DjamgaMind: Audio Intelligence for the C-Suite (Daily AI News, Energy, Healthcare, Finance)
Full-Stack AI Intelligence. Zero Noise.The definitive audio briefing for the C-Suite and AI Architects. From Daily News and Strategic Deep Dives to high-density Industrial & Regulatory Intelligence—decoded at the speed of the AI era. . 👉 Start your specialized audio briefing today at Djamgamind.com
AI Jobs and Career
I wanted to share an exciting opportunity for those of you looking to advance your careers in the AI space. You know how rapidly the landscape is evolving, and finding the right fit can be a challenge. That's why I'm excited about Mercor – they're a platform specifically designed to connect top-tier AI talent with leading companies. Whether you're a data scientist, machine learning engineer, or something else entirely, Mercor can help you find your next big role. If you're ready to take the next step in your AI career, check them out through my referral link: https://work.mercor.com/?referralCode=82d5f4e3-e1a3-4064-963f-c197bb2c8db1. It's a fantastic resource, and I encourage you to explore the opportunities they have available.
- Full Stack Engineer [$150K-$220K]
- Software Engineer, Tooling & AI Workflow, Contract [$90/hour]
- DevOps Engineer, India, Contract [$90/hour]
- More AI Jobs Opportunitieshere
| Job Title | Status | Pay |
|---|---|---|
| Full-Stack Engineer | Strong match, Full-time | $150K - $220K / year |
| Developer Experience and Productivity Engineer | Pre-qualified, Full-time | $160K - $300K / year |
| Software Engineer - Tooling & AI Workflows (Contract) | Contract | $90 / hour |
| DevOps Engineer (India) | Full-time | $20K - $50K / year |
| Senior Full-Stack Engineer | Full-time | $2.8K - $4K / week |
| Enterprise IT & Cloud Domain Expert - India | Contract | $20 - $30 / hour |
| Senior Software Engineer | Contract | $100 - $200 / hour |
| Senior Software Engineer | Pre-qualified, Full-time | $150K - $300K / year |
| Senior Full-Stack Engineer: Latin America | Full-time | $1.6K - $2.1K / week |
| Software Engineering Expert | Contract | $50 - $150 / hour |
| Generalist Video Annotators | Contract | $45 / hour |
| Generalist Writing Expert | Contract | $45 / hour |
| Editors, Fact Checkers, & Data Quality Reviewers | Contract | $50 - $60 / hour |
| Multilingual Expert | Contract | $54 / hour |
| Mathematics Expert (PhD) | Contract | $60 - $80 / hour |
| Software Engineer - India | Contract | $20 - $45 / hour |
| Physics Expert (PhD) | Contract | $60 - $80 / hour |
| Finance Expert | Contract | $150 / hour |
| Designers | Contract | $50 - $70 / hour |
| Chemistry Expert (PhD) | Contract | $60 - $80 / hour |
Microsoft Azure Administrator Certification Questions and Answers Dumps – AZ 104
Microsoft Azure Administrator AZ 104 is one of the most popular Microsoft Azure Administrator certification exams. To pass this exam, you need to have a good understanding of Microsoft Azure and its various components. The best way to prepare for this exam is to use this Microsoft AZ 104 dumps. These dumps will help you to understand the Microsoft Azure platform and its various features. In addition, you will also get an idea about the types of questions that are asked in this exam. With the help of these dumps, you can easily pass the Microsoft AZ 104 exam.
2022-2023 Azure Administrator AZ104 Latest Practice Exam
Microsoft Certified: Azure Administrator Associate Average Salary — $125,993

Candidates for the Azure Administrator Associate certification should have subject matter expertise implementing, managing, and monitoring an organization’s Microsoft Azure environment.
Responsibilities for this role include implementing, managing, and monitoring identity, governance, storage, compute, and virtual networks in a cloud environment, plus provision, size, monitor, and adjust resources, when needed.
AZ-104 Microsoft Azure Administrator Exam Breakdown:
Manage Azure identities and governance (15-20%),
Manage Azure AD objects,
Manage role-based access control (RBAC),
Manage subscriptions and governance,
Implement and manage storage (10-15%),
Manage storage accounts,
Manage data in Azure Storage,
Configure Azure files and Azure blob storage,
Deploy and manage Azure compute resources (25-30%),
Configure VMs for high availability and scalability,
Automate deployment and configuration of VMs,
Create and configure VMs,
Create and configure containers,
Create and configure Web Apps,
Configure and manage virtual networking (30-35%),
Implement and manage virtual networking,
Configure name resolution,
Secure access to virtual networks,
Configure load balancing,
Monitor and troubleshoot virtual networking,
Integrate an on-premises network with an Azure virtual network,
Monitor and back up Azure resources (10-15%),
Monitor resources by using Azure Monitor,
Implement backup and recovery,
2022-2023 Azure Administrator AZ104 Latest Practice Exam
Below are the top 50 Microsoft Azure Administrator Certification Questions and Answers Dumps.
AZ104 Exam Prep on ios – AZ104 Exam Prep on android
AZ104 Exam Prep on windows 10/11 – AZ104 Exam Prep on web
AI-Powered Professional Certification Quiz Platform
Web|iOs|Android|Windows
Are you passionate about AI and looking for your next career challenge? In the fast-evolving world of artificial intelligence, connecting with the right opportunities can make all the difference. We're excited to recommend Mercor, a premier platform dedicated to bridging the gap between exceptional AI professionals and innovative companies.
Whether you're seeking roles in machine learning, data science, or other cutting-edge AI fields, Mercor offers a streamlined path to your ideal position. Explore the possibilities and accelerate your AI career by visiting Mercor through our exclusive referral link:
Find Your AI Dream Job on Mercor
Your next big opportunity in AI could be just a click away!
2022-2023 Azure Administrator AZ104 Latest Practice Exam
https://youtu.be/hJD3Syf96dM
AI- Powered Jobs Interview Warmup For Job Seekers

⚽️Comparative Analysis: Top Calgary Amateur Soccer Clubs – Outdoor 2025 Season (Kids' Programs by Age Group)
Question 1: In our subscription, we have four different resource groups. They are RG1, RG2, RG3, RG4. RG2 has a Read-only lock at the resource group scope. RG3 has a Delete lock at the resource group scope. RG1 and RG4 do not have locks. We need to determine how we could move resources between resource groups during the lifecycle of these resources. Assuming all resources provisioned support moving between resource groups regardless of region. Which of the following statements are plausible?
AI Jobs and Career
And before we wrap up today's AI news, I wanted to share an exciting opportunity for those of you looking to advance your careers in the AI space. You know how rapidly the landscape is evolving, and finding the right fit can be a challenge. That's why I'm excited about Mercor – they're a platform specifically designed to connect top-tier AI talent with leading companies. Whether you're a data scientist, machine learning engineer, or something else entirely, Mercor can help you find your next big role. If you're ready to take the next step in your AI career, check them out through my referral link: https://work.mercor.com/?referralCode=82d5f4e3-e1a3-4064-963f-c197bb2c8db1. It's a fantastic resource, and I encourage you to explore the opportunities they have available.
A. We can move resources from RG1 to RG4.
B. We can move resources between any of these resource groups.
Invest in your future today by enrolling in this Azure Fundamentals - Pass the Azure Fundamentals Exam with Ease: Master the AZ-900 Certification with the Comprehensive Exam Preparation Guide!
- AWS Certified AI Practitioner (AIF-C01): Conquer the AWS Certified AI Practitioner exam with our AI and Machine Learning For Dummies test prep. Master fundamental AI concepts, AWS AI services, and ethical considerations.
- Azure AI Fundamentals: Ace the Azure AI Fundamentals exam with our comprehensive test prep. Learn the basics of AI, Azure AI services, and their applications.
- Google Cloud Professional Machine Learning Engineer: Nail the Google Professional Machine Learning Engineer exam with our expert-designed test prep. Deepen your understanding of ML algorithms, models, and deployment strategies.
- AWS Certified Machine Learning Specialty: Dominate the AWS Certified Machine Learning Specialty exam with our targeted test prep. Master advanced ML techniques, AWS ML services, and practical applications.
- AWS Certified Data Engineer Associate (DEA-C01): Set yourself up for promotion, get a better job or Increase your salary by Acing the AWS DEA-C01 Certification.
C. We can move resources from RG2 to RG4.
D. We can move resources from RG4 to RG3.
E. We can move resources from RG2 to RG3.
ANSWER1:
2022-2023 Azure Administrator AZ104 Latest Practice Exam
Azure Administrator Exam Prep App #Azure #AZ104 #AzureAdmnistrator #AzureDevOps #AzureAdmin #AzureTraining #AzureSysAdmin #AzureCloud #LearnAzure
AZ104 Exam Prep on ios – AZ104 Exam Prep on android
AZ104 Exam Prep on windows 10/11 – AZ104 Exam Prep on web
Question 2: Your company has recently added a few new users to your Azure Active Directory. You have already added them to an active directory group, and now you have asked them to add their devices to the domain. When they add their devices, you have to ensure they are prompted to use a mobile phone to verify their identity. How do you configure this?
