Azure AZ-400 DevOps Engineer Expert - Comprehensive Fact Sheet¶
Exam Overview¶
The π AZ-400: Designing and Implementing Microsoft DevOps Solutions - Official exam page with requirements and updates
Prerequisites: - π Azure Administrator Associate (AZ-104) - Recommended prerequisite certification - π Azure Developer Associate (AZ-204) - Alternative prerequisite certification
Exam Details: - Duration: 120 minutes - Question Types: Multiple choice, case studies, drag-and-drop - Passing Score: 700/1000 - Cost: $165 USD
Domain 1: DevOps Strategy and Transformation (10-15%)¶
DevOps Planning and Transformation¶
π DevOps Overview - Comprehensive introduction to DevOps principles and practices
π DevOps Culture - Building and fostering DevOps culture in organizations
π Agile Practices - Agile methodologies and their integration with DevOps
π Azure Boards Overview - Work tracking and agile project management
π Kanban Best Practices - Implementing Kanban boards effectively
π Scrum in Azure DevOps - Scrum framework implementation
π Azure DevOps Projects - Creating and managing Azure DevOps projects
Team Collaboration and Communication¶
π Azure DevOps Wiki - Creating and managing team wikis
π Microsoft Teams Integration - Integrating Azure DevOps with Microsoft Teams
π Slack Integration - Connecting Azure Pipelines to Slack
Metrics and KPIs¶
π DevOps Metrics - Key performance indicators for DevOps success
π Azure DevOps Analytics - Analytics and reporting capabilities
π Velocity and Burndown Charts - Sprint progress tracking
Domain 2: Source Control Management (15-20%)¶
Git Fundamentals¶
π Git in Azure Repos - Git version control in Azure DevOps
π Git Branching Strategy - Best practices for branch management
π Git Branch Policies - Enforcing code quality with branch policies
π Pull Requests - Creating and reviewing pull requests
π Code Reviews - Best practices for code reviews
π Git Hooks - Implementing Git hooks for automation
π Git Large File Storage (LFS) - Managing large files in Git repositories
GitHub and GitHub Actions¶
π GitHub Actions Documentation - Complete guide to GitHub Actions
π GitHub Actions Workflow Syntax - YAML syntax for workflows
π GitHub Actions Runners - Self-hosted and GitHub-hosted runners
π GitHub Secrets Management - Secure handling of secrets in workflows
π GitHub Environments - Environment-specific deployments
π GitHub Advanced Security - Security features for code scanning and secrets
π Dependabot - Automated dependency updates
Azure Repos Advanced Features¶
π TFVC Overview - Team Foundation Version Control
π Repository Permissions - Managing access and security
π Repository Templates - Importing and creating from templates
π Forks - Working with repository forks
Domain 3: Continuous Integration (20-25%)¶
Azure Pipelines Fundamentals¶
π Azure Pipelines Overview - Introduction to Azure Pipelines
π YAML Pipeline Schema - Complete YAML reference
π Pipeline Triggers - Configuring CI, scheduled, and manual triggers
π Pipeline Variables - Working with variables in pipelines
π Variable Groups - Sharing variables across pipelines
π Pipeline Templates - Creating reusable pipeline templates
π Multi-Stage Pipelines - Defining stages in YAML
π Pipeline Jobs - Jobs, dependencies, and conditions
π Pipeline Tasks - Built-in and custom tasks
Build Agents and Runners¶
π Microsoft-Hosted Agents - Using Microsoft-hosted build agents
π Self-Hosted Agents - Deploying and managing self-hosted agents
π Agent Pools - Managing agent pools and queues
π Scale Set Agents - Azure Virtual Machine Scale Sets for agents
Build Optimization and Caching¶
π Pipeline Caching - Speeding up builds with caching
π Pipeline Artifacts - Publishing and consuming pipeline artifacts
π Artifact Feeds - Azure Artifacts feeds overview
π NuGet Packages - Publishing and consuming NuGet packages
π npm Packages - Working with npm packages
π Maven Packages - Publishing Java packages
Container Build Strategies¶
