AZ-104 Manage Azure Identities and Governance Practice Question
A cloud operations team in the Corp business unit needs to read all Azure resources in every current and future subscription under the Corp management group to prepare monthly governance reports. They must not gain access to subscriptions that belong to other business units. What scope should the administrator use when assigning the Reader role?
⚠ Common exam trap
Many candidates choose subscription scope because they think each subscription needs a separate role assignment, failing to realize that management group scope provides inheritance to all current and future subscriptions under that management group.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Management group scope
The Reader role assigned at the management group scope grants read-only access to all subscriptions within that management group, including future subscriptions, because Azure RBAC permissions are inherited by child resources. This meets the requirement to cover all current and future subscriptions under the Corp management group while excluding subscriptions in other business units.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Subscription scope
Why it's wrong here
Assigning the Reader role at a single subscription scope limits access to only that subscription's resources. Azure RBAC permissions are inherited only downward from the subscription to its resource groups and resources, so any other subscriptions in the Corp management group would remain inaccessible. Moreover, subscriptions that are added later under the Corp management group would not automatically receive this role assignment. Thus, subscription scope is insufficient for a whole business unit that may span multiple subscriptions.
When this WOULD be correct
Assign the Reader role at subscription scope when a team needs to read all resources within a specific subscription (e.g., a dedicated subscription for a project) and no access to other subscriptions is required.
- ✗
Resource group scope
Why it's wrong here
A resource group scope would grant Reader permissions only to the resources contained within that specific resource group. This is too narrow for a business unit because it would require the operations team to be separately assigned reader rights on every resource group across all subscriptions in the business unit, which is not scalable and risks gaps in coverage. Also, any new resource groups created later would not be covered unless the assignment is explicitly replicated. Therefore, this scope fails to provide comprehensive read access for the entire corp business unit.
When this WOULD be correct
A scenario where a team needs to read resources only within a specific resource group, such as a project team managing a single application deployment, and no access to other resource groups or subscriptions is required.
- ✓
Management group scope
Why this is correct
This allows the Reader role to be assigned at the management group level, which applies inherited permissions to all subscriptions that are currently children of the Corp management group and automatically to any new subscriptions added later. Because Azure RBAC permissions are inherited from higher-level scopes like management groups down to subscriptions, resource groups, and resources, this scope provides the broadest and most future-proof coverage for the entire business unit. It ensures that the operations team can read resources across multiple subscriptions without needing separate assignments on each subscription. This is the correct choice when the business unit wants to manage a set of subscriptions under a common governance boundary.
- ✗
Resource scope
Why it's wrong here
The resource scope is the most granular RBAC scope, granting permissions only on a single resource, such as one virtual machine or one storage account. This would obviously be insufficient for a cloud operations team that needs to read all resources within an entire business unit, as it would require thousands of individual role assignments to cover everything. It also does not automatically cover any new resources created in the future. Hence, resource scope is inappropriate for the described requirement.
When this WOULD be correct
An administrator needs to grant a user read-only access to a specific Azure resource (e.g., a virtual machine or storage account) for monitoring or auditing purposes, without granting access to any other resources in the same subscription or resource group.
Option-by-option analysis
Why each answer is right or wrong
Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The AZ-104 exam frequently reuses these exact scenarios with slightly different constraints.
✓Management group scopeCorrect answer▾
Why this is correct
This allows the Reader role to be assigned at the management group level, which applies inherited permissions to all subscriptions that are currently children of the Corp management group and automatically to any new subscriptions added later. Because Azure RBAC permissions are inherited from higher-level scopes like management groups down to subscriptions, resource groups, and resources, this scope provides the broadest and most future-proof coverage for the entire business unit. It ensures that the operations team can read resources across multiple subscriptions without needing separate assignments on each subscription. This is the correct choice when the business unit wants to manage a set of subscriptions under a common governance boundary.
✗Subscription scopeWrong answer — click to see why▾
Why this is wrong here
Subscription scope would grant read access only to a single subscription, not to all current and future subscriptions under the Corp management group, failing the requirement for cross-subscription governance reporting.
★ When this WOULD be the correct answer
Assign the Reader role at subscription scope when a team needs to read all resources within a specific subscription (e.g., a dedicated subscription for a project) and no access to other subscriptions is required.
Why candidates choose this
Candidates may think subscription is the natural boundary for resource access, overlooking that management group scope can inherit permissions to multiple subscriptions and automatically include future ones.
✗Resource group scopeWrong answer — click to see why▾
Why this is wrong here
Resource group scope limits access to a single resource group, not all resources across all subscriptions under a management group, so it fails to meet the requirement of reading all resources in current and future subscriptions under Corp.
★ When this WOULD be the correct answer
A scenario where a team needs to read resources only within a specific resource group, such as a project team managing a single application deployment, and no access to other resource groups or subscriptions is required.
Why candidates choose this
Candidates may think resource group scope is sufficient because it grants read access to resources within a group, but they overlook the need to cover all subscriptions under the management group, including future ones.
✗Resource scopeWrong answer — click to see why▾
Why this is wrong here
Resource scope limits the role assignment to a single resource, which cannot cover all resources across multiple subscriptions under a management group, failing the requirement to read all resources in current and future subscriptions.
★ When this WOULD be the correct answer
An administrator needs to grant a user read-only access to a specific Azure resource (e.g., a virtual machine or storage account) for monitoring or auditing purposes, without granting access to any other resources in the same subscription or resource group.
Why candidates choose this
Candidates may mistakenly think that assigning the Reader role at a resource scope is sufficient for reading all resources, or they may confuse resource scope with management group scope due to similar terminology.
Analysis generated from the official AZ-104blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”
Quick reference
Access Control Model Comparison
| Model | Acronym | Who Controls Access? | Best For |
|---|---|---|---|
| Discretionary Access Control | DAC | Resource owner | Small teams, file shares |
| Mandatory Access Control | MAC | System / security labels | Classified govt / military |
| Role-Based Access Control | RBAC | Administrator (via roles) | Enterprise environments |
| Attribute-Based Access Control | ABAC | Policy engine (user + resource attributes) | Fine-grained, dynamic policies |
| Rule-Based Access Control | RuBAC | System rules / ACLs | Firewall rules, network ACLs |
Go deeper
Related to this question
Learn chapter
Privileged Identity Management (PIM)
Key term
Management group
A Management group is a container in Microsoft Azure that helps you organize and manage access, policies, and compliance across multiple Azure subscriptions.
Key term
Subscription
A subscription is a payment model where you pay a recurring fee to access a product or service instead of buying it once and owning it forever.
About these practice questions
This AZ-104 question is part of Courseiva's 1,049-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-104 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-104 exam.