A. Require multi-factor authentication to join devices
B. Configure a point-to-site VPN
C. Enable Conditional Access
D. You must sign up for Azure AD Premium
ANSWER2:
Question 3: Under your Azure Subscription, you are trying to identify VMs that are underutilized in order to shutdown all VMs with CPU utilization under 5%. Which blade should you use?
A. Customer Insights
B. Advisor recommendations
C. Monitor
D. Metrics
ANSWER3:
Question4: You have just purchased the domain name arseemagroup.com from a third party registrar. Using your Azure Active Directory domain, you’d like to create new users with the suffix @arseemagroup.com. Which three things must you do?
A. Access the custom domain names blade from Azure AD
B. Create a MX or TXT record from arseemagroup.com DNS
C. Verify that you own the domain name
D. Access the App registrations blade from Azure AD
ANSWER4:
AZ104 Exam Prep on ios – AZ104 Exam Prep on android
AZ104 Exam Prep on windows 10/11 – AZ104 Exam Prep on web
Question 5: You have two subscriptions named Subscription1 and Subscription2. You are logged into Azure using Azure PowerShell from Computer1. How can you identify which subscription you are currently viewing and then switch from one subscription to the other for the current session at Computer1.
A. Set-AzContext -SubscriptionName
B. Get-AzContext
C. Select-AzContext
D. AzShow-Context
ANSWER5:
Question 6: You have two subscriptions named Subscription1 and Subscription2. You are currently managing resources in Subscription1 from Computer1 that has the Azure CLI installed. You need to switch to Subscription2. Which command should you run?
A. az set account –subscription “Subscription2”
B. az account set –subscription “Subscription2”
C. az subscription set “Subscription2”
D. Select-AzureSubscription -SubscriptionName “Subscription2”
ANSWER6:
Question 7: You work at the IT help desk for Consilium Corporation. You have been getting an influx of calls into the help desk about resetting users’ passwords. They keep reporting that they can’t seem to figure out how to reset their password in order to gain access to their Customer Relationship Management (CRM) software. What do you do?
A. Ensure that the users who are having problems are within the correct AD group
B. Make sure you have Azure Active Directory Free
C. Make sure they have their verification device (mobile app or access to email)
D. Verify that self-service password reset is enabled in Azure Active Directory
ANSWER7:
Question 8: In this scenario, we are working for Cloud Chase Support. We our the active administrator, and we have been tasked with determining how to ensure we do not incur costs in either our Prod-Subscription and our Dev-Subscription for virtual machine resources. We have a CloudChase management group where both subscription nested. We decide to use Azure Policy to enforce compliance on Virtual Machines. Our Policy definition states that virtual machines are not an allowed resource type at the scope of our CloudChase management group. There are some existing virtual machines in our Prod-Subscription at the time this policy is created. After the enforcement of our new policy which of the below statements is true?
A. We cannot create virtual machines in any subscription under the scope of our management group and our existing virtual machines will be deallocated.
B. Virtual machines can be created in our Prod-Subscription if they are compliant.
C. Virtual machines can be created in our Dev-Subscription.
D. We cannot create virtual machines in any subscription under the scope of our management group.
ANSWER8:
Question 9: You recently signed up for Azure Active Directory Premium and need users to be able to reset their passwords if they are unable to login. What should you configure in Azure Active Directory?
A. Set “block sign-in” to off when creating the user
B. User password reset
C. User password change
D. Add user to sign-in group in Azure AD
ANSWER9:
Question 10: You have an Azure Pay-as-you-go Subscription named Subscription1. You have some concerns about cost for Subscription1, and you would like to spend less than $100.00 US per month on all resources in this subscription. If you spend more than $90.00 US, you would like to get an alert in the form of a text message. What should you do?
A. Shutdown VMs when you are not using them
B. Create an alert in Azure Monitor
C. Create a budget alert condition tied to an action group
D. Create a budget in the subscriptions blade
ANSWER10:
2022-2023 Azure Administrator AZ104 Latest Practice Exam
AZ104 Exam Prep on ios – AZ104 Exam Prep on android
AZ104 Exam Prep on windows 10/11 – AZ104 Exam Prep on web
Question 11: We want to be provide an Azure AD B2B guest user the ability to manage all resources inside of our DevRG resource group. We want to give them these abilities over managing all resources inside of this resource group and nothing more. What role would we assign to the user to accomplish this goal? Assume we are assigning the role to the DevRG scope.
A. User Access Administrator
B. Owner
C. Contributor
D. Global Admin
ANSWER11:
Question 12: You have just created a General-purpose V2 storage account in Azure. From a VM located in your on-prem environment, you’ve logged into your Azure subscription using the Connect-AzConnect command from the PowerShell command line. Next, you need to retrieve the key, in order to access your storage account. Which PowerShell cmdlet will you use to retrieve the access key?
A. Get-AzStorageAccount
B. Get-AzStorageContainerKey
C. Get-AzStorageContainerStoredAccessPolicy
D. Get-AzStorageAccountKey
ANSWER12:
Question 13: You have been directed to copy all data from one storage account to another using the AzCopy tool. You need to report which storage services you can copy. Which of those services would it be?
A. Only Azure File Shares
B. Azure Queues and Blobs
C. Azure Blob and File Shares
D. Azure Table and File Shares
ANSWER13:
Question 14: You have a general purpose v1 storage account named consiliumstore that has a private container named container2. You need to allow read access to the data inside container2, but only within a 14 day window. How do you accomplish this using the Azure Portal?
A. Upgrade the storage account to general purpose v2
B. Create a shared access signatures
C. Create a service SAS
D. Create a stored access policy
ANSWER14:
Question 15: You have an existing Microsoft Enterprise Agreement (EA) Subscription. You need to ship 34TB of data from an on-premise Windows 2016 server to your Azure storage account. You need to ensure that the data transfer has zero impact on the network, preserves your existing drives and is the fastest and most secure method. What should be your first step to starting the import job?
A. Open a ticket with Microsoft Support
B. Order an Azure Databox via the Azure Portal
C. Start an Import Job via the Azure Portal
D. Prepare your hard drives using the WAImportExport tool
ANSWER15:
Question 16: You have data in an AWS S3 Bucket named myS3Bucket and you need to copy all of its contents to a container named container1 in an Azure storage account named companydata. Which command would be most efficient use of getting the data from the S3 bucket to the Azure storage container?
A. azcopy copy ‘https://s3.amazonaws.com/myS3Bucket’ ‘https://companydata.blob.core.windows.net/container1’ –recursive=true
B. aws s3 cp s3://mybucket/test.txt https://companydata.blob.core.windows.net/container1
C. azcopy blob copy ‘https://s3.amazonaws.com/myS3Bucket’ ‘https://companydata.blob.core.windows.net/container1’
D. azcopy copy sync ‘https://s3.amazonaws.com/myS3Bucket’ ‘https://companydata.blob.core.windows.net/container1’
ANSWER16:
Question 17: You have the following Azure Storage Accounts in your Subscription: stor1 (BlockBlobStorage) stor2 (FileStorage) stor3 (StorageV2) Which of these storage accounts can be converted to Read-Access Geo-Redundant Storage (RA-GRS) based on their storage account kind? Please select the most appropriate answer.
A. stor1 and stor2
B. stor3
C. stor2
D. stor1, stor2, and stor3
ANSWER17:
Question 18: You create an Azure storage account named companystore with a publicly accessible container named container1. You upload a file to container1 named pic1.png. What will be the URL in order to access this blob?
A. https://companystore.blob.core.windows.net/container1/pic1.png
B. https://portal.azure.com/companystore.blob.core.windows.net/pic1.png
C. https://blob.core.windows.net/companystore/container1/pic.png
D. https://pic1.companystore.blob.core.windows.net
ANSWER18:
2022-2023 Azure Administrator AZ104 Latest Practice Exam
AZ104 Exam Prep on ios – AZ104 Exam Prep on android
AZ104 Exam Prep on windows 10/11 – AZ104 Exam Prep on web
Question 19: You have an Azure subscription named Subscription1. In Subscription1, you have an Azure virtual machine named VM1. Attached to VM1 are two network interface cards. You require a third network interface card with a network bandwidth above 1000 Mbps for your storage area network. What should you do?
A. Create an additional VM in the same subnet and connect to VM1 over the LAN
B. Create a new subnet with a sufficient number of available IP addresses
C. Create a new storage account to store data for VM1
D. Change the VM SKU to Standard_A4 or larger
ANSWER19:
Question 20: You are trying to create a new Azure Kubernetes Service (AKS) cluster from your local workstation. The AKS cluster must contain three nodes and ensure access to the worker nodes in order to troubleshoot the kubelet. You have authenticated to Azure from your local workstation with the Azure CLI. What command will you use to create an AKS cluster named AKS1 with the necessary components inside of the resource group named RG1?
