Courseiva
Manage Azure Identities and GovernanceeasyMultiple ChoiceObjective-mapped

AZ-104 Manage Azure Identities and Governance Practice Question

You need one assignment that requires a cost-center tag and also allows only approved locations. What should you use?

⚠ Common exam trap

Watch out — candidates often confuse a policy initiative with a management group, thinking the management group itself enforces rules, but a management group is only a hierarchy container—you must assign a policy or initiative to it to enforce compliance.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

A policy initiative

A policy initiative is the correct choice because it allows you to group multiple Azure Policy definitions (such as 'Require a cost-center tag' and 'Allowed locations') into a single, reusable assignment. This ensures both conditions are enforced simultaneously at a scope like a subscription or resource group, meeting the requirement for a cost-center tag and location restriction.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • A policy initiative

    Why this is correct

    A policy initiative is a collection of one or more Azure policy definitions (such as "require a cost center tag" and "only allow approved locations") grouped as a single unit for assignment. Assigning an initiative at a management group, subscription, or resource group scope allows Azure Policy to evaluate both requirements together and remediate noncompliant resources. This directly fulfills the need for one assignment that enforces both tagging and location constraints.

  • A role assignment

    Why it's wrong here

    A role assignment is an RBAC artifact that binds a security principal (user, group, or service principal) to a role definition such as Owner or Contributor, granting permissions to perform actions on a scope. It does not evaluate or enforce resource properties like tags or deployment locations, and it cannot be used to bundle multiple policy requirements. Role assignments govern who can act, not what conditions resources must satisfy.

    When this WOULD be correct

    A role assignment would be correct if the question asked: 'You need to grant a user the ability to manage virtual machines in a specific resource group.' It controls access, not compliance.

  • A resource lock

    Why it's wrong here

    A resource lock (CanNotDelete or ReadOnly) protects a resource or resource group from accidental deletion or modification by blocking Azure Resource Manager operations at that scope. Locks do not impose any deployment-time requirements, such as mandating a cost center tag or approved location, and they cannot group multiple compliance conditions into one entity. They are a safeguard applied after resources exist, not a policy bundle.

    When this WOULD be correct

    A resource lock would be correct if the question asked: 'You need to prevent accidental deletion of a critical resource that has a cost-center tag and is in an approved location.' The lock ensures the resource cannot be deleted or modified, protecting the existing compliance.

  • A management group

    Why it's wrong here

    A management group is a hierarchical container that organizes subscriptions and provides a scope for assigning governance controls like Azure Policy or RBAC, enabling consistent management across multiple subscriptions. However, it is not the bundle of policy rules itself; an initiative or policy is assigned at the management group scope, but the management group object merely serves as the boundary for that assignment. Since the requirement asks for a single assignment entity and not a governance container, a management group does not directly satisfy the need.

    When this WOULD be correct

    You need to organize multiple subscriptions under a common hierarchy for applying consistent policies, compliance, or cost management. A management group would be correct if the question asked for a logical container to group subscriptions for centralized governance.

Option-by-option analysis

Why each answer is right or wrong

Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The AZ-104 exam frequently reuses these exact scenarios with slightly different constraints.

A policy initiativeCorrect answer

Why this is correct

A policy initiative is a collection of one or more Azure policy definitions (such as "require a cost center tag" and "only allow approved locations") grouped as a single unit for assignment. Assigning an initiative at a management group, subscription, or resource group scope allows Azure Policy to evaluate both requirements together and remediate noncompliant resources. This directly fulfills the need for one assignment that enforces both tagging and location constraints.

A role assignmentWrong answer — click to see why

Why this is wrong here

A role assignment grants permissions to users or groups, but does not enforce resource configuration requirements like tags or location restrictions. It cannot enforce compliance policies.

★ When this WOULD be the correct answer

A role assignment would be correct if the question asked: 'You need to grant a user the ability to manage virtual machines in a specific resource group.' It controls access, not compliance.

Why candidates choose this

Candidates may confuse role assignments with policy assignments, thinking that assigning a role can enforce rules, but roles only control access, not resource properties.

A resource lockWrong answer — click to see why

Why this is wrong here

A resource lock prevents deletion or modification of resources but cannot enforce tagging or location restrictions. The question requires both a cost-center tag and approved locations, which are policy-based controls, not lock-based.

★ When this WOULD be the correct answer

A resource lock would be correct if the question asked: 'You need to prevent accidental deletion of a critical resource that has a cost-center tag and is in an approved location.' The lock ensures the resource cannot be deleted or modified, protecting the existing compliance.

Why candidates choose this

Candidates may confuse resource locks with policy enforcement, thinking locks can restrict configurations like tags or locations, when locks only prevent deletion or modification operations.

A management groupWrong answer — click to see why

Why this is wrong here

A management group is a container for organizing subscriptions and applying governance, but it cannot directly enforce tags or location restrictions. Policy assignments (via initiatives) are needed to enforce such rules.

★ When this WOULD be the correct answer

You need to organize multiple subscriptions under a common hierarchy for applying consistent policies, compliance, or cost management. A management group would be correct if the question asked for a logical container to group subscriptions for centralized governance.

Why candidates choose this

Candidates may confuse management groups with policy assignments because both are used for governance at scale, but management groups only provide structure, not enforcement.

Analysis generated from the official AZ-104blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”

Go deeper

Related to this question

About these practice questions

One of 1,049 original AZ-104 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AZ-104 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-104 exam.