• Wrong document? Swap it for free
  • Written by students who passed
  • Immediately available after payment
  • Read online or as PDF
Sell
Where do you study
Your language
Document preview thumbnail
Preview 4 out of 38 pages
Exam (elaborations)

AZ-104 RENEWAL ACTUAL EXAM 2026/2027 | Updated Questions & Verified Answers | Free Assessment Prep | Pass Guaranteed - A+ Graded

Document preview thumbnail
Preview 4 out of 38 pages

Pass the AZ-104 renewal assessment with updated questions and verified answers for 2026/2027. This A+ Graded resource covers all key renewal domains including Microsoft Entra ID, RBAC, Azure Policy, storage management, virtual networking, and backup recovery . Each question includes detailed rationales to reinforce understanding of updated Azure features like Bicep templates, container services, and Zero Trust governance . The renewal assessment is free, open-book, and unproctored, available only within 6 months before expiration, with unlimited retakes . With our Pass Guarantee, you have the definitive tool to renew on your first attempt. Download your complete AZ-104 renewal exam guide instantly!

Content preview

AZ-104 Renewal Exam — Question and Answer Updated 2026/2027 Microsoft Azure Administrator Renewal | High-Confidence Verified




AZ 104 RENEWAL EXAM QUESTION AND ANSWER UPDATED
2026/2027
110 Questions with High-Confidence Verified Rationales
Microsoft Azure Administrator (AZ-104) · Renewal Assessment · 2026/2027 Updates
Aligned with Microsoft Learn & Current Azure Service Updates


Total Questions 110 (EXACT) Cognitive Distribution 30% Recall | 50% Application | 20% Analysis

Sections 7 Azure Domain Areas Question Style 75% Scenario-based | 25% Direct Recall

Format MCQ, 4 options (A-D) Rationale Depth Azure Technical Reasoning + Best Practices

Exam Type Renewal Assessment Passing Standard Microsoft Azure Administrator Competency




Section 1: Identity and Governance Updates
Microsoft Entra ID, RBAC, Azure Policy, & Management Groups (Q1-16)


Q1: Your company recently renamed Azure Active Directory to Microsoft Entra ID. As the Azure administrator,
you need to grant a junior admin permissions to manage user accounts and group memberships but NOT to reset
passwords for privileged administrators. Which built-in role should you assign at the tenant scope?
A. Global Administrator
B. User Administrator [CORRECT]
C. Helpdesk Administrator
D. Authentication Administrator
Correct Answer: B
Rationale: The User Administrator role in Microsoft Entra ID can manage all aspects of users and groups, including
resetting passwords for non-administrator users, but cannot reset passwords for tenants' privileged administrator roles.
Global Administrator (A) is overprivileged — violates least-privilege. Helpdesk Administrator (C) can reset non-admin
passwords but cannot manage group memberships broadly. Authentication Administrator (D) is scoped to authentication
method management, not full user/group lifecycle.

Q2: A cloud engineer needs to invite an external consultant to collaborate on an Azure project. The consultant must
sign in with their own Gmail account without creating a new Microsoft account. Which feature should you
configure in Microsoft Entra ID?
A. Configure B2B collaboration and invite the consultant as a guest user using their Gmail address
[CORRECT]
B. Create a new member user in the tenant and require MFA on first login
C. Configure B2C with local email sign-in identity provider
D. Federate with Google Workspace using SAML and create a synced user
Correct Answer: A
Rationale: Microsoft Entra B2B collaboration lets you invite external users (including Gmail addresses) as guest users;
the invitee authenticates at their home identity provider and a verified one-time passcode flow is supported if they lack a
Microsoft account. Creating a new member user (B) requires the external consultant to manage new credentials. B2C (C)
is for customer-facing apps, not internal collaboration. SAML federation (D) is heavyweight and requires Google
Workspace admin consent; the simple B2B invitation flow is the right choice.



Page 1

,AZ-104 Renewal Exam — Question and Answer Updated 2026/2027 Microsoft Azure Administrator Renewal | High-Confidence Verified



Q3: Your organization requires self-service password reset (SSPR) for all users. Users must reset using BOTH their
mobile phone and an alternate email — and must not be allowed to use security questions. Which SSPR
configuration satisfies these requirements?
A. Set methods required to register = 1; authentication methods = mobile phone + email; security questions disabled
B. Set methods required to register = 2; authentication methods = mobile phone (SMS) + alternate email;
security questions disabled; require verification on reset [CORRECT]
C. Enable security questions as the primary method with mobile phone as fallback
D. Set methods required to reset = 1 and allow users to choose any combination
Correct Answer: B
Rationale: Microsoft Entra SSPR allows you to configure the number of methods required to register and reset, and which
methods are permitted. To enforce two specific methods (mobile phone + alternate email), set methods required to 2,
ensure those methods are enabled, disable security questions, and require verification at reset time. Choice A sets methods
to 1 — insufficient. Choice C allows security questions — explicitly forbidden. Choice D does not enforce the two
specific methods and lets the user choose — violates the requirement.