A. az aks create -g RG1 -n AKS1 –generate-ssh-keys –node-count 3
B. az kubernetes create –name AKS1 –group RG1 –nodes 3 –generate-keys
C. az aks create –name AKS1 –resource-group RG1 –nodes 3 –ssh-key-value ~/.ssh/id_rsa.pub
D. az kubernetes create –name AKS1 –resource-group RG1 –nodes 3 –generate-keys
ANSWER20:
Question 21: VM1 is located in the West US region, and the OS disk is Premium SSD. The size of VM1 is currently Standard_D2s_v3, but you need to change the size to Standard_D2. You are able to select the size from the size blade, but you receive an error message. Why can’t you change the VM size?
A. You need to provide the username and password for the OS to upgrade
B. Standard_D2 does not support premium SSD disks
C. The size Standard_D2 is not available in the West US region
D. You did not shut down (deallocated) VM1 before you change the size
ANSWER21:
AZ104 Exam Prep on ios – AZ104 Exam Prep on android
AZ104 Exam Prep on windows 10/11 – AZ104 Exam Prep on web
Question 22: You have an Azure Kubernetes Service (AKS) cluster named AKS1 within the resource group named RG1. You are trying run the command kubectl get all from the Azure Cloud Shell (https://shell.azure.com) to view your cluster resources. You received the error Error from server (BadRequest): the server rejected our request for an unknown reason. You’ve verified that the resources exist and the command is correct. What do you need to do in order to view your cluster resources from the Azure Cloud Shell?
A. Retrieve the access credentials using the command az aks get-credentials --name AKS1 --resource-group RG1
B. Log into the cluster GUI from the Azure Portal
C. Install the kubectl tool
D. Access the Kubernetes Dashboard using the command az aks browse --name AKS1 --resource-group RG1
ANSWER22:
Question 23: You have a subscription named Subscription1. You create a new Azure VM in your subscription named VM5 running Windows 2012 R2. You try to connect and login to VM5, but you get an error that says “We couldn’t connect to the remote PC. Make sure the PC is turned on and connected to the network, and that remote access is enabled.” You have verified that VM5 is running and has been assigned a public IP address. What change do you need to make in order to successfully connect and login to VM5?
A. Add a rule to the Network Security Group that will allow port 3389
B. Select Reset password from the VM blade
C. Use Network Watcher for detailed connection tracing
D. You need to access the VM from a computer that’s in the same subnet
ANSWER23:
Question 24: Subscription1 contains an Azure VM named VM1 with the following configuration:VM Size: Standard_D2s_v3
Public IP Address: 52.173.36.55
Resource Group: RG1
Availability Zone: None
Location: Japan East
Disk Type: Standard HDD
What are two things you can do to reduce data loss and achieve a 99.9% SLA?
A. Create a recovery services vault and enable replication for VM1
B. Move VM1 to a paired region
C. Place the VM in an availability zone
D. Change the disk type to Premium SSD
ANSWER24:
AZ104 Exam Prep on ios – AZ104 Exam Prep on android
AZ104 Exam Prep on windows 10/11 – AZ104 Exam Prep on web
Question 25: You have created an application that is to be run on Linux containers named ContainerApp1. You’ve created an Azure container instance with an FQDN, but you notice that when the container restarts, all application data is lost. What is the best solution to preserve the data associated with your application?
A. Create a public blob storage container and share the URI with the application
B. Create a storage account and share the SAS with the application
C. Mount an Azure file share as a volume in Azure Container Instances
D. Run the container on a VM, and use the managed disk attached to the VM
ANSWER25:
Question 26: You’ve created a Dockerfile that contains the necessary steps to build an image that you plan to use for your application running as a Web App in App Services named APP1. You have created an Azure Container Registry, which is where you plan to store your images to be used for APP1. What should your next step be?
A. Run the az acr build command
B. Create the App Service Plan
C. Run the docker push command
D. Run the docker login command
ANSWER26:
Question 27: You have an application that runs on instances in a Virtual Machine Scale Set. The number of instances in the VMSS is at three starting Monday. The minimum number of instances is one, and the maximum is 5 instances. There are two scaling rules for this VMSS:
| Rule | Condition | Action |
|---|---|---|
| Rule1 | CPU > 75% | +1 instance |
| Rule2 | CPU < 25% | -1 instance |
Based on the rules above and the chart below, on Wednesday how many instances will there be in our VMSS?
|CPU%|Time(UTC)|Day |:—|:—:|:—:|—:| |75|12:01|Tuesday| |20|13:36|Tuesday| |85|12:10|Wednesday| |20|19:07|Thursday|
A. 2 instances
B. 3 instances
C. 4 instances
D. 5 instances
ANSWER27:
AZ104 Exam Prep on ios – AZ104 Exam Prep on android
AZ104 Exam Prep on windows 10/11 – AZ104 Exam Prep on web
Question 28: Subscription1 contains an Azure VM named VM1. You have added a data disk to VM1, as well as a new network interface card. You need to create two more Azure VMs just like this one named VM2 and VM3. What is the most efficient way to create VM2 and VM3 that will minimize cost?
A. Backup the VM and recover to a different region
B. Redeploy VM1 with the new disk and NIC and deploy the template to VM2 and VM3
C. Select Export template from VM1 blade, then deploy VM2 and VM3 with that template
D. Create an image from VM1 and use the image to deploy VM2 and VM3
ANSWER28:
Question 29: You have an Azure subscription named Subscription1. You have created a web app named App1 in Subscription1 that is sourced from a git repository named Git1. You need to ensure that every commit to the master branch in Git1 triggers a deployment to a test version of the application before releasing it to production. What are two changes that you must make to App1 to fulfill this requirement?
A. Create a build server with the master branch of Git1 as the trigger
B. Configure custom domains for test and production versions of App1
C. Add a new deployment slot to App1 to release the test version of App1
D. Create a new web app and configure failover settings from test to production
ANSWER29:
Question 30: You plan to create an Azure Web App in the East US region. You need to ensure that this web app scales out with demand, to prevent downtime. You also need to ensure that the data that resides inside of the application will remain secure and never become exposed to anyone outside of the organization. Which App Service plan SKU will you chose that will meet these requirements and also save on cost?
A. FREE
B. B1
C. SHARED
D. I1
ANSWER30:
Question 31: VM1 is located in the East US region. You have added a premium SSD data disk to VM1, but the IOPS are not satisfying the needs of your application, how can you change the speed of the disk?
A. Select the disk configuration and increase the size
B. Shut down (Deallocate) the VM
C. Export the disk and convert to VHD
D. Create a new disk and migrate the data
ANSWER31:
Question 32: The NoName Company has just deployed a number of Azure VMs into a specific subnet in an Azure virtual network. They have also implemented a network security plan which includes the use of Azure Firewall. From those newly deployed VMs, the company wants to deny access to the website https://www.microsoft.com. How can you achieve this using their current Azure resources?
A. A network rule
B. Create a route via Route Table to the firewall (as a virtual appliance hop)
C. Configure an application rule on the Azure Firewall that blocks FQDNS www.microsoft.com
D. An Application Gateway
E. A Subnet named AzureFirewallSubnet
F. A VPN Gateway
ANSWER32:
AZ104 Exam Prep on ios – AZ104 Exam Prep on android
AZ104 Exam Prep on windows 10/11 – AZ104 Exam Prep on web
Question 33: You need to create an Azure virtual machine named VM1 that requires a static private IP address configured inside the IP address space for the VNet in which the VM resides. How do you configure a static IP address for this Azure VM?
A. After the VM has been created, create a new network interface and configure a static IP address for that network interface
B. After the VM has been created, go to the network interface attached to the VM and change the IP configuration to static assignment
C. When creating a VM in the portal, select New next to private ip address and choose static after assigning the correct IP address
D. When creating the VM in the portal, change the setting from dynamic to static on the networking tab under private IP address
ANSWER33:
Question 34: You have an Azure subscription named Subscription1. In Subscription1, you have a web server that has the IP address 10.1.0.83 and a database server that has the IP address 10.1.0.142. Instead of remembering the IP addresses of the servers, you’d like to connect to these servers using a DNS name. With no DNS server currently, and without having to create a new DNS server, how can you access your database server from your web server by the DNS name db.yourcompany.com?
A. Public DNS Zone
B. Promote Server to Domain Controller
C. Access the Domain Controller
D. Private DNS Zone
ANSWER34:
Question 35: You have an Azure subscription named Subscription1. In Subscription1 you have two VNets, one named VNet-Hub and one named VNet-Spoke. Within VNet-Hub, there is an Azure Firewall with a public IP address, configured as a Standard SKU. In VNet-Spoke, there is a Windows Server 2016 with no public IP address and no Network Security Group (NSG). Using which three items can you utilize the public IP address of the Azure firewall to connect to the Windows Server, without exposing the server to the public internet directly?
