LevelUpWith

Explore / Careers & Certification

Microsoft Azure Administrator (AZ-104) Exam Prep

Illustrated cover for the course “Microsoft Azure Administrator (AZ-104) Exam Prep”

Work through every bullet of the AZ-104 skills measured as of April 17, 2026, learning each task in the Azure portal, Azure CLI, PowerShell, and ARM templates or Bicep, with original scenario questions that explain every distractor. This is independent preparation, not affiliated with Microsoft, and

Expert · 60 levels · 2 free · Created Oct 2026 · Professionally curated by levelupwith.com

What's inside

  1. Level 1: AZ-104 Orientation and the Four Admin ToolsFree
    [Exam orientation] Sets out the exam (100 minutes, pass at 700 of 1,000, five skill areas by weighting), states that this course is independent of Microsoft and promises no pass, and introduces the four tools every later task is shown in: the Azure portal, Azure CLI, Azure PowerShell, and ARM templates or Bicep files.
  2. Level 2: Microsoft Entra ID Tenants and Creating UsersFree
    [Manage Azure identities and governance: Manage Microsoft Entra users and groups] Explains from first principles what a Microsoft Entra tenant is and how it relates to subscriptions, then teaches the 'Create users' bullet in the portal, Azure CLI and PowerShell.
  3. Level 3: Creating Groups: Types and Membership
    [Manage Azure identities and governance: Manage Microsoft Entra users and groups] Teaches the 'Create groups' bullet: Security versus Microsoft 365 groups and the Assigned, Dynamic user and Dynamic device membership types.
  4. Level 4: Managing User and Group Properties
    [Manage Azure identities and governance: Manage Microsoft Entra users and groups] Teaches the 'Manage user and group properties' bullet: editing profile attributes, writing and troubleshooting dynamic membership rules, nesting groups, and deleting and restoring users and groups.
  5. Level 5: Managing Licenses in Microsoft Entra ID
    [Manage Azure identities and governance: Manage Microsoft Entra users and groups] Teaches the 'Manage licenses in Microsoft Entra ID' bullet: direct versus group-based license assignment, the usage location requirement, and resolving assignment errors.
  6. Level 6: Managing External Users
    [Manage Azure identities and governance: Manage Microsoft Entra users and groups] Teaches the 'Manage external users' bullet: inviting guests through B2B collaboration, the invitation and redemption flow, and external collaboration settings.
  7. Level 7: Configuring Self-Service Password Reset (SSPR)
    [Manage Azure identities and governance: Manage Microsoft Entra users and groups] Teaches the 'Configure self-service password reset (SSPR)' bullet: enabling it for None, Selected or All users, authentication methods, registration and notifications.
  8. Level 8: Built-in Azure Roles and Role Definitions
    [Manage Azure identities and governance: Manage access to Azure resources] Teaches the 'Manage built-in Azure roles' bullet: how Azure role-based access control differs from Microsoft Entra roles, the key built-in roles, and how a role definition's Actions, NotActions, DataActions and NotDataActions are read.
  9. Level 9: Assigning Roles at Different Scopes
    [Manage Azure identities and governance: Manage access to Azure resources] Teaches the 'Assign roles at different scopes' bullet: the security principal, role definition and scope that make up a role assignment, and inheritance from management group to subscription, resource group and resource.
  10. Level 10: Interpreting Access Assignments
    [Manage Azure identities and governance: Manage access to Azure resources] Teaches the 'Interpret access assignments' bullet: working out a principal's effective access from several additive assignments, group memberships and deny assignments.
  11. Level 11: Management Groups and Subscriptions
    [Manage Azure identities and governance: Manage Azure subscriptions and governance] Teaches the 'Configure management groups' and 'Manage subscriptions' bullets: the tenant root management group, building a hierarchy, and placing and moving subscriptions within it.
  12. Level 12: Resource Groups and Resource Locks
    [Manage Azure identities and governance: Manage Azure subscriptions and governance] Teaches the 'Manage resource groups' and 'Configure resource locks' bullets: creating and deleting resource groups, moving resources between them, and the CanNotDelete and ReadOnly locks.
  13. Level 13: Applying and Managing Tags
    [Manage Azure identities and governance: Manage Azure subscriptions and governance] Teaches the 'Apply and manage tags on resources' bullet: tag name and value pairs, the fact that tags are not inherited by default, and using tags to organise and report on resources.
  14. Level 14: Implementing and Managing Azure Policy
    [Manage Azure identities and governance: Manage Azure subscriptions and governance] Teaches the 'Implement and manage Azure Policy' bullet: policy definitions, initiatives, assignments, effects, exclusions, compliance and remediation tasks.
  15. Level 15: Managing Costs: Alerts, Budgets and Azure Advisor
