Courseiva

Azure Custom RBAC Role: Grant VM Power Operations Without Delete Access

An administrator wants to let a help desk group start, stop, and restart virtual machines in one resource group, but the group must not be able to delete the VMs or any other resource in the group. Which two actions should the administrator take? Select two.

Quick Answer

The answer is to create a custom RBAC role and assign it at the resource group scope. This is correct because a custom role allows you to precisely define allowed actions, such as Microsoft.Compute/virtualMachines/start/action, stop, and restart, while explicitly excluding delete permissions like Microsoft.Compute/virtualMachines/delete. By scoping the assignment to the resource group, you ensure the help desk group can only perform these power operations on VMs within that specific group, without affecting resources elsewhere. On the AZ-104 exam, this scenario tests your understanding of the principle of least privilege and the difference between built-in roles (which often include delete rights) and custom roles. A common trap is choosing a built-in role like Virtual Machine Contributor, which grants delete access; always remember that custom roles are required when you need to strip away specific permissions. Memory tip: think “custom + scope” — custom for fine-grained actions, scope to limit the blast radius.

⚠ Common exam trap

Watch out — candidates often choose Virtual Machine Contributor (Option C) thinking it provides only VM management, but it actually includes delete permissions and broader resource control, or they incorrectly combine a CanNotDelete lock (Option D) with an existing role, not realizing the lock does not grant the required start/stop/restart actions.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Create a custom RBAC role with only VM start, stop, restart, and read actions.

Option A is correct because Azure RBAC's built-in Virtual Machine Contributor role also grants delete permissions, so the administrator must create a custom role scoped to only the required actions, such as Microsoft.Compute/virtualMachines/start/action, powerOff/action, restart/action, and read. Option B is correct because assigning that custom role at the resource group scope grants the help desk group the needed permissions on all VMs in that group while keeping the role limited to that boundary. Option C is incorrect because Virtual Machine Contributor includes Microsoft.Compute/virtualMachines/delete, which violates the requirement that the group must not delete VMs. Option D is incorrect because a CanNotDelete lock prevents deletion for everyone, including administrators, and does not grant start/stop/restart permissions. Option E is incorrect because Azure Policy can deny deletion but does not grant the start, stop, and restart permissions the help desk group needs.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Create a custom RBAC role with only VM start, stop, restart, and read actions.

    Why this is correct

    A custom RBAC role scoped to Microsoft.Compute/virtualMachines/start, stop, restart and read actions grants only those operations, excluding delete and every other resource type. Built-in roles such as Virtual Machine Contributor would also permit deletion, violating the constraint.

  • ✓

    Assign the custom role to the help desk group at the resource group scope.

    Why this is correct

    Assigning the custom role at the resource group scope limits the help desk's permissions to VMs within that group only, preventing deletion of VMs or other resources elsewhere. Scope assignment is what confines the granted actions to the intended boundary.

  • ✗

    Assign Virtual Machine Contributor to the help desk group.

    Why it's wrong here

    Virtual Machine Contributor grants full VM management including deletion, so the help desk could remove VMs, breaching the requirement. It is tempting because it covers start, stop and restart, but the correct approach is a custom role containing only those actions, scoped to the resource group.

  • ✗

    Apply a CanNotDelete lock to the resource group.

    Why it's wrong here

    A CanNotDelete lock prevents deletion of the resource group and its resources for everyone, including the help desk, but it grants no start, stop or restart permissions. It is tempting because it directly addresses deletion, yet the required capability comes from a custom role scoped to those VM actions.

  • ✗

    Use Azure Policy to block VM deletion and leave RBAC unchanged.

    Why it's wrong here

    Azure Policy evaluates resource properties and can deny delete operations, but it does not grant the help desk permission to start, stop or restart VMs. It is tempting because policy blocks deletion, yet RBAC must still supply those VM actions through a custom role.

Quick reference

Access Control Model Comparison

ModelAcronymWho Controls Access?Best For
Discretionary Access ControlDACResource ownerSmall teams, file shares
Mandatory Access ControlMACSystem / security labelsClassified govt / military
Role-Based Access ControlRBACAdministrator (via roles)Enterprise environments
Attribute-Based Access ControlABACPolicy engine (user + resource attributes)Fine-grained, dynamic policies
Rule-Based Access ControlRuBACSystem rules / ACLsFirewall rules, network ACLs

About these practice questions

This AZ-104 question is part of Courseiva's 1,053-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

1 more way this is tested on AZ-104

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. You need to let a junior administrator manage virtual machines only in the RG-Dev resource group. The administrator must not be able to change role assignments or manage other resource groups. Which role assignment should you use?

medium
  • A.Owner at the RG-Dev scope
  • ✓ B.Virtual Machine Contributor at the RG-Dev scope
  • C.Reader at the subscription scope
  • D.Contributor at the subscription scope

Why B: The Virtual Machine Contributor role at the RG-Dev scope grants the junior administrator full permissions to manage virtual machines (including start, stop, restart, delete, and modify VM configurations) but explicitly denies the ability to manage role assignments (RBAC) or access to other resource groups. This aligns with the principle of least privilege, ensuring the administrator can perform their required tasks without exceeding their authority.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AZ-104 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-104 exam.