A. NAT Rule for the Firewall
B. Route Table
C. Virtual Network Gateway
D. Virtual Network Peering
E. ExpressRoute Gateway
ANSWER35:
AZ104 Exam Prep on ios – AZ104 Exam Prep on android
AZ104 Exam Prep on windows 10/11 – AZ104 Exam Prep on web
Question 36: You have an on-premises environment as well as your Azure environment with a subscription named Subscription1. Subscription1 has a virtual network named VNET1 and you need to connect to the on-premises network securely using an ExpressRoute link and Site-to-site VPN. What Azure resources do you need in order to establish the connection while minimizing cost?
A. Azure VPN Gateway
B. Network virtual appliance
C. No resources needed, ExpressRoute is encrypted by default
D. A route table
AZ104 Exam Prep on ios – AZ104 Exam Prep on android
AZ104 Exam Prep on windows 10/11 – AZ104 Exam Prep on web
ANSWER36:
Question 37: You have a Network Security Group (NSG) that is associated with a network interface that is attached to an Azure virtual machine named VM1 running Windows Server 2019. VM1 is in subnet named subnet1, in a virtual network named VNet1. A different NSG is attached to subnet1, but you notice that there is an inbound rule to allow port 3389. When you try to connect to VM1, you cannot connect. You reviewed the NSG and the source IP address and the protocol are correct. How can you connect to VM1 using best practices for NSGs in Azure?
A. The protocol on the NSG rule is set to UDP
B. The NSG attached to the network interface needs to be removed
C. The source IP address on the NSG rule is incorrect
D. You need to add an inbound rule for the NSG attached to the network interface
ANSWER37:
Question 38: You have an Azure subscription named Subscription1. In Subscription1 you have an Azure VM named VM1 with Windows Server 2019 as the operating system. VM1 does not have a public IP address assigned to it. VM1 is located in a virtual network named VNet1, in subnet1. Attached to subnet1 is a Network Security Group (NSG) that has port 3389 open inbound. On your local machine, you do not have an RDP client installed, but you need to login into the VM. Without assigning a public IP address to the VM, what three things in combination can we use to log into VM1?
A. HTML5 supported Web Browser
B. Azure VPN Gateway
C. A subnet named AzureBastionSubnet
D. A Gateway Subnet
E. Azure Bastion Host
F. Inbound security rule to open port 443
ANSWER38:
Question 40: You have a subscription named Subscription1. Subscription1 has one Azure virtual machine named VM1 which is an Ubuntu server. You can’t seem to login to the server via SSH. What tool should you use to verify if the problem is the network security group?
A. IP flow verify tool in Azure Network Watcher
B. Azure Monitor VM metrics
C. Azure Traffic Manager traffic view
D. Azure Virtual Network logs
ANSWER40:
Question 41: You have two Azure virtual machines named VM1 and VM2. VM1 is using the Red Hat Enterprise Linux 8.1 (LVM) operating system and is located in VNet1, within subnet1. VM2 is using the Windows Server 2019 operating system, and is located in VNet1, within subnet2. VNet1 has custom DNS configured, pointing to a DNS server with the IP address 172.168.0.6. VM2 has 10.0.1.15 configured as the DNS server on its network interface. Which DNS server will VM2 use for DNS queries?
A. 8.8.8.8
B. 10.0.1.15 for primary, 172.168.0.6 as secondary
C. 10.0.1.15
D. 172.168.0.6
ANSWER41:
AZ104 Exam Prep on ios – AZ104 Exam Prep on android
AZ104 Exam Prep on windows 10/11 – AZ104 Exam Prep on web
Question 42: You have created a new Azure virtual machine in a subnet named Subnet1 with an attached network interface card named NIC1. The NIC1, attached to Subnet1, has the following effective routes:
| Source | State | Address Prefix | Next Hop |
|---|---|---|---|
| Default | Active | 10.1.0.0/16 | Virtual Network |
| Default | Invalid | 0.0.0.0/0 | Internet |
| Default | Active | 10.0.0.0/8 | None |
| Default | Active | 100.64.0.0/10 | None |
| Default | Active | 192.168.0.0/16 | None |
| Default | Active | 25.33.80.0/20 | None |
| Default | Active | 25.41.3.0/25 | None |
| User | Active | 0.0.0.0/0 | None |
What will happen when the virtual machine tried to communicate with a VM on a different network?
A. Traffic will be sent successfully
B. Traffic will be forced out to the internet
C. Traffic will be forced internally
D. Traffic will be dropped and no connection will be established
ANSWER42:
AZ104 Exam Prep on ios – AZ104 Exam Prep on android
AZ104 Exam Prep on windows 10/11 – AZ104 Exam Prep on web
Question 43: You have a standard load balancer that directs traffic from port 80 externally to three different virtual machines. You need to direct all incoming TCP traffic on port 5000 to port 22 internally for connecting to Linux VMs. What do you need in order to connect to the VM via SSH?
A. A public IP address for all three VMs
B. A Route Table with at least one rule
C. A Network Security Group (NSG)
D. A Network Address Translation (NAT) Rule
ANSWER43:
Question 44: You have a web application that serves video and images to those visiting the site. You start to notice that your web server is overloaded, and often crashes because the requests have consumed all of its resources. To combat this, you’ve added an additional web server and you plan to load balance these servers by serving images from the first server only and serving video from the second server only. Which Azure resource can you implement that will properly load balance (at OSI layer 7) with URL-based routing and secure with SSL at the lowest cost?
A. Azure Load Balancer
B. Azure Front Door
C. Azure Application Gateway
D. Web Application Firewall
ANSWER44:
Question 45: You manage a virtual network named VNet1 that is hosted in the West US region. Two virtual machines named VM1 and VM2, both running Windows Server, are on VNet1. You need to monitor traffic between VM1 and VM2 for a period of five hours. As a solution, you propose to create a connection monitor in Azure Network Watcher. Does this solution meet the goal?
A. Yes
B. –
C. –
D. No
ANSWER45:
AZ104 Exam Prep on ios – AZ104 Exam Prep on android
AZ104 Exam Prep on windows 10/11 – AZ104 Exam Prep on web
Question 46: You have an Azure subscription named Subscription1. You would like to connect your on-premises environment to Subscription1. You have to meet three requirements from the business. The first requirement is that the connection from the on-premises office and Azure must be a private connection. No network traffic is allowed to go over the public internet. The second requirement is that all traffic from the on-premises office and Azure must happen at layer 3 (network layer). The third requirement is that this connection from on-premises to Azure must be redundant to minimize the opportunity for failure. What type of connection fulfills these three requirements?
A. ExpressRoute with premium add-on
B. ExpressRoute
C. Site-to-Site VPN
D. Virtual WAN
ANSWER46:
Question 47: You have an Azure subscription as well as an on-premises environment that is connected via ExpressRoute circuit. You have two additional branch offices that you need to connect to the network, as well as ten remote employees that change locations frequently but still need access to Azure resources. What is the solution that will provide the quickest setup at the lowest cost?
A. Site-to-Site VPN
B. Point-to-Site VPN
C. Virtual WAN
D. Hub-and-Spoke Network Topology
ANSWER47:
Question 48: You have a small number of servers running a microservice, and you want to make sure that all the servers have connectivity to each other. You also need to calculate network performance metrics like packet loss and link latency. Which two Azure resources do you need to meet this requirement?
A. Log Analytics Workspace
B. Network Performance Monitor
C. Azure Monitor
D. Azure Traffic Manager
ANSWER48:
Question 49: You have two virtual networks named VNet1 and VNet2. VNet1 is located in the West US region, whereas VNet2 is located in the East US region. You need to configure a virtual machine that’s located in VNet1 to also communicate with VMs in VNet2. From the choices available how can we enable communication between resources in VNet1 and VNet2
A. Migrate the VNet1 VM to VNet2 and leave the other VM components on VNet1
B. Migrate the network interface card (NIC), the network security group (NSG) and the VM disks to VNet2
C. Just the VM disks will need to be migrated to VNet2
D. Configure a VNet-to-VNet VPN gateway connection to allow communication between VNets in different regions
ANSWER49:
AZ104 Exam Prep on ios – AZ104 Exam Prep on android
AZ104 Exam Prep on windows 10/11 – AZ104 Exam Prep on web
Question 50: You have two subscriptions, one named Subscription1 and the other named Subscription2. Both subscriptions are located within the same tenant. You have one Azure virtual machine located within Subscription1 and another Azure virtual machine within Subscription2 and you’d like to view CPU utilization metrics on both virtual machines. How can you achieve this while maintaining the minimum number of Azure resources and minimizing cost?