π Docker Build Task - Building Docker images in pipelines
π Azure Container Registry - Container registry service overview
π ACR Tasks - Automated container image builds
π Multi-Stage Docker Builds - Optimizing container images
π Container Image Scanning - Security scanning with Defender
Domain 4: Continuous Delivery and Release Management (20-25%)¶
Release Pipelines and Strategies¶
π Release Pipelines Overview - Classic and YAML release pipelines
π Deployment Jobs - Deployment job configuration
π Deployment Strategies - Rolling, canary, and blue-green deployments
π Environments - Creating and managing environments
π Approvals and Gates - Manual and automated approvals
π Checks and Policies - Environment protection with checks
Azure App Service Deployment¶
π Deploy to App Service - Web app deployment strategies
π App Service Deployment Slots - Using deployment slots for zero-downtime
π App Service Deployment Center - Continuous deployment configuration
π App Service Configuration - Application settings and connection strings
Azure Kubernetes Service (AKS) Deployment¶
π AKS Overview - Azure Kubernetes Service introduction
π Deploy to AKS - Kubernetes deployment pipelines
π Kubernetes Manifests Task - Deploying Kubernetes manifests
π Helm Task - Helm chart deployments
π AKS Blue-Green Deployment - Blue-green strategy for AKS
π AKS Canary Deployment - Canary deployment patterns
π AKS GitOps with Flux - GitOps-based deployments
π Kubernetes Service Connections - Connecting pipelines to Kubernetes
Infrastructure as Code (IaC)¶
π ARM Templates Overview - Azure Resource Manager templates
π ARM Template Best Practices - Design patterns and recommendations
π ARM Template Functions - Template expression functions
π Bicep Overview - Modern IaC language for Azure
π Bicep Best Practices - Bicep coding standards
π Bicep Modules - Creating reusable Bicep modules
π Bicep in Pipelines - Deploying Bicep with Azure Pipelines
π Terraform on Azure - Using Terraform with Azure
π Terraform in Azure Pipelines - CI/CD with Terraform
π Terraform Backends - Remote state in Azure Storage
π Azure CLI in Pipelines - Azure CLI task reference
π PowerShell in Pipelines - Azure PowerShell task
Package Management and Versioning¶
π Semantic Versioning - Version management strategies
π Azure Artifacts Overview - Getting started with Azure Artifacts
π Upstream Sources - Configuring upstream package sources
π Universal Packages - Publishing universal packages
Domain 5: Security and Compliance (15-20%)¶
DevSecOps Fundamentals¶
π DevSecOps on Azure - Security best practices
π Secure DevOps Kit - Secure development lifecycle
π Security in Azure DevOps - Identity and permission management
Secrets Management¶
π Azure Key Vault - Secrets, keys, and certificates management
π Key Vault in Pipelines - Accessing Key Vault secrets
π Azure Key Vault Task - Key Vault task reference
π Variable Groups with Key Vault - Linking secrets from Key Vault
π GitHub Actions Secrets - Managing secrets in GitHub
π Service Connections Security - Securing service connections
Code Security and Scanning¶
π GitHub Code Scanning - Automated code analysis
π CodeQL - Semantic code analysis engine
π SonarCloud Integration - Code quality and security analysis
π Dependency Scanning - Supply chain security
π Microsoft Defender for DevOps - Unified DevOps security management
Compliance and Auditing¶
π Azure Policy - Governance and compliance enforcement
π Azure Blueprints - Environment deployment standards
π Audit Logs - Azure DevOps auditing capabilities
π Pipeline Retention - Build and release retention policies
Managed Identities and RBAC¶
π Managed Identities - Authentication without credentials
π Azure RBAC - Role-based access control
π Service Principals - Application identities in Azure AD
π Workload Identity Federation - Passwordless authentication for workflows
Domain 6: Monitoring and Feedback (10-15%)¶
Application Monitoring¶
