Azure Administrator (AZ-104) is a hands-on course in running Microsoft Azure that covers the skills measured in the AZ-104 exam, from Microsoft Entra ID, RBAC and Azure Policy to storage, virtual machines, containers, virtual networks, Azure Monitor and backup, all practised in a real subscription. It suits system administrators, cloud engineers and anyone preparing for the AZ-104 exam.
Organisations that move to Microsoft Azure often start by creating machines and services as the need arises. Before long they face permissions that are far too broad, resources nobody can say who owns, costs that climb every month, networks exposed to the internet by accident and data with no backup. An Azure administrator therefore needs a complete grasp of identity, governance, storage, compute, networking and monitoring to keep cloud systems secure, under control and available.
This course covers the skills measured in the AZ-104 Microsoft Azure Administrator exam, following the latest outline on Microsoft Learn, with hands-on work in each learner's own Azure subscription. It starts with managing users and groups in Microsoft Entra ID, assigning access with RBAC and setting up governance with Azure Policy, resource locks, tags and budgets. It then covers storage accounts, Blob Storage, Azure Files and access control,
deploys resources with ARM templates and Bicep, and builds virtual machines, scale sets, containers and App Service. Learners design networks with VNets, NSGs, peering, DNS and load balancers, then look after the environment with Azure Monitor, Azure Backup and Site Recovery, before a closing capstone. The course helps with exam preparation, but learners book the exam with Microsoft themselves. (3 days, 6 hours per day, 18 hours in total, Intermediate level.)
What you’ll gain
Manage users, groups, licences and external users in Microsoft Entra ID
Assign access with Azure RBAC at the right scope and interpret access assignments
Set up governance with Azure Policy, resource locks, tags, management groups and budgets
Create and secure storage accounts, Blob Storage and Azure Files
Deploy resources with ARM templates and Bicep and build highly available virtual machines
Work with Container Registry, Container Instances, Container Apps and App Service
Design and secure virtual networks, DNS and load balancers
Monitor resources with Azure Monitor and set up Azure Backup and Site Recovery
Who this course is for
Windows or Linux administrators who are responsible for systems on Microsoft Azure
Cloud and infrastructure engineers who look after their organisation's subscriptions
IT teams moving systems from on-premises to Azure
Anyone preparing for the AZ-104 Microsoft Azure Administrator exam
DevOps engineers who need a deeper understanding of Azure infrastructure
Prerequisites
A basic understanding of servers, operating systems and virtualisation
Networking fundamentals such as IP addresses, subnets, DNS and routing
Some command-line experience on Windows or Linux and basic cloud knowledge
A laptop with a browser and an Azure subscription for the labs (a free trial or a company sandbox)
Curriculum
Course Details
This course covers the skills measured in the AZ-104 Microsoft Azure Administrator exam, following the latest outline on Microsoft Learn. It runs for 3 days, 6 hours per day (18 hours in total, 09:00-16:00), as lectures with labs. Intermediate level. Every lab runs in the learner's own Azure subscription (a free trial, pay-as-you-go or a company sandbox) through the Azure portal, Azure
CLI and Azure PowerShell, with clean-up scripts after each lab to keep costs under control. The course helps with exam preparation but is not official Microsoft courseware; it does not include the exam fee or a voucher, and learners book the exam with Microsoft themselves. Learners take home a lab guide, Azure CLI and PowerShell scripts, Bicep files and a summary of the skills in the exam outline.
Day 1Identity, Governance and Getting Started with Storage
Section 1: Lab: Azure Overview and Management Tools
The role of an Azure administrator and the AZ-104 skills outline
The hierarchy of management groups, subscriptions, resource groups and resources
Work with the Azure portal, Cloud Shell, Azure CLI and Azure PowerShell
Regions, availability zones and choosing where resources live
Lab: create a resource group and a first resource with all three tools
Section 2: Lab: Users and Groups in Microsoft Entra ID
What Microsoft Entra ID is and how it relates to subscriptions
Create users and groups, both assigned and dynamic
Manage user properties and assign licences through groups
Invite external users and manage their access
Lab: enable self-service password reset (SSPR) for a group of users
Section 3: Lab: Managing Access with Azure RBAC
The building blocks of RBAC: security principals, role definitions and scopes
Common built-in roles such as Owner, Contributor and Reader
Assign roles at different scopes and how access is inherited downwards
Read and check effective access with Access control (IAM)
The difference between Entra roles and Azure RBAC roles
Section 4: Lab: Governance and Cost Control
Azure Policy and initiatives to enforce organisational standards
CanNotDelete and ReadOnly resource locks
Define a tagging standard and enforce it with policy
Structure management groups and move resources between subscriptions
Set budgets and cost alerts and act on Azure Advisor recommendations
Section 5: Lab: Creating and Configuring Storage Accounts
Storage account types and the Blob, Files, Queue and Table services
Choose LRS, ZRS, GRS or GZRS redundancy to fit the workload
Storage encryption and customer-managed keys
Object replication between storage accounts
Lab: manage data with Azure Storage Explorer and AzCopy
Day 2Storage and Compute
Section 6: Lab: Blob Storage and Azure Files
Create containers and choose the Hot, Cool, Cold or Archive access tier
Lifecycle management to move tiers and delete data by age automatically
Soft delete and versioning for blobs and containers
Create an Azure Files share with snapshots and soft delete
