The answer is to configure a policy exemption at the rg-merger01 resource group scope. This is correct because an Azure Policy exemption allows you to create a temporary exception from compliance evaluation or enforcement for a specific scope, such as a resource group, without altering the underlying policy assignment or its effect. On the AZ-104 exam, this scenario tests your understanding of how to handle short-term compliance gaps—like a merger—while preserving the policy’s integrity for all other resources. A common trap is confusing exemptions with exclusions: exclusions remove a scope from the policy assignment entirely, whereas exemptions simply pause compliance reporting for that scope. Remember the memory tip: “Exemption for exception, exclusion for removal.”
AZ-104 Manage Azure Identities and Governance Practice Question
This AZ-104 practice question tests your understanding of manage azure identities and governance. This is a configuration task: choose the command set that satisfies every stated requirement. Small differences — like 'secret' vs 'password' or 'transport input ssh' vs 'all' — change whether the answer is correct. After answering, compare your reasoning against the explanation and wrong-answer breakdown below. Once you have made your selection, read the full explanation to reinforce the concept and understand why each distractor is designed to mislead on exam day.
Exhibit
Compliance report excerpt
Policy assignment: Require-department-tag
Scope: corp-root management group
Effect: Deny
Noncompliant resources:
- rg-merger01/storage accounts
- rg-merger02/storage accounts
Exception request:
- Allow only resource group rg-merger01 to bypass this policy for 45 days
- Keep the policy active for everyone else
Based on the exhibit, a compliance dashboard shows that several storage accounts are marked noncompliant because they do not have the required tag. The policy itself is correct, but one business unit needs a temporary exception for a single resource group during a merger. What should the administrator configure?
Compliance report excerpt
Policy assignment: Require-department-tag
Scope: corp-root management group
Effect: Deny
Noncompliant resources:
- rg-merger01/storage accounts
- rg-merger02/storage accounts
Exception request:
- Allow only resource group rg-merger01 to bypass this policy for 45 days
- Keep the policy active for everyone else
A
A policy exemption at the rg-merger01 resource group scope.
A policy exemption lets the administrator document and scope a temporary exception without disabling the policy for the rest of the environment. Because the request applies to one resource group for a limited time, an exemption at that scope is the cleanest governance solution.
B
Delete the policy assignment from corp-root and recreate it later.
Why wrong: Deleting the assignment would remove enforcement for the entire management group, not just the requested resource group. That would create a governance gap and allow other noncompliant resources to slip through during the merger period.
C
Move rg-merger01 to a separate subscription so the policy no longer applies.
Why wrong: Moving the resource group is disruptive and unnecessary. It also does not solve the policy control problem in the simplest way. Azure Policy exemptions are specifically designed for temporary, scoped exceptions without restructuring the environment.
D
Change the policy effect to Audit so the resources can remain noncompliant.
Why wrong: Audit removes enforcement for everyone and would permit any resource to violate the tag requirement. The organization wants a single temporary exception, not a weaker policy baseline for all resources under the management group.
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
A policy exemption at the rg-merger01 resource group scope.
A policy exemption at the rg-merger01 resource group scope is the correct solution because it allows the administrator to temporarily exclude a specific resource group from the policy's enforcement or compliance evaluation without modifying or deleting the original policy assignment. This is designed for scenarios like mergers where a short-term exception is needed, and it maintains the policy's integrity for all other scopes.
Key principle: Answer the scenario, not the keyword: identify the specific constraint before choosing the most familiar-sounding option.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
✓
A policy exemption at the rg-merger01 resource group scope.
Why this is correct
A policy exemption lets the administrator document and scope a temporary exception without disabling the policy for the rest of the environment. Because the request applies to one resource group for a limited time, an exemption at that scope is the cleanest governance solution.
Related concept
Read the scenario before looking for a memorised answer.
✗
Delete the policy assignment from corp-root and recreate it later.
Why it's wrong here
Deleting the assignment would remove enforcement for the entire management group, not just the requested resource group. That would create a governance gap and allow other noncompliant resources to slip through during the merger period.
✗
Move rg-merger01 to a separate subscription so the policy no longer applies.
Why it's wrong here
Moving the resource group is disruptive and unnecessary. It also does not solve the policy control problem in the simplest way. Azure Policy exemptions are specifically designed for temporary, scoped exceptions without restructuring the environment.
✗
Change the policy effect to Audit so the resources can remain noncompliant.
Why it's wrong here
Audit removes enforcement for everyone and would permit any resource to violate the tag requirement. The organization wants a single temporary exception, not a weaker policy baseline for all resources under the management group.
Common exam traps
Common exam trap: answer the scenario, not the keyword
The trap here is that candidates often confuse a policy exemption with modifying the policy effect or scope, not realizing that exemptions are the only built-in mechanism to grant a temporary, scoped exception without affecting the rest of the environment.
Detailed technical explanation
How to think about this question
Policy exemptions in Azure Policy are scoped to a specific resource, resource group, subscription, or management group and can be configured with an expiration date to enforce the temporary nature of the exception. Under the hood, the exemption is stored as a separate resource (Microsoft.Authorization/policyExemptions) that overrides the policy's compliance evaluation for the defined scope, but the policy assignment remains active and continues to evaluate other resources. In real-world scenarios, this is critical during mergers or acquisitions where legacy resources must remain noncompliant for a limited period while migration occurs, and the expiration date ensures the exception is automatically revoked.
KKey Concepts to Remember
Read the scenario before looking for a memorised answer.
Find the constraint that changes the correct option.
Eliminate answers that are true in general but not in this case.
TExam Day Tips
→Watch for words such as best, first, most likely and least administrative effort.
→Review why wrong options are wrong, not only why the correct option is correct.
Key takeaway
Answer the scenario, not the keyword: identify the specific constraint before choosing the most familiar-sounding option.
Real-world example
How this comes up in practice
A media company stores terabytes of video archives that are accessed once a year for audit purposes. Moving these objects to a cold storage tier (Azure Archive, S3 Glacier, or Google Nearline) costs a fraction of hot storage. Questions like this test whether you understand storage tiers, access frequency tradeoffs, and retrieval latency requirements.
Related glossary terms
Concepts from this question explained
These glossary pages explain the core terms tested in this AZ-104 question in full detail.
Manage Azure Identities and Governance — This question tests Manage Azure Identities and Governance — Read the scenario before looking for a memorised answer..
What is the correct answer to this question?
The correct answer is: A policy exemption at the rg-merger01 resource group scope. — A policy exemption at the rg-merger01 resource group scope is the correct solution because it allows the administrator to temporarily exclude a specific resource group from the policy's enforcement or compliance evaluation without modifying or deleting the original policy assignment. This is designed for scenarios like mergers where a short-term exception is needed, and it maintains the policy's integrity for all other scopes.
What should I do if I get this AZ-104 question wrong?
Identify which exam domain this question belongs to, review the core concept, then practise similar questions from the same domain.
What is the key concept behind this question?
Read the scenario before looking for a memorised answer.
About these practice questions
Courseiva creates original exam-style practice questions with explanations and wrong-answer analysis. It does not publish real exam questions, exam dumps, or protected exam content. Learn why practice questions differ from exam dumps →
Share a tip, memory trick, or ask about the reasoning behind this question. Do not post real exam questions, leaked content, braindumps, or copyrighted exam material. Comments are moderated and may be removed without notice.
This AZ-104 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-104 exam.
Question Discussion
Share a tip, memory trick, or ask about the reasoning behind this question. Do not post real exam questions, leaked content, braindumps, or copyrighted exam material. Comments are moderated and may be removed without notice.
Sign in to join the discussion.