• Wrong document? Swap it for free
  • Written by students who passed
  • Immediately available after payment
  • Read online or as PDF
Sell
Where do you study
Your language
Document preview thumbnail
Preview 4 out of 59 pages
Exam (elaborations)

AZ-104 RENEWAL ACTUAL EXAM 2026/2027 | Verified Questions & Answers | Free Assessment Prep | Pass Guaranteed - A+ Graded

Document preview thumbnail
Preview 4 out of 59 pages

Pass the AZ-104 Microsoft Azure Administrator renewal assessment with verified questions and answers for 2026/2027. This A+ Graded resource covers all five core renewal domains: Manage Azure identities and governance (20-25%), Implement and manage storage (15-20%), Deploy and manage Azure compute resources (20-25%), Implement and manage virtual networking (15-20%), and Monitor and maintain Azure resources (10-15%) . Each question includes detailed rationales to strengthen understanding of key renewal concepts like Microsoft Entra ID governance, RBAC for AI agents, Azure Policy enforcement, Bicep deployment, container administration, and Zero Trust architecture . The renewal assessment is free, open-book, and unproctored, available only within 6 months before expiration, with unlimited retakes . With our Pass Guarantee, you have the definitive tool to renew on your first attempt. Download your complete AZ-104 renewal exam guide instantly!

Content preview

AZ-104 Renewal Exam Questions & Answers
well verified answers - 2026/2027
Microsoft Azure Administrator Associate (AZ-104) - Certification Renewal Assessment - 120 questions with
verified answers and detailed rationales




Section 1: Identity and Governance

Q1: Your company uses Microsoft Entra ID. Several partner organizations need to access your
line-of-business applications by using their own corporate credentials. You must minimize
administrative overhead and avoid creating new passwords for these users. What should you do?
A. Invite the partner users as guest users by using Microsoft Entra B2B collaboration. [CORRECT]
B. Create new member user accounts in Microsoft Entra ID and assign temporary passwords to
each partner user.
C. Create computer accounts in the on-premises Active Directory domain and synchronize them to
Microsoft Entra ID by using Microsoft Entra Connect.
D. Enable self-service password reset (SSPR) for external users and send them enrollment
invitations.
Correct Answer: A
Rationale: Microsoft Entra B2B collaboration is designed exactly for this scenario: external partners
authenticate with their own work, school, or social identities, so you never manage their credentials or
lifecycles. Member accounts would require you to provision and maintain passwords, violating the
minimize-overhead requirement. Synchronizing on-premises accounts is irrelevant because the partners
have no accounts in your directory. SSPR applies to your own users and cannot be enabled for accounts
that do not exist in your tenant.

Q2: Your organization is rolling out self-service password reset (SSPR) in Microsoft Entra ID. The
security team requires that the help desk cannot pre-define secret answers on behalf of users. Which
SSPR authentication method should you avoid configuring?
A. Mobile app notification
B. Security questions [CORRECT]
C. Email message to the alternate email address
D. Mobile phone text message
Correct Answer: B
Rationale: Security questions are the only SSPR method that administrators define and pre-populate in
the tenant, and Microsoft documentation explicitly labels them as the least secure option because
answers may be guessable. Mobile app notification, email, and SMS are all enrolled and verified by the
end user during combined registration, so no administrator touches the user's secret data. For a security
team concerned about pre-defined answers, disabling security questions and relying on user-enrolled
factors is the documented best practice.




1

,AZ-104 Renewal Exam | Microsoft Azure Administrator | 2026/2027




Q3: You need to create a group in Microsoft Entra ID that supports a shared mailbox, a shared
calendar, and assignment of a Microsoft 365 license to its members. Which group type should you
create?
A. A security group with dynamic membership
B. A mail-enabled security group
C. A Microsoft 365 group [CORRECT]
D. A distribution group synced from on-premises Exchange
Correct Answer: C
Rationale: A Microsoft 365 group is the only group type that natively provides collaboration
workloads such as a shared mailbox, shared calendar, SharePoint site, Planner, and Teams, while also
supporting license assignment to members. A security group exists purely for access control to
resources and role assignment. A mail-enabled security group provides distribution and access control
but offers no associated collaboration services. A plain distribution list cannot hold licenses or provide
workloads at all.

Q4: You are creating a dynamic Microsoft Entra security group that must automatically contain all
users whose department attribute equals Sales and whose country attribute equals United States.
Which membership rule should you use?
A. user.department -match "Sales" -or user.country -match "US"
B. user.department -contains "Sales" -and user.country -contains "US"
C. user.department -eq "Sales" -or user.country -eq "United States"
D. user.department -eq "Sales" -and user.country -eq "United States" [CORRECT]
Correct Answer: D
Rationale: Dynamic membership rules use the property-value equality operator -eq for exact string
matches, and the -and operator requires both conditions to be true, which satisfies the requirement that
both attributes match exactly. The -match operator performs regular-expression matching and -or
would include users who satisfy only one condition, producing an over-broad group. The -contains
operator is not a valid rule operator for string attributes in dynamic group rules. Using -or or
approximate operators is a common exam trap because the rule looks superficially correct.




