Courseiva

Assign Reader Role at Management Group for All Subscriptions

A company has many subscriptions arranged under a management group named Corp. The audit team needs Reader access to every current and future subscription in Corp, and the administrator wants only one role assignment to maintain. Which two actions should be taken? Select two.

Quick Answer

The answer is to assign the Reader role at the Corp management group scope and ensure all existing and new subscriptions remain under that management group. This works because Azure RBAC roles assigned at a management group are inherited by every child subscription, so a single assignment grants read-only access to all current and future subscriptions without needing individual assignments. On the AZ-104 exam, this tests your understanding of management group hierarchy and role inheritance, a common trap being that candidates mistakenly assign the role at the root management group or try to assign it per subscription. The key insight is that inheritance flows downward, so placing all subscriptions under Corp and assigning the role there satisfies the requirement for a single, maintainable assignment. Remember the memory tip: “One role at the group, covers the whole troop.”

⚠ Common exam trap

Many exam-takers think Reader must be assigned at each subscription individually (Option C) or at the tenant root (Option D), overlooking the inheritance behavior of management groups that allows a single assignment to cover all current and future subscriptions under a management group.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Assign Reader at the Corp management group scope.

Option A is correct because assigning the Reader role at the Corp management group scope grants inherited access to every subscription currently under that management group, satisfying the requirement for a single role assignment to maintain. Option B is correct because Azure RBAC inheritance flows from the management group down to subscriptions, so any existing or future subscription must remain (or be placed) under Corp for that single assignment to cover it. Option C is wrong because per-subscription assignments would require many role assignments, contradicting the one-assignment requirement. Option D is wrong because assigning at the tenant root would grant access far beyond Corp and removing the management group defeats the intended scope. Option E is wrong because resource-group-level assignments do not cover entire subscriptions and would require many assignments.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Assign Reader at the Corp management group scope.

    Why this is correct

    Assigning Reader at the management group scope lets permissions inherit down to every current and future subscription beneath Corp. This satisfies the single-assignment constraint, since new subscriptions joining the group automatically receive Reader without further configuration.

  • ✓

    Ensure all existing and new subscriptions remain under the Corp management group.

    Why this is correct

    Management groups inherit role assignments to every child subscription, including future ones. Keeping all subscriptions under Corp means a single assignment at that scope automatically covers new additions, satisfying the requirement for one maintained role assignment.

  • ✗

    Assign Reader separately on each subscription.

    Why it's wrong here

    Per-subscription assignments satisfy current access but fail the single-assignment requirement and do not automatically cover future subscriptions in Corp. It tempts because it works for a small, fixed set of subscriptions, and would be correct if the scope were a handful of known subscriptions with no growth.

    When this WOULD be correct

    If the question required granting Reader access only to specific subscriptions (not all current and future) and the subscriptions were not under a common management group, assigning Reader at each subscription scope would be appropriate.

  • ✗

    Assign Reader at the tenant root and remove the management group.

    Why it's wrong here

    Assigning Reader at the tenant root grants access far beyond Corp and contradicts the requirement to scope access to that management group; removing the management group also destroys the intended hierarchy. It tempts because tenant-root assignments do cover future subscriptions with one assignment, which suits whole-tenant auditing rather than a single management group.

    When this WOULD be correct

    This would be correct if the question required granting Reader access to all subscriptions in the entire tenant (including future ones) with a single assignment, and there was no requirement to keep the management group structure. For example: 'The audit team needs Reader access to all subscriptions in the tenant, and the administrator wants to minimize role assignments. What should you do?'

  • ✗

    Create a resource group for each subscription and assign Reader there.

    Why it's wrong here

    Resource-group assignments inherit only within that group, so they cannot grant Reader across every subscription in Corp, and creating one per subscription multiplies assignments. It tempts because resource-group scoping is the standard way to delegate access to a workload, and would be correct if the requirement were per-workload rather than per-subscription.

