Exam AZ-101: Microsoft Azure Integration and Security

Candidates for this exam are Azure Administrators who manage cloud services that span storage, security, networking, and compute cloud capabilities. Candidates have a deep understanding of each service... across the full IT lifecycle, and take requests for infrastructure services, applications, and environments. They make recommendations on services to use for optimal performance and scale, as well as provision, size, monitor, and adjust resources as appropriate. Candidates for this exam should have proficiency in using PowerShell, the Command Line Interface, Azure Portal, ARM templates, operating systems, virtualization, cloud infrastructure, storage structures, and networking.

This exam has been retired

For currently available options, please see the Microsoft Certification exam list.

Schedule exam

Exam AZ-101: Microsoft Azure Integration and Security

Languages: English

This exam measures your ability to accomplish the following technical tasks: secure identities, evaluate and perform server migration to Azure, implement and manage application services, and implement advanced virtual networking.

Official Practice Test for Exam AZ-101

All objectives of the exam are covered in depth so you’ll be ready for any question on the exam.

Skills measured

Evaluate and perform server migration to Azure (15-20%)

Evaluate migration scenarios by using Azure Migrate

  • discover and assess environment
  • identify workloads that can and cannot be deployed
  • identify ports to open
  • identify changes to network
  • identify if target environment is supported
  • setup domain accounts and credentials

Migrate servers to Azure

  • migrate by using Azure Site Recovery (ASR)
  • migate using P2V
  • configure storage
  • create a recovery services vault
  • prepare source and target environments
  • backup and restore data
  • deploy Azure Site Recovery (ASR) agent
  • prepare virtual network

Implement and manage application services (20-25%)

Configure serverless computing

  • create and manage objects
  • manage a Logic App resource
  • manage Azure Function app settings
  • manage Event Grid
  • manage Service Bus

Manage App Service Plans

  • configure application for scaling
  • enable monitoring and diagnostics
  • configure App Service plans

Manage App services

  • assign SSL Certificates
  • configure application settings
  • configure deployment slots
  • configure Azure content delivery network (CDN) integration
  • manage App service protection
  • manage roles for an App service
  • create and manage App Service environment

Implement advanced virtual networking (30-35%)

Implement application load balancing

  • configure application gateway and load balancing rules
  • implement front end IP configurations
  • manage application load balancing

Implement Azure load balancer

  • configure internal load balancer, load balancing rules, and public load balancer
  • manage Azure load balancing

Monitor and manage networking

  • monitor on-premises connectivity
  • use network resource monitoring and Network Watcher
  • manage external networking and virtual network connectivity

Integrate on-premises network with Azure virtual network

  • create and configure Azure VPN Gateway
  • create and configure site to site VPN
  • configure Express Route
  • verify on-premises connectivity
  • manage on-premises connectivity with Azure

Secure identities (25-30%)

Implement Multi-Factor Authentication (MFA)

  • enable MFA for an Azure AD tenant
  • configure user accounts for MFA
  • configure fraud alerts
  • configure bypass options
  • configure trusted IPs
  • configure verification methods
  • manage role-based access control (RBAC)
  • implement RBAC policies
  • assign RBAC Roles
  • create a custom role
  • configure access to Azure resources by assigning roles
  • configure management access to Azure

Manage role-based access control (RBAC)

  • create a custom role
  • configure access to Azure resources by assigning roles
  • configure management access to Azure
  • troubleshoot RBAC
  • implement RBAC policies
  • assign RBAC roles

Implement Azure AD Privileged Identity Management (PIM)

  • activate a PIM role
  • configure just-in-time access, permanent access, PIM management access, and time-bound access
  • create a Delegated Approver account
  • enable PIM
  • process pending approval requests

Prepare for exam


In-browser access
Start learning


Explore courses

Guide to training

All self-paced and instructor-led courses in one comprehensive guide.


Related certifications

Microsoft Certified: Azure Administrator Associate

Azure Administrators implement, monitor, and maintain Microsoft Azure solutions, including major services related to compute, storage, network, and security.

*Pricing does not reflect any promotional offers or reduced pricing for Microsoft Imagine Academy program members, Microsoft Certified Trainers, and Microsoft Partner Network program members. Pricing is subject to change without notice. Pricing does not include applicable taxes. Please confirm exact pricing with the exam provider before registering to take an exam.

Additional resources

Guides to Training and Certifications

Explore all certifications in a concise training and certifications guide or the Training and Certifications poster.

Training guide

Discover training resources to become a Microsoft Certified: Azure Administrator Associate.

Support for certification exams

Get help through Microsoft Certification support forums. A forum moderator will respond in one business day.