Azure Administrator (AZ-
104) exam with verified
solutions
The billing unit of Azure Services that aggregates all the costs of the
x x x x x x x x x x x x x
underlying resources. - correct answer ✔Azure Subscriptions
x x x x x x
An identity in Azure Active Directory (AAD) or a directory that is trusted by
x x x x x x x x x x x x x x
AAD, such as a work or school organization. - correct answer ✔Azure
x x x x x x x x x x x x
Accounts
Also known as the account owner, this person is responsible for paying the
x x x x x x x x x x x x x
subscription bill to Microsoft when it is due. Normally, this user has financial
x x x x x x x x x x x x x
responsibilities in your company such as CFO, Accounts Payable Lead etc. -
x x x x x x x x x x x x
correct answer ✔Account Administrator
x x x
Also known as the Service Owner. This user manages the services that run in
x x x x x x x x x x x x x x
Windows Azure. They will have access to and uses the Window Azure
x x x x x x x x x x x x
Developer Portal or Service Management API to orchestrate the applications
x x x x x x x x x x
and data running in Azure. Normally, the user is a developer, system
x x x x x x x x x x x x
administrator, or other IT person responsible for IT services in your company.
x x x x x x x x x x x x
- correct answer ✔Service Administrator
x x x x
When an enterprise becomes to large for a single Service Administrator, the
x x x x x x x x x x x x
Service Administrator can create this role for other IT administrators to help
x x x x x x x x x x x x
,them out. They will have complete access to the subscription services. They
x x x x x x x x x x x x
can even add or delete other users in the same role. However, they cannot
x x x x x x x x x x x x x x
remove the Service Owner nor do they have access to payment/billing
x x x x x x x x x x x
information. - correct answer ✔Co-Administrators x x x x
The Microsoft recommended way to manage the permissions of your
x x x x x x x x x x
resources. However this will not work with Azure's classic deployment model.
x x x x x x x x x x
x- correct answer ✔Role-Based Access Control
x x x x x
Global Administrator - correct answer ✔Users who are assigned this role can
x x x x x x x x x x x x
read and modify every administrative setting in your Azure AD organization.
x x x x x x x x x x x
By default this role is given to the user that signed up for the Azure
x x x x x x x x x x x x x x x
subscription. It is one of the two roles that has an ability to delegate
x x x x x x x x x x x x x x
administrator roles. To reduce the risk to your business, it is recommended
x x x x x x x x x x x x
by Microsoft that you assign this role to the fewest possible people in your
x x x x x x x x x x x x x x
organization.
Application Developer - correct answer ✔Users in this role can create
x x x x x x x x x x x
application registrations when the "Users can register applications" setting is
x x x x x x x x x x
set to No. This role also grants permission to consent on one's own behalf
x x x x x x x x x x x x x x
when the "Users can consent to apps accessing company data on their
x x x x x x x x x x x x
behalf" setting is set to No. Users assigned to this role are added as owners
x x x x x x x x x x x x x x x
when creating new application registrations or enterprise applications.
x x x x x x x
Application Administrator - correct answer ✔This role grants the ability to
x x x x x x x x x x x
manage application credentials. Users assigned this role can add credentials
x x x x x x x x x x
to an application, and use those credentials to impersonate the application's
x x x x x x x x x x x
identity.
, Authentication Administrator - correct answer ✔Users with this role can set x x x x x x x x x x x
or reset non-password credentials and can update passwords for all users.