π Azure Monitor Overview - Complete monitoring solution
π Application Insights - Application performance management
π Application Insights SDK - Instrumenting applications
π Live Metrics - Real-time application monitoring
π Availability Tests - Proactive availability monitoring
π Application Map - Distributed application topology
Log Analytics and Queries¶
π Log Analytics Overview - Log query environment
π KQL (Kusto Query Language) - Query language reference
π Log Analytics Workspaces - Workspace design and management
π Diagnostic Settings - Collecting resource logs
Alerting and Notifications¶
π Azure Alerts - Alert rules and notifications
π Action Groups - Notification and automated actions
π Smart Detection - AI-powered anomaly detection
π Workbooks - Interactive monitoring reports
Container Monitoring¶
π Container Insights - AKS and container monitoring
π Prometheus Integration - Prometheus metrics in Azure Monitor
π Grafana Integration - Azure Managed Grafana
Advanced Topics and Integration¶
Azure DevOps Extensions¶
π Azure DevOps Marketplace - Extensions and integrations
π Create Pipeline Extensions - Building custom pipeline tasks
π Service Hooks - Webhook integrations
REST APIs and CLI¶
π Azure DevOps REST API - Programmatic access to Azure DevOps
π Azure DevOps CLI - Command-line interface
π GitHub REST API - GitHub API reference
π GitHub CLI (gh) - GitHub command-line tool
Migration and Hybrid Scenarios¶
π Migrate to Azure DevOps - Migration planning and tools
π GitHub to Azure DevOps - Repository migration
π Jenkins to Azure Pipelines - CI/CD migration guide
Performance Optimization¶
π Pipeline Performance - Optimizing build performance
π Parallel Jobs - Understanding parallelism and licensing
π Pipeline Reports - Analyzing pipeline performance
Exam Preparation Resources¶
Official Microsoft Learning¶
π Exam Skills Outline - Detailed skills measured document
π Microsoft Learn AZ-400 Path - Official learning path
π Practice Assessment - Official practice questions
Hands-On Labs¶
π Azure DevOps Labs - Free hands-on labs
π Microsoft Learn Sandbox - Free Azure sandbox environment
π GitHub Skills - Interactive GitHub tutorials
Quick Reference Commands and Snippets¶
Azure CLI Common Commands¶
# Login to Azure
az login
# Set subscription
az account set --subscription "subscription-id"
# Create resource group
az group create --name myRG --location eastus
# Create AKS cluster
az aks create --resource-group myRG --name myAKS --node-count 3
# Get AKS credentials
az aks get-credentials --resource-group myRG --name myAKS
# Create container registry
az acr create --resource-group myRG --name myACR --sku Basic
# Build image in ACR
az acr build --registry myACR --image myapp:v1 .
Azure DevOps CLI Commands¶
# Set default organization and project
az devops configure --defaults organization=https://dev.azure.com/myorg project=myproject
# Create pipeline
az pipelines create --name myPipeline --yml-path azure-pipelines.yml
# Run pipeline
az pipelines run --name myPipeline
# List pipelines
az pipelines list --output table
# Create variable group
az pipelines variable-group create --name myVarGroup --variables key1=value1 key2=value2
GitHub CLI (gh) Commands¶
# Authenticate
gh auth login
# Create workflow file
gh workflow view
# List workflows
gh workflow list
# Run workflow
gh workflow run workflow-name
# View workflow runs
gh run list
# Create secret
gh secret set SECRET_NAME
Kubectl Commands for AKS¶
# Get pods
kubectl get pods -n namespace
# Apply manifest
kubectl apply -f deployment.yaml
# Get services
kubectl get services
# Describe deployment
kubectl describe deployment myapp
# View logs
kubectl logs -f pod-name
# Scale deployment
kubectl scale deployment myapp --replicas=5
# Rollout status
kubectl rollout status deployment/myapp
# Rollback deployment
kubectl rollout undo deployment/myapp
Terraform Commands¶
# Initialize Terraform
terraform init
# Plan infrastructure changes
terraform plan -out=tfplan
