Objective ↔ Vault Coverage Matrix

This matrix maps every Microsoft exam skill area to the exact vault artifact (MOC / module / concept / lab / question) that covers it. It is the remediation specification produced from the independent pedagogical review. Status legend:

  • covered — taught explicitly and correctly
  • 🟡 partial — present but thin / incomplete
  • 🔴 missing — not addressed; must be added
  • ✏️ fixed — was wrong, now corrected

Source coverage reflects the review’s cross-check against Microsoft’s current charters (AZ-104 effective 2026-04-17; AZ-400 effective 2026-07-27) and the verified module structures of az-104t00 / az-400t00.


AZ-104 — Azure Administrator

Domain 1 · Manage Azure identities & governance

Microsoft objectiveVault coverageStatus
Microsoft Entra ID users, groupsuser-account, groups, module create-configure-manage-identities🟡 partial
License management🔴 missing
External / guest users (B2B)mentioned in user-account🟡 partial
Built-in Microsoft Entra roles + interpreting assignmentsazure-ad-roles, role-assignment🟡 partial
SSPR & MFApassword-reset, mfa (both ✏️ fixed)
Browse & query directory / settings🟡 partial
RBAC assignments, scopes, inheritance (additive)rbac, scope, role-assignment (✏️ fixed)
Azure Policy (Deny/Audit/initiatives)azure-policy
Resource locksresource-locks
Resource groups (create/delete/organize)resource-group, module manage-subscriptions-governance🟡 partial
Tags (with limits)resource-tags (✏️ fixed)
Management groupsmanagement-groups🟡 partial
Subscriptions / cost management / budgetssubscription, azure-cost-management🟡 partial
Azure Advisor cost recommendationsazure-advisor

Domain 2 · Implement & manage storage

ObjectiveCoverageStatus
Storage account kind / tier / redundancystorage-account, redundancy-lrs-zrs-grs
Blob & container managementblob-storage, module blob-storage
Object replicationobject-replication
Lifecycle management / access tiersaccess-tier🟡 partial
Blob versioning / soft deleteblob-versioning
Azure Files SMB identity-based accessazure-files🟡 partial
Azure Files snapshots / soft deletefile-snapshots, blob-versioning
Stored access policies + SASsas-token🟡 partial (no stored-access-policy note)
Storage-account encryptionstorage-encryption
Storage access keys / connection stringsstorage-access-keys
Storage network rules / firewall / private endpointsstorage-network-rule, module storage-security
Storage Explorerstorage-browser
AzCopy data movementazcopy

Domain 3 · Deploy & manage compute

ObjectiveCoverageStatus
VM create/configure (sizes, disks)azure-vm, vm-sizes, managed-disks
VM availability (set vs zones vs VMSS)availability-set, availability-zones, virtual-machine-scale-set
VM movementvm-move
VM encryption-at-host / EncryptionAtHostvm-encryption-at-host
VM extensions / custom scriptazure-vm-extension
App Service plans & slotsapp-service-plan, deployment-slots
App Service TLS / certificates / custom domainsapp-service-tls-custom-dns
App Service backup / networkingapp-service-backup, app-service-networking
ACR (Azure Container Registry)acr
ACI (Container Instances) sizing/scalingaci🟡 partial
Azure Container Appsazure-app-container-apps
ARM / Bicep templated deploymentsarm, bicep, arm-template
AKS / Functions (re-weighted in 2026)aks, azure-functions🟡 partial

Domain 4 · Implement & manage virtual networking

ObjectiveCoverageStatus
VNet + subnets + IP addressingvnet, subnet, cidr-ip-addressing
VNet peeringvnet-peering (✏️ question fixed)
Route tables / UDRroute-table
NSG / ASGnsg, asg
Azure DNS / Private DNSazure-dns, private-dns
VPN Gateway / ExpressRoute / VWANvpn-gateway, expressroute, azure-virtual-wan
Load Balancer / App Gateway / Traffic Manager / Front Doorload-balancer, application-gateway, traffic-manager, azure-front-door
Azure Firewall / DDoSazure-firewall, ddos-protection
Network troubleshooting (Network Watcher, connection monitor)network-watcher🟡 partial

