AZ-104 Renewal Actual Exam Questions (60
Questions)
2026/2027 Latest Edition — 100% Verified Answers (A+ Grade Guaranteed)
Microsoft Azure Administrator Associate Certification Renewal
Total Questions: 60 Time Limit: 90 minutes Passing Score: 70%
Instructions: This exam contains 60 multiple-choice questions across 6 sections. Each question has exactly
ONE correct answer (A, B, C, or D). The correct answer is marked with [CORRECT] and a detailed rationale is
provided below each question. Use this exam to assess your readiness for the AZ-104 Microsoft Azure
Administrator renewal assessment.
Exam Structure: Section 1: Azure Identity and Access Management (Q1-Q12) | Section 2: Azure Networking
(Q13-Q24) | Section 3: Azure Compute Resources (Q25-Q36) | Section 4: Azure Storage Solutions (Q37-Q44)
| Section 5: Azure Governance, Monitoring, and Compliance (Q45-Q52) | Section 6: Azure Cost Management
and SLA Optimization (Q53-Q60)
Section 1: Azure Identity and Access Management
Q1. You administer an Azure AD tenant for Contoso Ltd. The HR department uploads a daily CSV
file of new hires to a SharePoint site. You need to ensure that every new hire is automatically
added to the 'NewHires-2026' group within 24 hours of being created in Azure AD, and removed
when their department attribute changes to 'Engineering'. Which Azure AD feature should you
configure?
A. Configure a self-service group with dynamic membership rules based on the userPrincipalName
attribute.
B. Create a dynamic security group with a membership rule based on the department attribute
equal to 'NewHires' and enable the 'Wait for rules to apply' flag. [CORRECT]
C. Assign a Logic App that runs every 24 hours and invokes the Microsoft Graph API to add or remove
users from a static group.
D. Enable Azure AD Connect group sync with declarative provisioning and a scoping filter on the
department attribute.
Correct Answer: B
Rationale: Dynamic security groups evaluate attribute-based membership rules (e.g., user.department -eq
'NewHires') and automatically add or remove members as attributes change, which exactly meets the 24-hour
auto-membership requirement. Self-service groups (A) require manual join requests and cannot react to
attribute changes. A Logic App (C) is operationally heavy, fragile, and reimplements functionality Azure AD
provides natively. Azure AD Connect (D) synchronizes on-premises objects to the cloud but does not provide
the cloud-side dynamic membership engine.
Page 1 | A+ Grade Guaranteed | 100% Verified Answers
,AZ-104 Microsoft Azure Administrator Renewal Exam 2026/2027 Edition | 60 Questions
Q2. You are asked to grant a junior administrator the ability to reset passwords for users in the
'Customer Support' organizational unit only, without granting tenant-wide Helpdesk
Administrator rights. Which approach should you use?
A. Create a custom Azure AD role with the 'microsoft.directory/users/password/update'
permission and assign it scoped to an administrative unit containing Customer Support users.
[CORRECT]
B. Assign the built-in Helpdesk Administrator role at the tenant scope and rely on Conditional Access to
restrict the actions.
C. Grant the User Administrator role and create a Conditional Access policy that blocks writes outside
the OU.
D. Use Privileged Identity Management (PIM) to make the user eligible for the Password Administrator
role on demand.
Correct Answer: A
Rationale: Azure AD Administrative Units (AUs) allow scoping of role assignments to a subset of users;
combined with a custom role that exposes only the password reset permission
(microsoft.directory/users/password/update), the junior admin can reset passwords for Customer Support
users without affecting the rest of the tenant. The built-in Helpdesk Administrator (B) is tenant-wide and cannot
be constrained by Conditional Access, which controls authentication, not authorization. User Administrator (C)
is over-broad and also tenant-wide. PIM (D) only governs activation of an already-overprivileged role; it does
not narrow the scope of permissions.
Q3. Contoso requires that all administrators accessing the Azure portal from non-corporate
networks must register for Azure AD Multi-Factor Authentication (MFA) and complete MFA at
sign-in. Administrators signing in from the corporate network must only complete MFA when
their sign-in risk is medium or higher. Which Conditional Access configuration should you
deploy?
A. One policy: include all admin roles, require MFA for all cloud apps, exclude trusted locations, and
require Azure MFA registration.
B. Two policies: (1) include admins, exclude trusted locations, grant access with MFA; (2)
include admins, include trusted locations, grant access with MFA only when sign-in risk is
medium or higher. [CORRECT]
C. One policy that uses session control 'Sign-in frequency' set to 1 hour for all admins regardless of
location.