A. Create a Log Analytics Workspace for both VMs
B.Turn on VM Insights in Azure Monitor
C. Install the Log Analytics (OMS) Agent on the VMs
D. Enable guest-level monitoring on each VM
ANSWER50:
Question 51: You have created a new Azure virtual machine named VM1. You plan to use VM1 as a web server, which will require the VM to be accessible using HTTP/S (HTTP and HTTPS) protocol. A Network Security Group (NSG) is attached to the NIC of VM1 with the following rules:
Priority|Name|Port|Protocol|SRC|DEST|Action| |:—|:—:|:—:|:—:|:—:|:—:|—:| |300|Rule2|80|TCP|Any|Any|Deny| |400|Rule1|443|TCP|Any|Any|Deny| |500|Rule4|60-500|TCP|Any|Any|Allow| |600|Rule5|22|TCP|72.166.177.14/32|Any|Deny| |1000|Rule3|22|TCP|Any|Any|Allow|
What changes do you have to make to the NSG in order to meet the requirements for VM1?
A. Change the priority of Rule3 to 200
B. Change the action of Rule1 to Allow
C. Change the priority of Rule4 to 200
D. Change the port of Rule5 to 443
ANSWER51:
Question 52: You have an Azure virtual machine running Windows Server 2016. You need to collect OS level metrics on this virtual machine, including Windows event logs and performance counters. Which of the following items do you need in order to collect this metrics data?
A. Enable guest-level monitoring
B. Windows Diagnostics Extension
C. Log Analytics Agent
D. InfluxData Telegraf Agent
E. Storage Account for Diagnostic Data
ANSWER52:
AZ104 Exam Prep on ios – AZ104 Exam Prep on android
AZ104 Exam Prep on windows 10/11 – AZ104 Exam Prep on web
Question 53: You have an Azure subscription with a virtual machine named VM1. You are using Recovery Services Vault (RSV) to backup VM1 with soft delete enabled. The backup policy is set to backup daily at 11 PM UTC, retain an instant recovery snapshot for 2 days, and retain the daily backup point for 14 days. After the initial backup of VM1, you are instructed to delete the vault and all of the backup data. What should you do?
A. Turn off soft delete in the vault security settings
B. Wait 14 days
C. Stop the backup of VM1 and delete backup data
D. Delete the backup policy
E. Delete Backup Jobs Workload
F. Wait 15 days
ANSWER53:
Question 54: You have a number of virtual machines and web applications running in your Azure environment. These Azure resources are critical for business operations, so you’ve locked the resources in order to prevent deletion. In addition, how can you alert on these actions in the portal, and notify your team via email and SMS when a user is trying to delete or create a new resource from within your Azure subscription?
A. Pin the activity log to your dashboard
B. Create a new alert rule
C. Query Administrative Events and Copy Link to Query
D. Create a new action group
ANSWER54:
AZ104 Exam Prep on ios – AZ104 Exam Prep on android
AZ104 Exam Prep on windows 10/11 – AZ104 Exam Prep on web
Question 55: You have a .NET Core application running in Azure App Services. You are expecting a huge influx of traffic to your application in the coming days. When your application experiences this spike in traffic, you want to detect any anomalies such as request errors or failed queries immediately. What service can you use to assure that you know about these types of errors related to your .NET application immediately?
A. Client-side monitoring
B. Live Metrics Stream in Application Insights
C. Application Insights Search
D. Log analytics workspace
ANSWER55:
Question 56: You have an Azure subscription named Subscription1. In Subscription1 you have two Azure VMs named VM1 and VM2, both running Windows Server 2016. VM1 is backed up using Recovery Services Vault, with a backup policy of producing a daily backup and keeping that daily backup for seven days. Also, a snapshot is kept for 2 days. VM1 is compromised by a virus that infects the entire system, including the files. You need to restore the files from yesterday’s backup of VM1. Where can you restore the files to in the quickest manner?
A. A new Azure VM
B. Restore the VM1 snapshot
C. VM2
D. In-place
ANSWER56:
AZ104 Exam Prep on ios – AZ104 Exam Prep on android
AZ104 Exam Prep on windows 10/11 – AZ104 Exam Prep on web
Question 57: You have a subscription named Subscription1. You would like to be alerted upon certain administrative events within Subscription1 to detect unauthorized access. Which of the following is the quickest method to setup these types of alerts?
A. Monitor > Alerts > New Alert Rule
B. Log Analytics Workspace > myWorkdspace > Advanced Settings
C. Policy > Assignments > Assign Policy
D. Subscriptions > mySubscription > Activity Log > New Alert
ANSWER57:
Microsoft Azure Administrator Certification Q&A:
What does az vmss deallocate do?
The az vmss deallocate command will deallocate and remove the VMs within a VMSS. Azure Doc
A company is planning to use Azure for the various services they offer. They want to ensure that they can bill each department for the resources they consume. They decide to use Azure resource tags to separate the bills department wise. Would this fulfill the requirement?
– Yes, you can use resource tags to organize your Azure resources and also apply billing techniques department wise. The Microsoft documentation mentions the following.
– Reference: Azure resource tags
A company is planning to use Azure for the various services they offer. They want to ensure that they can bill each department for the resources they consume. They decide to use Azure rolebased access control to separate the bills department wise. Would this fulfill the requirement?
– No, This is used to control access to resources and can’t be used for billing purposes.
– Reference: Azure Role Based Access Control
A company is planning to use Azure for the various services they offer. They want to ensure that they can bill each department for the resources they consume. They decide to use Azure policies to separate the bills department wise. Would this fulfill the requirement?
– No, Azure policies are used from a governance perspective and can’t be used to create bills department wise.
– Reference: Azure Gov policies
A company is planning to use the Azure Import/Export service to move data out of its Azure Storage account. Which of the following service could be used when defining the Azure Export job?
– Only the BLOB service is supported by the Export job feature. This is also given in the Microsoft documentation.
– Reference: Azure Blob Storage
Suppose you have an application running on a windows virtual machine in azure. what is the best-practice guidance on where the app should store data files?
– Dedicated data disks are generally considered the best place to store application data files. They can be larger than OS disks and you can optimize them for the cost and performance characteristics appropriate for your data.

AZ104 Exam Prep on ios – AZ104 Exam Prep on android
AZ104 Exam Prep on windows 10/11 – AZ104 Exam Prep on web
Sources/References:
AZ104 Exam Prep on ios – AZ104 Exam Prep on android
AZ104 Exam Prep on windows 10/11 – AZ104 Exam Prep on web
1- Exam AZ-104: Microsoft Azure Administrator
3- Exam AZ-104: Microsoft Azure Administrator – Skills Measured
4- Whizlab
5- Udemy
Azure Breaking News – Azure Certifications Testimonials
- Lmaoooo sorry if this doesn't fit but reddit thought my post taking about the Forsaken character Azure would fit here.by /u/TorrentialChaos2 (Microsoft Azure) on July 16, 2026 at 2:55 am
Didn't realize this wasn't roblox related so if you saw a repost, no u didn't... submitted by /u/TorrentialChaos2 [link] [comments]
- AutoJack: chaining 3 weaknesses to turn AutoGen Studio's browsing agent into localhost RCEby /u/Expert_Sort7434 (Microsoft Azure) on July 16, 2026 at 1:54 am
Based on the technical breakdown Microsoft's Defender Security Research Team published on their Security Blog June 18, here's the architectural impact: AutoGen Studio's MCP WebSocket only validated origin as 127.0.0.1/localhost — fine against a human browser tab on evil.com, useless against an agent's own headless browser, which inherits localhost identity. Combine that with auth middleware that explicitly skipped MCP paths (assuming the WebSocket handler enforced its own checks — it never did), plus unsanitized params reaching a shell call, and a malicious page gets code exec on the dev's own account. PoC fired calc.exe within seconds. Main branch only, PyPI stable (0.4.2.2) unaffected, patched at b047730. Wrote a full breakdown with the CWE mapping and remediation checklist here (background link, previous coverage on the same "implicit local trust" pattern in Writer AI's session-hijack bug): https://www.techgines.com/post/autojack-exploit-chain-autogen-studio-localhost-rce Open question for the thread: for those running agent frameworks with browsing + local MCP/tool servers on the same host — are you actually isolating them in separate containers/VMs, or is localhost-only binding still doing double duty as your auth layer? https://www.techgines.com/post/writeout-writer-ai-vulnerability-cross-tenant-session-hijack submitted by /u/Expert_Sort7434 [link] [comments]
- Built a Zendesk ticket classifier with Microsoft Foundry. Some notes from the build.by /u/sdhilip (Microsoft Azure) on July 15, 2026 at 11:35 pm
I recently built a Zendesk ticket classification workflow for a client. The problem was simple. Support staff were reading every inbound Zendesk ticket and manually assigning it to a business category. It was slow and repetitive, but the bigger issue was consistency. Two people could read the same ticket and classify it differently, especially when the categories were close. The workflow I built looked like this: Zendesk ticket created → webhook sends the ticket data → Azure Function receives subject, description, requester and tags → workflow automation handles processing, routing and error handling → RAG retrieval pulls the relevant sections from the approved classification guide → Microsoft Foundry runs the classification step → classifier returns ranked category recommendations with confidence and reasoning → result is posted to a Microsoft Teams channel → support agent approves or overrides the recommendation A few things I learned from the build: 1. Grounding mattered more than prompt wording. The first version used the category list directly in the prompt. It worked for obvious tickets, but struggled when categories were similar. The model would sometimes pick something that sounded right, but did not match the client’s actual category rules. Adding retrieval over the approved classification guide helped a lot. The model had the client’s own definitions and guidance in context instead of guessing from category names. 2. Fixed categories are important. The model does not return any random category text. It has to return a category from the approved list. If the result cannot be mapped back to that list, the ticket gets flagged for manual review. That made the workflow much more reliable. 