• Wrong document? Swap it for free
  • Written by students who passed
  • Immediately available after payment
  • Read online or as PDF
Sell
Where do you study
Your language
Document preview thumbnail
Preview 4 out of 82 pages
Exam (elaborations)

AZ-104 MICROSOFT AZURE ADMINISTRATOR TEST BANK 2026/2027 | 313 Questions | Topic 1: 45 Questions | Verified Answers | Pass Guaranteed - A+ Graded

Document preview thumbnail
Preview 4 out of 82 pages

Pass the AZ-104 Microsoft Azure Administrator exam with this comprehensive 313-question test bank, starting with Topic 1 featuring 45 questions (Pages 1-81). This A+ Graded resource is updated for 2026/2027 and covers all five core exam domains: Manage Azure identities and governance, Implement and manage storage, Deploy and manage Azure compute resources, Implement and manage virtual networking, and Monitor and maintain Azure resources. Each question includes detailed rationales to strengthen understanding of key concepts like RBAC scopes, Azure Policy, storage redundancy, ARM templates, VNet peering, and Azure Monitor. With our Pass Guarantee, you have the definitive tool to pass on your first attempt. Download your complete AZ-104 Test Bank instantly!

Content preview

M I C R O S O F T A Z U R E A D M I N I S T R AT O R
C E R T I F I C AT I O N E X A M T E S T B A N K




AZ-104
TESTBANK
A complete practice question bank aligned with current AZ-104
exam objectives and Azure service capabilities: 313 scenario-
based and recall questions across six topics spanning
identities and governance, storage, compute, networking,
monitoring, and automation - each with the correct answer and
a detailed technical rationale.




NO. OF QUESTIONS: 313
TOPIC 1: 45 QUESTIONS (PG 1 TO 36) · ANSWERS AND DETAILED
RATIONALES INCLUDED




M IC R O S O F T A Z U R E A DM IN IS TR ATO R · 2 0 2 6 E DITIO N

,AZ-104 TESTBANK | Microsoft Azure Administrator Questions 1-313




AZ-104 TESTBANK
Microsoft Azure Administrator - Certification Exam Test Bank
NO. OF QUESTIONS: 313 | TOPIC 1: 45 QUESTIONS (PG 1 TO 36)
Aligned with current AZ-104 Microsoft Azure Administrator exam objectives and current Azure service capabilities.
Scenario-based administration questions, command identification, template interpretation, and troubleshooting
diagnostics with complete answer rationales.


TOPIC 1: MANAGE AZURE IDENTITIES AND GOVERNANCE |
Questions 1-45
SUBSECTION 1a: Microsoft Entra ID Users, Groups, and Licenses | Questions 1-15
Q1: Your company plans to onboard 250 seasonal contractors over the next month. The identity team wants to
minimize manual effort by creating all accounts in a single operation using a structured file. What should you
recommend?
A. Use bulk create users with a CSV template in Microsoft Entra ID [CORRECT]
B. Create a dynamic device group that auto-populates with contractor devices
C. Create each user account manually in the Microsoft Entra admin center
D. Assign an Azure Policy definition that creates the user accounts
Correct Answer: A
Rationale: Microsoft Entra ID supports bulk user creation through a downloadable CSV template that can create
thousands of users in one upload. Azure Policy governs Azure resources and cannot create user objects, and dynamic
groups only organize existing users into memberships. Manual creation directly violates the requirement to minimize
effort.

Q2: Employees of a partner organization need access to your internal expense application. Security requires that
they continue signing in with their own corporate credentials and that their accounts remain managed by their
home organization. Which solution should you implement?
A. Deploy Microsoft Entra External ID (B2C) for the expense application
B. Establish an on-premises forest trust with the partner domain
C. Create new member user accounts with locally managed passwords
D. Use Microsoft Entra B2B collaboration to invite them as guest users [CORRECT]
Correct Answer: D
Rationale: Entra B2B collaboration creates guest user objects that authenticate against their home identity provider,
so the partner keeps managing the accounts. B2C is designed for customer-facing applications where you own the
identity lifecycle, and member accounts force you to manage passwords for external staff. Forest trusts apply to
on-premises Active Directory, not Entra ID tenant collaboration.




Answer key with detailed rationales included 1

,AZ-104 TESTBANK | Microsoft Azure Administrator Questions 1-313




Q3: You are the administrator for Contoso Ltd. The security team wants to pilot self-service password reset
(SSPR) with the IT staff before rolling it out to all employees. Users outside the pilot must not be able to reset
their own passwords. What should you do?
A. Enable SSPR for all users and apply a conditional access filter
B. Enable SSPR for None and register users manually in the pilot
C. Enable SSPR only in the Microsoft Entra admin center Users page for each pilot user
D. Enable SSPR for the Selected group and add the IT staff group [CORRECT]
Correct Answer: D
Rationale: SSPR enablement offers three scopes: None, Selected, and All. Choosing Selected scopes the feature to a
designated group, which is exactly how a controlled pilot is performed. Conditional access policies control access to
applications, not SSPR enrollment, and per-user toggles on the Users page do not exist.