D. Configure Azure AD Security Defaults to enforce MFA for all users, then exclude admins from the
policy.
Correct Answer: B
Rationale: Conditional Access evaluates conditions per sign-in, so two policies cleanly model the requirement:
one covers untrusted locations requiring MFA always, the second covers trusted locations requiring MFA only
when sign-in risk is medium or higher. A single policy excluding trusted locations (A) would never evaluate
risk-based access for trusted users. Sign-in frequency (C) is a session control that does not enforce MFA itself;
it only shortens reauthentication windows. Security Defaults (D) cannot be combined with Conditional Access
and do not support risk-based conditions.
Q4. Your Identity Protection dashboard shows 240 users with 'High' user risk and 1,800 sign-ins
flagged as 'Risky' in the last 7 days. The CISO mandates that high-risk users must be
auto-remediated and high-risk sign-ins must be blocked. Which configuration should you apply?
A. Enable the user risk policy to require password change on 'High' risk, and enable the sign-in
risk policy to block access on 'High' risk. [CORRECT]
Page 2 | A+ Grade Guaranteed | 100% Verified Answers
, AZ-104 Microsoft Azure Administrator Renewal Exam 2026/2027 Edition | 60 Questions
B. Configure a Conditional Access policy granting access when sign-in risk is Low only, and rely on
users to self-reset.
C. Enable Azure AD Identity Protection with 'Block' on all sign-ins and require MFA for user risk = High.
D. Deploy Azure AD Password Protection and ban custom passwords; risk policies are deprecated in
2026.
Correct Answer: A
Rationale: Identity Protection exposes two policies: the user risk policy (which can require secure password
reset when user risk is High) and the sign-in risk policy (which can block access when sign-in risk is High).
Together these satisfy auto-remediation for compromised users and blocking of risky sessions. Option B omits
user-risk remediation. Option C conflates the two policies and inverts the MFA assignment. Option D is
incorrect because risk policies are still fully supported, and Password Protection only blocks weak passwords,
not session risk.
Q5. An auditor requires that engineers in the 'OpsEng' group cannot permanently hold the
'Virtual Machine Contributor' role on the 'Production' subscription. They must activate it on
demand for a maximum of 4 hours and provide a ticket number. Which configuration meets the
requirement?
A. Assign the OpsEng group as 'Eligible' for Virtual Machine Contributor in PIM on the
Production subscription, with a maximum activation duration of 4 hours and a ticket-number
requirement. [CORRECT]
B. Assign the OpsEng group as 'Active' for Virtual Machine Contributor and create a Conditional Access
policy that requires a ticket claim.
C. Use Azure AD Conditional Access with the 'Privileged authentication context' to time-limit role use to
4 hours.
D. Create a custom RBAC role with a 4-hour expiration token and assign it directly to each engineer.
Correct Answer: A
Rationale: Privileged Identity Management (PIM) is designed exactly for time-bound, justification-gated
elevation; assigning OpsEng as Eligible with a 4-hour maximum activation duration and a ticket-number
justification requirement satisfies all constraints. Active assignment (B) violates the 'no permanent access' rule.
Conditional Access with Privileged authentication context (C) governs authentication strength when accessing
resources that already have an assigned role, but it does not itself time-box a role assignment. RBAC roles (D)
do not support token-based expiration; role assignments are persistent until removed.
Q6. You deploy a Linux VM named appvm01 that must authenticate to an Azure Key Vault to
retrieve a database connection string without storing any credentials in code or VM metadata.
Which configuration should you perform?
A. Enable a system-assigned managed identity on appvm01, grant that identity's principal a Key
Vault Access Policy with 'Get' secret permissions, then use the IMDS endpoint to obtain an
access token for https://vault.azure.net. [CORRECT]
B. Create a user-assigned managed identity, store its client secret in /etc/azure-creds, and use it to
authenticate to Key Vault.
C. Deploy the VM into a subnet that has a service endpoint for Microsoft.KeyVault, then access the
vault over the public endpoint using the VM's network identity.
D. Register an Azure AD app, embed its client secret in the VM's cloud-init script, and acquire tokens
using the client_credentials flow.
Correct Answer: A
Rationale: A system-assigned managed identity is automatically tied to the VM lifecycle, requires no secrets,
and can be granted a Key Vault Access Policy with Get secret permissions; the application then obtains tokens
Page 3 | A+ Grade Guaranteed | 100% Verified Answers