The Integrated AZ-104: Microsoft Azure Administrator Associate Study Guide [220 Minute Read]
A First-Principles Approach to Azure Administration, Exam Readiness, and Professional Application on Azure
Welcome to 'The Integrated AZ-104 Study Guide,' meticulously crafted to embody a craftsman's spirit – in its design and content, fostering a deep, practical understanding of Azure administration principles. You will build knowledge from foundational truths, understanding the 'why' behind every configuration, every management decision, and every security control.
This guide is structured into digestible, focused learning blocks, each designed to deliver a specific piece of knowledge. Every topic is aligned with the official AZ-104 exam objectives, targeting the 'implement, manage, and monitor' cognitive level required for success. Prepare to design, build, optimize, and troubleshoot cloud solutions on Azure, and to approach the exam with confidence and a profound understanding of operational excellence in cloud administration.
(Table of Contents - For Reference)
-
Phase 1: Foundational Principles & Core Azure Concepts
- 1.1. Welcome to the AZ-104 Study Guide: A Craftsman's Approach
- 1.2. Understanding the AZ-104 Exam: Purpose & Audience
- 1.3. Core Azure Concepts First Principles
- 1.3.1. 💡 First Principle: Regions & Availability Zones
- 1.3.2. 💡 First Principle: Resource Groups
- 1.3.3. 💡 First Principle: Azure Resource Manager (ARM)
- 1.3.4. 💡 First Principle: Subscriptions
- 1.3.5. 💡 First Principle: Management Groups
- 1.4. The Azure Shared Responsibility Model
- 1.4.1. Shared Responsibility: Microsoft's Role
- 1.4.2. Shared Responsibility: Customer's Role
- 1.5. Navigating the Azure Portal and CLI
- 1.6. Reflection Checkpoint: Setting the Stage
-
Phase 2: Implementing & Managing Azure Identities & Governance
- 2.1. Domain Overview: Managing Azure Identities & Governance
- 2.1.1. Create and Configure Users and Groups
- 2.1.1.1. Create Users and Groups
- 2.1.1.2. Manage User and Group Properties
- 2.1.1.3. Manage Device Identities
- 2.1.1.4. Configure Entra ID Join
- 2.1.2. Manage Role-Based Access Control (RBAC)
- 2.1.2.1. Create Custom Roles
- 2.1.2.2. Configure Azure Built-in Roles
- 2.1.2.3. Assign Roles to Users, Groups, and Applications
- 2.1.2.4. Interpret Access Assignments
- 2.1.3. Configure Azure Policy and Resource Locks
- 2.1.3.1. Implement Azure Policy
- 2.1.3.2. Configure Resource Locks
- 2.1.4. Manage Azure Subscriptions and Governance
- 2.1.4.1. Manage Resource Groups
- 2.1.4.2. Manage Azure Subscriptions
- 2.1.4.3. Configure Cost Management
- 2.1.4.4. Configure Management Groups
- 2.1.1. Create and Configure Users and Groups
- 2.2. Reflection Checkpoint: Identity and Governance Mastery
- 2.1. Domain Overview: Managing Azure Identities & Governance
-
Phase 3: Implementing & Managing Azure Storage
- 3.1. Domain Overview: Implementing & Managing Azure Storage
- 3.1.1. Create and Configure Storage Accounts
- 3.1.1.1. Create and Configure Storage Accounts
- 3.1.1.2. Configure Network Access to Storage Accounts
- 3.1.1.3. Configure Blob Storage
- 3.1.1.4. Configure Storage Tiers
- 3.1.1.5. Configure Azure Files
- 3.1.1.6. Implement Azure Storage Explorer
- 3.1.2. Manage Blob Storage Lifecycle
- 3.1.2.1. Upload and Download Blobs
- 3.1.2.2. Manage Blob Lifecycle Policies
- 3.1.2.3. Implement Blob Versioning
- 3.1.2.4. Configure Blob Soft Delete
- 3.1.3. Manage Azure File Shares
- 3.1.3.1. Create and Configure Azure File Shares
- 3.1.3.2. Configure Azure File Sync
- 3.1.4. Implement Azure Backup and Recovery
- 3.1.4.1. Create and Configure a Recovery Services Vault
- 3.1.4.2. Configure Azure Backup for VMs