    [Manage Azure identities and governance: Manage Azure subscriptions and governance] Teaches the 'Manage costs by using alerts, budgets, and Azure Advisor recommendations' bullet using cost analysis, budgets, cost alerts and Advisor's Cost recommendations.
  16. Level 16: Creating and Configuring Storage Accounts
    [Implement and manage storage: Configure and manage storage accounts] Explains Azure Storage from first principles (blob, file, queue and table services and their endpoints) and teaches the 'Create and configure storage accounts' bullet: account kinds, performance tiers and naming rules.
  17. Level 17: Configuring Azure Storage Redundancy
    [Implement and manage storage: Configure and manage storage accounts] Teaches the 'Configure Azure Storage redundancy' bullet: LRS, ZRS, GRS, GZRS and the read-access variants RA-GRS and RA-GZRS, the secondary endpoint, and failover.
  18. Level 18: Azure Storage Firewalls and Virtual Networks
    [Implement and manage storage: Configure access to storage] Teaches the 'Configure Azure Storage firewalls and virtual networks' bullet: public network access settings, the default network rule, IP rules, virtual network rules and exceptions for trusted Azure services.
  19. Level 19: Managing Storage Access Keys
    [Implement and manage storage: Configure access to storage] Teaches the 'Manage access keys' bullet: what the two account keys authorise, how to rotate them without downtime, and how to disallow Shared Key authorization in favour of Microsoft Entra ID.
  20. Level 20: Creating and Using SAS Tokens
    [Implement and manage storage: Configure access to storage] Teaches the 'Create and use shared access signature (SAS) tokens' bullet: account SAS, service SAS and user delegation SAS, and the permissions, start and expiry times, allowed IP addresses and protocol encoded in a token.
  21. Level 21: Azure Storage Redundancy: LRS, ZRS, GRS and GZRS
    [Implement and manage storage] Serves 'Configure Azure Storage redundancy': how locally redundant, zone-redundant, geo-redundant and geo-zone-redundant storage copy data, what read access to the secondary region adds, and how to change the setting or fail over.
  22. Level 22: Storage Account Encryption and Key Management
    [Implement and manage storage] Serves 'Configure storage account encryption': how Azure Storage encrypts data at rest, and how to move from Microsoft-managed keys to customer-managed keys in Azure Key Vault, add infrastructure encryption and use encryption scopes.
  23. Level 23: Moving Data with Azure Storage Explorer and AzCopy
    [Implement and manage storage] Serves 'Manage data by using Azure Storage Explorer and AzCopy': connecting to storage and uploading, downloading, copying and synchronising blobs and files with the graphical tool and the command-line tool.
  24. Level 24: Azure Files: File Shares, Snapshots and Soft Delete
    [Implement and manage storage] Serves 'Create and configure a file share in Azure Files' and 'Configure snapshots and soft delete for Azure Files': creating SMB and NFS shares, setting size and tier, mounting them, and protecting them with share snapshots and soft delete.
  25. Level 25: Blob Containers, Storage Tiers and Lifecycle Management
    [Implement and manage storage] Serves 'Create and configure a container in Azure Blob Storage', 'Configure storage tiers' and 'Configure blob lifecycle management': creating containers, placing blobs in the hot, cool, cold and archive access tiers, and automating tier changes and deletion with rules.
  26. Level 26: Blob Soft Delete, Versioning and Object Replication
    [Implement and manage storage] Serves 'Configure soft delete for blobs and containers', 'Configure blob versioning' and 'Configure object replication': protecting blob data from deletion and overwrite, and asynchronously copying block blobs between storage accounts.
  27. Level 27: Interpreting ARM Templates and Bicep Files
    [Deploy and manage Azure compute resources] Serves 'Interpret an Azure Resource Manager template or a Bicep file': how Azure Resource Manager deploys declaratively, and how to read the same deployment written as ARM template JSON and as Bicep.
  28. Level 28: Modifying ARM Templates and Bicep Files
    [Deploy and manage Azure compute resources] Serves 'Modify an existing Azure Resource Manager template' and 'Modify an existing Bicep file': editing a working template to add resources, parameters, constraints and outputs without breaking it.
  29. Level 29: Deploying, Exporting and Converting Templates
    [Deploy and manage Azure compute resources] Serves 'Deploy resources by using an Azure Resource Manager template or a Bicep file' and 'Export a deployment as an Azure Resource Manager template or convert an Azure Resource Manager template to a Bicep file'.
  30. Level 30: Creating a Virtual Machine
    [Deploy and manage Azure compute resources] Serves 'Create a virtual machine': the resources a virtual machine is built from (image, size, OS disk, network interface, virtual network, public IP address) and how to create and connect to Windows and Linux VMs with each tool.
  31. Level 31: VM Sizes, Disks and Encryption at Host
