AZ-104 Manage Azure Identities and Governance Practice Question
A company wants to group several subscriptions for Finance, HR, and Engineering so that the same governance settings can be applied above the subscription level. What should the administrator create?
⚠ Common exam trap
Test-takers frequently confuse management groups with resource groups, thinking resource groups can span subscriptions, but resource groups are strictly scoped to a single subscription and cannot aggregate governance across multiple subscriptions.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
A management group
A management group is the correct choice because it allows you to organize multiple Azure subscriptions into a hierarchy and apply governance policies, role-based access control (RBAC), and compliance settings at a scope above the subscription level. By creating a management group for Finance, HR, and Engineering, the administrator can enforce consistent Azure Policy initiatives and RBAC assignments across all three subscriptions, ensuring uniform governance without needing to configure each subscription individually.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
A management group
Why this is correct
Management groups are designed to contain subscriptions and provide a hierarchy above the subscription level. Policies, access controls, and other governance settings can be assigned at the management group level and inherited by the subscriptions underneath it, which makes them the correct choice for organizing Finance, HR, and Engineering subscriptions together.
- ✗
A resource group
Why it's wrong here
A resource group is a container for Azure resources such as virtual machines, storage accounts, and databases within a single subscription. It helps organize and manage resources that share a lifecycle, but it cannot group multiple subscriptions or provide governance inheritance across subscriptions.
When this WOULD be correct
An administrator needs to organize resources (e.g., VMs, databases) for a specific project within a single subscription, applying policies and access control at that scope.
- ✗
A tag
Why it's wrong here
Tags are metadata key-value pairs used to categorize resources, such as by department or cost center. They are useful for reporting and filtering, but they do not create a hierarchy and cannot apply governance settings above the subscription level.
When this WOULD be correct
An administrator needs to enforce a policy that all resources in a subscription must have a 'CostCenter' tag. The correct action would be to create a tag and assign it via Azure Policy.
- ✗
A resource lock
Why it's wrong here
A resource lock prevents accidental deletion or modification of a specific resource or resource group, depending on where it is applied. It is a protection mechanism, not an organizational structure, and it does not group subscriptions or enable inherited governance across them.
When this WOULD be correct
An administrator needs to prevent critical resources in a production subscription from being deleted or modified. Creating a resource lock (e.g., CanNotDelete) on those resources would be the correct solution.
Option-by-option analysis
Why each answer is right or wrong
Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The AZ-104 exam frequently reuses these exact scenarios with slightly different constraints.
✓A management groupCorrect answer▾
Why this is correct
Management groups are designed to contain subscriptions and provide a hierarchy above the subscription level. Policies, access controls, and other governance settings can be assigned at the management group level and inherited by the subscriptions underneath it, which makes them the correct choice for organizing Finance, HR, and Engineering subscriptions together.
✗A resource groupWrong answer — click to see why▾
Why this is wrong here
Resource groups are containers for resources within a single subscription, not for grouping multiple subscriptions to apply governance settings above the subscription level.
★ When this WOULD be the correct answer
An administrator needs to organize resources (e.g., VMs, databases) for a specific project within a single subscription, applying policies and access control at that scope.
Why candidates choose this
Candidates may confuse resource groups with management groups because both are hierarchical containers, but resource groups operate within a subscription, not across subscriptions.
✗A tagWrong answer — click to see why▾
Why this is wrong here
Tags are metadata applied to Azure resources for categorization and cost tracking, not for grouping subscriptions or applying governance settings above the subscription level.
★ When this WOULD be the correct answer
An administrator needs to enforce a policy that all resources in a subscription must have a 'CostCenter' tag. The correct action would be to create a tag and assign it via Azure Policy.
Why candidates choose this
Candidates may confuse tags with management groups because both can be used for organization, but tags lack the hierarchical governance capabilities needed for subscription-level grouping.
✗A resource lockWrong answer — click to see why▾
Why this is wrong here
Resource locks prevent accidental deletion or modification of resources but do not provide governance settings above the subscription level. They operate at the resource or resource group level, not across multiple subscriptions.
★ When this WOULD be the correct answer
An administrator needs to prevent critical resources in a production subscription from being deleted or modified. Creating a resource lock (e.g., CanNotDelete) on those resources would be the correct solution.
Why candidates choose this
Candidates may confuse resource locks with governance controls, thinking locks can enforce policies across subscriptions, or they may overlook the requirement for 'above the subscription level' and focus on protection instead of governance.
Analysis generated from the official AZ-104blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”
Quick reference
Access Control Model Comparison
| Model | Acronym | Who Controls Access? | Best For |
|---|---|---|---|
| Discretionary Access Control | DAC | Resource owner | Small teams, file shares |
| Mandatory Access Control | MAC | System / security labels | Classified govt / military |
| Role-Based Access Control | RBAC | Administrator (via roles) | Enterprise environments |
| Attribute-Based Access Control | ABAC | Policy engine (user + resource attributes) | Fine-grained, dynamic policies |
| Rule-Based Access Control | RuBAC | System rules / ACLs | Firewall rules, network ACLs |
Go deeper
Related to this question
Learn chapter
Privileged Identity Management (PIM)
Key term
Scope
In IT, scope defines the boundaries, goals, and deliverables of a project, assessment, or engagement, specifying what is included and what is excluded.
Key term
Compliance
Compliance is the process of ensuring that an organization follows laws, regulations, standards, and internal policies that apply to its operations and data handling.
About these practice questions
Courseiva writes every AZ-104 question from scratch — 1,049 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-104 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-104 exam.