# Apply changes
terraform apply tfplan
# Destroy infrastructure
terraform destroy
# Show state
terraform show
# Import existing resource
terraform import azurerm_resource_group.example /subscriptions/xxx/resourceGroups/myRG
PowerShell Azure Commands¶
# Connect to Azure
Connect-AzAccount
# Select subscription
Set-AzContext -SubscriptionId "subscription-id"
# Create resource group
New-AzResourceGroup -Name myRG -Location "East US"
# Deploy ARM template
New-AzResourceGroupDeployment -ResourceGroupName myRG -TemplateFile template.json
# Get deployment history
Get-AzResourceGroupDeployment -ResourceGroupName myRG
Common Pipeline Patterns¶
Multi-Stage YAML Pipeline Example¶
trigger:
branches:
include:
- main
- develop
variables:
buildConfiguration: 'Release'
vmImageName: 'ubuntu-latest'
stages:
- stage: Build
displayName: 'Build Stage'
jobs:
- job: Build
displayName: 'Build Job'
pool:
vmImage: $(vmImageName)
steps:
- task: UseDotNet@2
inputs:
packageType: 'sdk'
version: '8.x'
- task: DotNetCoreCLI@2
displayName: 'Restore packages'
inputs:
command: 'restore'
- task: DotNetCoreCLI@2
displayName: 'Build solution'
inputs:
command: 'build'
configuration: $(buildConfiguration)
- task: DotNetCoreCLI@2
displayName: 'Run tests'
inputs:
command: 'test'
projects: '**/*Tests.csproj'
- task: PublishBuildArtifacts@1
inputs:
pathToPublish: '$(Build.ArtifactStagingDirectory)'
artifactName: 'drop'
- stage: Deploy_Dev
displayName: 'Deploy to Dev'
dependsOn: Build
condition: succeeded()
jobs:
- deployment: DeployWeb
displayName: 'Deploy Web App'
pool:
vmImage: $(vmImageName)
environment: 'dev'
strategy:
runOnce:
deploy:
steps:
- task: AzureWebApp@1
inputs:
azureSubscription: 'service-connection'
appName: 'myapp-dev'
package: '$(Pipeline.Workspace)/drop/**/*.zip'
- stage: Deploy_Prod
displayName: 'Deploy to Production'
dependsOn: Deploy_Dev
condition: succeeded()
jobs:
- deployment: DeployWeb
displayName: 'Deploy Web App'
pool:
vmImage: $(vmImageName)
environment: 'production'
strategy:
runOnce:
deploy:
steps:
- task: AzureWebApp@1
inputs:
azureSubscription: 'service-connection'
appName: 'myapp-prod'
package: '$(Pipeline.Workspace)/drop/**/*.zip'
deploymentMethod: 'zipDeploy'
GitHub Actions Workflow Example¶
name: CI/CD Pipeline
on:
push:
branches: [ main, develop ]
pull_request:
branches: [ main ]
env:
AZURE_WEBAPP_NAME: myapp
AZURE_WEBAPP_PACKAGE_PATH: '.'
DOTNET_VERSION: '8.x'
jobs:
build:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
- name: Setup .NET
uses: actions/setup-dotnet@v3
with:
dotnet-version: ${{ env.DOTNET_VERSION }}
- name: Restore dependencies
run: dotnet restore
- name: Build
run: dotnet build --configuration Release --no-restore
- name: Test
run: dotnet test --no-build --verbosity normal
- name: Publish
run: dotnet publish -c Release -o ./publish
- name: Upload artifact
uses: actions/upload-artifact@v3
with:
name: webapp
path: ./publish
deploy:
runs-on: ubuntu-latest
needs: build
if: github.ref == 'refs/heads/main'
environment: production
steps:
- name: Download artifact
uses: actions/download-artifact@v3
with:
name: webapp
path: ./publish
- name: Azure Login
uses: azure/login@v1
with:
creds: ${{ secrets.AZURE_CREDENTIALS }}
- name: Deploy to Azure Web App
uses: azure/webapps-deploy@v2
with:
app-name: ${{ env.AZURE_WEBAPP_NAME }}
package: ./publish
Docker Build and Push Pipeline¶
# Azure Pipelines
trigger:
- main
pool:
vmImage: 'ubuntu-latest'
variables:
dockerRegistryServiceConnection: 'acr-connection'
imageRepository: 'myapp'
containerRegistry: 'myregistry.azurecr.io'
dockerfilePath: '$(Build.SourcesDirectory)/Dockerfile'
tag: '$(Build.BuildId)'
stages:
- stage: Build
displayName: 'Build and Push Docker Image'
jobs:
- job: Build
steps:
- task: Docker@2
displayName: 'Build and Push'
inputs:
command: buildAndPush
repository: $(imageRepository)
dockerfile: $(dockerfilePath)
containerRegistry: $(dockerRegistryServiceConnection)
tags: |
$(tag)
latest
- task: PublishPipelineArtifact@1