- 3.1.4.3. Configure Azure Backup for Azure Files
- 3.1.4.4. Perform a Restore Operation
- 3.1.1. Create and Configure Storage Accounts
- 3.2. Reflection Checkpoint: Storage Solutions
- 3.1. Domain Overview: Implementing & Managing Azure Storage
-
Phase 4: Deploying & Managing Azure Compute Resources
- 4.1. Domain Overview: Deploying & Managing Azure Compute Resources
- 4.1.1. Configure Virtual Machines (VMs)
- 4.1.1.1. Configure VM Sizes
- 4.1.1.2. Configure VM Availability Options
- 4.1.1.3. Configure VM Storage
- 4.1.1.4. Configure VM Networking
- 4.1.2. Deploy Virtual Machines (VMs)
- 4.1.2.1. Create VMs from Azure Marketplace
- 4.1.2.2. Create VMs from Custom Images
- 4.1.2.3. Deploy VMs using Azure Resource Manager (ARM) Templates
- 4.1.3. Implement VM Security
- 4.1.3.1. Configure Azure Disk Encryption
- 4.1.3.2. Configure Azure Bastion
- 4.1.4. Configure Load Balancing for VMs
- 4.1.4.1. Configure Azure Load Balancer
- 4.1.4.2. Configure Azure Application Gateway
- 4.1.4.3. Implement Azure Virtual Machine Scale Sets (VMSS)
- 4.1.5. Manage App Service Resources
- 4.1.5.1. Create and Configure App Service Plans
- 4.1.5.2. Configure App Service Deployments
- 4.1.5.3. Configure Custom Domains and SSL Certificates
- 4.1.6. Manage Container Resources
- 4.1.6.1. Create and Configure ACI
- 4.1.6.2. Deploy Containerized Applications to ACI
- 4.1.6.3. Create and Configure AKS Clusters
- 4.1.6.4. Deploy Applications to AKS
- 4.1.1. Configure Virtual Machines (VMs)
- 4.2. Reflection Checkpoint: Compute Resources
- 4.1. Domain Overview: Deploying & Managing Azure Compute Resources
-
Phase 5: Configuring & Managing Azure Virtual Networking
- 5.1. Domain Overview: Configuring & Managing Azure Virtual Networking
- 5.1.1. Configure Virtual Networks
- 5.1.1.1. Configure Virtual Networks and Subnets
- 5.1.1.2. Configure Network Security Groups (NSGs)
- 5.1.1.3. Configure Azure Firewall
- 5.1.1.4. Configure Azure DNS
- 5.1.2. Configure IP Addressing
- 5.1.2.1. Configure Public and Private IP Addresses
- 5.1.2.2. Configure Network Interfaces
- 5.1.3. Implement Connectivity Between Networks
- 5.1.3.1. Configure VNet Peering
- 5.1.3.2. Configure VPN Gateway
- 5.1.3.3. Configure ExpressRoute
- 5.1.4. Implement Azure Load Balancing and Application Gateway
- 5.1.4.1. Configure Internal and Public Load Balancers
- 5.1.4.2. Configure Load Balancing Rules
- 5.1.4.3. Configure Application Gateway Listeners, Rules, and Backend Pools
- 5.1.4.4. Configure Web Application Firewall (WAF)
- 5.1.5. Configure Azure DNS for Networking
- 5.1.5.1. Configure Azure DNS Zones and Record Sets
- 5.1.5.2. Configure Private DNS Zones
- 5.1.1. Configure Virtual Networks
- 5.2. Reflection Checkpoint: Networking Solutions
- 5.1. Domain Overview: Configuring & Managing Azure Virtual Networking
-
Phase 6: Monitoring & Maintaining Azure Resources
- 6.1. Domain Overview: Monitoring & Maintaining Azure Resources
- 6.1.1. Configure Azure Monitor Metrics and Logs
- 6.1.2. Implement Azure Monitor Alerts
- 6.1.2.1. Create Alert Rules
- 6.1.2.2. Configure Action Groups
- 6.1.3. Analyze Monitoring Data
- 6.1.3.1. Configure Log Analytics Workspaces
- 6.1.3.2. Perform Log Queries by Using Kusto Query Language (KQL)
- 6.1.3.3. Configure Diagnostic Settings
- 6.1.4. Utilize Network Watcher
- 6.1.5. Configure Azure Service Health Alerts
- 6.2. Reflection Checkpoint: Monitoring and Maintenance
- 6.1. Domain Overview: Monitoring & Maintaining Azure Resources
-
Phase 7: Exam Readiness & Mastery
- 7.1. Practice Exam Strategies
- 7.1.2. Time Management and Pacing
- 7.1.3. Review of Key Concepts
- 7.1.4. Next Steps in Your Azure Journey
- 7.1.5. Final Encouragement
-
Phase 8: Glossary