AZ-104 Manage Azure Identities and Governance Practice Question
Finance, HR, and Engineering each use separate subscriptions. The compliance team wants a simple hierarchy that lets them apply governance to groups of subscriptions and produce resource ownership reports by department and environment. Which two features should the administrator use? Select two.
⚠ Common exam trap
A common mix-up: candidates confuse resource locks with management groups for organizational control, or think availability sets or private endpoints can serve as grouping mechanisms for governance, when they are designed for entirely different purposes (high availability and network security, respectively).
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Management groups to organize the subscriptions into a hierarchy.
Management groups (A) are the correct Azure construct for building a hierarchy above subscriptions, so Finance, HR, and Engineering subscriptions can be nested under a department structure and inherit governance (Azure Policy, RBAC) at each level. Tags (B) are key-value metadata that let the team record department and environment on resources, enabling cost and ownership reports filtered by those values. Resource locks (C) only prevent modification or deletion of individual resources and cannot group subscriptions by business unit. Availability sets (D) are a compute construct for VM fault/update domain resiliency within a region, not an organizational grouping. Private endpoints (E) provide private network connectivity to PaaS services and do not separate or organize subscriptions.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Management groups to organize the subscriptions into a hierarchy.
Why this is correct
Management groups provide a hierarchy above subscriptions, letting the compliance team apply governance such as Azure Policy and RBAC to grouped subscriptions by department. This satisfies the requirement for a simple hierarchy covering multiple subscriptions.
- ✓
Tags on resources to record department and environment values.
Why this is correct
Tags record department and environment as key-value metadata directly on resources, which Microsoft Entra ID does not provide. This satisfies the reporting constraint: resource ownership reports can be filtered and grouped by department and environment across the separate Finance, HR, and Engineering subscriptions.
- ✗
Resource locks to group subscriptions by business unit.
Why it's wrong here
Resource locks prevent modification or deletion of individual resources; they neither group subscriptions nor report ownership. They tempt because governance and protection are easily conflated, so locks are the right choice when the requirement is guarding a specific production resource against accidental deletion or change.
When this WOULD be correct
A question asks: 'An administrator needs to prevent critical resources in a production subscription from being deleted. Which feature should be used?' Resource locks (e.g., CanNotDelete) would be correct to protect specific resources.
- ✗
Availability sets to group applications by department.
Why it's wrong here
Availability sets group virtual machines within a single subscription for fault domains and update domains; they cannot span subscriptions or model a governance hierarchy. They tempt because grouping workloads by department sounds organisational, so availability sets are the right choice when the requirement is VM resiliency inside one subscription.
When this WOULD be correct
A question asks: 'Which feature ensures that at least one VM remains available during planned or unplanned maintenance?' Availability sets would be the correct answer.
- ✗
Private endpoints to separate Finance from HR.
Why it's wrong here
Private endpoints give a service a private IP inside a virtual network; they do not separate subscriptions or produce ownership reporting. They tempt because isolating Finance traffic from HR sounds like segmentation, so private endpoints are the right choice when the requirement is removing public exposure of a PaaS resource.
When this WOULD be correct
An administrator needs to ensure that Finance and HR departments access their respective Azure SQL databases privately and securely without exposing them to the public internet. Using private endpoints for each database would be correct.
Option-by-option analysis
Why each answer is right or wrong
Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The AZ-104 exam frequently reuses these exact scenarios with slightly different constraints.
✓Management groups to organize the subscriptions into a hierarchy.Correct answer▾
Why this is correct
Management groups provide a hierarchy above subscriptions, letting the compliance team apply governance such as Azure Policy and RBAC to grouped subscriptions by department. This satisfies the requirement for a simple hierarchy covering multiple subscriptions.
✗Resource locks to group subscriptions by business unit.Wrong answer — click to see why▾
Why this is wrong here
Resource locks prevent accidental deletion or modification of resources but do not group subscriptions or support hierarchical governance; they operate at the resource or resource group level, not across subscriptions.
★ When this WOULD be the correct answer
A question asks: 'An administrator needs to prevent critical resources in a production subscription from being deleted. Which feature should be used?' Resource locks (e.g., CanNotDelete) would be correct to protect specific resources.
Why candidates choose this
Candidates may confuse 'resource locks' with 'management groups' because both involve grouping or controlling resources, but locks are for protection, not organization or governance hierarchy.
✗Availability sets to group applications by department.Wrong answer — click to see why▾
Why this is wrong here
Availability sets are used to ensure high availability of virtual machines by distributing them across fault domains, not for grouping applications by department or for governance and reporting purposes.
★ When this WOULD be the correct answer
A question asks: 'Which feature ensures that at least one VM remains available during planned or unplanned maintenance?' Availability sets would be the correct answer.
Why candidates choose this
Candidates may confuse the grouping concept of availability sets with organizational grouping, thinking they can logically group applications by department, but availability sets are strictly for VM redundancy.
✗Private endpoints to separate Finance from HR.Wrong answer — click to see why▾
Why this is wrong here
Private endpoints are used to securely connect to Azure services over a private IP address, not to separate subscriptions or create governance hierarchies. They do not help organize subscriptions or produce resource ownership reports.
★ When this WOULD be the correct answer
An administrator needs to ensure that Finance and HR departments access their respective Azure SQL databases privately and securely without exposing them to the public internet. Using private endpoints for each database would be correct.
Why candidates choose this
Candidates may think private endpoints can isolate resources between departments, confusing network isolation with organizational governance and reporting needs.
Analysis generated from the official AZ-104blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”
Quick reference
Access Control Model Comparison
| Model | Acronym | Who Controls Access? | Best For |
|---|---|---|---|
| Discretionary Access Control | DAC | Resource owner | Small teams, file shares |
| Mandatory Access Control | MAC | System / security labels | Classified govt / military |
| Role-Based Access Control | RBAC | Administrator (via roles) | Enterprise environments |
| Attribute-Based Access Control | ABAC | Policy engine (user + resource attributes) | Fine-grained, dynamic policies |
| Rule-Based Access Control | RuBAC | System rules / ACLs | Firewall rules, network ACLs |
Go deeper
Related to this question
Learn chapter
Azure DNS and Private DNS Zones
Key term
Update domain
An update domain is a logical grouping of resources in a cloud or datacenter environment that can be patched or updated together without causing downtime to the entire application.
Key term
Group
A group is a collection of users, devices, or other objects that are assigned permissions and policies together for simplified management in identity and governance systems like Microsoft Entra ID.
About these practice questions
This AZ-104 question is part of Courseiva's 1,053-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-104 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-104 exam.