2

,AZ-104 Renewal Exam | Microsoft Azure Administrator | 2026/2027




Q5: Your company has a department named Support. You must delegate the ability to reset
passwords only for users in the Support department, without granting any permissions to other
departments. User Administrators currently have tenant-wide scope. What should you implement?
A. Create an administrative unit, add only the Support department users to it, and assign the
Password Administrator role to the support team members scoped to the administrative unit.
[CORRECT]
B. Assign the Password Administrator role to the support team members at the tenant root scope.
C. Create a security group containing the Support users and assign the Global Administrator role to
the group at the tenant root scope.
D. Configure self-service password reset for the Support users and instruct the support team to reset
passwords through the user portal.
Correct Answer: A
Rationale: Administrative units (AUs) provide role scoping in Microsoft Entra ID: assigning a role
such as Password Administrator over an AU restricts the assignee's privileges to the users inside that
AU, which is the least-privilege design. A tenant-wide Password Administrator assignment would let
the team reset passwords across every department. Global Administrator is excessive and violates least
privilege entirely. SSPR is a user self-service feature and does not create a delegated administrative
capability for the support team.

Q6: You review the following custom RBAC role definition in your Azure subscription:
"Actions": [ "Microsoft.Compute/virtualMachines/read",
"Microsoft.Compute/virtualMachines/start/action",
"Microsoft.Compute/virtualMachines/restart/action",
"Microsoft.Compute/virtualMachines/deallocate/action" ]
"NotActions": [ "Microsoft.Compute/virtualMachines/delete" ]
What can a user assigned this role do?
A. Create new virtual machines but not delete them.
B. Read, start, restart, and deallocate existing virtual machines, but not delete them. [CORRECT]
C. Read, start, restart, and delete existing virtual machines.
D. Read, create, and delete virtual machines but not restart them.
Correct Answer: B
Rationale: The Actions array explicitly grants read, start, restart, and deallocate operations, while
NotActions subtracts the delete operation from the effective permission set. Nothing in the definition
grants the create or write action, so option describing creation is wrong, and every option that includes
delete is wrong because NotActions removes it. When analyzing custom roles, always compute
effective permissions as Actions minus NotActions and check that create/write operations are actually
listed before assuming they exist.




3

, AZ-104 Renewal Exam | Microsoft Azure Administrator | 2026/2027




Q7: Your organization has three Azure subscriptions and a management group hierarchy with a root
management group named MG-Root. An external audit team must be able to view all resources
across all three subscriptions, and new subscriptions added in the future must be covered
automatically. You need to assign access by using the principle of least privilege. What should you
do?
A. Assign the Reader role to the audit team on each subscription individually.
B. Assign the Contributor role to the audit team at the MG-Root management group scope.
C. Assign the Reader role to the audit team at the MG-Root management group scope.
[CORRECT]
D. Assign the Global Reader role in Microsoft Entra ID to the audit team.
Correct Answer: C
Rationale: Role assignments at management group scope are inherited by every subscription and
resource underneath, and future subscriptions moved under MG-Root automatically inherit the
assignment, which satisfies the future-coverage requirement with a single assignment. Assigning
Reader on each subscription individually would need manual repetition for every new subscription.
Contributor grants write access, violating least privilege. Global Reader is a Microsoft Entra ID
directory role and does not provide read access to Azure ARM resources.

Q8: You need to ensure that users in your organization can only create resources in the West Europe
and North Europe regions. Users must be blocked at the moment they attempt the deployment, not
flagged afterwards. What should you implement?
A. A resource lock on each resource group
B. An RBAC role assignment that denies the Microsoft.Resources/deployments/write action
C. An Azure Monitor alert that notifies administrators when resources are created outside Europe
D. An Azure Policy definition using the built-in allowed-locations policy assigned at the
management group scope [CORRECT]
Correct Answer: D
Rationale: The built-in Allowed locations policy with a deny effect evaluates during resource creation
and blocks the deployment request in real time when the region is not on the allowed list, which
matches the requirement to block at deployment time. Resource locks protect existing resources from
deletion or modification but do not constrain region choice. RBAC has no native deny role assignment,
and deployment write permissions would block all deployments rather than filtering by region. Azure
Monitor alerts only observe and notify after the fact, which is exactly the reactive behavior the
requirement rules out.




4

Document information

Uploaded on
September 29, 2026
Number of pages
59
Written in
2026/2027
Type
Exam (elaborations)
Contains
Questions & answers
$19.50

Wrong document? Swap it for free Within 14 days of purchase and before downloading, you can choose a different document. You can simply spend the amount again.
Written by students who passed
Immediately available after payment
Read online or as PDF

Seller avatar
Reputation scores are based on the amount of documents a seller has sold for a fee and the reviews they have received for those documents. There are three levels: Bronze, Silver and Gold. The better the reputation, the more your can rely on the quality of the sellers work.
NURSEEXAMITY
3.4
(110)
Sold
597
Followers
275
Items
6880
Last sold
18 hours ago




Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Working on your references?

Create accurate citations in APA, MLA and Harvard with our free citation generator.

Working on your references?

Frequently asked questions