Home › Certifications › AZ-400 Certification Guide
Microsoft Certification Guide · 2026AZ-400 Certification Guide 2026: DevOps Engineer Expert
Everything about the AZ-400 exam — the prerequisite rule people misread, why a single domain is over half the exam, all 86 examinable objectives mapped, the two domains that cost the most for the least, DevOps salary bands, and a 12-week roadmap.
Authorized Training & Technology Partners
Microsoft
AZ-400 — DevOps Engineer Expert
The credential this guide coversThe certification listing says “Prerequisites: 2 certifications”, and a lot of people read that as needing both. You do not. Microsoft’s wording is: “To become a Microsoft Certified: DevOps Engineer Expert, you must earn at least one of the following: Microsoft Certified: Azure Administrator Associate, Microsoft Certified: Azure Developer Associate.” It is AZ-104 or AZ-204 — the “2” counts the options, not the requirement. But one of them you must have: passing AZ-400 alone earns you no certification.
AZ-400 (Designing and Implementing Microsoft DevOps Solutions) is Microsoft’s Expert-tier DevOps exam. Five domains, 86 objectives — the largest blueprint in this guide series — and pass at 700 out of 1000. The number that matters: one domain, build and release pipelines, is 50–55% of the entire exam. The other four share what is left.
There is a second thing the blueprint makes unmistakable. This is a two-platform exam. The audience profile states you should have experience implementing both GitHub and Azure DevOps solutions, and the objectives bear that out relentlessly: GitHub Flow, GitHub Issues, GitHub Projects, GitHub Actions, GitHub Packages, GitHub Advanced Security, GITHUB_TOKEN, Dependabot and CodeQL sit alongside Azure Boards, Azure Repos, Azure Pipelines, Azure Artifacts and Azure DevOps service connections. Knowing one platform well prepares you for roughly half of it.
AZ-400 exam at a glance
| Attribute | Detail |
|---|---|
| Exam code | AZ-400 — Designing and Implementing Microsoft DevOps Solutions |
| Certification earned | Microsoft Certified: DevOps Engineer Expert |
| Level | Expert — Microsoft’s highest role-based tier |
| Prerequisite | At least one of Azure Administrator Associate (AZ-104) or Azure Developer Associate (AZ-204) — either, not both |
| Required exams | AZ-400 — a single exam, on top of the prerequisite certification |
| Passing score | 700 out of 1000 |
| Domains | Five — but one of them is 50–55% |
| Examinable objectives | 86 across 16 sub-domains — the largest blueprint in this guide series |
| Platforms | Both GitHub and Azure DevOps — stated in the audience profile |
| Skills measured version | Current as of 27 July 2026 |
| Languages | Ten, including English, Japanese, Simplified and Traditional Chinese, Korean, German, French, Spanish, Portuguese (Brazil) and Italian |
| Renewal | Annually — expert certifications expire each year, renewed by a free online assessment on Microsoft Learn |
What is the AZ-400 certification?
Microsoft’s audience profile opens with an unusual sentence: “As a DevOps engineer, you’re a developer or infrastructure administrator who also has subject matter expertise in working with people, processes, and products.” People and processes come before products. That ordering is deliberate, and it is why the exam has an entire domain about flow of work, metrics, dashboards and communication.
The stated responsibility is delivering solutions that provide continuous security, integration, testing, delivery, deployment, monitoring and feedback. Seven continuous things — and note that security is named first, before integration.
Microsoft states: “You must have experience both administering and developing in Azure, with strong skills in at least one of these areas.” That is the reason the prerequisite accepts either AZ-104 or AZ-204 — you may come from either side, but you cannot be ignorant of the other. Administrators who have never written a pipeline in YAML, and developers who have never provisioned infrastructure, both find this exam harder than its Expert label suggests.
AZ-400 skills measured and weightings
Five domains. This is the most lopsided blueprint we have mapped in this series, and the chart makes the point better than any sentence could.
AZ-400 exam blueprint — share of exam by domain
Official Microsoft weightings, skills measured as of 27 July 2026. Bars show the midpoint of each range.