Lab: mount a file share on Windows and Linux
Section 7: Lab: Controlling Access to Storage
Storage firewalls and restricting access from virtual networks
Access keys and rotating them safely
Create SAS tokens and use stored access policies so they can be revoked
Identity-based access for Azure Files
Lab: share files with an external system through a SAS limited in rights and time
Section 8: Lab: ARM Templates and Bicep
The structure of ARM templates and Bicep files
Read and modify existing templates and Bicep files
Deploy resources from templates through the portal, CLI and PowerShell
Export a deployment as an ARM template and convert it to Bicep
Lab: build storage and networking repeatably with Bicep
Section 9: Lab: Virtual Machines and Scale Sets
Create VMs, choose sizes and manage OS and data disks
Encryption at host and resizing VMs later
Availability sets and availability zones for high availability
Move a VM to another resource group, subscription or region
Lab: build a Virtual Machine Scale Set with autoscale
Section 10: Lab: Containers and App Service
Create an Azure Container Registry and push images
Run containers with Azure Container Instances and Azure Container Apps
Create an App Service plan and an App Service and configure scaling
Custom domains, certificates and TLS for App Service
Deployment slots, backup and networking settings for App Service
Day 3Networking, Monitoring and Backup
Section 11: Lab: Virtual Networks and Peering
Plan address spaces and divide them into subnets
Public IP addresses and how to use them safely
Connect VNets with virtual network peering
User-defined routes to control how traffic flows
Section 12: Lab: Securing the Network
Network security groups and application security groups
Check effective security rules to find why a connection fails
Reach VMs securely with Azure Bastion
Service endpoints and private endpoints for PaaS services
Section 13: Lab: Azure DNS and Load Balancer
Azure DNS public and private zones
Public and internal load balancers
Health probes, load balancing rules and troubleshooting
Check connectivity with Network Watcher and Connection Monitor
Section 14: Lab: Azure Monitor and Log Analytics
Read metrics and configure diagnostic settings to send logs to a workspace
Write basic KQL queries in Log Analytics
Alert rules, action groups and alert processing rules
Azure Monitor Insights for VMs, storage and networks
Section 15: Lab: Backup and Site Recovery
How a Recovery Services vault differs from a Backup vault
Create a backup policy and test VM backup and restore
Set up Azure Site Recovery and fail over to another region
Backup reports and alerts
Section 16: Workshop: Capstone and Exam Preparation
Build a web application environment with a VNet, NSGs, a load balancer and storage
Add RBAC, policy, tags, monitoring and backup throughout
Review against the AZ-104 outline and try the free practice assessment
Clean up resources and wrap up with a pre-production checklist
Schedule & training options
For individuals — public rounds
No public rounds are open right now. Join the waiting list and we will contact you first when the next round opens, or ask us on LINE. Or call 02-570-8449 or 088-807-9770
Who is Azure Administrator (AZ-104) for, and what background is needed?
Built for Windows or Linux administrators who are responsible for systems on Microsoft Azure · Cloud and infrastructure engineers who look after their organisation's subscriptions · IT teams moving systems from on-premises to Azure Background you should have: A basic understanding of servers, operating systems and virtualisation · Networking fundamentals such as IP addresses, subnets, DNS and routing Not sure the fit is right? Talk to our team on LINE @itgenius or call 02-570-8449.
How much does Azure Administrator (AZ-104) cost and how long does it run?
THB 9,900 (currently THB 8,910 on promotion). The course runs 18 hours. The price excludes 7% VAT (for payment in a company's name). Pay by bank transfer to the company account, confirm it on our payment page, and we can issue the receipt or tax invoice in your company's name.
Do I get a certificate?
Yes. Everyone who completes the course receives a Certificate of Completion from IT Genius Institute. Each certificate carries its own number, and anyone holding that number can verify it online on our certificate page, so you can add it to your portfolio or pass it to HR as evidence of training.
Where does the training take place, and is there an online option?
You can attend onsite at IT Genius Institute or arrange to join online, and we also run it as a private in-house session for your team. Ask about dates and venues on LINE @itgenius or call 02-570-8449.
What if I fall behind or miss a session — can I retake it?
Yes. You may retake the same course free of charge in a later round, under the institute's conditions. Tell our team which course and round you attended, and we will check it and offer you the rounds that still have seats. Ask us on LINE @itgenius or call 02-570-8449.
How do I enrol, or request a quotation for my company?
Enrol online with the registration form on this page. You can register several attendees at once and enter your tax ID and billing address for the tax invoice. Or request a company quotation straight from the quote button. For anything else call 02-570-8449 or reach us on LINE @itgenius.
Microsoft Azure is widely used by Thai organizations, especially those already running Microsoft 365 and Windows. The Microsoft Certified: Azure Fundamentals (AZ-900) credential is the best starting point for anyone who wants to understand the cloud and…
AWS is the world's leading cloud provider, and the AWS Certified Cloud Practitioner (CLF-C02) is the first gateway into a cloud career, with the highest enrollment of any cloud course worldwide. It suits people without an IT background as well as those…
Knowing AWS services one by one is not enough for architecture work. What the market wants is someone who can say, given a business problem, which services to choose, how to connect them, how much failure the system can absorb, whether it is secure enough,…