AZ-104 Manage Azure Identities and Governance Practice Question
Help desk staff must start, stop, and restart virtual machines in one application resource group. They must not create or delete VMs or modify networking or disks. Which built-in role should you assign?
⚠ Common exam trap
It's easy for candidates to choose Virtual Machine Contributor (Option B) because it sounds like it covers VM operations, but they overlook that it also includes create and delete permissions, which are explicitly prohibited in the question.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Virtual Machine Operator
The Virtual Machine Operator role allows starting, stopping, and restarting virtual machines, but explicitly denies creating, deleting, or modifying VMs, networking, or disks. This matches the help desk staff's required permissions exactly, making it the correct built-in role for this scenario.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Reader
Why it's wrong here
The Reader role grants only read access to resource properties and metadata, with no permissions for any write or action operations such as Microsoft.Compute/virtualMachines/start/action, powerOff, or restart/action. As a result, users assigned this role can view a virtual machine's status and configuration but cannot initiate any state changes, making it an invalid choice for help desk staff who must start, stop, and restart VMs.
When this WOULD be correct
Assign the Reader role when users only need to view virtual machine properties, status, and configuration without making any changes, such as for monitoring or auditing purposes.
- ✗
Virtual Machine Contributor
Why it's wrong here
Virtual Machine Contributor allows full management of virtual machines, including creating, deleting, and configuring VMs and their disks, but it also includes far more permissions than the minimal start, stop, and restart operations required. This role is not least-privilege because it grants the ability to provision and remove VM resources, change networking associations, and manage extensions, which exceeds the operational scope needed for day-to-day power actions.
When this WOULD be correct
If the requirement were to allow full management of virtual machines (including creation and deletion) but not management of networking or disks, Virtual Machine Contributor would be the correct role.
- ✓
Virtual Machine Operator
Why this is correct
Virtual Machine Operator is the appropriate least-privilege choice for operational control of VMs. It allows actions such as starting, stopping, and restarting virtual machines without giving full management rights over creation, deletion, or related networking and disk resources. That makes it a better fit than broader contributor roles when the team only needs day-to-day operations.
- ✗
Contributor
Why it's wrong here
The Contributor role grants broad management access to all Azure resources, including virtual machines, storage, networking, and more, but it lacks the ability to grant role assignments. While it can indeed start and stop VMs, it is excessively privileged for this task, exposing the help desk team to full management rights across every resource in the subscription, which violates the principle of least privilege and increases the risk of unintended or destructive changes.
When this WOULD be correct
Assign the Contributor role when help desk staff need full management of all resources in a resource group, including creating and deleting VMs, modifying networking, and managing disks, but not managing access or policies.
Option-by-option analysis
Why each answer is right or wrong
Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The AZ-104 exam frequently reuses these exact scenarios with slightly different constraints.
✓Virtual Machine OperatorCorrect answer▾
Why this is correct
Virtual Machine Operator is the appropriate least-privilege choice for operational control of VMs. It allows actions such as starting, stopping, and restarting virtual machines without giving full management rights over creation, deletion, or related networking and disk resources. That makes it a better fit than broader contributor roles when the team only needs day-to-day operations.
✗ReaderWrong answer — click to see why▾
Why this is wrong here
The Reader role allows read-only access to all resources, but does not permit starting, stopping, or restarting VMs, which require write-level permissions.
★ When this WOULD be the correct answer
Assign the Reader role when users only need to view virtual machine properties, status, and configuration without making any changes, such as for monitoring or auditing purposes.
Why candidates choose this
Candidates may think Reader is sufficient because they overlook the need for write actions like start/stop, or they confuse read access with the ability to perform management operations.
✗Virtual Machine ContributorWrong answer — click to see why▾
Why this is wrong here
Virtual Machine Contributor allows creating and deleting VMs, which violates the requirement that help desk staff must not create or delete VMs.
★ When this WOULD be the correct answer
If the requirement were to allow full management of virtual machines (including creation and deletion) but not management of networking or disks, Virtual Machine Contributor would be the correct role.
Why candidates choose this
Candidates may think 'Contributor' implies only modification, but the VM-specific role actually grants broader permissions including create/delete, which is not allowed here.
✗ContributorWrong answer — click to see why▾
Why this is wrong here
The Contributor role allows creating and deleting VMs, as well as modifying networking and disks, which exceeds the required permissions of only starting, stopping, and restarting VMs.
★ When this WOULD be the correct answer
Assign the Contributor role when help desk staff need full management of all resources in a resource group, including creating and deleting VMs, modifying networking, and managing disks, but not managing access or policies.
Why candidates choose this
Candidates may mistakenly believe Contributor is the least permissive role that allows VM state changes, overlooking the more restrictive Virtual Machine Operator role that specifically limits actions to start, stop, and restart.
Analysis generated from the official AZ-104blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”
Go deeper
Related to this question
Learn chapter
Azure RBAC Role Assignments
Key term
Group
A group is a collection of users, devices, or other objects that are assigned permissions and policies together for simplified management in identity and governance systems like Microsoft Entra ID.
Key term
Resource group
A logical container in Microsoft Azure that holds related resources for an application or solution, enabling unified management, security, and billing.
About these practice questions
This AZ-104 question is part of Courseiva's 1,049-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-104 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-104 exam.