Domain 5 · Monitor & maintain resources

ObjectiveCoverageStatus
Azure Monitor (metrics, logs, activity log)azure-monitor, azure-monitor-metrics, azure-monitor-activity-log, log-analytics
KQL querieskql
Alerts + alert processing rulesmetric-alert, action-group, alert-processing-rules
Azure Monitor Insights (VM/storage/network)azure-monitor-insights
Workbooksworkbooks
Azure Backup + Backup vaults / reportsazure-backup, recovery-services-vault🟡 partial
Azure Site Recovery / DRazure-site-recovery

AZ-400 — DevOps Solutions

Note on AZ-400 audit limits: the review could not fully traverse the published AZ-400 paths from the Home page (fixed). Below maps the five high-level domains plus the blueprinted weight (build/release = 50–55%).

Domain 1 · Design & implement processes & communications (≈)

ObjectiveCoverageStatus
DevOps culture / shift-leftdevops-culture, shift-left🟡 partial
Agile / boards / work trackingazure-boards🟡 partial

Domain 2 · Source control strategy

ObjectiveCoverageStatus
Git, branching, PRs, conflictsgit, branching-strategy, pull-request, merge-conflict
GitHub + Azure Repos integrationgithub, azure-repos🟡 partial
Monorepo / repo sizing / outbound identity🔴 missing

Domain 3 · Build & release pipelines (50–55%)

ObjectiveCoverageStatus
YAML pipelinespipeline-yaml, pipeline-run, 30-glossary/advanced-yaml-pipelines as module
Agents / pools / self-hostedagent-pool, self-hosted-agent, module pipeline-security-controls
Templates / steps / jobsjobs-steps, pipeline-templates, module pipeline-components-and-stage
Build & test (unit/integration)build-artifact, ci-trigger, pipeline-integration-tests, test-coverage
Deployment strategies (blue-green/canary/rings/gates/rollback)blue-green-deployment, canary-deployment, deployment-ring, deployment-gate, rollback-strategy, deployment-automation
Service connections / workload identitysubscription-connection, workload-identity-federation
Release management / approvalsenvironment-approvals, dynamic-approval-checks🟡 partial
GitHub Actions as an alternativegithub-actions, modules use-github-actions-for-ci, branch-protection-and-policies

Domain 4 · Infrastructure as Code

ObjectiveCoverageStatus
Bicep / ARM / Terraformbicep, arm-template, terraform
Desired state / driftdesired-state, configuration-drift
IaC in pipelinesinfrastructure-as-code, provisioning-pipeline🟡 partial

Domain 5 · Security / instrumentation

ObjectiveCoverageStatus
Secrets (Key Vault) + variable groupskey-vault, secrets-management, variables-groups, pipeline-security
SAST / DAST / dependency & secret scanningstatic-analysis, dynamic-analysis, dependency-vulnerabilities, secret-scanning🟡 partial
Compliance gatescompliance-gate🟡 partial
Telemetry / Application Insights / synthetic tests / alertingtelemetry, application-insights, synthetic-testing, alerting🟡 partial

Top gaps to close (from the matrix)

AZ-104 (highest priority — many now added, remaining):

  1. Zero-to-Azure foundation path — no sequential onboarding (still missing)
  2. License management — no dedicated note (still 🔴)
  3. Labs + question expansion (cross-cutting, all courses)

AZ-400: 4. Deepen the whole build/release pipeline domain (YAML, agents, deployment strategies, service connections) — the 50–55% blueprinted core is thin 5. Real implementation depth for Git workflows, Boards/GitHub, telemetry

Ready for cross-cutting build-outs

  • Update this matrix as the vault grows (single source of truth for coverage).
  • Labs: one procedural “Learn → Do → Verify → Break → Fix” exercise per module.
  • Questions: expand from 40 toward 250+ weighted by domain.