    When this WOULD be correct

    If the question required granting Reader access only to specific resources within each subscription (e.g., a set of VMs), and the administrator was willing to manage multiple assignments, assigning Reader at the resource group scope would be appropriate.

Option-by-option analysis

Why each answer is right or wrong

Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The AZ-104 exam frequently reuses these exact scenarios with slightly different constraints.

✓Assign Reader at the Corp management group scope.Correct answer▾

Why this is correct

Assigning Reader at the management group scope lets permissions inherit down to every current and future subscription beneath Corp. This satisfies the single-assignment constraint, since new subscriptions joining the group automatically receive Reader without further configuration.

✗Assign Reader separately on each subscription.Wrong answer — click to see why▾

Why this is wrong here

Assigning Reader separately on each subscription violates the requirement for only one role assignment to maintain, as it requires multiple assignments and ongoing management for new subscriptions.

★ When this WOULD be the correct answer

If the question required granting Reader access only to specific subscriptions (not all current and future) and the subscriptions were not under a common management group, assigning Reader at each subscription scope would be appropriate.

Why candidates choose this

Candidates may think that assigning roles at the subscription level is the standard method, overlooking the efficiency of management group scoping for bulk assignments.

✗Assign Reader at the tenant root and remove the management group.Wrong answer — click to see why▾

Why this is wrong here

Assigning Reader at the tenant root grants access to all subscriptions in the tenant, but the requirement is to maintain only one role assignment under the Corp management group. Removing the management group contradicts the goal of using management groups for governance and would affect other management groups or subscriptions not under Corp.

★ When this WOULD be the correct answer

This would be correct if the question required granting Reader access to all subscriptions in the entire tenant (including future ones) with a single assignment, and there was no requirement to keep the management group structure. For example: 'The audit team needs Reader access to all subscriptions in the tenant, and the administrator wants to minimize role assignments. What should you do?'

Why candidates choose this

Candidates may think that assigning at the tenant root is the simplest way to cover all subscriptions with one assignment, and they might overlook the requirement to keep the management group or the fact that tenant root assignments affect all subscriptions, not just those under Corp.

✗Create a resource group for each subscription and assign Reader there.Wrong answer — click to see why▾

Why this is wrong here

Assigning Reader at a resource group scope does not grant access to the subscription itself or future subscriptions, and it requires one assignment per resource group, violating the requirement for a single role assignment.

★ When this WOULD be the correct answer

If the question required granting Reader access only to specific resources within each subscription (e.g., a set of VMs), and the administrator was willing to manage multiple assignments, assigning Reader at the resource group scope would be appropriate.

Why candidates choose this

Candidates may think resource groups are a convenient way to organize permissions, but they overlook that the requirement is for subscription-level access and future subscriptions, which resource group assignments cannot cover.

Analysis generated from the official AZ-104blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”

Quick reference

Access Control Model Comparison

ModelAcronymWho Controls Access?Best For
Discretionary Access ControlDACResource ownerSmall teams, file shares
Mandatory Access ControlMACSystem / security labelsClassified govt / military
Role-Based Access ControlRBACAdministrator (via roles)Enterprise environments
Attribute-Based Access ControlABACPolicy engine (user + resource attributes)Fine-grained, dynamic policies
Rule-Based Access ControlRuBACSystem rules / ACLsFirewall rules, network ACLs

About these practice questions

One of 1,053 original AZ-104 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

1 more way this is tested on AZ-104

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. Based on the exhibit, where should the Reader role be assigned so the audit team automatically has access to every current and future subscription under Corp?

medium
  • ✓ A.Assign Reader at the Corp management group scope.
  • B.Assign Reader at the subscription scope for Sub-001.
  • C.Assign Reader at the resource group scope in each subscription.
  • D.Assign Reader directly to each resource that the audit team might review.

Why A: Assigning the Reader role at the Corp management group scope uses Azure RBAC inheritance to grant the audit team read-only access to all current and future subscriptions under that management group. Because management group scope propagates role assignments to all child subscriptions and resource groups, this ensures automatic coverage without manual updates.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AZ-104 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-104 exam.