Courseiva
Manage Azure Identities and GovernancemediumMultiple ChoiceObjective-mapped

AZ-104 Manage Azure Identities and Governance Practice Question

Exhibit

Microsoft Entra group details
Group name: AppOps-Admins
Owners: Mia Lopez
Members: Sam Patel, Contractor01
Notes: Contractor01 is a temporary contractor with no existing Azure role assignments.
Requirement: Contractor01 must be able to add or remove members from AppOps-Admins for 30 days, but must not be able to manage Azure resources or receive broader directory permissions.

Based on the exhibit, which action should the administrator take so Contractor01 can manage the team membership without receiving Azure resource permissions?

⚠ Common exam trap

Candidates often confuse Azure AD group ownership with Azure RBAC roles, assuming that managing a group requires a high-privilege directory role like User Administrator, or they mistakenly think adding the user as a member of the group will suffice without understanding that membership inherits the group's resource permissions.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Add Contractor01 as an owner of the AppOps-Admins group.

Adding Contractor01 as an owner of the AppOps-Admins group grants them the ability to manage group membership (add/remove members) without inheriting any Azure resource permissions. Group ownership is an Azure AD role that controls group administration only, not access to Azure resources like VMs or storage. This meets the requirement of managing team membership without resource permissions.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Add Contractor01 as an owner of the AppOps-Admins group.

    Why this is correct

    Adding Contractor01 as an owner of the AppOps-Admins group grants them the Azure AD delegated permission to manage membership and ownership-related settings for that specific group. This allows the contractor to add or remove members without receiving any Azure RBAC rights to access subscription or resource group resources. It is the least-privilege solution that precisely matches the stated need.

  • Add Contractor01 as a member of the AppOps-Admins group.

    Why it's wrong here

    Adding Contractor01 as a member of AppOps-Admins gives the contractor whatever permissions the group is used for, such as access to a specific application or resource, but it confers no ability to administer the group itself. Group members cannot add or remove other members or change ownership; those actions require the group owner role or a higher-privileged directory role. Since the requirement is to let the contractor manage the group's membership, a member role fails to fulfill it.

    When this WOULD be correct

    This option would be correct if the goal was to grant Contractor01 the same permissions as other team members (e.g., access to resources) without allowing them to manage group membership. For example, if the question asked 'Which action grants Contractor01 access to the resources assigned to AppOps-Admins?'

  • Assign Contractor01 the User Administrator role at the tenant scope.

    Why it's wrong here

    Assigning Contractor01 the User Administrator role at the tenant scope grants directory-wide authority to manage all users and groups, including password resets, group membership, and licensing across the entire Azure AD tenant. This is far beyond the need to administer a single group and introduces significant security risk, as the contractor could modify other privileged groups or reset admin credentials. User Administrator is an Azure AD role, not scoped to a specific group, and therefore is not a precise delegation mechanism for this scenario.

    When this WOULD be correct

    This option would be correct if the question asked for an administrator who needs to manage user accounts, groups, and licensing for all users in the tenant, without any focus on Azure resource permissions or team membership management within a specific group.

  • Assign Contractor01 Contributor on the subscription.

    Why it's wrong here

    Assigning Contractor01 the Contributor role on the subscription grants full management access to all resources within that subscription, including the ability to create, modify, and delete any resource at that scope. Worse, Azure RBAC roles like Contributor do not grant any Azure AD permissions, so this role would not allow the contractor to manage the AppOps-Admins group's membership. It is both vastly overprivileged and ineffective for the stated requirement.

    When this WOULD be correct

    A question where the goal is to allow a user to manage all resources in a subscription (e.g., deploy and configure VMs, storage, etc.) without granting access to manage Azure AD or user permissions. For example: 'You need to grant a developer the ability to deploy and manage virtual machines in a subscription. Which role should you assign?'

Option-by-option analysis

Why each answer is right or wrong

Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The AZ-104 exam frequently reuses these exact scenarios with slightly different constraints.

Add Contractor01 as an owner of the AppOps-Admins group.Correct answer

Why this is correct

Adding Contractor01 as an owner of the AppOps-Admins group grants them the Azure AD delegated permission to manage membership and ownership-related settings for that specific group. This allows the contractor to add or remove members without receiving any Azure RBAC rights to access subscription or resource group resources. It is the least-privilege solution that precisely matches the stated need.

Add Contractor01 as a member of the AppOps-Admins group.Wrong answer — click to see why

Why this is wrong here

Adding Contractor01 as a member of AppOps-Admins grants them only group membership, not the ability to manage team membership. To manage membership, they need owner permissions on the group, not member permissions.

★ When this WOULD be the correct answer

This option would be correct if the goal was to grant Contractor01 the same permissions as other team members (e.g., access to resources) without allowing them to manage group membership. For example, if the question asked 'Which action grants Contractor01 access to the resources assigned to AppOps-Admins?'

Why candidates choose this

Candidates may confuse 'member' with 'owner' roles, assuming that being a member of a group allows management of that group, or they may think that adding as a member is sufficient to delegate group management.

Assign Contractor01 the User Administrator role at the tenant scope.Wrong answer — click to see why

Why this is wrong here

The User Administrator role at tenant scope grants permissions to manage user accounts and groups across the entire Azure AD tenant, which includes Azure resource permissions indirectly through group management. The question requires managing team membership without receiving Azure resource permissions, and this role provides broader administrative access than needed.

★ When this WOULD be the correct answer

This option would be correct if the question asked for an administrator who needs to manage user accounts, groups, and licensing for all users in the tenant, without any focus on Azure resource permissions or team membership management within a specific group.

Why candidates choose this

Candidates may think the User Administrator role is appropriate because it allows management of group memberships, but they overlook that it also grants broader Azure AD administrative privileges that could lead to unintended Azure resource permissions.

Assign Contractor01 Contributor on the subscription.Wrong answer — click to see why

Why this is wrong here

The Contributor role grants full management access to Azure resources, including permissions to create, modify, and delete resources, which contradicts the requirement to avoid giving Contractor01 Azure resource permissions.

★ When this WOULD be the correct answer

A question where the goal is to allow a user to manage all resources in a subscription (e.g., deploy and configure VMs, storage, etc.) without granting access to manage Azure AD or user permissions. For example: 'You need to grant a developer the ability to deploy and manage virtual machines in a subscription. Which role should you assign?'

Why candidates choose this

Candidates may confuse 'managing team membership' with general resource management, assuming Contributor is a catch-all role for any administrative task, or they may overlook the specific requirement to avoid Azure resource permissions.

Analysis generated from the official AZ-104blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”

About these practice questions

This AZ-104 question is part of Courseiva's 1,049-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AZ-104 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-104 exam.