A complete, exam-focused companion to the official documentation — rebuilt around the latest Skills Measured (effective July 27, 2026). Learn the concepts, memorize the caveats, and walk into the exam ready.
AZ-400 validates your ability to combine people, processes and products to enable continuous delivery of value. It is unusual among Azure exams in that it spans two toolchains — Azure DevOps and GitHub — and expects you to pick the right one for a scenario, not just to know one of them.
How to use these notes
Work through the five domains in order, but budget your time by weight — Domain 3 alone is over half the exam and is split into six sub-pages. Then drill the Exam Tips & Caveats page before test day. These notes are a companion — pair every section with hands-on practice in a free Azure DevOps organization and a GitHub repo.
Exam weightings — focus your time accordingly. Build and release pipelines is more than half the exam on its own.
Where the marks actually are
If you only have limited time, Domain 3 is the exam. Roughly one question in two comes from pipelines, deployments, IaC, packaging, testing and pipeline maintenance. Domains 1, 2 and 4 are each worth about a quarter of Domain 3; Domain 5 is the smallest but is cheap to learn — basic KQL and Application Insights concepts carry most of it.
Flow of work and traceability, GitHub Flow, Azure Boards ↔ GitHub integration, DORA and flow metrics, dashboards, wikis, Mermaid, release notes, webhooks and Teams integration.
Start here → Domain 2 · 10–15%Branching strategies, branch policies vs branch protection rules, merge types, Git LFS and git-fat, Scalar, permissions, tags, data recovery and secret removal.
Explore → Domain 3 · 50–55%The core of the exam, in six parts: package management, testing strategy, pipelines, deployments, infrastructure as code, and maintaining pipelines.
6 sub-pages → Domain 4 · 10–15%Service principals vs managed identities, workload identity federation, GitHub and Azure DevOps permissions, Key Vault, secure files, GitHub Advanced Security and Defender for Cloud.
Explore → Domain 5 · 5–10%Azure Monitor and Log Analytics, Application Insights, VM/Container/Storage/Network Insights, GitHub insights, alerting, distributed tracing and basic KQL.
Explore → Final reviewThe "which tool" decision tables, Azure DevOps ↔ GitHub terminology map, precedence rules, and the traps AZ-400 reuses year after year.
Read before test day →Prerequisite — read this before you schedule
Passing AZ-400 alone does not grant the certification. Microsoft Certified: DevOps Engineer Expert requires AZ-400 plus either Azure Administrator Associate (AZ-104) or Azure Developer Associate (AZ-204). You may sit AZ-400 first, but the expert badge is only issued once the associate prerequisite is also held.
Exam reality check
Expect case studies, drag-and-drop ordering, "build list" sequencing, hotspot (dropdown) and yes/no statement sets — plus a fair amount of YAML reading. Many questions hinge on which tool / which strategy / which order, and a large share ask you to choose between the Azure DevOps and the GitHub way of doing the same thing. Most questions cover GA features; commonly-used Preview features can appear.
What changed in the July 27, 2026 update
The five functional groups and their weightings are unchanged. Microsoft flagged minor revisions to traceability and flow of work (Domain 1), automate security and compliance scanning (Domain 4), and both instrumentation objectives (Domain 5). In practice this means more emphasis on GitHub-native tooling — GitHub Projects and Issues, GitHub Advanced Security for Azure DevOps, and GitHub insights — rather than new subject areas.
Disclaimer
These notes are an independent study aid for learning purposes only and are not affiliated with or endorsed by Microsoft. Microsoft constantly renames and re-scopes products — always verify every detail against the official Microsoft documentation linked throughout before relying on it.