3. Confidence scores need reasoning. A confidence number by itself was not very useful. Reviewers wanted to know why the model picked a category. Once each recommendation had a short reason, they could quickly see whether the model understood the ticket or just matched a keyword. That made the review process much easier. 4. Human review was still needed. The goal was not to auto-classify everything blindly. The client wanted an audit trail, so the final decision still sits with a human reviewer. The AI does the first pass, and the support agent approves or overrides it in Teams. For validation, we compared the AI output against historical human-assigned categories. The first run was around 68% agreement. That was lower than expected, but it exposed an important issue: some of the categories and guidance in the source PDF needed updating. After the guide was improved, the workflow reached about 82% agreement with the human-assigned category. That was the useful lesson for me. Some wrong predictions were not only model problems. They showed where the business rules and source guidance were unclear. The final architecture was: Zendesk → Azure Functions → Workflow automation → Azure AI Search for RAG retrieval → Microsoft Foundry → Classification agent → Microsoft Teams channel → Human approval or override Model-wise, this used GPT-5.5 through Microsoft Foundry, with Azure AI Search as the vector store over the approved classification guide. I am not including exact monthly cost because I could not verify billing access cleanly. The main cost areas are model calls, Azure AI Search, Azure Functions, workflow automation, storage and monitoring. Not the flashiest AI project, but it solved a real workflow problem: faster first-pass classification, more consistent category handling, and a review process the support team could actually trust. Curious how others are handling ticket classification or human review in similar workflows. submitted by /u/sdhilip [link] [comments]
- Potential Azure SQL Server/DB Issuesby /u/Coinageddon (Microsoft Azure) on July 15, 2026 at 8:03 pm
Noting an issue we had a couple weeks back and brushed it off at the time as it was not critical, but we were unable to scale our Business Critical Tier DB to 80 cores. We cancelled it after a couple hours and a case was logged. Now we attempting to increase the cores again and same issue occurs where the process sits at 25% and doesn't progress. We left this running for 12 hours and eventually cancelled. MS has been notified and are investigating, but we not getting a clear picture from them. Affecting our UAE North resource. Our Geo replicas not affected as we successfully scaled these. Is anyone else able to confirm this issue ? submitted by /u/Coinageddon [link] [comments]
- Can Azure Policy be used to create activity alerts if they don't exist?by /u/cybersecguy9000 (Microsoft Azure) on July 15, 2026 at 6:48 pm
I'm having a hard time working through this. Can Azure Policy be used to create Azure Monitor Activity Alerts if they don't exist on the resource/subscription or can it only report if they do exist? submitted by /u/cybersecguy9000 [link] [comments]
- 🥇 𝐓𝐨𝐝𝐚𝐲 𝐢𝐬 𝐚 𝐯𝐞𝐫𝐲 𝐬𝐩𝐞𝐜𝐢𝐚𝐥 𝐝𝐚𝐲!by /u/No-Grapefruit7498 (Microsoft Azure) on July 15, 2026 at 5:25 pm
I’m really proud to share that I’ve been renewed for another year as a Microsoft MVP! 💙 It’s an incredible honor to continue being part of this amazing community and to be recognized for contributing through knowledge sharing, community events, and supporting others on their Azure journey. Tonight, I’m definitely going to bed with a big smile on my face. 😊 A huge thank you to everyone who’s been part of this journey, you know who you are! submitted by /u/No-Grapefruit7498 [link] [comments]
- The problem with AI-generated architecture diagrams isn't promptingby /u/Aromatic_Pain5252 (Microsoft Azure) on July 15, 2026 at 5:20 pm
submitted by /u/Aromatic_Pain5252 [link] [comments]
- Is Microsoft for Startups (Founders Hub) Azure credit validity still 12 months?by /u/kiranpeter (Microsoft Azure) on July 15, 2026 at 4:27 pm
I'm applying for Microsoft for Startups and I'm seeing conflicting information about the Azure credit validity. Some older articles and discussions say: Azure credits are valid for 12 months from the date they are granted. As your startup progresses through the program, you can receive additional Azure credits. However, I've also seen recent Microsoft documentation mentioning 90 days to activate the credits and up to 2 years of validity after activation. I'm currently applying through the Azure Portal (Microsoft_Azure_Startups/ProgramApplication.ReactView). Can anyone who has been recently approved confirm: Are Azure credits still valid for 12 months, or has Microsoft changed it? If it has changed, what validity period did you receive? When were you approved? submitted by /u/kiranpeter [link] [comments]
- Microsoft MVP!by /u/brianveldman (Microsoft Azure) on July 15, 2026 at 3:53 pm
I wanted to thank you all for your support throughout the past year. It means a lot, and I'm happy to share that it resulted in another year as a Microsoft MVP! 😍 https://preview.redd.it/odtrfezr0fdh1.png?width=1262&format=png&auto=webp&s=a6041abeae305e66218898699aee3166f0087052 submitted by /u/brianveldman [link] [comments]
- Migration of Security Groups and Users from AD to Entra IDby /u/AdNational6744 (Microsoft Azure) on July 15, 2026 at 12:29 pm
Hi there. I am currently working on a project. We have our AD synced with 'Microsoft Entra Connect Sync'. Our Users/Groups are currently exist in AD and are read only in Entra ID. Some might be used already for Azure RBAC / To give access to Enterprise Applications. Someone suggested the approach: Delete the security groups from Entra ID and restore them from the soft-delete state. This way they become Cloud-only. Is this a legit migration method? Are there any other things to take into account? Does anyone has experience with this? Help appericiated! 😁 submitted by /u/AdNational6744 [link] [comments]
- Built a small tool to stop getting paged for expired Azure SAML certs / app secretsby /u/banx7 (Microsoft Azure) on July 15, 2026 at 12:05 pm
A few months back one of our client tenants had Salesforce SSO just... stop working on a Monday morning. Turned out the SAML signing cert had expired over the weekend. Nobody caught it because the only warning was an email Azure sent to the app owner - who'd left the company a year earlier. Went looking for a better way to stay on top of this and wasn't thrilled with the options: Azure's own heads-up is one email, sent to whoever created the app registration, not necessarily anyone still checking that inbox The portal shows expiry per app, one at a time - if you're running more than a handful of enterprise apps across a few tenants you're clicking through each one manually to piece together the picture Entra ID Governance and the bigger GRC platforms handle this fine but they're priced for orgs a lot bigger than a small MSP or an internal IT team just trying to not get paged again So I built Certy (https://getcerty.com) to fix it for myself, and figured other people probably deal with the same thing. It connects to a tenant with a read-only app registration (just Application.Read.All, never touches the actual cert or secret values) and then watches everything - SAML certs, app secrets, Key Vault certs - across as many tenants as you connect. When something's close to expiring it emails or hits a webhook, and you set the warning window yourself (30/14/7 days out, whatever). A few things it doesn't do yet: It's not real-time - checks run hourly or daily depending on plan, so there's a small gap if something changes between checks Key Vault monitoring just shipped and is still a little rough around the edges API access is only on the higher plan for now Curious what people running bigger multi-tenant setups actually want from something like this - does it need to be broken out per tenant, or is one combined view across all your client tenants enough once you're past a certain number? submitted by /u/banx7 [link] [comments]
- My AI agents run on my personal PC. Azure handles the parts I do not want to lose.by /u/MRobinsonTX (Microsoft Azure) on July 15, 2026 at 10:55 am
My agent stack runs on my personal PC. Azure is the backend and failover environment. Between December and July, I built and operated a multi-agent AI platform that originally ran almost entirely in Azure. The architecture worked, but I kept running into the same problem: I could not get the Azure bill below $50 a month while still meeting my goals for a reasonably robust and secure platform. I wanted private memory, managed secrets, model routing, logging, private networking, repeatable deployment, and a failover path. Once I kept enough Azure services running to support all of that, the monthly cost was closer to $165 to $210. For one user… me. So I changed the design. Instead of asking Azure to host every part of the platform all the time, I kept Azure for the things it is especially good at: - PostgreSQL as the persistent database and memory backend - Key Vault for secrets management - Container registry and standby container environment - Azure AI Foundry as the preferred LLM gateway - Centralized logs and monitoring - A warm failover environment The primary compute now runs on my personal PC. The local services connect to the same persistent Azure backend, so the database, secrets, container images, and model gateway remain available even if the local compute disappears. That gives me most of the Azure benefits I wanted without paying for the full agent stack to sit in Container Apps around the clock. My Azure cost is now under $40 a month, excluding the local hardware, power, and LLM token usage. The move itself was not the hardest part. The harder part was learning that a failover environment is not just a copy of production that happens to be turned off. A few lessons stood out. The standby has to be unable to act by accident. My platform has a Telegram gateway. If the local environment and the Azure standby both start with the same bot token, they both answer every message. Twice. The fix was intentionally simple: the live bot token does not exist in the standby environment. Adding that secret is part of the failover procedure. If the Azure environment wakes up unexpectedly, it can start, connect to the backend, and report its health… but it cannot become a second responder. State synchronization can be more dangerous than downtime. Most durable state lives in PostgreSQL, but some file-based state still needs to be synchronized to Azure. An hourly job copies that state into Azure Files. The problem is that a bad sync can copy deletions and mistakes just as efficiently as good data. Before any destructive sync, the Azure file share now gets a snapshot. That has already saved me once, which is exactly one more time than I expected. Failover is not real until you have tested both directions. Health checks told me everything was fine. The first actual failover found a runbook parameter that had been silently doing nothing for weeks. Failback found more issues. A later audit uncovered eleven separate