Courseiva
Manage Azure Identities and GovernanceeasyMultiple ChoiceObjective-mapped

AZ-104 Manage Azure Identities and Governance Practice Question

A central audit team needs Reader access on every current and future subscription under the company hierarchy. Which scope should you use for the role assignment?

⚠ Common exam trap

A common mix-up: candidates default to subscription scope because they think of subscriptions as the primary boundary for access control, overlooking that management groups provide a broader, hierarchical inheritance that automatically covers future subscriptions.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Management group scope

A management group scope allows role assignments to be inherited by all subscriptions and resource groups within that management group hierarchy. By assigning the Reader role at the management group level, the central audit team automatically gains read access to every current subscription and any future subscription added under that management group, ensuring consistent governance without manual updates.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Management group scope

    Why this is correct

    Management groups are hierarchical containers that aggregate Azure subscriptions. Assigning the Reader role at a management group scope applies that permission to every subscription within that management group, including any subscriptions added in the future. This makes it the only option here that provides centralized, inheritance-based read access across the entire environment without requiring per-subscription or per-resource assignments. It also supports governance by enabling the audit team's access to be managed in a single place.

  • Subscription scope

    Why it's wrong here

    A subscription scope restricts the Reader role assignment to exactly one subscription and all resource groups and resources within that subscription. This would require creating a separate role assignment for each existing subscription, and any future subscriptions would not automatically gain access. Therefore, while it might cover a subset of the environment, it cannot satisfy the requirement of every current and future subscription. The central audit team needs a broader, single assignment that scales across the organization.

    When this WOULD be correct

    If the requirement is to grant Reader access to a single subscription (e.g., for a project-specific auditor) without covering future subscriptions or other subscriptions in the hierarchy, subscription scope would be correct.

  • Resource group scope

    Why it's wrong here

    Assigning Reader at a resource group scope grants access only to that resource group's resources, not to other resource groups or subscriptions. Because an audit team needs organization-wide visibility, this scope would not cover resources outside that group, and new resource groups created later would be excluded unless separately configured. It is broader than resource scope but still insufficient for the stated central audit requirement, which demands complete coverage of all current and future subscriptions.

    When this WOULD be correct

    A question requiring Reader access only to a specific resource group and its resources, with no need for cross-subscription or future subscription access.

  • Resource scope

    Why it's wrong here

    Resource scope applies the Reader role only to a specific resource, such as a single storage account or virtual machine. This is far too granular for an audit team that needs visibility across the entire Azure estate; it would require thousands of individual assignments and would miss all other resources. Additionally, future resources would never be included unless individually assigned, so resource scope is operationally impractical and fails the "every" requirement.

    When this WOULD be correct

    When the question specifies granting Reader access to a specific resource (e.g., a virtual machine or storage account) for a user or group, resource scope is correct.

Option-by-option analysis

Why each answer is right or wrong

Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The AZ-104 exam frequently reuses these exact scenarios with slightly different constraints.

Management group scopeCorrect answer

Why this is correct

Management groups are hierarchical containers that aggregate Azure subscriptions. Assigning the Reader role at a management group scope applies that permission to every subscription within that management group, including any subscriptions added in the future. This makes it the only option here that provides centralized, inheritance-based read access across the entire environment without requiring per-subscription or per-resource assignments. It also supports governance by enabling the audit team's access to be managed in a single place.

Subscription scopeWrong answer — click to see why

Why this is wrong here

Subscription scope only grants Reader access to the selected subscription, not to future subscriptions or other subscriptions under the management group hierarchy.

★ When this WOULD be the correct answer

If the requirement is to grant Reader access to a single subscription (e.g., for a project-specific auditor) without covering future subscriptions or other subscriptions in the hierarchy, subscription scope would be correct.

Why candidates choose this

Candidates may think that assigning at the subscription level covers all current subscriptions under the tenant, but they overlook the need to include future subscriptions and the broader management group hierarchy.

Resource group scopeWrong answer — click to see why

Why this is wrong here

Resource group scope limits access to a single resource group, not all current and future subscriptions under the company hierarchy.

★ When this WOULD be the correct answer

A question requiring Reader access only to a specific resource group and its resources, with no need for cross-subscription or future subscription access.

Why candidates choose this

Candidates may confuse resource group scope as a way to cover multiple resources within a group, but it does not scale to multiple subscriptions or future subscriptions.

Resource scopeWrong answer — click to see why

Why this is wrong here

Resource scope applies to a single resource, not to all current and future subscriptions, so it cannot provide Reader access across multiple subscriptions.

★ When this WOULD be the correct answer

When the question specifies granting Reader access to a specific resource (e.g., a virtual machine or storage account) for a user or group, resource scope is correct.

Why candidates choose this

Candidates may think resource scope is sufficient because it's the most granular level, overlooking the requirement for coverage across all subscriptions.

Analysis generated from the official AZ-104blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”

About these practice questions

This AZ-104 question is part of Courseiva's 1,049-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AZ-104 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-104 exam.