Q4: The security team at Northwind requires that any user performing a self-service password reset must verify
their identity with two different methods instead of one. Where should you configure this requirement?
A. In the user registration policy under authentication method strength
B. In the Authentication methods policy under the number of methods required to
reset [CORRECT]
C. In the password expiration policy for each user account
D. In the conditional access policy grant controls
Correct Answer: B
Rationale: The SSPR authentication methods policy includes a setting called "Number of methods required to reset,"
which can be set to one or two. Conditional access grant controls gate application access, not password reset flows, and
password expiration governs password age only. Method strength is used for sign-in scenarios in Microsoft
Authenticator policies, not SSPR.

Q5: You need a security group that automatically includes every user whose department attribute equals Sales
and excludes them automatically when they transfer to another department. Which membership type should you
configure?
A. Dynamic device membership with an operating system rule
B. Microsoft 365 group with owner approval workflow
C. Dynamic user membership with a rule based on user.department [CORRECT]
D. Assigned membership with manual owner maintenance
Correct Answer: C
Rationale: Dynamic user membership evaluates a membership rule against user attributes on every change, adding
and removing users automatically as department values change. Assigned groups require manual member management,
and dynamic device groups evaluate device objects, not users. Microsoft 365 group types do not solve the automation
requirement.

Q6: Your organization plans to use dynamic membership groups and group-based license assignment. The tenant
currently has only Microsoft Entra ID Free licenses. What must you do before these features will function?
A. Enable the Microsoft Entra ID Governance add-on for the tenant
B. Upgrade the Azure subscription to an Enterprise Agreement
C. Purchase Microsoft Entra ID P1 licenses for the affected users [CORRECT]
D. Register and verify a custom domain name
Correct Answer: C
Rationale: Dynamic groups and group-based licensing are premium features that require Microsoft Entra ID P1. The
Governance add-on adds access reviews and lifecycle workflows on top of P2, an Enterprise Agreement changes
billing only, and custom domains are unrelated to feature licensing.




Answer key with detailed rationales included 2

, AZ-104 TESTBANK | Microsoft Azure Administrator Questions 1-313




Q7: You assign a Microsoft 365 E5 license to a new user account through group-based licensing, but the
assignment fails with an error stating the license could not be provisioned. What is the most likely cause?
A. The tenant has exceeded its directory object quota
B. The user account was created as a guest user
C. The user's usage location is not set [CORRECT]
D. The group has dynamic membership enabled
Correct Answer: C
Rationale: Group-based licensing requires each member to have a usage location defined before a license can be
provisioned, because service availability varies by region. Guests can be licensed in many scenarios, dynamic groups
are fully compatible with group-based licensing, and directory quotas are rarely hit at this scale.

Q8: A project team needs a shared workspace in Microsoft Teams, a shared mailbox, and a SharePoint
document library. The team will add and remove members frequently. Which object should you create?
A. A distribution list in Exchange Online
B. A Microsoft 365 group [CORRECT]
C. An administrative unit containing the project members
D. A security group with dynamic membership
Correct Answer: B
Rationale: A Microsoft 365 group provisions the connected workspace experiences including Teams, a shared
mailbox, and a SharePoint site with a single membership object. Security groups only grant access to resources,
distribution lists only provide email distribution, and administrative units are scoping containers for delegated
administration.

Q9: The European helpdesk team should be able to reset passwords and manage groups only for users located in
Europe. Global administrators must not grant them rights over users in other regions. What should you
configure?
A. Scoped role assignments through administrative units [CORRECT]
B. A separate Microsoft Entra tenant for Europe
C. Azure RBAC custom roles scoped to a resource group
D. Conditional access policies named for each region
Correct Answer: A
Rationale: Administrative units partition a tenant so directory roles like Password Administrator or Groups
Administrator can be assigned over just the users placed in the unit. Creating a second tenant multiplies management
overhead, Azure RBAC scopes apply to Azure resources rather than directory objects, and conditional access governs
authentication rather than administrative rights.

Q10: Your tenant uses the default contoso.onmicrosoft.com UPN suffix for all users. The company now owns
the domain fabrikam.com and wants all new users to receive user principal names under that domain. What
should you do first?
A. Create a conditional access policy that blocks the onmicrosoft.com domain
B. Add fabrikam.com as a custom domain and complete DNS verification [CORRECT]
C. Change each user's UPN suffix manually in the Microsoft Entra admin center
D. Configure fabrikam.com as an alternative UPN suffix in the password policy
Correct Answer: B
Rationale: A custom UPN suffix can only be used after the domain is added to the tenant and verified through its
DNS TXT record. Changing users manually does not scale and is impossible until the domain exists, UPN suffixes are
not configured in password policy, and conditional access does not influence domain verification.




Answer key with detailed rationales included 3

Document information

Uploaded on
September 29, 2026
Number of pages
82
Written in
2026/2027
Type
Exam (elaborations)
Contains
Questions & answers
$19.50

Wrong document? Swap it for free Within 14 days of purchase and before downloading, you can choose a different document. You can simply spend the amount again.
Written by students who passed
Immediately available after payment
Read online or as PDF

Seller avatar
Reputation scores are based on the amount of documents a seller has sold for a fee and the reviews they have received for those documents. There are three levels: Bronze, Silver and Gold. The better the reputation, the more your can rely on the quality of the sellers work.
NURSEEXAMITY
3.4
(110)
Sold
597
Followers
275
Items
6880
Last sold
19 hours ago




Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Working on your references?

Create accurate citations in APA, MLA and Harvard with our free citation generator.

Working on your references?

Frequently asked questions