Four design domains, with weights set by Microsoft's April 2026 update. Every domain summary below is paraphrased from the official skills outline. AZ-305 questions test design judgement — picking the right Azure service for a given requirement — rather than configuration recall. Bullet-level objectives in Azure Mastery are tagged so you always know which domain you're being tested on.
Design identity, governance, and monitoring solutions25–30%
Recommend authentication and identity-management solutions (Microsoft Entra ID, B2B/B2C, Conditional Access, Privileged Identity Management); recommend solutions for authorising access to Azure resources and on-premises resources; recommend a solution to manage secrets, certificates, and keys (typically Azure Key Vault). Design governance — management group / subscription / resource group hierarchies, resource tagging strategy, compliance via Azure Policy and Microsoft Purview, identity governance. Plus design solutions for logging and monitoring across the Azure estate. Around 10–18 questions per sitting.
Design data storage solutions20–25%
Pick the right database service for relational data (SQL Database, SQL Managed Instance, MySQL, PostgreSQL, Synapse SQL pools) — including service tier, compute tier, scalability strategy, and protection. For semi-structured and unstructured data, balance Blob Storage, Azure Files, Disk Storage, and Cosmos DB across features, performance, and cost. Recommend solutions for data integration (Azure Data Factory, Synapse pipelines, Event Hubs, Stream Analytics) and analysis (Synapse Analytics, Microsoft Fabric). AZ-305 questions in this domain frequently take the form "cheapest option that meets X RTO/RPO/throughput". Around 8–15 questions.
Design business continuity solutions15–20%
Recommend recovery solutions for Azure and hybrid workloads that meet specific recovery objectives (RTO, RPO, recovery-point granularity). Backup and recovery design for compute (VMs, containers), databases, and unstructured data — Azure Backup, Recovery Services vaults, point-in-time restore, geo-redundant backups, Azure Site Recovery for failover. High-availability designs across compute (zone-redundant scale sets, regional pairs) and data (read replicas, active geo-replication, multi-region writes for Cosmos DB). Around 6–12 questions.
Design infrastructure solutions30–35%
The largest domain. Compute solutions — VMs vs containers (AKS, ACI, ACA) vs serverless (Functions, Logic Apps) vs batch processing — with the trade-offs that matter at design time. Application architecture — messaging (Service Bus, Storage Queues), event-driven (Event Grid, Event Hubs), API integration (API Management), caching (Azure Cache for Redis), application configuration management (App Configuration), automated deployment patterns. Migrations evaluated through the Cloud Adoption Framework, including IaaS/PaaS migrations and database migrations. Network solutions — internet connectivity, hybrid connectivity (ExpressRoute, VPN Gateway, Virtual WAN), performance optimisation, network security (NSGs, Application Gateway, Azure Firewall, Web Application Firewall), and load balancing/routing. Around 12–20 questions.