Source: Microsoft Learn, “Study guide for Exam AZ-400”, skills measured as of 27 July 2026. Midpoints are 52.5 / 12.5 / 12.5 / 12.5 / 7.5, summing to 97.5% — Microsoft publishes ranges, so midpoints rarely total exactly 100. The pipelines domain alone outweighs the other four combined.
Where the reading is, versus where the marks are
Eighty-six objectives is a lot to carry. Counting them by domain shows which study hours actually convert into marks — and on this exam, two domains are conspicuously bad value.
Examinable objectives by domain
Count of published bullet-level objectives, against 86 in total
Counted by us from the published blueprint. Pipelines carry 1.50 marks per objective; processes-and-communications and security-and-compliance carry 0.74 each — the same 17 objectives for a third of the reward. Source control is efficient at 1.39, instrumentation middling at 0.94. Pipelines are twice the value per objective of the two weakest domains.
Give the pipelines domain more than half your study time and do not feel guilty about it — it is more than half the exam and the highest yield per topic. Processes-and-communications and security-and-compliance are the traps: 34 objectives between them for 25% of the marks. Learn them, but learn them once and move on. Do not build dashboards for a week because the metrics sub-domain has seven bullets.
The five domains as flashcards
Build and release pipelines — over half the exam
Package management: GitHub Packages and Azure Artifacts, feeds and views, SemVer and CalVer, artifact versioning. Testing: quality and release gates, unit/integration/load tests, test agents, code coverage. Pipelines: GitHub Actions versus Azure Pipelines, runner and agent infrastructure, trigger rules, YAML, parallelism and multi-stage, self-hosted runners, reusable templates and variable groups, YAML-based environment checks and approvals. Deployments: blue-green, canary, ring, progressive exposure, feature flags, A/B testing, deployment slots, hotfix paths, database tasks. IaC: ARM, Bicep, Azure Machine Configuration, Deployment Environments. Maintenance: pipeline health, flaky tests, cost and concurrency optimisation, retention, and classic-to-YAML migration.
50–55% · 35 objectivesProcesses and communications
Traceability and flow of work: GitHub Flow, feedback cycles with notifications and GitHub Issues, tracking across GitHub Projects, Azure Boards and repositories, and source/bug/quality traceability. Metrics: dashboards covering cycle time, time to recovery and lead time, plus queries for planning, development, testing, security, delivery and operations. Collaboration: wikis and process diagrams in Markdown and Mermaid, release notes and API documentation, automating docs from Git history, webhooks, and integrations with Microsoft Teams.
10–15% · 17 objectivesSecurity and compliance
Identity: service principals versus managed identities (system- and user-assigned), GitHub Apps and GITHUB_TOKEN, Azure DevOps service connections and PATs, permissions and roles, stakeholder and outside-collaborator access. Secrets: Azure Key Vault, and secretless authentication via workload identity federation / OpenID Connect, secure files, and designing pipelines that cannot leak. Scanning: dependency, code, secret and licensing scanning, Defender for Cloud DevOps Security, GitHub Advanced Security, container scanning, CodeQL and Dependabot.
Source control strategy
Branching: trunk-based, feature branch and release branch strategies; pull request workflows using branch policies and branch protection rules; merge restrictions. Repositories: large files with Git LFS and git-fat, scaling and optimising with Scalar and cross-repository sharing, permissions, tags, recovering specific data with Git commands, and removing specific data from source control. Nine objectives for 10–15% — efficient, and the domain most likely to reward what you already do daily.
10–15% · 9 objectivesInstrumentation strategy
Monitoring: Azure Monitor and Monitor Logs integrated with DevOps tools; telemetry via Application Insights, VM Insights, Container Insights, Storage and Networks; GitHub insights and charts; alerts for GitHub Actions and Azure Pipelines events. Analysis: CPU, memory, disk and network indicators; usage and application performance; distributed tracing in Application Insights; and interrogating logs with basic KQL — the same Kusto Query Language that DP-700 demands.