configuration, environment, and secret-wiring gaps that had been hidden by assumptions in the original environment. There is also a small lease file that decides which site is allowed to hold the live tunnel connector. Two active connectors can create split routing and a very confusing afternoon. All of this became part of AzureAgentForge v1.7. AzureAgentForge combines PaperClip for orchestration, Hermes for agent execution, and Honcho for private memory, then adds the Azure and operational plumbing around them. The larger goal is to run a complete open-source agent stack with: - Multi-agent orchestration and management - Private, self-hosted memory - Model routing and spending controls - Role-scoped tools - Secrets management - Private networking - Logs and model-call observability - Human approval for destructive actions - End-to-end validation that proves agents can actually complete work - Self-hosted primary compute with Azure as the persistent backend and failover environment It is not a one-click SaaS, and some advanced capabilities are disabled by default until the operator intentionally enables them. But after working on this from December through July, the architecture finally feels like it matches the workload. My personal PC handles the day-to-day compute. Azure keeps the durable services, security controls, model access, container assets, and recovery path available. Azure is still doing a lot of the important work. It is just no longer being paid to host idle compute all month. Here’s a link to the MIT-licensed repo if it’s useful to you - https://github.com/mrobinson2/AzureAgentForge For anyone running Telegram, Discord, Slack, or similar gateways with an active-passive setup like I am, how do you prevent the double-responder problem? Removing the live token from the standby feels almost too simple… which is usually a sign that it might be the right answer. submitted by /u/MRobinsonTX [link] [comments]
- Free Blue Team Labs for Azure Security?by /u/udit_p (Microsoft Azure) on July 15, 2026 at 10:54 am
Have to teach a class for Azure Security Training (SOC and Engineering and IAM); need to brush up on my skills so I'd like a set of CTFs with ready made assets and data etc to practice hands-on stuff with. Of course, the lower the cost the better Any recommendations? submitted by /u/udit_p [link] [comments]
- External guest invites displays tenant login page nowby /u/BarbieAction (Microsoft Azure) on July 15, 2026 at 9:20 am
submitted by /u/BarbieAction [link] [comments]
- [ Removed by Reddit ]by /u/Phoenix_6767 (Microsoft Azure) on July 15, 2026 at 8:28 am
[ Removed by Reddit on account of violating the content policy. ] submitted by /u/Phoenix_6767 [link] [comments]
- Host pocketbase without credits?by /u/ShallotPuzzled9326 (Microsoft Azure) on July 15, 2026 at 7:55 am
Hi, being a student, I dont want to add a billing method that doesnt belong to me And I'm out of trial credits If I want to host a BaaS like PocketBase what are my options and alternatives? submitted by /u/ShallotPuzzled9326 [link] [comments]
- Azure SWA cant run tanstack startby /u/ShallotPuzzled9326 (Microsoft Azure) on July 15, 2026 at 7:52 am
submitted by /u/ShallotPuzzled9326 [link] [comments]
- Azure VM shows "Can be onboarded" in Defender despite successful MDE onboardingby /u/Ready-Safety-310 (Microsoft Azure) on July 15, 2026 at 6:12 am
Hi everyone, I'm troubleshooting an issue with Microsoft Defender for Endpoint / Defender for Cloud on Azure VMs and would appreciate any insights. Environment Azure VMs (Windows Server 2019) Defender for Servers Plan 2 enabled MDE integration enabled in Defender for Cloud MDE.Windows extension installed VMs are Entra ID joined Not managed by Intune AMA and MMA present in environment Daily VM shutdown/startup schedule (currently keeping test VMs online) Issue Several VMs show: Onboarding Status: Can be onboarded / Unsupported Discovery Source: Defender for Cloud only Exposure Level: No data available Missing Device AAD ID Missing Sense Client Version Missing Defender Engine Version However, locally on the VM: Get-Service Sense returns Running. dsregcmd /status shows: AzureAdJoined : YES AzureAdPrt : YES Registry shows: OnboardingState = 1 LastConnected = recent LastCncError = 0 Connectivity tests to Microsoft Defender endpoints over TCP 443 are successful. Working vs Non-Working Devices Healthy VMs show: Discovery Sources = Defender for Cloud + Defender for Endpoint Device AAD ID populated Onboarding Status = Onboarded Exposure data available Problem VMs show: Discovery Source = Defender for Cloud only Device AAD ID missing Onboarding Status = Can be onboarded No exposure data What I've Checked Sense service running Defender AV healthy and updated Entra device object exists and Device ID matches No duplicate device records in Defender portal MDE.Windows extension installed and updated Connectivity to Defender endpoints verified VMs kept online for 24+ hours Enabled Microsoft Defender Security Settings Management (MSSM) for Windows Server devices No change after 24 hours Current Theory It feels like the device is successfully onboarded locally, but Defender is failing to correlate the Defender for Endpoint device record with the Azure VM / Entra device object, causing incomplete metadata and incorrect onboarding status. Has anyone seen: Discovery Source stuck on Defender for Cloud only Device showing Can be onboarded despite OnboardingState = 1 Missing Device AAD ID and exposure data Incorrect OS reporting (some devices showing Windows 2000 when they are actually Server 2019) Any suggestions on additional checks before Microsoft Support gets back to me? Thanks in advance. submitted by /u/Ready-Safety-310 [link] [comments]
- Azure Visibility Adviceby /u/Kanyes-middle-nut (Microsoft Azure) on July 15, 2026 at 4:16 am
Hello, I'm humbly coming to you as a vibe coder looking for some advice on this enterprise scale all in one cloud computing 200+ tool behemoth of a software that's Azure is. I just switched roles from an extremely small manufacturing company where I was able to spin up a significant amount of automation tools on a single fairly comprehensive web app via a Vercel, SupaBase (DB+Auth+Storage), and Render paying a total of 25$ a month just for SupaBase. (It's funny I as a solo dev made a company GitHub and just used GitHub sign in to make all the other accounts, essentially no user oversight/differentiality technically if someone else where to ever join the project) My new company is of similar size but does magnitudes more revenue and deals in much more sensitive information. While I was envisioning a similar stack to what I had (going to Clerk for MS SSO Auth, Neon for DB, Modal for VMs and sandboxing), it seems there was already a 'vibe coded' project struck up by the interns. It's pretty in depth and impressive, as part of this new role this project would be handed off to me. Of which they have created in Azure (one of them has true SWE experience(?) ) I've been struggling over the stack as I've never been introduced to Azure before other than running Graph API email automations. After a good week of deliberation I've come to terms that this project and future developments/tools will be in Azure, yet I'm left with one question... HOW IS THIS ENTERPRISE GRADE SOFTWARE UI SO BAD. It feels almost impossible to understand from a single page (or a few) what is being ran under a 'subscription' and if it is actually working at all. We have a postgre db, a VM or 2 (not sure), 20 cron jobs effectively, and a static(?) web app tying it all together. And all this is costing 170$ a month... I feel like I have no visibility into when the VMs are running, getting into the postgre db is a pain (they downgraded the App so now I have to go through VS Code extension if I don't want to download a csv?) I feel like the costing is unclear, cant view the cron job runs easily and see errors (maybe I haven't found this yet?), where's my egress or RAM? Part of this is unfamiliarity and shock, the other part is genuine confusion. I understand (and am thankful) for the benefits of Azure, aka in my current view - user management (previous mention vibe stack is cost effective but can't add more than 3 users w o jumping to $200+ tiers), bullet proof Auth and security that I don't have to deal with or ever have auditors question, and unified billing. BUT HOW DO YALL RUN TS!!! I have heard about workbooks or shared dashboards but are these really the answer? Right now I simply have a ps1 that creates a static Claude artifact of all the above included on one page, I will be transitioning this to API and simply had this live as a separate page in the web app, is this the right decision or should I look more into the former options? It seems like no one is a fan of Click Ops and all prefer az cmd usage but is running your azure from cmd (and at this point Claude/codex generated cmd) really the best method here? Obviously extremely powerful tool but I am dumb founded at the lack of UX and visibility these enterprise grade platforms have (looking at you Google Cloud Console) Ty for reading, I'm just a lowly vibe coder getting introduced to true enterprise grade systems wonder how all you beautiful people deal with the madness. Please let me know any custom tips/tricks/support/criticisms you have. (Wish I could flair as question and rant, mods lmk if I need to change this to rant) submitted by /u/Kanyes-middle-nut [link] [comments]
- 680 on SC-100 1st attempt - Just ranting and venting out, apologies.by /u/ihazchanges (Microsoft Azure) on July 14, 2026 at 7:10 pm
I took my first attempt of SC-100 a few days ago and I felt good before clicking on submit exam. I know I didn't score high but at least a close pass but saw the final score and it was a gut punch. I have about 3 years of Azure Experience but definitely had to learn some new things also as part of the exam which isn't covered with my day-to-day work objectives. I guess I might've underestimated the exam. I studied for about 2 weeks and was getting 85-95% sometimes higher consistently on practice exams. Learning materials that I used: MeasureUp Microsoft Learn for SC 100 Clicking through my work Azure Tenant for learning purposes. It's good a thing that I bought a re-play and will try again next week. Wish me luck! submitted by /u/ihazchanges [link] [comments]

AZ104 Exam Prep on ios – AZ104 Exam Prep on android
AZ104 Exam Prep on windows 10/11 – AZ104 Exam Prep on web
Azure Certification Path 2022- 2023 for someone with no experience coding
This is what I would recommend as the path since you have no coding experience:
AZ900–>AZ104–>SC900–>AZ305 or AZ400 or AZ500 -> AI900
Azure Fundamentals –> Azure Administrator –> Microsoft Security, Compliance, and Identity Fundamentals –> Azure Solutions Architect Expert or Microsoft Azure Security Technologies
or Designing and Implementing Microsoft DevOps Solutions
That being said, I’d recommend learn scripting as that would come in handy for this admin path expert. If you passed SAA, I’m positive you can pass any cert with proper dedication.
