AZ-104 Manage Azure Identities and Governance Practice Question
Exhibit
Compliance report excerpt Policy assignment: Require-department-tag Scope: corp-root management group Effect: Deny Noncompliant resources: - rg-merger01/storage accounts - rg-merger02/storage accounts Exception request: - Allow only resource group rg-merger01 to bypass this policy for 45 days - Keep the policy active for everyone else
Based on the exhibit, a compliance dashboard shows that several storage accounts are marked noncompliant because they do not have the required tag. The policy itself is correct, but one business unit needs a temporary exception for a single resource group during a merger. What should the administrator configure?
⚠ Common exam trap
It's easy for candidates to confuse a policy exemption with modifying the policy effect or scope, not realizing that exemptions are the only built-in mechanism to grant a temporary, scoped exception without affecting the rest of the environment.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
A policy exemption at the rg-merger01 resource group scope.
A policy exemption at the rg-merger01 resource group scope is the correct solution because it allows the administrator to temporarily exclude a specific resource group from the policy's enforcement or compliance evaluation without modifying or deleting the original policy assignment. This is designed for scenarios like mergers where a short-term exception is needed, and it maintains the policy's integrity for all other scopes.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
A policy exemption at the rg-merger01 resource group scope.
Why this is correct
A policy exemption lets the administrator document and scope a temporary exception without disabling the policy for the rest of the environment. Because the request applies to one resource group for a limited time, an exemption at that scope is the cleanest governance solution.
- ✗
Delete the policy assignment from corp-root and recreate it later.
Why it's wrong here
Deleting the assignment would remove enforcement for the entire management group, not just the requested resource group. That would create a governance gap and allow other noncompliant resources to slip through during the merger period.
When this WOULD be correct
If a policy was incorrectly assigned or no longer needed for any resource, and the goal was to permanently remove it from all scopes, then deleting the assignment would be appropriate.
- ✗
Move rg-merger01 to a separate subscription so the policy no longer applies.
Why it's wrong here
Moving the resource group is disruptive and unnecessary. It also does not solve the policy control problem in the simplest way. Azure Policy exemptions are specifically designed for temporary, scoped exceptions without restructuring the environment.
- ✗
Change the policy effect to Audit so the resources can remain noncompliant.
Why it's wrong here
Changing the policy effect to Audit would alter the enforcement behavior for every resource under the corp-root management group, not just rg-merger01. Audit mode only logs noncompliance without blocking or remediating, so it would silently allow all tag violations across the entire hierarchy, creating a broad governance gap. This is a disproportionate, global change when a scoped exemption is the intended mechanism for a temporary, single-resource-group exception.
When this WOULD be correct
If the question asked for a way to monitor noncompliance without enforcing the policy, such as during a pilot or testing phase, changing the effect to Audit would be correct to track violations without blocking deployments.
Option-by-option analysis
Why each answer is right or wrong
Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The AZ-104 exam frequently reuses these exact scenarios with slightly different constraints.
✓A policy exemption at the rg-merger01 resource group scope.Correct answer▾
Why this is correct
A policy exemption lets the administrator document and scope a temporary exception without disabling the policy for the rest of the environment. Because the request applies to one resource group for a limited time, an exemption at that scope is the cleanest governance solution.
✗Delete the policy assignment from corp-root and recreate it later.Wrong answer — click to see why▾
Why this is wrong here
Deleting the policy assignment from corp-root would remove compliance enforcement for all resources, not just rg-merger01, and would require recreating it later, causing unnecessary disruption and administrative overhead.
★ When this WOULD be the correct answer
If a policy was incorrectly assigned or no longer needed for any resource, and the goal was to permanently remove it from all scopes, then deleting the assignment would be appropriate.
Why candidates choose this
Candidates might think removing the policy is a quick fix to stop noncompliance alerts, overlooking that it affects all resources and that a targeted exemption is more appropriate.
✗Change the policy effect to Audit so the resources can remain noncompliant.Wrong answer — click to see why▾
Why this is wrong here
Changing the policy effect to Audit would allow noncompliance but would not provide a temporary exception for a single resource group; it would affect all resources under the policy scope, violating the requirement for a targeted exception.
★ When this WOULD be the correct answer
If the question asked for a way to monitor noncompliance without enforcing the policy, such as during a pilot or testing phase, changing the effect to Audit would be correct to track violations without blocking deployments.
Why candidates choose this
Candidates may think Audit is a quick fix to stop enforcement while still tracking compliance, overlooking that it applies globally and doesn't meet the need for a temporary, scoped exception.
Analysis generated from the official AZ-104blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”
Go deeper
Related to this question
Learn chapter
Customer-Managed Keys (CMK) for Storage Encryption
Key term
Policy
A policy is a set of rules or guidelines that defines how an organization manages, secures, and operates its IT systems and services.
Key term
Group
A group is a collection of users, devices, or other objects that are assigned permissions and policies together for simplified management in identity and governance systems like Microsoft Entra ID.
About these practice questions
This AZ-104 question is part of Courseiva's 1,049-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-104 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-104 exam.