
An independent study guide for Microsoft Certified: DevOps Engineer Expert · by Tony Rough
Know which branch policy, pipeline feature or deployment pattern fits the delivery requirement, in GitHub or Azure DevOps, and why.
Due on Amazon in November 2026, in Kindle and paperback editions.
This independent study guide for the Microsoft Certified: DevOps Engineer Expert exam distils what AZ-400 really expects you to understand into the comparisons, configuration choices and traps that DevOps decisions turn on, with GitHub and Azure DevOps side by side and short YAML, Git and Azure CLI examples throughout.
Thirteen chapters, each readable on its own and together covering all five AZ-400 skill areas:
DevOps tooling changes quickly. This edition reflects Microsoft's documentation as of October 2026: Managed DevOps Pools as the successor to scale set agents, workload identity federation with the Microsoft Entra issuer, organisation-scoped PATs as global PATs end, GitHub Secret Protection and GitHub Code Security, and the retirement dates for Azure Deployment Environments and Azure Automation State Configuration.
This book contains no exam questions. It explains the knowledge the exam expects, so you can answer questions you have never seen and apply the same judgement in real delivery pipelines.
Written by Tony Rough, a cloud architect with more than twenty years in IT infrastructure who holds the Azure Solutions Architect Expert, Azure Administrator and Azure Security Engineer certifications.
Part of the Ultra Transcenders series from Distilled Press. An independent publication, not affiliated with, sponsored by or endorsed by Microsoft Corporation.
Hold Azure Administrator Associate (AZ-104) or an Azure developer associate certification, then pass AZ-400. The series covers every exam it needs:
Know which role, setting or tool does the job, and why.
Every skill area in Microsoft's AZ-400 outline (as of July 27, 2026), and the chapters that cover it.
| Skill area | Weight | Chapters |
|---|---|---|
| Design and implement processes and communications | 10–15% | 1, 2, 13 |
| Design and implement a source control strategy | 10–15% | 3, 4 |
| Design and implement build and release pipelines | 50–55% | 2, 3, 5, 6, 7, 8, 9, 10 |
| Develop a security and compliance plan | 10–15% | 4, 8, 10, 11, 12 |
| Implement an instrumentation strategy | 5–10% | 13 |
Plus an appendix glossary of 400+ terms, each linked to Microsoft Learn, with the same terms explained free online for print readers.



Some sections of the book, free to read online:
How trunk-based development, GitHub Flow, feature branches, release branches and forks differ, and which fits a team's release cadence.
How the two CI/CD platforms compare on hosting, YAML, integrations and licensing, and when to combine them.
Which agent or runner option fits private network access, custom software, scale and maintenance requirements.
How each release pattern limits risk, what it costs and how traffic or users move to the new version.
How @Local, @Prerelease and @Release views work, how promotion moves packages through them and who consumes each view.
When a pipeline should use a service principal, a system-assigned or a user-assigned managed identity, and the trade-offs of each.
The four DORA metrics, where to get the data in Azure DevOps and GitHub, and which metrics suit planning, development, testing, security, delivery and operations.
How Git LFS pointer files and storage work in Azure Repos and GitHub, the limits on each platform and what pipelines need to fetch LFS content.