FYI – I created this free tool to carve out your certification path. Give it a try here. Open to feedback on how it can be improved for everyone.
Certifications for Microsoft Azure
There’s a Microsoft certification for you, whether or not you’re thinking about what Microsoft Azure is and where to start, or where you should go next in your cloud job. There are around 16 Azure cloud assertions open. Here is an overview of current Microsoft Azure assertions.
Nuts and bolts Level Certifications
Microsoft Certified: Azure Fundamentals
Microsoft Certified: Azure Data Fundamentals
Microsoft Certified: Azure AI Fundamentals
Accomplice Level Certifications
Microsoft Certified: Azure Administrator Associate
Microsoft Certified: Azure Developer Associate
Microsoft Certified: Azure Database Administrator Associate
Microsoft Certified: Azure Security Engineer Associate
Microsoft Certified: Azure Data Scientist Associate
Microsoft Certified: Azure Data Engineer Associate
Microsoft Certified: Azure AI Engineer Associate
Microsoft Certified: Azure Stack Hub Operator Associate
Expert Level Certifications
Microsoft Certified: Azure Solutions Architect Expert
Microsoft Certified: DevOps Engineer Expert
Specialty Certifications
Microsoft Certified: Azure IoT Developer Specialty
Microsoft Certified: Azure for SAP Workloads Specialty
Microsoft Certified: Azure Virtual Desktop Specialty
There are also two other Microsoft assertions that are Azure-related. While we won’t cautiously depict them in this post, dependent upon your master way and limit, they might justify researching.
For security engineers responsible for peril the leaders, checking, and response, the Microsoft Certified: Security Operations Analyst Associate confirmation is required. It requires completing the SC-200 appraisal.
Test SC-300 is required for the Microsoft Certified: Identity and Access Administrator Associate, which is for heads who use Azure AD to manage IAM.
What might be prudent for you to do first?
In particular, you should make certain with regards to what a Microsoft Azure confirmation is and isn’t. Is simply clear? Phenomenal! Then, at that point, we ought to explore three circumstances that can assist you with picking where to start.
“I’m new to development. I’m essentially uninformed in regards to this ‘cloud’ that is quite serious.”
You can sort out some way to cloud in the event that you’re the kind of person who counts “Microsoft Word” as a specific capacity on your resume. On the off chance that you’re just beginning started, a section level certification will outfit you with the language and understanding you’ll need to all the more promptly analyze your ensuing stages. The AZ-900 Azure Fundamentals accreditation is your first stop on the Azure road.
The cloud might be alarming, yet the capacities you’ll get as you seek after this accreditation will help you with understanding it in a way that even an all out beginner can understand — especially if you have the right getting ready. (Look at me as a hotshot, yet I think our Azure Fundamentals getting ready is astonishing.)
“I have a fundamental cognizance of the cloud.”
Perhaps you’ve worked in the IT field beforehand. Perhaps you’ve attempted various things with AWS, GCP, or Azure. Do you accept you’re ready to make a dive? Press the brakes. Start with the Azure Fundamentals affirmation, if you haven’t at this point. In the best circumstance, you’ll see it to be a breeze. Regardless, paying little heed to how far you advance in Azure, this accreditation will give the establishment to future accomplishment. The accompanying crosspiece on the ladder (Azure Administrator Associate) can be an inconvenient one to ascend. Before dealing with it, you’ll need all of the Fundamentals data notwithstanding a huge load of Azure included knowledge.
Here are different Azure Certifications (Microsoft Certified)
AZ-900
For beginners, this is the best Microsoft Azure accreditation. It’s an unprecedented spot to start on the off chance that you’re new to appropriated processing or Microsoft Azure. This one would be Azure 101 if test names appeared to be okay and acceptable.
Test AZ-900: Microsoft Azure Fundamentals ($99 USD) is required.
There are no fundamentals.
For whom this is for?
In a general sense, everyone. Non-particular individuals with a cloud-related calling, similarly as new or cheerful designers or IT experts, could benefit from acknowledging what the cloud is and isn’t. Any person who needs to comprehend the Microsoft Azure environment should have the data expected to complete this evaluation.
Fundamentals DP-900 Microsoft Certified
For inescapable data focused cloud subject matter experts, this is a significant beginning advance assertion.
Test DP-900: Microsoft Azure Data Fundamentals ($99 USD) is required.
There are no fundamentals.
For whom this is for?
This helper is for informational collection draftsmen and data base administrators who are essentially starting with cloud data.
AI Fundamentals AI-900 Microsoft Certified
This Microsoft Azure affirmation exhibits that you appreciate the fundamentals of man-made mental ability (AI) and AI (ML) in Azure for amateurs with both particular and non-specific establishments.
Test AI-900: Microsoft Azure AI Fundamentals ($99 USD) is required.
There are no basics.
For whom this is for?
Reproduced insight Engineers, Data Scientists, Developers, and Solutions Architects with a working data on AL and ML, similarly as Azure organizations related with them. This affirmation, like the others in the Azure Fundamentals series, is normal for those with both specific and non-particular establishments. That proposes data science and PC programming experience aren’t required, but Microsoft recommends making them program data or experience.
Administrator Associate AZ-104 is a Microsoft attestation.
For the IT swarm, this is the rudiments of Azure organization. This takes you from a fundamental perception of the cloud to having the alternative to perform cloud tasks (and get repaid to do them).
Test AZ-104: Microsoft Azure Administrator ($165 USD) is required.
For whom this is for?
This affirmation is for IT specialists and administrators who screen cloud assets and resources and direct cloud system. This test is (mistakenly) seen as an entry level test, yet you’ll need to know an immense heap of anticipated that information should pass and do whatever it takes not to have your AZ denied.
Azure Container Apps:
Azure Container Apps is a serverless offering you can use to host your containers. It is a good fit for containerized apps and hosting microservices. Integrated services like KEDA, Envoy proxy, and Dapr provide you with out-of-the-box auto-scaling, ingress, traffic splitting, and simplified microservice connectivity.
Container Apps service is built on top of Kubernetes. Container Apps are an Azure Resource Manager deployment object, meaning you can’t just use your existing Kubernetes object descriptions and migrate them to Container Apps. You need to rewrite your deployment stack using Bicep or ARM templates. Terraform is not yet supported.
A Twitter List by enoumen





























96DRHDRA9J7GTN6