Microsoft • AZ-700
Validates expertise in designing, implementing, and maintaining Azure networking solutions including hybrid connectivity, application delivery services, private access to Azure services, and network security.
Questions
554
Duration
120 minutes
Passing Score
700/1000
Difficulty
AssociateLast Updated
Jan 2026
The Microsoft Certified: Azure Network Engineer Associate (AZ-700) validates subject matter expertise in designing, implementing, and managing Azure networking solutions. The certification covers five core domains: core network infrastructure (virtual networks, IP addressing, DNS, routing, and NAT), hybrid connectivity (site-to-site VPN, point-to-site VPN, Azure ExpressRoute, and Azure Virtual WAN), application delivery services (Azure Load Balancer, Traffic Manager, Application Gateway, and Azure Front Door), private access to Azure services (Private Link, private endpoints, and service endpoints), and network security (NSGs, Azure Firewall, Firewall Manager, and Web Application Firewall). The exam was last updated on January 21, 2026, reflecting the latest Azure networking capabilities.
Earning this certification demonstrates that a professional can optimize performance, resiliency, scale, and security across Azure networking environments, proactively monitor network health, diagnose routing and connectivity issues, and collaborate effectively with solution architects, cloud administrators, security engineers, and application developers. It is recognized across the industry as a benchmark for Azure network engineering proficiency at the associate level.
This certification targets network engineers and cloud infrastructure professionals who plan, implement, and manage Azure networking solutions as part of their day-to-day responsibilities. Ideal candidates typically hold roles such as Azure Network Engineer, Cloud Network Architect, Infrastructure Engineer, or Network Administrator working in organizations that operate workloads in Azure or are migrating from on-premises environments.
Candidates should have hands-on experience creating and managing compute, storage, and networking resources in Azure, along with a solid understanding of networking fundamentals including name resolution, network protocols (TCP/IP, BGP, IPsec/IKE), and network address management (CIDR, subnetting). Those who regularly work with Azure VNets, ExpressRoute circuits, Application Gateway, Azure Firewall, or hybrid connectivity scenarios will find the exam content closely aligned with their practical experience.
There are no formal prerequisite certifications required to sit for the AZ-700 exam. However, Microsoft recommends that candidates possess practical experience creating and managing compute, storage, and networking resources in Azure before attempting the exam. A working knowledge of Azure fundamentals—such as the concepts covered in the AZ-900 (Azure Fundamentals) certification—provides a useful foundation, though it is not mandatory.
Candidates should be proficient in core networking concepts including IP addressing and subnetting, DNS, routing protocols (including BGP for ExpressRoute scenarios), VPN technologies (IPsec/IKE, SSL/TLS), and network security principles. Familiarity with Azure-specific services such as Virtual Networks, Azure Portal, Azure CLI, and Azure PowerShell is strongly recommended. Prior experience with on-premises networking technologies and hybrid connectivity scenarios involving site-to-site VPNs or MPLS/ExpressRoute circuits will be advantageous.
Exam AZ-700 is a proctored assessment delivered through Pearson VUE, available in both online proctored and in-person test center formats. Candidates are given 100 minutes to complete the exam. The exam may include interactive components such as labs or case studies in addition to standard question types like multiple choice, multiple select, drag-and-drop, and scenario-based questions.
The passing score is 700 out of 1000 on Microsoft's scaled scoring system, which uses a compensatory model—meaning candidates do not need to achieve a minimum score in each individual domain, only an overall scaled score of 700 or above. The exam is available in English, German, Spanish, French, Italian, Japanese, Korean, Portuguese (Brazil), Chinese (Simplified), and Chinese (Traditional). The exam fee is $165 USD (pricing varies by country/region). Certification earned is valid for 12 months and can be renewed at no cost by passing an online renewal assessment on Microsoft Learn.
The Azure Network Engineer Associate certification opens doors to roles such as Azure Network Engineer, Cloud Infrastructure Engineer, Network Architect, and Cloud Solutions Architect at organizations across virtually every industry undertaking Azure adoption or hybrid cloud migrations. As of early 2026, Azure Network Engineers in the United States earn average annual salaries of approximately $109,000–$145,000, with top earners in high-cost markets such as California, Massachusetts, and Washington D.C. commanding $155,000–$165,000 or more depending on experience and seniority.
Demand for certified Azure networking professionals continues to grow as enterprises expand hybrid connectivity using ExpressRoute and Virtual WAN, adopt Zero Trust network security models, and migrate application delivery infrastructure to Azure-native services like Front Door and Application Gateway. Compared to general cloud associate certifications, the AZ-700's specialization in networking positions holders for higher-compensation, more technically complex roles. The certification also serves as a natural stepping stone toward expert-level credentials such as the Azure Solutions Architect Expert (AZ-305) or specialized security certifications, making it a strategically valuable milestone in a cloud networking career path.
1. Wingtip Toys implements Azure Virtual Network Manager security admin configuration with multiple rule collections. They create Always Allow rules for management traffic from specific subnets but discover that some management connections are still being blocked by Network Security Groups. What is the expected behavior of Always Allow rules?
2. Fabrikam Logistics needs to implement Application Gateway with Web Application Firewall to protect against common web vulnerabilities. They want to use the latest security rules while allowing legitimate traffic from their mobile application that doesn't strictly follow standard HTTP specifications. Which WAF configuration approach should they adopt?
3. An administrator at Crestwood University wants to logically separate the network in the student dormitory from the network used by the faculty administration, even though both sets of users are connected to the same physical network switches. This separation is for security and traffic management. What technology allows for the creation of these separate logical networks on the same physical infrastructure?
4. Adventure Works wants to create a load balancing solution where traffic is distributed based on a hash of the source IP, destination IP, source port, destination port, and protocol. They need this distribution to remain consistent for the same connection parameters but want to modify the stickiness behavior for certain applications. Which load balancer distribution method and configuration should they use?
5. An administrator needs to configure a Point-to-Site VPN connection from a Windows 11 laptop ('CLIENT1') to an Azure VPN gateway ('VPNGW1'). The connection must use Microsoft Entra ID for authentication. What is the correct sequence of actions to set up and establish this connection?
All exams included • Cancel anytime