inputs:
targetPath: '$(Build.SourcesDirectory)/manifests'
artifact: 'manifests'
- stage: Deploy
displayName: 'Deploy to AKS'
dependsOn: Build
jobs:
- deployment: Deploy
environment: 'kubernetes-cluster'
strategy:
runOnce:
deploy:
steps:
- task: KubernetesManifest@0
displayName: 'Deploy to Kubernetes'
inputs:
action: 'deploy'
manifests: |
$(Pipeline.Workspace)/manifests/deployment.yml
$(Pipeline.Workspace)/manifests/service.yml
containers: |
$(containerRegistry)/$(imageRepository):$(tag)
Troubleshooting Common Issues¶
Pipeline Failures¶
Issue: Agent job timeout Solution: Increase timeout in pipeline YAML or adjust agent configuration
Issue: Insufficient permissions Solution: Review service connection permissions and Azure RBAC roles
Issue: Missing dependencies Solution: Verify package feeds, upstream sources, and network connectivity
Authentication Issues¶
Issue: Service principal authentication failure Solution: Verify credentials, check expiration, ensure proper RBAC assignment
Issue: Key Vault access denied Solution: Configure Key Vault access policies or use RBAC model
Container Issues¶
Issue: Image pull failures in AKS Solution: Attach ACR to AKS cluster or configure image pull secrets
Issue: Container startup failures Solution: Review pod logs, check resource limits, verify configuration
Performance Issues¶
Issue: Slow build times Solution: Implement caching, use parallel jobs, optimize dependencies
Issue: Agent shortage Solution: Add more agents to pool or use Microsoft-hosted agents
Best Practices Summary¶
Pipeline Design¶
- Use YAML pipelines over classic for version control
- Implement pipeline templates for reusability
- Use variable groups for environment-specific configuration
- Enable pipeline caching for faster builds
- Implement proper staging with approvals
Security¶
- Store secrets in Azure Key Vault
- Use managed identities when possible
- Implement least-privilege access
- Enable code scanning and dependency checks
- Rotate secrets regularly
Source Control¶
- Implement branch policies
- Require pull request reviews
- Use semantic versioning
- Protect main/production branches
- Keep repositories focused and manageable
Monitoring¶
- Implement comprehensive logging
- Set up proactive alerting
- Use Application Insights for APM
- Configure availability tests
- Create dashboards for visibility
Infrastructure as Code¶
- Use Bicep or Terraform consistently
- Version control all IaC
- Implement testing for infrastructure
- Use modules for reusability
- Document infrastructure dependencies
Important Notes for the Exam¶
-
Hands-On Experience: The exam heavily tests practical knowledge. Use Azure DevOps and GitHub Actions extensively.
-
YAML Syntax: Be comfortable writing and debugging YAML pipelines from scratch.
-
Security First: Understand secrets management, managed identities, and secure DevOps practices.
-
Container Knowledge: Know Docker, ACR, and AKS deployment strategies thoroughly.
-
IaC Tools: Be proficient in ARM templates, Bicep, and Terraform for Azure.
-
Monitoring: Understand Application Insights, Log Analytics, and KQL queries.
-
Git Workflows: Master branching strategies, pull requests, and branch policies.
-
Case Studies: Practice scenario-based questions that test decision-making skills.
-
Time Management: The exam has case studies that can be time-consuming. Manage your time wisely.
-
Azure CLI/PowerShell: Know common commands for automation and troubleshooting.
Exam Day Tips¶
- Read each question carefully, especially case studies
- Flag uncertain questions for review
- Watch for keywords like "most cost-effective" or "least administrative effort"
- Eliminate obviously wrong answers first
- Trust your hands-on experience
- Manage time effectively - don't spend too long on any single question
- Review flagged questions if time permits
Good luck with your AZ-400 certification exam!
Last Updated: 2025-10-13 Total Documentation Links: 120 Total Lines: 700+