Courseiva
Manage Azure Identities and GovernanceeasyMultiple ChoiceObjective-mapped

AZ-104 Manage Azure Identities and Governance Practice Question

Exhibit

Workload note:
- VM01 and VM02 both need to read the same Azure SQL connection metadata from an app registration-protected service.
- The identity must be reusable across multiple VMs.
- The team wants to avoid secrets in scripts and configuration.

Based on the exhibit, which identity approach should the administrator use so both VMs can share the same access without managing secrets or recreating role assignments when a VM is replaced?

⚠ Common exam trap

Many candidates confuse system-assigned and user-assigned managed identities, incorrectly assuming that a system-assigned identity can be shared across VMs or that it persists after VM deletion, when in fact it is deleted with the VM.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

A single user-assigned managed identity attached to both VMs.

A user-assigned managed identity is an independent Azure resource that can be attached to multiple VMs, allowing them to share the same identity for accessing Azure resources. This approach eliminates the need to manage secrets (like passwords or keys) and avoids recreating role assignments when a VM is replaced, because the identity persists independently of the VM lifecycle.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • A separate system-assigned managed identity on each VM.

    Why it's wrong here

    A system-assigned managed identity is created and tied to the lifecycle of a single VM resource; deleting the VM deletes the identity. Because it cannot be shared, attaching a separate system-assigned identity to each VM would require configuring role assignments twice, and each VM would have a distinct identity, so they would not act as a single principal. If one VM is rebuilt, its new identity would need permissions re-applied, and if the VM is deleted, the identity is gone—this does not meet the requirement for a persistent, shared identity across both VMs.

    When this WOULD be correct

    This option would be correct if the question required each VM to have its own unique identity for independent access control, such as when each VM needs distinct permissions to different resources and there is no need to share access or simplify replacement.

  • A single user-assigned managed identity attached to both VMs.

    Why this is correct

    A user-assigned managed identity is independent of any one VM and can be attached to multiple resources. That makes it ideal when several VMs need the same permissions and the access must continue even if one VM is deleted or rebuilt.

  • An administrator username and password stored in the script.

    Why it's wrong here

    Storing an administrator username and password in the script is a security anti-pattern: it embeds long-lived secrets in plaintext, risks exposure through logs, source control, or the script file itself, and violates the principle of using managed identities for secret-free authentication. The password would need to be rotated manually and synchronized across the VMs, or any change breaks access. Additionally, a local admin credential is not scoped to Azure RBAC and cannot grant access to Azure resources such as storage or Key Vault without further configuration, so it does not fulfill the identity requirement.

    When this WOULD be correct

    A question that asks for the simplest authentication method for a legacy application that does not support managed identities, where the application runs on a single VM and credentials are rotated manually via Azure Key Vault.

  • A shared access signature assigned to the virtual network.

    Why it's wrong here

    A shared access signature (SAS) is a delegated URI that grants time-limited, permission-scoped access to a specific storage resource, such as a blob or container. It is not an identity object and cannot be assigned to an Azure virtual network; networks do not authenticate to Azure Active Directory and cannot hold a SAS token. Moreover, a SAS would only provide access to storage, not to other Azure services the VMs may need, and managing a SAS for two VMs would require embedding it in scripts or configuration, creating a credential-management problem rather than solving it.

    When this WOULD be correct

    This option would be correct in a scenario where the administrator needs to grant a specific set of users or applications time-limited access to a storage account (e.g., blob or file share) from a defined IP range or virtual network, without requiring full storage account keys. For example, allowing a reporting tool running on a VM to download data from a storage container for a limited period.

Option-by-option analysis

Why each answer is right or wrong

Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The AZ-104 exam frequently reuses these exact scenarios with slightly different constraints.

A single user-assigned managed identity attached to both VMs.Correct answer

Why this is correct

A user-assigned managed identity is independent of any one VM and can be attached to multiple resources. That makes it ideal when several VMs need the same permissions and the access must continue even if one VM is deleted or rebuilt.

A separate system-assigned managed identity on each VM.Wrong answer — click to see why

Why this is wrong here

A separate system-assigned managed identity on each VM would require managing two identities and recreating role assignments for each new VM, failing to meet the requirement of sharing the same access without managing secrets or recreating role assignments when a VM is replaced.

★ When this WOULD be the correct answer

This option would be correct if the question required each VM to have its own unique identity for independent access control, such as when each VM needs distinct permissions to different resources and there is no need to share access or simplify replacement.

Why candidates choose this

Candidates may think system-assigned managed identities are simpler because they are automatically created with the VM, overlooking that they are tied to the VM lifecycle and require separate role assignments per VM.

An administrator username and password stored in the script.Wrong answer — click to see why

Why this is wrong here

Storing an administrator username and password in a script introduces secrets management overhead and security risks, and does not eliminate the need to update credentials or role assignments when a VM is replaced.

★ When this WOULD be the correct answer

A question that asks for the simplest authentication method for a legacy application that does not support managed identities, where the application runs on a single VM and credentials are rotated manually via Azure Key Vault.

Why candidates choose this

Candidates may think that using a stored admin credential is a straightforward way to share access between VMs, overlooking the security and maintenance drawbacks compared to managed identities.

A shared access signature assigned to the virtual network.Wrong answer — click to see why

Why this is wrong here

A shared access signature (SAS) assigned to the virtual network provides delegated access to storage resources, not identity-based access to VMs. It cannot be used to grant VMs access to Azure resources without managing secrets, and it does not persist across VM replacements without manual updates.

★ When this WOULD be the correct answer

This option would be correct in a scenario where the administrator needs to grant a specific set of users or applications time-limited access to a storage account (e.g., blob or file share) from a defined IP range or virtual network, without requiring full storage account keys. For example, allowing a reporting tool running on a VM to download data from a storage container for a limited period.

Why candidates choose this

Candidates may confuse SAS with managed identities because both can provide secure access without hardcoding credentials. They might think a SAS scoped to a virtual network can be used for VM identity, not realizing SAS is for storage access delegation, not VM authentication to Azure services.

Analysis generated from the official AZ-104blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”

About these practice questions

Courseiva writes every AZ-104 question from scratch — 1,049 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AZ-104 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-104 exam.