Five domains, with weights set by Microsoft's April 2026 update. Every domain summary below is paraphrased from the official skills outline; bullet-level objectives in Azure Mastery are tagged so you always know which domain you're being tested on and where your weak spots cluster.
Manage Azure identities and governance20–25%
The largest domain by typical question count, and the one everything else depends on. Covers Microsoft Entra ID user and group management, license assignment, external users, and self-service password reset (SSPR); managing access via built-in Azure roles assigned at different scopes (management group, subscription, resource group, resource); subscription and governance tooling — Azure Policy, resource locks, tags, resource groups, cost management with alerts and budgets, and management groups. Around 8–15 questions per sitting.
Implement and manage storage15–20%
Configure access to storage via firewalls and virtual network rules, SAS tokens, stored access policies, access keys, and identity-based access for Azure Files. Configure storage accounts including redundancy options, object replication, and encryption. Configure Azure Files (file shares, snapshots, soft delete) and Azure Blob Storage (containers, tiers, soft delete, lifecycle management, versioning). Around 6–12 questions.
Deploy and manage Azure compute resources20–25%
Automate deployment using ARM templates or Bicep — interpret existing files, modify them, deploy resources, and convert between formats. Create and configure virtual machines including encryption at host, sizing, disks, availability zones and sets, and Virtual Machine Scale Sets. Provision and manage containers via Azure Container Registry, Container Instances, and Container Apps. Configure Azure App Service — service plans, scaling, certificates, custom DNS, deployment slots, and networking. Around 8–15 questions.
Implement and manage virtual networking15–20%
Configure virtual networks, subnets, peering, public IPs, user-defined routes, and troubleshoot connectivity. Configure secure access via NSGs, application security groups, Azure Bastion, service endpoints, and private endpoints. Configure name resolution (Azure DNS) and load balancing (internal and public load balancers). Around 6–12 questions.
Monitor and maintain Azure resources10–15%
Monitor with Azure Monitor — metrics, log settings, log queries, alert rules, action groups, alert processing rules, Insights for VMs/storage/networks, plus Azure Network Watcher with Connection Monitor. Implement backup and recovery using Recovery Services vaults, Azure Backup vaults, backup policies, and Azure Site Recovery for failover to a secondary region. Around 4–9 questions.