5–10% · smallest domainTwo products, one exam
Almost every sub-domain has a GitHub answer and an Azure DevOps answer, and the exam expects you to choose between them on the merits: GitHub Actions or Azure Pipelines, GitHub Packages or Azure Artifacts, GitHub Projects or Azure Boards, branch protection rules or branch policies. If your experience is one-sided, that gap — not the technical depth — is what will cost you marks.
Stated in the audience profileWho AZ-400 is actually for
- AZ-104 or AZ-204 holders moving into platform, DevOps or release engineering — either prerequisite qualifies.
- Developers who own their pipelines and have quietly become the person everyone asks about YAML, runners and release gates.
- Site reliability engineers — the profile names SRE as a team you work alongside, and the instrumentation and deployment-resiliency objectives are squarely SRE work.
- Architects pairing it with AZ-305 — design plus delivery, which is the combination that opens principal-level roles.
Where it will not carry you
- It is not an entry point. An Associate prerequisite is enforced, and the profile asks for experience on both the admin and developer sides.
- Reading will not be enough. Thirty-five pipeline objectives written by people who expect you to have debugged a failing multi-stage YAML build at least once.
- It is Microsoft-ecosystem specific. The DevOps principles are universal; Azure Pipelines syntax, Bicep and Azure Monitor are not.
DevOps and SRE pay
DevOps sits in an unusual position in the pay market. It is the one engineering role where being on call for production is priced in from the start — and where the senior bands are set less by years served than by whether you have owned a release process that could not be allowed to fail.
The DevOps progression
Entry
Mid
Senior
Lead / Principal SRE
DevOps engineer pay by market
India and the US shown as two separate charts, because rupee and dollar bands are different measures on different scales and should never share an axis.
India — annual CTC
DevOps engineer and SRE roles, ₹ lakh per annum
Bar length maps the upper bound of each band against a ₹75 L scale. Bands compiled from published Indian DevOps engineer and SRE ranges. Product companies and global capability centres sit at the top of each band; managed-services roles at the bottom.
United States — annual base
DevOps engineer and SRE roles, US$ thousands
Bar length maps each figure against a $240K scale. Bands compiled from published US DevOps engineer and site reliability engineer ranges; base pay only, excluding bonus, equity and on-call compensation.
These are role bands, not certification outcomes. No published figure attaches a salary increase to holding AZ-400 by itself. What it does do is unusually concrete for a certification: 35 pipeline objectives map almost one-to-one onto what a DevOps interview actually probes — deployment strategies, YAML templating, secretless authentication, pipeline cost and concurrency. Preparing properly for this exam makes you better at the interview whether or not you ever sit it.
Compensation figures are compiled from independent, publicly available industry sources and are shown for role context. They are not a guarantee of pay in any specific market, company or outcome, and 360DT does not promise a salary result from any certification or programme.
Why AZ-400 matters right now
1. Secretless authentication has become the expected default
The blueprint names workload identity federation and OpenID Connect explicitly, alongside managed identities. Long-lived secrets in pipelines are now treated as a defect rather than a convenience, and the exam tests the modern alternative directly. This one objective is worth more in a job interview than most of the domain it sits in.
2. Supply-chain security moved into the pipeline
Dependency scanning, secret scanning, licensing scanning, container image scanning, CodeQL analysis, Dependabot alerts, GitHub Advanced Security integrated with Defender for Cloud. Security is no longer a review stage at the end; it is a set of gates inside the build, and AZ-400 examines it that way.
3. Classic pipelines are a real migration burden
One objective reads simply: migrate a pipeline from classic to YAML in Azure Pipelines. That is on the blueprint because a large installed base still runs classic pipelines, and someone has to move them. It is unglamorous, it is well paid, and very few certifications acknowledge that work exists.
4. Deployment strategy is now a named skill, not a preference
Blue-green, canary, ring, progressive exposure, feature flags, A/B testing, deployment slots and a hotfix path plan — all in one sub-domain. Choosing the right release strategy for a given risk profile is exactly the judgement that separates a DevOps engineer from someone who maintains a build server.