Q4: You assign a user the 'Virtual Machine Contributor' role at the resource group scope. The user attempts to
assign a managed identity to a VM in that resource group but receives a 403 Forbidden error. What is the
underlying cause, and what is the minimum change needed?
A. Virtual Machine Contributor role has been deprecated; assign 'Contributor' role
B. Assigning managed identities requires Microsoft.Authorization/*/Write permission, which is not in the
Virtual Machine Contributor role; assign 'Managed Identity Contributor' or create a custom role with
Microsoft.ManagedIdentity/identities/assign/action [CORRECT]
C. Move the VM to a different resource group
D. Enable managed identities for Azure resources at the subscription level
Correct Answer: B
Rationale: The 'Virtual Machine Contributor' built-in role allows VM lifecycle management but does not include the
permission to assign a managed identity to a VM (Microsoft.ManagedIdentity/identities/assign/action) or write role
assignments at the Authorization namespace. Assigning a managed identity is essentially a role assignment on the identity.
The least-privilege fix is to assign 'Managed Identity Contributor' or build a custom role that grants only the needed action.
Choice A is incorrect — VM Contributor is not deprecated and would still be over-broad. C and D do not address the
missing permission.

Q5: You need to deny resource creation in any region other than 'East US' and 'West Europe' across all
subscriptions in the management group 'CorpMG'. What is the most efficient way to enforce this?
A. Create a custom RBAC role with deny assignment and apply to each subscription
B. Create an Azure Policy definition 'Allowed Locations' and assign it at the management group 'CorpMG'
scope [CORRECT]
C. Apply resource locks to all non-compliant resource groups
D. Configure Azure Advisor recommendations on each subscription
Correct Answer: B
Rationale: Azure Policy is the governance tool for enforcing rules such as allowed locations. The 'Allowed Locations'
built-in policy definition can be assigned at the management group scope, automatically inheriting to all subscriptions
underneath. RBAC (A) is for access control, not allowed-locations enforcement. Resource locks (C) prevent
deletion/modification but do not control where resources are created. Azure Advisor (D) is advisory only —
non-enforcing.




Page 2

,AZ-104 Renewal Exam — Question and Answer Updated 2026/2027 Microsoft Azure Administrator Renewal | High-Confidence Verified



Q6: A developer needs read access to a single storage account but currently has the 'Reader' role at the subscription
scope. Following least-privilege principles, what is the BEST change?
A. Remove the Reader role at subscription scope and assign 'Storage Account Contributor' at the storage account
scope
B. Remove the Reader role at subscription scope and assign 'Reader and Data Access' at the storage account
scope [CORRECT]
C. Keep the Reader role at subscription scope and add 'Storage Account Contributor' at the storage account
D. Assign 'Storage Blob Data Reader' at the resource group scope
Correct Answer: B
Rationale: Least-privilege means scoping permissions as narrowly as possible. The developer needs only read access at
the storage account level. The 'Reader and Data Access' role provides read access to the storage account object AND read
access to data via Microsoft.Storage/storageAccounts/listKeys/action, which is exactly what a developer needing read
access would need. 'Storage Account Contributor' (A) gives management plane write — too much. Choice C leaves the
over-broad subscription Reader role in place. 'Storage Blob Data Reader' at the resource group scope (D) gives only blob
(container) data plane read; it would not let the user inspect the storage account management properties.

Q7: Your company has the following hierarchy: Root Management Group (Tenant Root Group) → 'Corp' →
'Prod' and 'Dev' → individual subscriptions. You need to apply a policy that ONLY affects 'Prod' subscriptions and
their descendants. Where should you assign the policy?
A. Tenant Root Group
B. 'Corp' management group
C. 'Prod' management group [CORRECT]
D. Each individual subscription under 'Prod'
Correct Answer: C
Rationale: Azure Policy is inherited downward. Assigning at the 'Prod' management group will apply to 'Prod' and all its
child subscriptions/resources — exactly what is needed. Assigning at the Tenant Root (A) or 'Corp' (B) would also affect
'Dev'. Assigning per subscription (D) works but is operationally inefficient and error-prone; management group
assignment is preferred for organizational governance.

