AZ-104 Manage Azure Identities and Governance Practice Question
Exhibit
Policy assignment: Require-Environment-Tag Compliance summary: - Compliant resources: 18 - Non-compliant resources: 5 - Evaluation time: 2026-04-26 10:30 UTC Need: - Identify the specific non-compliant resources - Review why they failed the policy evaluation
Based on the exhibit, where should the administrator go to see which resources are non-compliant with the assigned policy?
⚠ Common exam trap
A common mix-up: candidates confuse the Azure Activity log (which records who did what) with the Azure Policy compliance view (which shows what is out of compliance), leading them to pick the Activity log instead of the dedicated compliance dashboard.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Azure Policy compliance view.
The Azure Policy compliance view is the correct place to see which resources are non-compliant with assigned policies. This view aggregates compliance states across all policies and initiatives, showing a per-resource breakdown of compliant, non-compliant, and exempt statuses. It directly reflects the evaluation results from the Azure Policy engine, which runs periodic scans and on-demand evaluations.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Azure Policy compliance view.
Why this is correct
The Azure Policy compliance view, accessible under the Policy blade, provides the authoritative report of evaluation results for assigned policy definitions and initiatives. It displays per-resource and per-policy compliance states such as Compliant, Non-compliant, and Conflicting, and you can filter by scope, export to CSV, or open the raw compliance data. This is where an administrator must go to see which specific resources are non-compliant and why, including the triggering policy rule and any effect applied.
- ✗
Entra ID users and groups.
Why it's wrong here
Entra ID users and groups manages identity and access objects within Microsoft Entra ID (formerly Azure AD), such as sign-in events, roles, and group memberships. Azure Policy compliance tracks Azure Resource Manager resource attributes against assignable policies, not identity properties, and Entra ID has no native resource compliance aggregation. Even where policy affects users indirectly, e.g., conditional access, that is not Azure Policy compliance which is scoped to subscriptions and management groups, not directory identities.
When this WOULD be correct
This option would be correct if the question asked: 'Where should the administrator go to assign a user to a role that can manage policy compliance?' or 'Where to review which users have access to modify policies?'
- ✗
Azure Activity log only.
Why it's wrong here
The Azure Activity log only records control-plane operations, such as create, update, and delete actions on management plane resources, and it never contains a resource's ongoing compliance state against policy assignments. Although some policy effects like 'deny' may generate an activity log entry when a create/update is blocked, the Activity log is not a compliance report and cannot show the full list of non-compliant resources or their policy evaluation results. Therefore, relying solely on the Activity log would miss the intended policy compliance dashboard complete with assessment timestamps and resource-level details.
- ✗
Resource locks blade.
Why it's wrong here
The Resource locks blade, found under Settings for a resource, allows you to apply a CanNotDelete or ReadOnly lock to prevent accidental deletion or modification, but it has no visibility into policy evaluation outcomes. Locks are an additional authorization check that operates separately from Azure Policy's resource-state evaluation, so they never show compliance percentages, non-compliant resources, or policy initiative results. Checking this blade would only show lock assignments, not the policy compliance data the administrator is looking for.
When this WOULD be correct
An administrator needs to prevent deletion of a critical resource by applying a lock (e.g., CanNotDelete) to ensure it is not accidentally removed. The question would ask: 'Where should the administrator go to prevent accidental deletion of a resource?'
Option-by-option analysis
Why each answer is right or wrong
Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The AZ-104 exam frequently reuses these exact scenarios with slightly different constraints.
✓Azure Policy compliance view.Correct answer▾
Why this is correct
The Azure Policy compliance view, accessible under the Policy blade, provides the authoritative report of evaluation results for assigned policy definitions and initiatives. It displays per-resource and per-policy compliance states such as Compliant, Non-compliant, and Conflicting, and you can filter by scope, export to CSV, or open the raw compliance data. This is where an administrator must go to see which specific resources are non-compliant and why, including the triggering policy rule and any effect applied.
✗Entra ID users and groups.Wrong answer — click to see why▾
Why this is wrong here
The question asks for non-compliance with an assigned policy, which is specifically tracked in Azure Policy compliance view. Entra ID users and groups manage identity and access, not policy compliance.
★ When this WOULD be the correct answer
This option would be correct if the question asked: 'Where should the administrator go to assign a user to a role that can manage policy compliance?' or 'Where to review which users have access to modify policies?'
Why candidates choose this
Candidates may confuse identity management with policy management, thinking that users and groups are involved in policy assignment or compliance, but Azure Policy compliance is separate from Entra ID.
✗Resource locks blade.Wrong answer — click to see why▾
Why this is wrong here
The Resource locks blade is used to prevent accidental deletion or modification of resources, not to check policy compliance. Non-compliant resources are identified in the Azure Policy compliance view.
★ When this WOULD be the correct answer
An administrator needs to prevent deletion of a critical resource by applying a lock (e.g., CanNotDelete) to ensure it is not accidentally removed. The question would ask: 'Where should the administrator go to prevent accidental deletion of a resource?'
Why candidates choose this
Candidates may confuse resource locks with policy enforcement, thinking locks are a way to enforce compliance, or they may not clearly distinguish between governance tools (policy) and operational controls (locks).
Analysis generated from the official AZ-104blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”
Go deeper
Related to this question
Learn chapter
Managed Identities for Azure Resources
Key term
Compliance
Compliance is the process of ensuring that an organization follows laws, regulations, standards, and internal policies that apply to its operations and data handling.
Key term
Policy
A policy is a set of rules or guidelines that defines how an organization manages, secures, and operates its IT systems and services.
About these practice questions
Courseiva writes every AZ-104 question from scratch — 1,049 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-104 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-104 exam.