Courseiva

AZ-104 · topic practice

Manage Azure Identities and Governance practice questions

Identity and governance is the foundation of AZ-104. The RBAC scope hierarchy and the difference between Azure AD roles and Azure RBAC roles cause the most confusion — get these right before exam day.

Courseiva uses original exam-style practice questions designed for learning and revision. The goal is to understand the concepts, recognise exam patterns, and improve through explanations — not memorise copied exam dumps.

Reviewed byJohnson Ajibi· MSc IT Security
20 questionsDomain: Manage Azure Identities and Governance

What the exam tests

What to know about Manage Azure Identities and Governance

Manage Azure Identities and Governance tests Azure AD users and groups, RBAC role assignments, management groups, subscriptions, and Azure Policy.

Azure AD objects: users, groups, service principals, and managed identities.

RBAC: built-in roles (Owner, Contributor, Reader), custom roles, and scope hierarchy.

Management groups, subscriptions, resource groups, and how policy inheritance flows down.

Azure Policy effects: Deny, Audit, Append, DeployIfNotExists, and Modify.

Watch out for

Common Manage Azure Identities and Governance exam traps

  • Assuming Owner at the resource group level grants Owner access to the subscription — roles do not inherit upward.
  • Confusing Azure AD roles (directory-level) with Azure RBAC roles (resource-level).
  • Forgetting that Azure Policy can only enforce compliance going forward — existing non-compliant resources require a remediation task.
  • Mixing up Deny (blocks creation) and Audit (logs non-compliance) policy effects.

Practice set

Manage Azure Identities and Governance questions

20 questions · select your answer, then reveal the explanation

A help desk team must be able to reset passwords for cloud users in Microsoft Entra ID, but they must not be able to create or delete users. Which built-in role should you assign?

An administrator grants the Helpdesk group the User Administrator role at the tenant scope. The team should be able to reset passwords only for users in the Europe-Users administrative unit. What should the administrator do?

You need to prevent accidental deletion of a resource group while still allowing administrators to create and modify resources inside it. Which lock should you apply?

You need to let a junior administrator manage virtual machines only in the RG-Dev resource group. The administrator must not be able to change role assignments or manage other resource groups. Which role assignment should you use?

A support engineer must start and restart one specific virtual machine from the Azure portal, but must not be able to delete the VM, change networking, or grant access to others. Which two actions should be included in a custom role? Select two.

A storage automation service principal must upload, read, and delete blob data in one container by using Microsoft Entra authentication. It must not manage storage account settings, keys, or other containers. Which approach is best?

A resource group has a ReadOnly lock applied to it. An operator can view the resources, but several portal changes fail. Which two operations will fail because of the lock? Select two.

A developer has the Contributor role on a resource group and tries to deploy a Windows VM with a public IP address. The deployment fails, even though the role assignment is active. Which two checks should you perform first to confirm why the deployment failed? Select two.

Your company wants one governance baseline to apply automatically to all current and future production subscriptions, and finance wants cost reporting by application across many resource groups. Which two design choices best satisfy the requirements? Select two.

A bootstrap script must install software on three VMs, then download configuration files from Blob Storage. Security forbids secrets in templates or scripts, and the same authentication method must work after the VMs are rebuilt. Which two choices should you make? Select two.

A shared resource group contains a critical virtual machine and a storage account. Administrators must still be able to update settings, but nobody should accidentally delete either resource during routine maintenance. Which lock should be applied?

An operations team needs to let helpdesk staff restart virtual machines and view their properties only in RG-Dev. The staff must not be able to manage virtual networks, disks, or delete any resources. What is the best built-in role assignment?

A production resource group contains application VMs and databases. Operators must be able to update resources inside the group, but nobody should be able to delete the whole group by accident. Finance also wants ownership data to remain with the resources if they are moved to another resource group. Which two actions should you take? Select two.

Finance, HR, and Engineering each have their own subscriptions, and one production resource group must not be deleted by mistake. Which two Azure features should be used? Select two.

A company has many subscriptions arranged under a management group named Corp. The audit team needs Reader access to every current and future subscription in Corp, and the administrator wants only one role assignment to maintain. Which two actions should be taken? Select two.

A team needs Reader access to exactly two Azure resources that are in the same resource group, and they must not gain access to other resources in that group. Which two scope choices are appropriate? Select two.

A project team adds and removes contractors every month. The team wants Azure role assignments to stay the same when individual contractors leave or join, and access should be granted to everyone on the team through one control point. What should the administrator assign the Azure role to?

A central audit group must have Reader access for every current and future subscription in the company hierarchy. You want one assignment that will apply broadly as new subscriptions are added. Where should the role be assigned?

Based on the exhibit, which lock should the administrator apply to protect the resource group from accidental deletion while still allowing normal updates to the resources inside it?

Exhibit

Resource group details
Name: rg-payroll-prod
Resources:
- 6 virtual machines
- 2 storage accounts
- 1 Key Vault
Maintenance requirement: Administrators must continue starting, stopping, resizing, and updating the resources during the maintenance window. The only thing that must be prevented is accidental deletion of the entire resource group.

An Azure Policy that appends the Environment tag is assigned to a subscription. New virtual machines get the tag, but existing VMs do not. What should the administrator do next?

Free account

Track your progress over time

Create a free account to save your results and see which topics improve across sessions.

Focused Manage Azure Identities and Governance sessions

Start a Manage Azure Identities and Governance only practice session

Every question in these sessions is drawn from the Manage Azure Identities and Governance domain — nothing else.

Related practice questions

Related AZ-104 topic practice pages

Move into related areas when this topic feels solid.

Frequently asked questions

What does the AZ-104 exam test about Manage Azure Identities and Governance?
Manage Azure Identities and Governance tests Azure AD users and groups, RBAC role assignments, management groups, subscriptions, and Azure Policy.
How should I use these practice questions?
Select your answer before revealing the explanation. Then read why each option is right or wrong — this active recall approach builds retention far faster than re-reading notes.
Can I practise just Manage Azure Identities and Governance questions in a focused session?
Yes — the session launcher on this page draws every question from the Manage Azure Identities and Governance domain. Use a 10-question session first to gauge your baseline, then move to 20 or 30 once the weak spots are clear.
Where can I practise other AZ-104 topics?
Use the topic links above to move to related areas, or go back to the AZ-104 question bank to see all topics.
Are these real exam questions or dumps?
These are original practice questions written to test the same concepts the AZ-104 exam covers. They are not copied from any real exam or dump site.