Q8: An administrator accidentally deleted a production resource group. The deletion occurred 5 days ago. The
resource group was NOT protected by a resource lock. Which statement is TRUE?
A. The resource group can be restored from Azure Backup if Recovery Services Vault was configured in the same
region
B. Soft delete for Azure Resource Manager allows recovery of the deleted resource group within the retention
window (default 14 days) using the subscription's 'Restore' operation [CORRECT]
C. The resource group cannot be recovered; only individual resources within have soft delete
D. Restoration requires opening a Microsoft support ticket within 7 days
Correct Answer: B
Rationale: Azure Resource Manager (ARM) soft delete for resource groups was rolled out in 2024 and is enabled by
default at the subscription level. Deleted resource groups can be recovered via the 'Validate' and 'Restore' operations
within a configurable retention window (default 14 days, extendable). Resource-level soft delete (e.g., for storage
accounts) is separate and different from resource group recovery. Azure Backup (A) protects data, not resource group
objects. Opening a support ticket (D) is no longer required for the standard recovery flow.




Page 3

, AZ-104 Renewal Exam — Question and Answer Updated 2026/2027 Microsoft Azure Administrator Renewal | High-Confidence Verified



Q9: You have an existing custom Azure role defined in JSON. You need to update the role definition to add a new
permission. After updating the JSON, which Azure CLI command applies the change?
A. az role definition create --role-definition updated-role.json
B. az role definition update --role-definition updated-role.json [CORRECT]
C. az role assignment create --role updated-role.json
D. az role definition apply --role-definition updated-role.json
Correct Answer: B
Rationale: Existing custom Azure roles are updated with 'az role definition update --role-definition <file>.json'. Use 'az
role definition create' only for new role definitions; create will fail on an existing role name/ID. Role assignment (C) is
unrelated to role definition modification. 'az role definition apply' (D) is not a valid CLI verb for this operation.

Q10: You need to tag all resources in a subscription with their cost center and environment automatically when
created, and remediate existing resources. Which combination of Azure services should you use?
A. Azure Policy with 'Modify' effect and a remediation task; policy assigned at the subscription scope
[CORRECT]
B. Azure Advisor cost recommendations applied manually
C. Azure Resource Manager template with tag values hardcoded in each template
D. Azure CLI script run nightly from Azure Automation to add missing tags
Correct Answer: A
Rationale: Azure Policy with the 'Modify' effect can append or replace tags on both new resources (deny/audit if
non-compliant) and existing resources (via a remediation task). The 'Modify' effect can also be used to enforce tag
inheritance from the resource group. Advisor (B) is advisory only. ARM templates (C) only affect resources deployed
through that template, not pre-existing resources. A nightly CLI script (D) is brittle, requires a service principal with
contributor rights, and is not policy-enforced.

Q11: A user has both 'Reader' (assigned at subscription scope) and 'Contributor' (assigned at resource group
scope) on the same resource. When the user attempts to write to a resource in that resource group, what is the
effective permission?
A. Reader only; the most restrictive role always wins
B. Contributor; Azure RBAC is additive — the union of permissions across all applicable assignments is the
effective permission [CORRECT]
C. The user cannot write because Reader denies writes
D. The user must explicitly select the Contributor role in the portal before performing writes
Correct Answer: B
Rationale: Azure RBAC is an additive allow-only model; the effective permission is the union of all assigned roles across
all scopes that apply to the resource. There are no 'deny' permissions in built-in roles. Reader provides read; Contributor
provides read/write on the resource group. The user can write to resources in that resource group because Contributor
grants Write. Choice A is wrong — RBAC is not 'most restrictive wins'. Choice C is wrong — Reader does not 'deny'; it
just doesn't grant write. Choice D is wrong — no role selection is needed; the user authenticates and gets the union of all
assigned roles.




Page 4

Document information

Uploaded on
September 29, 2026
Number of pages
38
Written in
2026/2027
Type
Exam (elaborations)
Contains
Questions & answers
$20.50

Wrong document? Swap it for free Within 14 days of purchase and before downloading, you can choose a different document. You can simply spend the amount again.
Written by students who passed
Immediately available after payment
Read online or as PDF

Seller avatar
Reputation scores are based on the amount of documents a seller has sold for a fee and the reviews they have received for those documents. There are three levels: Bronze, Silver and Gold. The better the reputation, the more your can rely on the quality of the sellers work.
NURSEEXAMITY
3.4
(110)
Sold
597
Followers
275
Items
6880
Last sold
19 hours ago




Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Working on your references?

Create accurate citations in APA, MLA and Harvard with our free citation generator.

Working on your references?

Frequently asked questions