Your 12-week AZ-400 roadmap
Weighted honestly to the blueprint, which means six of the twelve weeks go to pipelines. Assume 8–10 hours per week. This plan assumes you already hold AZ-104 or AZ-204 — if not, that comes first.
Close the platform gap first
Whichever of GitHub or Azure DevOps you use less, spend this week there. Map the equivalents deliberately: Actions and Pipelines, Packages and Artifacts, Projects and Boards, branch protection rules and branch policies. The exam asks you to choose between them, so you cannot know only one.
Source control strategy — efficient, so bank it early
Trunk-based, feature branch and release branch. Pull request workflows with branch policies and protection rules. Merge restrictions. Git LFS and git-fat, Scalar and cross-repo sharing, permissions, tags, recovering data with Git commands, and removing data from source control. Nine objectives, domain closed.
Pipelines, part one — the fundamentals
GitHub Actions versus Azure Pipelines and when each wins. Runner and agent infrastructure, weighing cost, licensing, connectivity and maintainability. Integrating GitHub repositories with Azure Pipelines. Trigger rules. Writing pipelines in YAML — by hand, not from a template.
Pipelines, part two — structure at scale
Job execution order, parallelism and multi-stage pipelines. Hybrid pipelines, VM templates, self-hosted runners and agents. Reusable elements: YAML templates, task groups, variables and variable groups. Checks and approvals via YAML-based environments.
Deployment strategies
Blue-green, canary, ring, progressive exposure, feature flags, A/B testing. Ordering dependent deployments reliably. Minimising downtime with load balancing, rolling deployments and slot swap. A hotfix path plan. Deployment resiliency. Feature flags with Azure App Configuration Feature Manager. Containers, binaries, scripts, and database tasks.
Infrastructure as code
Choosing and implementing a configuration management technology. Defining an IaC strategy with source control and automated testing and deployment. Desired state configuration — Azure Automation State Configuration, ARM, Bicep, Azure Machine Configuration. Azure Deployment Environments for on-demand self-service.
Packages and testing in pipelines
GitHub Packages and Azure Artifacts, feeds and views for local and upstream packages, dependency versioning with SemVer and CalVer, artifact versioning. Then quality and release gates, a full testing strategy from unit to load, test tasks and agents, and code coverage analysis.
Maintaining pipelines — domain closed
Monitoring pipeline health: failure rate, duration, flaky tests. Optimising for cost, time, performance and reliability. Concurrency tuning. Artifact and dependency retention. Migrating a pipeline from classic to YAML. Completes the 35-objective domain — over half the exam banked.
Identity and secrets in automation
Service principals versus managed identities, system- and user-assigned. GitHub Apps, GITHUB_TOKEN, personal access tokens. Azure DevOps service connections. Permissions, roles and security groups. Access levels. Then Key Vault, secure files, and secretless authentication with workload identity federation and OIDC.
Security scanning — domain closed
A scanning strategy across dependency, code, secret and licensing. Defender for Cloud DevOps Security. GitHub Advanced Security for both GitHub and Azure DevOps, and its Defender for Cloud integration. Container image scanning and CodeQL in a container. Dependabot alerts for open-source vulnerabilities.
Instrumentation, processes and metrics
Azure Monitor and Monitor Logs with DevOps tools. Application Insights, VM, Container, Storage and Network Insights. GitHub insights and charts. Alerts for Actions and Pipelines. Distributed tracing. Basic KQL. Then the processes domain in one pass: GitHub Flow, Issues, Projects and Boards, dashboards for cycle time, time to recovery and lead time, wikis in Markdown and Mermaid, release notes, webhooks, Teams integration.
Build one, practice assessment, book the exam
Build a complete multi-stage YAML pipeline end to end: build, test with coverage, scan, approve, deploy blue-green to two environments, authenticate without a single stored secret, and emit telemetry you can query. If you can do that, the exam holds few surprises. Then the free official practice assessment, scored by domain, and book.
Microsoft states it directly on the AZ-400 certification page: “We strongly recommend that you register for an exam with a personal MSA account. If you register with an organizational (work/school) AAD account, your exam records will be lost if you leave your organization and they will be unrecoverable.” With a prerequisite certification and an annual renewal both tied to that record, losing it is expensive.
