AZ-104 Manage Azure Identities and Governance Practice Question
Network Topology
Based on the exhibit, a contractor must be able to restart only one virtual machine named vm-pay-01 and read its properties. The contractor must not be able to manage any other VM in the resource group. Where should the role assignment be created?
⚠ Common exam trap
Watch out — candidates often assume role assignments must be at the resource group or subscription scope, forgetting that Azure RBAC supports direct assignments at the individual resource scope, which is the most precise way to grant permissions to a single VM.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
At the resource scope for vm-pay-01 so the contractor receives permissions only on that VM.
Azure RBAC allows role assignments at the resource scope, which in this case is the virtual machine vm-pay-01. By assigning a role (e.g., Virtual Machine Contributor or a custom role with restart and read permissions) directly to the VM resource, the contractor receives permissions only on that specific VM, fulfilling the requirement to restrict access to other VMs in the resource group.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
At the subscription scope so the contractor inherits access everywhere in the subscription.
Why it's wrong here
Subscription scope is broader than required and would grant access to all current and future resource groups. That violates least privilege because the contractor only needs access to one virtual machine. It would also make accidental overreach more likely if new resources are added later.
When this WOULD be correct
If the question required the contractor to manage all VMs in the subscription (e.g., restart any VM and read properties), then assigning the role at the subscription scope would be correct to provide inherited access across all resources.
- ✓
At the resource scope for vm-pay-01 so the contractor receives permissions only on that VM.
Why this is correct
Assigning the role at the specific virtual machine resource scope limits the contractor to that VM only. Because Azure RBAC permissions inherit downward, this is the narrowest scope that still allows restart and read operations on vm-pay-01 without exposing other resources in the resource group.
- ✗
At the resource group scope because resource assignments cannot be applied to virtual machines.
Why it's wrong here
Azure RBAC assignments can absolutely be applied at individual resource scope. Resource group scope would be valid technically, but it is wider than needed and would affect every resource in RG-Payroll. The question asks for the least-privilege placement.
When this WOULD be correct
A question where a role must be assigned to all resources within a resource group, and the requirement is to grant permissions to manage multiple VMs or other resources collectively, not a single VM. For example, 'A team needs to manage all VMs in a resource group; where should you assign the Virtual Machine Contributor role?'
- ✗
At the management group scope so the same role can be reused for all payroll subscriptions.
Why it's wrong here
Management group scope is intended for broad governance patterns across multiple subscriptions. It is not appropriate for a contractor who must manage only one VM. That scope would grant far more access than required and could affect unrelated subscriptions.
When this WOULD be correct
This option would be correct if the question required the contractor to restart and read properties of vm-pay-01 across multiple subscriptions (e.g., all payroll subscriptions) and the role needed to be reused consistently, with no restriction to a single resource group.
Option-by-option analysis
Why each answer is right or wrong
Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The AZ-104 exam frequently reuses these exact scenarios with slightly different constraints.
✓At the resource scope for vm-pay-01 so the contractor receives permissions only on that VM.Correct answer▾
Why this is correct
Assigning the role at the specific virtual machine resource scope limits the contractor to that VM only. Because Azure RBAC permissions inherit downward, this is the narrowest scope that still allows restart and read operations on vm-pay-01 without exposing other resources in the resource group.
✗At the subscription scope so the contractor inherits access everywhere in the subscription.Wrong answer — click to see why▾
Why this is wrong here
Assigning the role at the subscription scope would grant the contractor permissions to restart and read properties for all VMs in the subscription, not just vm-pay-01, violating the requirement to restrict access to only that VM.
★ When this WOULD be the correct answer
If the question required the contractor to manage all VMs in the subscription (e.g., restart any VM and read properties), then assigning the role at the subscription scope would be correct to provide inherited access across all resources.
Why candidates choose this
Candidates may think subscription scope is simpler or more comprehensive, or they might overlook the principle of least privilege, assuming broader scope is acceptable for a single VM task.