    [Deploy and manage Azure compute resources] Serves 'Manage virtual machine sizes', 'Manage virtual machine disks' and 'Configure encryption at host for Azure virtual machines': resizing VMs, working with managed disks, and encrypting data on the VM host.
  32. Level 32: Availability Zones, Availability Sets and Moving VMs
    [Deploy and manage Azure compute resources] Serves 'Deploy virtual machines to availability zones and availability sets' and 'Move a virtual machine to another resource group, subscription, or region'.
  33. Level 33: Azure Virtual Machine Scale Sets
    [Deploy and manage Azure compute resources] Serves 'Deploy and configure an Azure Virtual Machine Scale Sets': running a group of load-balanced VMs that scale manually or by autoscale rules, and keeping their instances up to date.
  34. Level 34: Azure Container Registry
    [Deploy and manage Azure compute resources] Serves 'Create and manage an Azure Container Registry': what a container image and a private registry are, and how to create a registry, put images into it and control who can pull them.
  35. Level 35: Azure Container Instances: Provisioning and Sizing
    [Deploy and manage Azure compute resources] Serves 'Provision a container by using Azure Container Instances' and the Container Instances part of 'Manage sizing and scaling for containers': running containers without managing VMs, in container groups with fixed CPU and memory.
  36. Level 36: Azure Container Apps: Provisioning and Scaling
    [Deploy and manage Azure compute resources] Serves 'Provision a container by using Azure Container Apps' and the Container Apps part of 'Manage sizing and scaling for containers', and contrasts the service with Azure Container Instances.
  37. Level 37: App Service Plans, Apps and Scaling
    [Deploy and manage Azure compute resources] Serves 'Provision an App Service plan', 'Configure scaling for an App Service plan' and 'Create an App Service': how a plan supplies the compute that web apps run on, and how to scale it up and out.
  38. Level 38: App Service Custom DNS Names, Certificates and TLS
    [Deploy and manage Azure compute resources] Serves 'Map an existing custom DNS name to an App Service' and 'Configure certificates and Transport Layer Security (TLS) for an App Service'.
  39. Level 39: App Service Backup and Networking Settings
    [Deploy and manage Azure compute resources] Serves 'Configure backup for an App Service' and 'Configure networking settings for an App Service': protecting app content and controlling inbound and outbound traffic.
  40. Level 40: App Service Deployment Slots
    [Deploy and manage Azure compute resources] Serves 'Configure deployment slots for an App Service': running staging copies of an app with their own hostnames, and swapping them into production without downtime.
  41. Level 41: Virtual Networks and Subnets
    [Implement and manage virtual networking] Serves "Create and configure virtual networks and subnets": explains from first principles what a virtual network is, how address spaces and subnets are planned and which addresses Azure reserves in each subnet, then creates them in the portal, Azure CLI, PowerShell and Bicep.
  42. Level 42: Virtual Network Peering
    [Implement and manage virtual networking] Serves "Create and configure virtual network peering": teaches how peering joins two virtual networks over the Microsoft backbone, why it is not transitive, and how the peering settings for forwarded traffic and gateway transit change what can communicate.
  43. Level 43: Public IP Addresses
    [Implement and manage virtual networking] Serves "Configure public IP addresses": covers what a public IP address resource is, its SKU, static allocation and availability zone options, public IP prefixes, and how it is associated with network interfaces, load balancers and other resources.
  44. Level 44: User-Defined Routes and Connectivity Troubleshooting
    [Implement and manage virtual networking] Serves "Configure user-defined routes" and "Troubleshoot network connectivity": explains Azure system routes, how a route table with user-defined routes overrides them, and how to read effective routes and use next hop to find out why traffic takes the path it does.
  45. Level 45: Network Security Groups and Application Security Groups
    [Implement and manage virtual networking] Serves "Create and configure network security groups (NSGs) and application security groups": teaches how NSG security rules filter traffic by priority, the default rules, service tags, association with subnets and network interfaces, and how application security groups group virtual machines by role.
  46. Level 46: Evaluating Effective Security Rules
    [Implement and manage virtual networking] Serves "Evaluate effective security rules in NSGs": teaches how rules from a subnet NSG and a network interface NSG combine for inbound and outbound traffic, and how to read the effective security rules view and IP flow verify to decide whether a given packet is allowed.
  47. Level 47: Azure Bastion
    [Implement and manage virtual networking] Serves "Implement Azure Bastion": explains how Azure Bastion gives RDP and SSH access to virtual machines without public IP addresses on them, what the AzureBastionSubnet requires, and how the Bastion SKUs differ in features.