Learn from Microsoft Certified Trainers
Certification prep at 360DT is delivered live by Microsoft Certified Trainers, Anthropic Authorized Instructors and a Microsoft Business Applications MVP — our full international faculty.
Arshad Ahmad
Microsoft Certified Trainer (MCT), Cybersecurity & Power Platform Expert
Technology Trainer with 15 years in strategic client delivery, holding MCT, Azure Solutions Architect Expert, Cybersecurity Architect Expert and Power BI Data Analyst credentials, with 200+ trainings delivered.
Akim Nyamande
Microsoft, CompTIA, Juniper and Cisco Certified Trainer
IT training facilitator with over five years of experience and certifications across Microsoft, CompTIA, Juniper, and Cisco. Previously a Network Administrator before moving into technical training, now delivering hands-on courses in networking, systems administration, and cybersecurity fundamentals.
Ali El Khatib
Cisco Certified Systems Instructor (CCSI) and Microsoft Certified Trainer
Infrastructure Engineer at RHUH with 13 years in the training field, holding CCSI, MCSE, CCNP Routing and Switching, CCNP Security, CompTIA and Microsoft Azure certifications.
Florian Garcia Compte
Cisco Certified Systems Instructor (CCSI)
Partner Director at AVAANZA FORMACION, a Cisco Learning Partner based in Madrid. Certified Cisco Systems Instructor (CCSI No. 21053) specializing in Cisco Data Center (ACI/SDN), Nexus, and Wireless, delivering official Cisco certification courses including CCNA, CCNP Enterprise, and CCNP Data Center.
Shantanu Pandey
Microsoft, Google, NVIDIA and HPE Certified Trainer
Director of Engineering at Meteoros Automation, ranked in Microsoft's Top 100 Trainers of 2025, holding MCT, Google Cloud, NVIDIA and PeopleCert credentials, with 500+ trainings delivered since 2011.
Vikas Mittal
Google and Anthropic Authorized AI Instructor
Veteran technology trainer with more than 25 years of rich industry experience spanning Google, Microsoft, and emerging AI platforms. An exceptional mentor recognized for proven teaching excellence.
Deep
Anthropic Authorized Instructor and AI Cloud Specialist
Seasoned technology leader with over 20 years of experience across AI, cloud computing, and enterprise training. Known for simplifying complex ideas and delivering practical, real world learning.
Sid
Anthropic Authorized Instructor and Azure Data Engineer
Dynamic corporate trainer and consultant with more than 10 years of experience across Microsoft Fabric, Azure Data Engineering, and modern cloud platforms. Focused on clear, practical learning that sticks.
Bipeen
AWS, Microsoft, and Anthropic Certified Trainer
AI, machine learning, and cloud transformation expert with more than 25 years of experience. A renowned global corporate trainer and conference speaker known for practical, outcome driven sessions.
Sravia
NVIDIA Authorized Instructor and AI Data Specialist
Passionate AI and data evangelist with over 10 years of experience across machine learning, MLOps, and cloud native technologies. Dedicated to delivering impactful, engaging enterprise training programs.
Johan
Microsoft Business Applications MVP and Microsoft Certified Trainer
D365 Customer Service Lead – Europe at Avanade, and founder of the Power Platform School. A Microsoft Business Applications MVP and Microsoft Certified Trainer based in London, specializing in Dynamics 365 Customer Service and Power Platform.
Azure DevOps + Solutions Architect Program
The 360DT Azure DevOps + Solutions Architect Program covers the full AZ-400 blueprint — the 35-objective pipelines domain in depth, deployment strategies from blue-green to progressive exposure, infrastructure as code with Bicep, secretless authentication, and supply-chain scanning — alongside AZ-305 for the architecture half. Design and delivery together, on both GitHub and Azure DevOps.
Explore the Azure DevOps Program
AZ-400 frequently asked questions
Do I need both AZ-104 and AZ-204 before AZ-400?
