AZ-103: Microsoft Azure Administrator

AZ-103: Microsoft Azure Administrator is part of the requirements for the Microsoft Certified: Azure Administrator Associate

Exam requirements

The official exam document are published here:

Exam preparation

This exam preparation is the for the old AZ-100: Infrastructure & Deployment and not the updated AZ-103 exam.

Books covering the exam

Exam Ref AZ-103 Microsoft Azure Administrator, 1st Edition

  • Author: Michael Washam, Jonathan Tuliani, Scoot Hoag
  • ISBN-13: 978-0135466582
  • ISBN-10: 013546658X

Pre-order on or Microsoft Press Store by Pearson

Video training for the exam



Online training

Microsoft Learn (free)

Open edX (free)

Instructor-led training

Exam Objectives

Manage Azure subscriptions and resources (15-20%)

  • Manage Azure subscriptions
    • Assign administrator permissions
    • Configure cost center quotas and tagging
    • Configure Azure subscription policies at Azure subscription level
  • Analyze resource utilization and consumption
    • Configure diagnostic settings on resources
    • Create baseline for resources
    • Create and rest alerts
    • Analyze alerts across subscription
    • Analyze metrics across subscription
    • Create action groups
    • Monitor for unused resources
    • Monitor spend
    • Report on spend
    • Utilize Log Search query functions
    • View alerts in Log Analytics
  • Manage resource groups
    • Use Azure policies for resource groups
    • Configure resource locks
    • Configure resource policies
    • Identify auditing requirements
    • Implement and set tagging on resource groups
    • Move resources across resource groups
    • Remove resource groups
  • Managed role based access control (RBAC)
    • Create a custom role
    • Configure access to Azure resources by assigning roles
    • Configure management access to Azure, troubleshoot RBAC, implement RBAC policies, assign RBAC Roles

Implement and manage storage (15-20%)

  • Create and configure storage accounts
    • Configure network access to the storage account
    • Create and configure storage account
    • Generate shared access signature
    • Install and use Azure Storage Explorer
    • Manage access keys
    • Monitor activity log by using Log Analytics
    • Implement Azure storage replication
  • Import and export data to Azure
    • Create export from Azure job
    • Create import into Azure job
    • Use Azure Data Box
    • Configure and use Azure blob storage
    • Configure Azure content delivery network (CDN) endpoints
  • Configure Azure files
    • Create Azure file share
    • Create Azure File Sync service
    • Create Azure sync group
    • Troubleshoot Azure File Sync
  • Implement Azure backup
    • Configure and review backup reports
    • Perform backup operation
    • Create Recovery Services Vault
    • Create and configure backup policy
    • Perform a restore operation

Deploy and manage virtual machines (VMs) (15-20%)

  • Create and configure a VM for Windows and Linux
    • Configure high availability
    • Configure monitoring, networking, storage, and virtual machine size
    • Deploy and configure scale sets
  • Automate deployment of VMs
    • Modify Azure Resource Manager (ARM) template
    • Configure location of new VMs
    • Configure VHD template
    • Deploy from template
    • Save a deployment as an ARM template
    • Deploy Windows and Linux VMs
  • Manage Azure VM
    • Add data discs
    • Add network interfaces
    • Automate configuration management by using PowerShell Desired State Configuration (DSC) and VM Agent by using custom script extensions
    • Manage VM sizes
    • Move VMs from one resource group to another
    • Redeploy VMs
  • Manage VM backups
    • Configure VM backup
    • Define backup policies
    • Implement backup policies
    • Perform VM restore
    • Azure Site Recovery

Configure and manage virtual networks (30-35%)

  • Create connectivity between virtual networks
    • Create and configure VNET peering
    • Create and configure VNET to VNET
    • Verify virtual network connectivity
    • Create virtual network gateway
  • Implement and manage virtual networking
    • Configure private and public IP addresses
    • Configure network routes
    • Configure network interface
    • Configure subnets
    • Configure virtual network
  • Configure name resolution
    • Configure Azure DNS
    • Configure custom DNS settings
    • Configure private and public DNS zones
  • Create and configure a Network Security Group (NSG)
    • Create security rules
    • Associate NSG to a subnet or network interface
    • Identify required ports
    • Evaluate effective security rules
  • Implement Azure load balancer
    • Configure internal load balancer
    • Configure load balancing rules
    • Configure public load balancer
    • Troubleshoot load balancing
  • Monitor and troubleshoot virtual networking
    • Monitor on-premises connectivity
    • Use Network resource monitoring
    • Use Network Watcher
    • Troubleshoot external networking
    • Troubleshoot virtual network connectivity
  • Integrate on premises network with Azure virtual network
    • Create and configure Azure VPN Gateway
    • Create and configure site to site VPN
    • Configure Express Route
    • Verify on premises connectivity
    • Troubleshoot on premises connectivity with Azure

Manage identities (15-20%)

  • Manage Azure Active Directory (AD)
    • Add custom domains
    • Azure AD Join
    • Configure self-service password reset
    • Manage multiple directories
  • Manage Azure AD objects (users, groups, and devices)
    • Create users and groups
    • Manage user and group properties
    • Manage device settings
    • Perform bulk user updates
    • Manage guest accounts
  • Implement and manage hybrid identities
    • Install Azure AD Connect, including password hash and pass-through synchronization
    • Use Azure AD Connect to configure federation with on-premises Active Directory Domain Services (AD DS)
    • Manage Azure AD Connect
    • Manage password sync and password writeback
  • Implement multi-factor authentication (MFA)
    • Configure user accounts for MFA
    • Enable MFA by using bulk update
    • Configure fraud alerts
    • Configure bypass options
    • Configure Trusted IPs
    • Configure verification methods