✗At the resource group scope because resource assignments cannot be applied to virtual machines.Wrong answer — click to see why▾
Why this is wrong here
Role assignments can be applied directly to virtual machines at the resource scope, so the claim that 'resource assignments cannot be applied to virtual machines' is false. Azure RBAC supports assigning roles at the resource level, including individual VMs.
★ When this WOULD be the correct answer
A question where a role must be assigned to all resources within a resource group, and the requirement is to grant permissions to manage multiple VMs or other resources collectively, not a single VM. For example, 'A team needs to manage all VMs in a resource group; where should you assign the Virtual Machine Contributor role?'
Why candidates choose this
Candidates may mistakenly believe that Azure RBAC only supports assignment at subscription or resource group scopes, not at the individual resource level, due to a lack of familiarity with resource-scoped role assignments.
✗At the management group scope so the same role can be reused for all payroll subscriptions.Wrong answer — click to see why▾
Why this is wrong here
Assigning the role at the management group scope would grant the contractor permissions to all virtual machines across all subscriptions under that management group, not just vm-pay-01, violating the requirement to restrict access to only that VM.
★ When this WOULD be the correct answer
This option would be correct if the question required the contractor to restart and read properties of vm-pay-01 across multiple subscriptions (e.g., all payroll subscriptions) and the role needed to be reused consistently, with no restriction to a single resource group.
Why candidates choose this
Candidates may think that using a management group scope is efficient for reusing role assignments across multiple subscriptions, overlooking the need for granular, single-VM access control in this scenario.
Analysis generated from the official AZ-104blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”
Quick reference
Access Control Model Comparison
| Model | Acronym | Who Controls Access? | Best For |
|---|---|---|---|
| Discretionary Access Control | DAC | Resource owner | Small teams, file shares |
| Mandatory Access Control | MAC | System / security labels | Classified govt / military |
| Role-Based Access Control | RBAC | Administrator (via roles) | Enterprise environments |
| Attribute-Based Access Control | ABAC | Policy engine (user + resource attributes) | Fine-grained, dynamic policies |
| Rule-Based Access Control | RuBAC | System rules / ACLs | Firewall rules, network ACLs |
Go deeper
Related to this question
Learn chapter
Managed Identities for Azure Resources
Key term
RBAC
RBAC is a method of restricting network access based on the roles of individual users within an organization, where permissions are assigned to roles rather than to individuals directly.
Key term
Resource group
A logical container in Microsoft Azure that holds related resources for an application or solution, enabling unified management, security, and billing.
About these practice questions
One of 1,049 original AZ-104 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
Same concept, more angles
2 more ways this is tested on AZ-104
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. A contractor must manage only VM1 and VM2 in rg-prod. The contractor must not be able to manage any other resource in the resource group. Which two role assignment scopes should you create? Select two.
medium- ✓ A.Assign the role at the VM1 resource scope.
- ✓ B.Assign the role at the VM2 resource scope.
- C.Assign the role at the rg-prod resource group scope.
- D.Assign the role at the subscription scope.
- E.Assign the role at the management group scope.
Why A: Assigning the role at the VM1 resource scope (Option A) is correct because Azure RBAC allows you to scope a role assignment to an individual resource, such as a virtual machine. This grants the contractor permissions to manage only VM1, without affecting any other resources in the resource group. The same logic applies to VM2, making the resource-level scope the precise way to restrict management to just those two VMs.
Variation 2. A finance analyst needs read-only access to one storage account named stprod01. The analyst must not see other resources in the subscription. Where should you assign the Reader role?
easy- A.At the management group scope that contains the subscription
- B.At the subscription scope that contains the storage account
- C.At the resource group that contains the storage account
- ✓ D.At the storage account resource scope
Why D: Assigning the Reader role at the storage account resource scope (stprod01) grants read-only access exclusively to that specific storage account. This meets the requirement of restricting the analyst from seeing any other resources in the subscription, as role assignments at a higher scope (e.g., resource group, subscription, management group) would inherit permissions to all resources under that scope.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-104 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-104 exam.