No — you need one of them. The certification listing says “Prerequisites: 2 certifications”, which reads as though both are required, but Microsoft’s wording is “you must earn at least one of the following: Microsoft Certified: Azure Administrator Associate, Microsoft Certified: Azure Developer Associate”. The two are alternatives. You do, however, need one of them — passing AZ-400 alone earns no certification.
What is the biggest domain on the AZ-400 exam?
Build and release pipelines, at 50–55% — more than the other four domains combined. It holds 35 of the exam’s 86 objectives, covering package management, testing, pipeline design, deployment strategies, infrastructure as code and pipeline maintenance. Plan for it to take more than half your study time, because it is more than half the exam.
Do I need to know both GitHub and Azure DevOps?
Yes. The audience profile states you should have experience implementing both GitHub and Azure DevOps solutions, and the objectives pair them throughout: GitHub Actions and Azure Pipelines, GitHub Packages and Azure Artifacts, GitHub Projects and Azure Boards, branch protection rules and branch policies. The exam frequently asks which to choose, so one-sided experience is the most common preparation gap.
Which AZ-400 domains are the worst value to study?
Processes-and-communications and security-and-compliance. Each carries 17 objectives for only 10–15% of the marks — about 0.74 marks per objective, against 1.50 for pipelines. That is twice the return per topic in the pipelines domain. Learn the weak two properly but once; do not let the seven-bullet metrics sub-domain consume a week.
How long does it take to prepare for AZ-400?
Around twelve weeks at 8–10 hours per week for someone already holding AZ-104 or AZ-204 — the roadmap on this page, which gives six of those weeks to pipelines. At 86 objectives it is the largest blueprint in this guide series, and much of it assumes you have actually operated a release process rather than read about one.
Is AZ-400 harder than AZ-305?
Broader rather than harder. AZ-305 has 49 objectives and almost all of them ask you to recommend; AZ-400 has 86 and asks you to design and implement. AZ-305 rewards judgement under constraints; AZ-400 rewards hands-on breadth across two platforms. Most people find whichever one is furthest from their day job to be the harder sit.
Does the DevOps Engineer Expert certification expire?
Yes. Microsoft’s role-based and specialty certifications expire annually, and Expert tier is included. Renewal is free through a short online assessment on Microsoft Learn during your renewal window. You will also need to keep your prerequisite Associate certification current.
AZ-400 or AZ-305 — which should I take first?
AZ-400 if your next role is delivery, pipelines and release engineering; AZ-305 if it is architecture and design. Both are Expert tier and both require an Associate prerequisite — and conveniently, AZ-104 satisfies both, so taking that route first keeps either door open. Our programme pairs them because architecture without delivery is a diagram, and delivery without architecture is a fast route to the wrong system.
Sources and further reading
- Microsoft Learn — Study guide for Exam AZ-400: Designing and Implementing Microsoft DevOps Solutions (audience profile requiring both GitHub and Azure DevOps experience; five skills-measured domains and weightings; full objective list; skills measured as of 27 July 2026; change log)
- Microsoft Learn — Microsoft Certified: DevOps Engineer Expert certification page, which states: “To become a Microsoft Certified: DevOps Engineer Expert, you must earn at least one of the following: Microsoft Certified: Azure Administrator Associate, Microsoft Certified: Azure Developer Associate”, and carries the personal-MSA registration warning quoted on this page
- Microsoft Learn — exam scoring and score reports (a score of 700 or greater is required to pass)
- Microsoft Learn — certification renewal (associate, expert and specialty certifications expire annually and renew via a free online assessment)
- Objective counts and marks-per-objective figures on this page were tallied by us from the published blueprint: 35 / 17 / 17 / 9 / 8 objectives, 86 in total
- Published Indian and US DevOps engineer and site reliability engineer compensation ranges, used for role context only
360DT is an independent training provider. Microsoft certification exams are administered by Microsoft through Pearson VUE and are not included in programme tuition. Exam details are accurate as of 20 August 2026; always confirm current format, pricing, prerequisites, renewal policy and skills measured on Microsoft Learn before booking.