AZ-104 Manage Azure Identities and Governance Practice Question
You want to group subscriptions for Finance, HR, and Engineering so you can apply governance consistently at a higher level. What should you create?
⚠ Common exam trap
Candidates often confuse resource groups (which group resources within a subscription) with management groups (which group subscriptions themselves), leading them to select resource groups as the answer for cross-subscription governance.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Management groups
Management groups are the correct choice because they allow you to organize Azure subscriptions into a hierarchy for applying governance policies, role-based access control (RBAC), and cost management consistently across multiple subscriptions. By creating a management group hierarchy (e.g., Finance, HR, Engineering), you can assign Azure Policy initiatives or RBAC roles at the management group level, which are inherited by all subscriptions within that group. This provides a scalable and centralized governance model without needing to configure each subscription individually.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Resource groups
Why it's wrong here
Resource groups are wrong because they are logical containers for resources (VMs, databases, networks) within a single subscription, not for grouping subscriptions themselves. Each resource group belongs to exactly one subscription and cannot span or aggregate multiple subscriptions. While you can organize resources into resource groups, they do not provide a governance, policy, or RBAC inheritance boundary across subscriptions like management groups do.
When this WOULD be correct
You need to organize resources within a single subscription by lifecycle or team, and apply role-based access control or policies at that level. For example, grouping all virtual machines for a project into one resource group for easier management.
- ✓
Management groups
Why this is correct
Management groups are the correct construct because they sit above subscriptions in the Azure hierarchy, enabling you to organize multiple subscriptions (finance, HR, engineering) into logical containers. Through management groups, you can enforce governance consistently across those subscriptions by applying Azure Policy, Azure RBAC roles, and cost-management settings that inherit down to all contained subscriptions. Unlike resource groups or tags, management groups create a true parent-child structure for subscriptions, not just a grouping of resources or metadata.
- ✗
Tags
Why it's wrong here
Tags are wrong because they are metadata key-value pairs attached to resources, resource groups, or subscriptions for purposes like cost allocation, classification, and filtering. While tags can help identify or categorize subscriptions, they do not create a hierarchy, enforce policies, or centralize access control across multiple subscriptions. Unlike management groups, tags have no inheritance or management capability; they are simply labels, not a governance structure.
When this WOULD be correct
You need to categorize resources by cost center or environment (e.g., 'Finance', 'Production') and apply cost tracking or filtering based on that categorization. Tags would be the correct answer.
- ✗
Resource locks
Why it's wrong here
Resource locks are wrong because they are protection mechanisms, not organizational grouping structures. A lock (DeleteOnly or ReadOnly) is applied to a resource, resource group, or management group to prevent accidental deletion or modification; it does not group subscriptions for governance or cost management. Locks affect operational safety, not the hierarchical organization of subscriptions, and they do not enable policy or RBAC inheritance across finance, HR, and engineering subscriptions.
When this WOULD be correct
You need to prevent critical resources (e.g., a production database) from being deleted or modified by users. Creating a resource lock (e.g., CanNotDelete) on the resource or resource group would be the correct answer.
Option-by-option analysis
Why each answer is right or wrong
Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The AZ-104 exam frequently reuses these exact scenarios with slightly different constraints.
✓Management groupsCorrect answer▾
Why this is correct
Management groups are the correct construct because they sit above subscriptions in the Azure hierarchy, enabling you to organize multiple subscriptions (finance, HR, engineering) into logical containers. Through management groups, you can enforce governance consistently across those subscriptions by applying Azure Policy, Azure RBAC roles, and cost-management settings that inherit down to all contained subscriptions. Unlike resource groups or tags, management groups create a true parent-child structure for subscriptions, not just a grouping of resources or metadata.
✗Resource groupsWrong answer — click to see why▾
Why this is wrong here
Resource groups are containers for resources within a single subscription, not for grouping multiple subscriptions. They cannot apply governance across subscriptions.
★ When this WOULD be the correct answer
You need to organize resources within a single subscription by lifecycle or team, and apply role-based access control or policies at that level. For example, grouping all virtual machines for a project into one resource group for easier management.
Why candidates choose this
Candidates confuse resource groups with management groups because both are hierarchical containers, but resource groups operate only within a subscription, not across subscriptions.
✗TagsWrong answer — click to see why▾
Why this is wrong here
Tags are metadata applied to Azure resources for categorization, not a grouping mechanism for subscriptions. They cannot enforce governance policies across multiple subscriptions.
★ When this WOULD be the correct answer
You need to categorize resources by cost center or environment (e.g., 'Finance', 'Production') and apply cost tracking or filtering based on that categorization. Tags would be the correct answer.
Why candidates choose this
Candidates may confuse tags with management groups because both can organize resources, but tags lack the hierarchical policy enforcement capability needed for subscription-level governance.
✗Resource locksWrong answer — click to see why▾
Why this is wrong here
Resource locks prevent accidental deletion or modification of resources but do not group subscriptions for governance. Management groups are the correct construct for hierarchical subscription grouping and policy application.
★ When this WOULD be the correct answer
You need to prevent critical resources (e.g., a production database) from being deleted or modified by users. Creating a resource lock (e.g., CanNotDelete) on the resource or resource group would be the correct answer.
Why candidates choose this
Candidates may confuse resource locks with governance controls, thinking they can enforce policies across subscriptions, but locks only protect individual resources, not group or govern multiple subscriptions.
Analysis generated from the official AZ-104blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”
Quick reference
Access Control Model Comparison
| Model | Acronym | Who Controls Access? | Best For |
|---|---|---|---|
| Discretionary Access Control | DAC | Resource owner | Small teams, file shares |
| Mandatory Access Control | MAC | System / security labels | Classified govt / military |
| Role-Based Access Control | RBAC | Administrator (via roles) | Enterprise environments |
| Attribute-Based Access Control | ABAC | Policy engine (user + resource attributes) | Fine-grained, dynamic policies |
| Rule-Based Access Control | RuBAC | System rules / ACLs | Firewall rules, network ACLs |
Go deeper
Related to this question
Learn chapter
Dynamic Membership Groups
Key term
Management group
A Management group is a container in Microsoft Azure that helps you organize and manage access, policies, and compliance across multiple Azure subscriptions.
Key term
Azure Policy
Azure Policy is a service in Microsoft Azure that lets you create, assign, and manage rules to ensure your resources stay compliant with your company standards and service-level agreements.
About these practice questions
One of 1,049 original AZ-104 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-104 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-104 exam.