.
Explore how to safeguard storage account access keys, rotate keys regularly, and monitor key rotation using the portal and PowerShell, with reminders and built-in policies for AZ-104 readiness.
Enable Azure AD authentication for blob, queue, and table data by toggling from access keys in the portal, and use built-in RBAC roles to control access and verify permissions.
Explore how Azure storage encryption protects data at rest and in transit, covering default encryption, Microsoft managed keys, customer managed keys, key vaults, and encryption scopes.
Learn how to securely plan, prepare, and execute import and export data jobs with Azure data box and import export service, including encryption, journaling, and drive logistics.
Install and use the cross-platform Azure Storage Explorer to manage Azure storage locally with a graphical interface, supporting blob, file, queue, table, and data lake storage, plus local emulators.
Master azcopy to move blobs and files into an Azure storage account from outside Azure, set up and authenticate with Azure Active Directory, and run cross-platform transfers.
Learn how Azure storage redundancy protects data by creating three copies in the primary region and optionally replicating to a secondary region using local, zone, or geo redundant storage.
Configure object replication to asynchronously copy block blobs between storage accounts, improving latency and availability, with prerequisites like change feed and versioning, and noting it applies only to block blobs.
Create and configure an Azure file share in a storage account, enable large file share support, and map the share across Windows, Linux, and Mac clients.
Learn how to configure Azure blob storage, create storage accounts and containers, and manage block and page blobs with access levels, encryption options, and replication considerations.
Configure Azure storage tiers for blob data—hot, cool, and archive—at account or per-blob level to optimize performance and cost. Move between tiers via portal, PowerShell, Azure CLI, or AzCopy.
Discover blob lifecycle management in Azure storage, using policy-based rules to move blobs between tiers and delete or archive them based on creation date, modification, or last access.
Master azure resource manager templates to automate at-scale deployments with json blueprints that define resources, resource groups, regions, and dependencies for repeatable, error-free infrastructure.
Learn how virtual machine extensions extend functionality and automate deployments in Azure VMs. Deploy them during creation or on existing VMs via templates, the portal, or PowerShell, including third-party extensions.
Explore what virtual machines are and how to create them using the wizard and automation in Azure. Learn to configure compute resources, storage, networking, security, and deployment templates for automation.
Azure Compute Gallery centralizes images and application definitions, enabling global replication, zone-redundant storage, secure sharing, and access control for OS and VM images with high availability.
Learn how to configure Azure disk encryption for virtual machines, encrypting OS and data disks with BitLocker on Windows or DM-Crypt on Linux, using a Key Vault and TPM.
Move running virtual machines between resource groups, subscriptions, or regions using a three-step wizard, but validate dependencies and update tools since resource IDs change.
Learn how to resize an Azure virtual machine and add data disks, including restart implications, resource constraints, and encryption options like BitLocker and disk encryption for the AZ-104 exam.
Configure vm network settings by managing virtual networks, public ip addresses, network security groups, and load balancers to secure and optimize vm connectivity in Azure.
Explore Azure virtual machine availability options, including availability zones, availability sets, and virtual machine skill sets, with guidance on choosing for reliability, latency, and disaster recovery.
Create and manage virtual machine scale sets, configure availability zones, and select uniform or flexible orchestration with auto-scaling policies and health monitoring.
Explore Azure container instances (ACI) for simple, isolated container workloads, including single containers and container groups, with sizing, quotas, networking, persistence, and monitoring.
Configure storage for AKS by creating persistent volumes and claims, selecting storage classes and CSI drivers, and persisting data across pods using disks, files, or blob storage.
Configure scaling for AKS by adjusting the scale pool and node counts from the command line or portal, balancing manual and auto scaling for workloads.
Explore networking concepts for AKS and evaluate configuration options, including cluster networking with ingress controllers, load balancers, network policies, and private versus public connectivity in Azure.
Learn how to upgrade an Azure Kubernetes Service (AKS) cluster, using the portal or command line, manage the control plane and pool upgrades, verify versions, and handle upgrade options.
Explore creating and configuring Azure container apps, deploying container instances, and managing scale, networking, and monitoring for AZ-104, with hands-on portal and command-line guidance.
Learn how to create and deploy an Azure app service and its hosting plan, select languages and operating systems, choose regions, and use CI/CD, networking, and scaling options.
Secure an app service by configuring authentication and authorization, TLS/SSL and HTTPS, IP restrictions, private endpoints, and virtual network integration to protect app service plans and on-premises connectivity.
Map existing custom domain names to Azure services and configure DNS records such as A records and CNAME records, plus domain verification to prevent subdomain takeover.
Configure automated backups and custom backups for your Azure App Service, schedule backups, and restore from a backup to minimize downtime.
Configure deployment center options for ci/cd with external repositories, and manage staging slots to swap preproduction into production with zero downtime for high availability.
The Microsoft Azure Administrator (AZ-104) course is designed to prepare individuals for the role of Azure Administrator. The course covers a range of topics related to managing and monitoring Azure resources, implementing and managing Azure storage, deploying and managing Azure compute resources, configuring and managing Azure virtual networks, and managing Azure identities and governance.
Topics covered in the course include:
1. Azure administration, including managing Azure subscriptions, resources, and role-based access control (RBAC)
2. Azure storage, including implementing and managing Azure Blob storage, Azure Files, and Azure storage accounts
3. Azure compute, including deploying and managing Azure virtual machines (VMs) and Azure App Services
4. Azure networking, including configuring and managing Azure virtual networks (VNETs), Azure VPN Gateway, and Azure ExpressRoute
5. Azure identity, including managing Azure Active Directory (AD) users and groups, managing Azure AD integration with on-premises AD, and managing Azure AD application and service principals
6. Azure governance, including managing Azure policy and Azure Resource Manager (ARM) templates.
Upon completing the course and passing the certification exam, candidates will have a solid understanding of managing and monitoring Azure resources and will be able to implement and manage Azure storage, compute, and networking resources. They will also have a strong understanding of Azure identity and governance, and will be able to manage Azure Active Directory and implement Azure policies.