1.0 Manage Azure identities and governance AZ-104 Practice Quiz

110 exam-style questions covering 23% of the AZ-104 exam. Instant feedback on every answer, progress tracking, no signup required.

This domain is part of the Microsoft Azure Administrator practice test. Each question is tagged by exam objective and difficulty so you can drill exactly the areas you need.

Sample Questions

A new Azure environment requires an administrator to implement create Microsoft Entra users and groups. Which option should be selected?
  • A. Create the user in Microsoft Entra ID, assign required group memberships, and verify the account sign-in settings
  • B. Configure MFA only after a security incident has already occurred
  • C. Assign privileged roles permanently to all team members
  • D. Treat Azure RBAC role assignments as automatically inherited from on-premises Active Directory

Creating the account and placing it in the correct groups gives the user the intended access path and keeps membership manageable.

An organization is standardizing Azure administration. Which implementation best addresses create Microsoft Entra users and groups?
  • A. Create a dynamic group when membership should be based on user or device attributes
  • B. Use Azure Spot VMs for stateful database workloads requiring zero downtime
  • C. Assign licenses by editing CSV files instead of using group-based licensing
  • D. Treat Azure Policy as an alert system rather than an enforcement mechanism

Dynamic membership can automatically maintain group membership from rules.

An audit finding shows that the current process for create Microsoft Entra users and groups is inconsistent. What is the best administrative action?
  • A. Use a ReadOnly lock to allow VM resizing
  • B. Create a security group in Microsoft Entra ID and add the required users as members
  • C. Use Azure RBAC alone to manage user license assignments
  • D. Use a CanNotDelete lock on every resource by default

Security groups are commonly used to manage access for multiple users instead of assigning access one user at a time.

During an access and governance review, the team identifies a need for create Microsoft Entra users and groups. What should be configured?
  • A. Use a single shared service principal across all CI/CD pipelines
  • B. Create the user with the correct usage location before assigning services that require licensing
  • C. Use Azure Blueprints as a real-time monitoring solution
  • D. Use a security group as a distribution list for external mail

Some Microsoft cloud services require a usage location before the license can be applied correctly.

An Azure administrator is asked to complete a production task for manage user and group properties. What should the administrator do?
  • A. Treat tenant root group ownership as the default scope for all role assignments
  • B. Create a new group of the correct type when the existing group type does not support the needed feature
  • C. Use a custom role at subscription scope when a built-in role at resource group scope is sufficient
  • D. Disable Microsoft Entra audit logs to reduce storage cost

Some group capabilities depend on group type and cannot be changed after creation.

An Azure administrator is asked to complete a production task for create Microsoft Entra users and groups. What should the administrator do?
  • A. Invite a B2B guest by creating a new Entra ID user with a temporary password
  • B. Use management groups to bill resources without organizing access policies
  • C. Create a Microsoft 365 group when the team needs collaboration features such as a shared mailbox and SharePoint resources
  • D. Move resources between subscriptions without checking resource-type support

Microsoft 365 groups support collaboration scenarios in addition to group membership.

A new Azure environment requires an administrator to implement create Microsoft Entra users and groups. Which option should be selected?
  • A. Use Azure Policy to grant additional permissions beyond RBAC
  • B. Use a single shared admin account for all team members to simplify access
  • C. Use the Azure portal, Microsoft Entra admin center, Microsoft Graph, or PowerShell depending on the required automation level
  • D. Pay full PAYG rates for stable production VMs running 24/7 for years

Azure administrators can create users and groups interactively or through scripted methods.

A support ticket reports a configuration issue involving create Microsoft Entra users and groups. Which action is most appropriate?
  • A. Use Microsoft Entra roles in place of Azure RBAC roles for resource access
  • B. Configure Self-Service Password Reset (SSPR) only for global administrators
  • C. Use SSPR without registering authentication methods for users
  • D. Use bulk user creation when many users must be created from a prepared CSV file

Bulk creation reduces manual effort and supports consistent creation of many Microsoft Entra users.

Key Terms in This Domain

Link to this quiz

Studying with a group or teaching a class? Send this address or paste the link into your notes, wiki, or course page:

https://quizbuffet.com/microsoft-az-104/manage-azure-identities-and-governance/

<a href="https://quizbuffet.com/microsoft-az-104/manage-azure-identities-and-governance/">AZ-104 Azure Administrator Manage Azure identities and governance practice quiz on QuizBuffet</a>

Other AZ-104 Domains

← Back to AZ-104 practice test overview

Questions are written against the published AZ-104 objectives and checked for accuracy and balance before they go live. How QuizBuffet writes and reviews its questions.