Courseiva
Manage Azure Identities and GovernanceeasyMultiple ChoiceObjective-mapped

AZ-104 Manage Azure Identities and Governance Practice Question

Exhibit

Current access review:
- User: Alex
- Existing role: Virtual Machine Contributor
- Scope: RG-Training
- Requirement: Alex must read VM properties and restart only VM-Training01.
- Alex must not delete the VM, manage disks, or change networking settings.

Based on the exhibit, what should the administrator create to let Alex restart one VM and read its properties without giving broader permissions?

⚠ Common exam trap

It's easy for candidates to confuse Azure Policy (which enforces configurations) with RBAC (which controls permissions), or they mistakenly think locks or management groups can grant specific actions like restart.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Create a custom role that includes only the required VM read and restart actions.

Azure custom roles allow you to define granular permissions by specifying only the required actions in the `Actions` field of the role definition. For Alex to restart a VM (`Microsoft.Compute/virtualMachines/restart/action`) and read its properties (`Microsoft.Compute/virtualMachines/read`), a custom role with exactly these two actions provides the least-privilege access without granting broader permissions like VM write or delete.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Create a custom role that includes only the required VM read and restart actions.

    Why this is correct

    A custom role lets the administrator define only the actions needed for the task, such as reading VM properties and restarting the VM. That is the cleanest least-privilege solution when built-in roles are broader than necessary.

  • Create an Azure Policy assignment that allows restart operations on the VM.

    Why it's wrong here

    Azure Policy is a governance tool that enforces rules on resource configurations (e.g., tagging, allowed locations, SKU sizes), but it cannot grant or deny a specific user's permission to perform an action like restarting a VM. Policy assignments evaluate compliance at the resource level, not user authorization; they don't issue access tokens or modify the caller's effective RBAC permissions. A policy definition that 'allows restart operations' has no basis in the Azure Policy schema, which only contains IF/THEN conditions about properties and effects, not action permissions.

    When this WOULD be correct

    An Azure Policy assignment would be correct if the question asked for a way to automatically tag all VMs in a subscription with a specific cost center, or to enforce that VMs are only deployed in certain regions.

  • Apply a CanNotDelete lock to the VM resource.

    Why it's wrong here

    A CanNotDelete lock prevents the VM resource from being deleted by any user, but it does not grant permissions to read properties or trigger a restart. Locks in Azure Resource Manager only enforce deletion or read-only protections, never authorize control-plane actions. Alex's restart request would still fail with an authorization error because his identity lacks the Microsoft.Compute/virtualMachines/restart/action permission, regardless of the lock.

    When this WOULD be correct

    If the question asked how to prevent accidental deletion of a VM while still allowing authorized users to manage it, applying a CanNotDelete lock would be correct.

  • Move the VM to a management group so the permissions become more specific.

    Why it's wrong here

    Management groups are logical containers for subscriptions and are used for hierarchical organization, policy inheritance, and RBAC role assignments at scale. VMs cannot be moved directly into a management group because they reside within a resource group inside a subscription; only subscriptions can be placed in management groups. Even if a VM's subscription were relocated to a different management group, that action alone would not grant a user specific read/restart permissions—it would only change the inheritance scope for existing role assignments, potentially altering effective permissions but not making them more precise. The only way to grant exactly the required actions is a role assignment at an appropriate scope, such as the VM's resource group or the VM resource itself.

    When this WOULD be correct

    An administrator needs to apply a common set of policies (e.g., allowed VM sizes) to multiple subscriptions. Moving the VM to a management group would allow policy inheritance across those subscriptions.

Option-by-option analysis

Why each answer is right or wrong

Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The AZ-104 exam frequently reuses these exact scenarios with slightly different constraints.

Create a custom role that includes only the required VM read and restart actions.Correct answer

Why this is correct

A custom role lets the administrator define only the actions needed for the task, such as reading VM properties and restarting the VM. That is the cleanest least-privilege solution when built-in roles are broader than necessary.

Create an Azure Policy assignment that allows restart operations on the VM.Wrong answer — click to see why

Why this is wrong here

Azure Policy is used to enforce compliance rules on resources, not to grant permissions. It cannot allow a user to perform actions like restarting a VM; it only evaluates and enforces conditions.

★ When this WOULD be the correct answer

An Azure Policy assignment would be correct if the question asked for a way to automatically tag all VMs in a subscription with a specific cost center, or to enforce that VMs are only deployed in certain regions.

Why candidates choose this

Candidates may confuse Azure Policy with Azure RBAC, thinking that policies can grant or deny actions, when in fact policies only audit or enforce resource configurations.

Apply a CanNotDelete lock to the VM resource.Wrong answer — click to see why

Why this is wrong here

A CanNotDelete lock prevents deletion of the VM but does not grant permissions to restart it or read its properties; it only blocks delete operations, not controls access.

★ When this WOULD be the correct answer

If the question asked how to prevent accidental deletion of a VM while still allowing authorized users to manage it, applying a CanNotDelete lock would be correct.

Why candidates choose this

Candidates may confuse locks with permissions, thinking that a lock can restrict operations like restart, or they may assume that preventing deletion is equivalent to granting restart rights.

Move the VM to a management group so the permissions become more specific.Wrong answer — click to see why

Why this is wrong here

Moving a VM to a management group does not grant specific permissions like restart or read properties; it only changes the scope for policy and compliance inheritance, not role-based access control.

★ When this WOULD be the correct answer

An administrator needs to apply a common set of policies (e.g., allowed VM sizes) to multiple subscriptions. Moving the VM to a management group would allow policy inheritance across those subscriptions.

Why candidates choose this

Candidates may think that management groups provide more granular control over permissions, but they are for policy and compliance, not for assigning specific actions like restart.

Analysis generated from the official AZ-104blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”

About these practice questions

One of 1,049 original AZ-104 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AZ-104 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-104 exam.