AZ-104 Manage Azure Identities and Governance Practice Question
A central audit team needs Reader access on every current and future subscription under the company hierarchy. Which scope should you use for the role assignment?
⚠ Common exam trap
A common mix-up: candidates default to subscription scope because they think of subscriptions as the primary boundary for access control, overlooking that management groups provide a broader, hierarchical inheritance that automatically covers future subscriptions.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Management group scope
A management group scope allows role assignments to be inherited by all subscriptions and resource groups within that management group hierarchy. By assigning the Reader role at the management group level, the central audit team automatically gains read access to every current subscription and any future subscription added under that management group, ensuring consistent governance without manual updates.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Management group scope
Why this is correct
Management groups are hierarchical containers that aggregate Azure subscriptions. Assigning the Reader role at a management group scope applies that permission to every subscription within that management group, including any subscriptions added in the future. This makes it the only option here that provides centralized, inheritance-based read access across the entire environment without requiring per-subscription or per-resource assignments. It also supports governance by enabling the audit team's access to be managed in a single place.
- ✗
Subscription scope
Why it's wrong here
A subscription scope restricts the Reader role assignment to exactly one subscription and all resource groups and resources within that subscription. This would require creating a separate role assignment for each existing subscription, and any future subscriptions would not automatically gain access. Therefore, while it might cover a subset of the environment, it cannot satisfy the requirement of every current and future subscription. The central audit team needs a broader, single assignment that scales across the organization.
When this WOULD be correct
If the requirement is to grant Reader access to a single subscription (e.g., for a project-specific auditor) without covering future subscriptions or other subscriptions in the hierarchy, subscription scope would be correct.
- ✗
Resource group scope
Why it's wrong here
Assigning Reader at a resource group scope grants access only to that resource group's resources, not to other resource groups or subscriptions. Because an audit team needs organization-wide visibility, this scope would not cover resources outside that group, and new resource groups created later would be excluded unless separately configured. It is broader than resource scope but still insufficient for the stated central audit requirement, which demands complete coverage of all current and future subscriptions.
When this WOULD be correct
A question requiring Reader access only to a specific resource group and its resources, with no need for cross-subscription or future subscription access.
- ✗
Resource scope
Why it's wrong here
Resource scope applies the Reader role only to a specific resource, such as a single storage account or virtual machine. This is far too granular for an audit team that needs visibility across the entire Azure estate; it would require thousands of individual assignments and would miss all other resources. Additionally, future resources would never be included unless individually assigned, so resource scope is operationally impractical and fails the "every" requirement.
When this WOULD be correct
When the question specifies granting Reader access to a specific resource (e.g., a virtual machine or storage account) for a user or group, resource scope is correct.
Option-by-option analysis
Why each answer is right or wrong
Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The AZ-104 exam frequently reuses these exact scenarios with slightly different constraints.
✓Management group scopeCorrect answer▾
Why this is correct
Management groups are hierarchical containers that aggregate Azure subscriptions. Assigning the Reader role at a management group scope applies that permission to every subscription within that management group, including any subscriptions added in the future. This makes it the only option here that provides centralized, inheritance-based read access across the entire environment without requiring per-subscription or per-resource assignments. It also supports governance by enabling the audit team's access to be managed in a single place.
✗Subscription scopeWrong answer — click to see why▾
Why this is wrong here
Subscription scope only grants Reader access to the selected subscription, not to future subscriptions or other subscriptions under the management group hierarchy.
★ When this WOULD be the correct answer
If the requirement is to grant Reader access to a single subscription (e.g., for a project-specific auditor) without covering future subscriptions or other subscriptions in the hierarchy, subscription scope would be correct.
Why candidates choose this
Candidates may think that assigning at the subscription level covers all current subscriptions under the tenant, but they overlook the need to include future subscriptions and the broader management group hierarchy.
✗Resource group scopeWrong answer — click to see why▾
Why this is wrong here
Resource group scope limits access to a single resource group, not all current and future subscriptions under the company hierarchy.
★ When this WOULD be the correct answer
A question requiring Reader access only to a specific resource group and its resources, with no need for cross-subscription or future subscription access.
Why candidates choose this
Candidates may confuse resource group scope as a way to cover multiple resources within a group, but it does not scale to multiple subscriptions or future subscriptions.
✗Resource scopeWrong answer — click to see why▾
Why this is wrong here
Resource scope applies to a single resource, not to all current and future subscriptions, so it cannot provide Reader access across multiple subscriptions.
★ When this WOULD be the correct answer
When the question specifies granting Reader access to a specific resource (e.g., a virtual machine or storage account) for a user or group, resource scope is correct.
Why candidates choose this
Candidates may think resource scope is sufficient because it's the most granular level, overlooking the requirement for coverage across all subscriptions.
Analysis generated from the official AZ-104blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”
Go deeper
Related to this question
Learn chapter
Dynamic Membership Groups
Key term
Scope
In IT, scope defines the boundaries, goals, and deliverables of a project, assessment, or engagement, specifying what is included and what is excluded.
Key term
Group
A group is a collection of users, devices, or other objects that are assigned permissions and policies together for simplified management in identity and governance systems like Microsoft Entra ID.
About these practice questions
This AZ-104 question is part of Courseiva's 1,049-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-104 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-104 exam.