Courseiva
Manage Azure Identities and GovernanceeasyMultiple ChoiceObjective-mapped

AZ-104 Manage Azure Identities and Governance Practice Question

You want to group subscriptions for Finance, HR, and Engineering so you can apply governance consistently at a higher level. What should you create?

⚠ Common exam trap

Candidates often confuse resource groups (which group resources within a subscription) with management groups (which group subscriptions themselves), leading them to select resource groups as the answer for cross-subscription governance.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Management groups

Management groups are the correct choice because they allow you to organize Azure subscriptions into a hierarchy for applying governance policies, role-based access control (RBAC), and cost management consistently across multiple subscriptions. By creating a management group hierarchy (e.g., Finance, HR, Engineering), you can assign Azure Policy initiatives or RBAC roles at the management group level, which are inherited by all subscriptions within that group. This provides a scalable and centralized governance model without needing to configure each subscription individually.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Resource groups

    Why it's wrong here

    Resource groups are wrong because they are logical containers for resources (VMs, databases, networks) within a single subscription, not for grouping subscriptions themselves. Each resource group belongs to exactly one subscription and cannot span or aggregate multiple subscriptions. While you can organize resources into resource groups, they do not provide a governance, policy, or RBAC inheritance boundary across subscriptions like management groups do.

    When this WOULD be correct

    You need to organize resources within a single subscription by lifecycle or team, and apply role-based access control or policies at that level. For example, grouping all virtual machines for a project into one resource group for easier management.

  • Management groups

    Why this is correct

    Management groups are the correct construct because they sit above subscriptions in the Azure hierarchy, enabling you to organize multiple subscriptions (finance, HR, engineering) into logical containers. Through management groups, you can enforce governance consistently across those subscriptions by applying Azure Policy, Azure RBAC roles, and cost-management settings that inherit down to all contained subscriptions. Unlike resource groups or tags, management groups create a true parent-child structure for subscriptions, not just a grouping of resources or metadata.

  • Tags

    Why it's wrong here

    Tags are wrong because they are metadata key-value pairs attached to resources, resource groups, or subscriptions for purposes like cost allocation, classification, and filtering. While tags can help identify or categorize subscriptions, they do not create a hierarchy, enforce policies, or centralize access control across multiple subscriptions. Unlike management groups, tags have no inheritance or management capability; they are simply labels, not a governance structure.

    When this WOULD be correct

    You need to categorize resources by cost center or environment (e.g., 'Finance', 'Production') and apply cost tracking or filtering based on that categorization. Tags would be the correct answer.

  • Resource locks

    Why it's wrong here

    Resource locks are wrong because they are protection mechanisms, not organizational grouping structures. A lock (DeleteOnly or ReadOnly) is applied to a resource, resource group, or management group to prevent accidental deletion or modification; it does not group subscriptions for governance or cost management. Locks affect operational safety, not the hierarchical organization of subscriptions, and they do not enable policy or RBAC inheritance across finance, HR, and engineering subscriptions.

    When this WOULD be correct

    You need to prevent critical resources (e.g., a production database) from being deleted or modified by users. Creating a resource lock (e.g., CanNotDelete) on the resource or resource group would be the correct answer.

Option-by-option analysis

Why each answer is right or wrong

Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The AZ-104 exam frequently reuses these exact scenarios with slightly different constraints.

Management groupsCorrect answer

Why this is correct

Management groups are the correct construct because they sit above subscriptions in the Azure hierarchy, enabling you to organize multiple subscriptions (finance, HR, engineering) into logical containers. Through management groups, you can enforce governance consistently across those subscriptions by applying Azure Policy, Azure RBAC roles, and cost-management settings that inherit down to all contained subscriptions. Unlike resource groups or tags, management groups create a true parent-child structure for subscriptions, not just a grouping of resources or metadata.

Resource groupsWrong answer — click to see why

Why this is wrong here

Resource groups are containers for resources within a single subscription, not for grouping multiple subscriptions. They cannot apply governance across subscriptions.

★ When this WOULD be the correct answer

You need to organize resources within a single subscription by lifecycle or team, and apply role-based access control or policies at that level. For example, grouping all virtual machines for a project into one resource group for easier management.

Why candidates choose this

Candidates confuse resource groups with management groups because both are hierarchical containers, but resource groups operate only within a subscription, not across subscriptions.

TagsWrong answer — click to see why

Why this is wrong here

Tags are metadata applied to Azure resources for categorization, not a grouping mechanism for subscriptions. They cannot enforce governance policies across multiple subscriptions.

★ When this WOULD be the correct answer

You need to categorize resources by cost center or environment (e.g., 'Finance', 'Production') and apply cost tracking or filtering based on that categorization. Tags would be the correct answer.

Why candidates choose this

Candidates may confuse tags with management groups because both can organize resources, but tags lack the hierarchical policy enforcement capability needed for subscription-level governance.

Resource locksWrong answer — click to see why

Why this is wrong here

Resource locks prevent accidental deletion or modification of resources but do not group subscriptions for governance. Management groups are the correct construct for hierarchical subscription grouping and policy application.

★ When this WOULD be the correct answer

You need to prevent critical resources (e.g., a production database) from being deleted or modified by users. Creating a resource lock (e.g., CanNotDelete) on the resource or resource group would be the correct answer.

Why candidates choose this

Candidates may confuse resource locks with governance controls, thinking they can enforce policies across subscriptions, but locks only protect individual resources, not group or govern multiple subscriptions.

Analysis generated from the official AZ-104blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”

Quick reference

Access Control Model Comparison

ModelAcronymWho Controls Access?Best For
Discretionary Access ControlDACResource ownerSmall teams, file shares
Mandatory Access ControlMACSystem / security labelsClassified govt / military
Role-Based Access ControlRBACAdministrator (via roles)Enterprise environments
Attribute-Based Access ControlABACPolicy engine (user + resource attributes)Fine-grained, dynamic policies
Rule-Based Access ControlRuBACSystem rules / ACLsFirewall rules, network ACLs

About these practice questions

One of 1,049 original AZ-104 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AZ-104 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-104 exam.