  48. Level 48: Service Endpoints for Azure PaaS
    [Implement and manage virtual networking] Serves "Configure service endpoints for Azure platform as a service (PaaS)": teaches how a service endpoint extends a subnet's identity to an Azure service over the backbone, how it pairs with virtual network rules on the service, and what it does not protect.
  49. Level 49: Private Endpoints for Azure PaaS
    [Implement and manage virtual networking] Serves "Configure private endpoints for Azure PaaS": teaches how a private endpoint places a private IP address for a specific PaaS resource in a subnet through Azure Private Link, the DNS configuration it depends on, and when to choose it over a service endpoint.
  50. Level 50: Azure DNS: Public and Private Zones
    [Implement and manage virtual networking] Serves "Configure Azure DNS": covers hosting a public DNS zone and delegating a domain to Azure name servers, record sets and alias records, and private DNS zones with virtual network links and auto-registration.
  51. Level 51: Azure Load Balancer: Configure and Troubleshoot
    [Implement and manage virtual networking] Serves "Configure an internal or public load balancer" and "Troubleshoot load balancing": teaches the frontend IP configuration, backend pool, health probe, load-balancing rule, inbound NAT rule and outbound rule, the difference between internal and public load balancers, and how to find why traffic is not reaching the backend.
  52. Level 52: Azure Monitor Metrics and Log Settings
    [Monitor and maintain Azure resources] Serves "Interpret metrics in Azure Monitor" and "Configure log settings in Azure Monitor": explains the Azure Monitor data platform from first principles, reads platform metrics in metrics explorer, and routes resource logs and the activity log with diagnostic settings to a Log Analytics workspace, storage account or event hub.
  53. Level 53: Querying Logs with KQL in Log Analytics
    [Monitor and maintain Azure resources] Serves "Query and analyze logs in Azure Monitor": teaches how to read and write Kusto Query Language queries in Log Analytics against workspace tables to filter, aggregate and chart log data.
  54. Level 54: Alert Rules, Action Groups and Alert Processing Rules
    [Monitor and maintain Azure resources] Serves "Set up alert rules, action groups, and alert processing rules in Azure Monitor": teaches how metric, log search and activity log alert rules evaluate a signal, how action groups define who is notified and what runs, and how alert processing rules suppress or add actions to fired alerts.
  55. Level 55: Azure Monitor Insights for VMs, Storage and Networks
    [Monitor and maintain Azure resources] Serves "Configure and interpret monitoring of virtual machines, storage accounts, and networks by using Azure Monitor Insights": teaches how to enable VM insights and read its performance and map views, and how to interpret the curated storage and network insights workbooks.
  56. Level 56: Azure Network Watcher and Connection Monitor
    [Monitor and maintain Azure resources] Serves "Use Azure Network Watcher and Connection monitor": surveys the Network Watcher monitoring and diagnostic tools beyond those used in earlier levels, and configures Connection monitor to test reachability and latency between sources and destinations continuously.
  57. Level 57: Recovery Services Vaults, Backup Vaults and Backup Policies
    [Monitor and maintain Azure resources] Serves "Create a Recovery Services vault", "Create an Azure Backup vault" and "Create and configure a backup policy": explains what each vault type stores and which workloads it protects, the vault's redundancy and soft delete settings, and how a backup policy sets schedule and retention.
  58. Level 58: Azure Backup Operations, Reports and Alerts
    [Monitor and maintain Azure resources] Serves "Perform backup and restore operations by using Azure Backup" and "Configure and interpret reports and alerts for backups": teaches how to enable backup, run on-demand backups and restore virtual machines, disks, files and file shares, then how to configure Backup reports and alerts and read them.
  59. Level 59: Azure Site Recovery and Failover to a Secondary Region
    [Monitor and maintain Azure resources] Serves "Configure Azure Site Recovery for Azure resources" and "Perform a failover to a secondary region by using Site Recovery": teaches how Site Recovery replicates Azure virtual machines to another region, how replication policies and recovery plans work, and the sequence of test failover, failover, commit, reprotect and failback.
  60. Level 60: Timed Mock Exam: 50 Questions in 100 Minutes Timed mock
    [All five skill areas] A timed mock exam of 50 original scenario questions in 100 minutes with a 70% pass mark, testing identities and governance, storage, compute, virtual networking, and monitoring and maintenance in proportion to their exam weightings; it is independent of Microsoft and does not guarantee a pass on the real exam.

Access

The first 2 levels are free with a free account. Every level, the podcast edition and the AI tutor come with All Access at £4.99/month or any Creator plan — see pricing.

Start free →