Resource Tags: The Key to Compliance Reporting for Azure Resources
A compliance report must show which department and environment owns each Azure resource, even when the resources are spread across many resource groups and subscriptions. Which feature should the administrator use?
Quick Answer
The answer is resource tags. These metadata key-value pairs are the correct feature because they allow you to attach custom labels like “Department: Finance” or “Environment: Production” directly to any Azure resource, regardless of which resource group or subscription it lives in. This flexibility is essential for compliance reporting, as the tags are automatically included in Azure Policy and cost management reports, giving you a unified view across your entire environment. On the AZ-104 exam, this question tests your understanding of how to logically organize resources for governance without relying on rigid structures like management groups or resource group names—a common trap is assuming resource group names alone suffice, but they cannot span multiple subscriptions. Remember the memory tip: “Tags travel with the resource,” meaning they stick to the resource even if it moves between groups or subscriptions, making them the only portable metadata for cross-boundary compliance reporting.
⚠ Common exam trap
Many exam-takers confuse management groups (which organize subscriptions for policy and RBAC) with resource tags (which provide per-resource metadata), leading them to select management groups even though they cannot express department or environment ownership at the individual resource level.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Resource tags.
Resource tags are metadata key-value pairs that can be attached to Azure resources, resource groups, and subscriptions. They allow administrators to logically organize resources by department, environment, cost center, or any custom category, and this metadata is included in compliance reports. Unlike resource group names or management groups, tags are flexible and can be applied across multiple resource groups and subscriptions, making them the correct choice for this requirement.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Resource group names only.
Why it's wrong here
Resource group names can help with organization, but they do not provide structured metadata across all resources and subscriptions.
When this WOULD be correct
If the question asked for a method to organize resources for policy enforcement or cost management at scale across multiple subscriptions, management groups would be correct.
- ✗
Management groups.
Why it's wrong here
Management groups organize subscriptions for governance, but they do not label each individual resource with business metadata such as department or environment.
When this WOULD be correct
An administrator needs to apply consistent policies (e.g., allowed regions) or RBAC assignments across multiple subscriptions. Management groups would be the correct feature to use.
- ✓
Resource tags.
Why this is correct
Tags are the correct feature because they attach metadata like department and environment directly to resources. That metadata can then be queried, filtered, and reported across multiple resource groups and subscriptions. Tags are a common Azure governance tool when business ownership must be tracked independently of the resource hierarchy.
- ✗
Resource locks.
Why it's wrong here
Locks protect resources from deletion or modification, but they do not store reporting metadata and cannot be used as an ownership classification mechanism.
When this WOULD be correct
An administrator needs to ensure that critical production resources cannot be deleted or modified by unauthorized users. The question would ask: 'Which feature should be used to prevent accidental deletion of a resource?'
Option-by-option analysis
Why each answer is right or wrong
Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The AZ-104 exam frequently reuses these exact scenarios with slightly different constraints.
✓Resource tags.Correct answer▾
Why this is correct
Tags are the correct feature because they attach metadata like department and environment directly to resources. That metadata can then be queried, filtered, and reported across multiple resource groups and subscriptions. Tags are a common Azure governance tool when business ownership must be tracked independently of the resource hierarchy.
✗Resource group names only.Wrong answer — click to see why▾
Why this is wrong here
Resource group names alone cannot encode ownership metadata like department and environment across multiple subscriptions; they are just naming conventions without enforced queryability or reporting capability.
★ When this WOULD be the correct answer
If the question asked for a method to organize resources for policy enforcement or cost management at scale across multiple subscriptions, management groups would be correct.
Why candidates choose this
Candidates may think that naming resource groups with department and environment prefixes is sufficient for compliance reporting, underestimating the need for a flexible, queryable metadata solution like tags.
✗Management groups.Wrong answer — click to see why▾
Why this is wrong here
Management groups organize subscriptions for policy and access management but do not provide metadata about department or environment ownership for individual resources.
★ When this WOULD be the correct answer
An administrator needs to apply consistent policies (e.g., allowed regions) or RBAC assignments across multiple subscriptions. Management groups would be the correct feature to use.
Why candidates choose this
Candidates may confuse management groups with resource organization, thinking they can enforce ownership metadata, but they lack the key-value tagging capability needed for custom attributes like department and environment.
✗Resource locks.Wrong answer — click to see why▾
Why this is wrong here
Resource locks prevent accidental deletion or modification of resources but do not provide metadata about ownership or environment. They cannot be used to report which department or environment owns a resource.
★ When this WOULD be the correct answer
An administrator needs to ensure that critical production resources cannot be deleted or modified by unauthorized users. The question would ask: 'Which feature should be used to prevent accidental deletion of a resource?'
Why candidates choose this
Candidates may confuse resource locks with tagging or governance features, thinking locks can also store ownership information, or they may overestimate the capabilities of locks in resource management.
Analysis generated from the official AZ-104blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”
Go deeper
Related to this question
Learn chapter
Dynamic Membership Groups
Key term
Group
A group is a collection of users, devices, or other objects that are assigned permissions and policies together for simplified management in identity and governance systems like Microsoft Entra ID.
Key term
Compliance
Compliance is the process of ensuring that an organization follows laws, regulations, standards, and internal policies that apply to its operations and data handling.
About these practice questions
One of 1,049 original AZ-104 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on AZ-104
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. Finance, HR, and Engineering each use separate subscriptions. The compliance team wants a simple hierarchy that lets them apply governance to groups of subscriptions and produce resource ownership reports by department and environment. Which two features should the administrator use? Select two.
medium- ✓ A.Management groups to organize the subscriptions into a hierarchy.
- ✓ B.Tags on resources to record department and environment values.
- C.Resource locks to group subscriptions by business unit.
- D.Availability sets to group applications by department.
- E.Private endpoints to separate Finance from HR.
Why A: Management groups (A) are correct because they allow you to organize multiple subscriptions into a hierarchical structure for applying governance policies and role-based access control at scale. This directly supports the compliance team's need to apply governance to groups of subscriptions and produce resource ownership reports by department and environment.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-104 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-104 exam.