x x x x x x x x x x x
Authentication Administrators can require users to re-register against existing x x x x x x x x x
non-password credential x
Azure gives you the ability to see the number of resources you've deployed
x x x x x x x x x x x x x
into your subscription and what your limits are. This ability makes it easier
x x x x x x x x x x x x x
for you to track current usage and plan for new deployments in the near
x x x x x x x x x x x x x x
future. - correct answer ✔Azure Resource Limits
x x x x x x
A good way to keep track of your resources is through tagging them. Each
x x x x x x x x x x x x x x
"Tag" consists of a Name and a Key Value Pair, such as
x x x x x x x x x x x x
"Environment" : "Production" where you could tag all your resources that are x x x x x x x x x x x
xin production. Tags applied to the resource group are not inherited by the
x x x x x x x x x x x x x
resources in that resource group. - correct answer ✔Tagging Resources
x x x x x x x x x
A service used to create, assign and manage different policies. These policies
x x x x x x x x x x x x
enforce different rules over your resources so they stay compliant with your
x x x x x x x x x x x x
corporate standards and service level agreements, The service does this by
x x x x x x x x x x x
running evaluations against your resources and scanning for those that are
x x x x x x x x x x x
not in compliance with your policies. - correct answer ✔Azure Policy
x x x x x x x x x x
A policy definition that has been assigned to take place within a specific
x x x x x x x x x x x x x
scope. This scope could range from a management group to a resource
x x x x x x x x x x x x
group. The term scope refers to all the resource groups, subscriptions, or
x x x x x x x x x x x x
management groups that the policy definition is assigned to. Policy x x x x x x x x x x
assignments are inherited by all child resources. This design means that a
x x x x x x x x x x x x
policy applied to a resource group is also applied to resources in that
x x x x x x x x x x x x x
resource group. However, you can exclude a sub-scope from the policy
x x x x x x x x x x x
assignment. - correct answer ✔Policy Assignment x x x x x
104) exam with verified
solutions
The billing unit of Azure Services that aggregates all the costs of the
x x x x x x x x x x x x x
underlying resources. - correct answer ✔Azure Subscriptions
x x x x x x
An identity in Azure Active Directory (AAD) or a directory that is trusted by
x x x x x x x x x x x x x x
AAD, such as a work or school organization. - correct answer ✔Azure
x x x x x x x x x x x x
Accounts
Also known as the account owner, this person is responsible for paying the
x x x x x x x x x x x x x
subscription bill to Microsoft when it is due. Normally, this user has financial
x x x x x x x x x x x x x
responsibilities in your company such as CFO, Accounts Payable Lead etc. -
x x x x x x x x x x x x
correct answer ✔Account Administrator
x x x
Also known as the Service Owner. This user manages the services that run in
x x x x x x x x x x x x x x
Windows Azure. They will have access to and uses the Window Azure
x x x x x x x x x x x x
Developer Portal or Service Management API to orchestrate the applications
x x x x x x x x x x
and data running in Azure. Normally, the user is a developer, system
x x x x x x x x x x x x
administrator, or other IT person responsible for IT services in your company.
x x x x x x x x x x x x
- correct answer ✔Service Administrator
x x x x
When an enterprise becomes to large for a single Service Administrator, the
x x x x x x x x x x x x
Service Administrator can create this role for other IT administrators to help
x x x x x x x x x x x x
,them out. They will have complete access to the subscription services. They
x x x x x x x x x x x x
can even add or delete other users in the same role. However, they cannot
x x x x x x x x x x x x x x
remove the Service Owner nor do they have access to payment/billing
x x x x x x x x x x x
information. - correct answer ✔Co-Administrators x x x x
The Microsoft recommended way to manage the permissions of your
x x x x x x x x x x
resources. However this will not work with Azure's classic deployment model.
x x x x x x x x x x
x- correct answer ✔Role-Based Access Control
x x x x x
Global Administrator - correct answer ✔Users who are assigned this role can
x x x x x x x x x x x x
read and modify every administrative setting in your Azure AD organization.
x x x x x x x x x x x
By default this role is given to the user that signed up for the Azure
x x x x x x x x x x x x x x x
subscription. It is one of the two roles that has an ability to delegate
x x x x x x x x x x x x x x
administrator roles. To reduce the risk to your business, it is recommended
x x x x x x x x x x x x
by Microsoft that you assign this role to the fewest possible people in your
x x x x x x x x x x x x x x
organization.
Application Developer - correct answer ✔Users in this role can create
x x x x x x x x x x x
application registrations when the "Users can register applications" setting is
x x x x x x x x x x
set to No. This role also grants permission to consent on one's own behalf
x x x x x x x x x x x x x x
when the "Users can consent to apps accessing company data on their
x x x x x x x x x x x x
behalf" setting is set to No. Users assigned to this role are added as owners
x x x x x x x x x x x x x x x
when creating new application registrations or enterprise applications.
x x x x x x x
Application Administrator - correct answer ✔This role grants the ability to
x x x x x x x x x x x
manage application credentials. Users assigned this role can add credentials
x x x x x x x x x x
to an application, and use those credentials to impersonate the application's
x x x x x x x x x x x
identity.
, Authentication Administrator - correct answer ✔Users with this role can set x x x x x x x x x x x
or reset non-password credentials and can update passwords for all users.
x x x x x x x x x x x
Authentication Administrators can require users to re-register against existing x x x x x x x x x
non-password credential x
Azure gives you the ability to see the number of resources you've deployed
x x x x x x x x x x x x x
into your subscription and what your limits are. This ability makes it easier
x x x x x x x x x x x x x
for you to track current usage and plan for new deployments in the near
x x x x x x x x x x x x x x
future. - correct answer ✔Azure Resource Limits
x x x x x x
A good way to keep track of your resources is through tagging them. Each
x x x x x x x x x x x x x x
"Tag" consists of a Name and a Key Value Pair, such as
x x x x x x x x x x x x
"Environment" : "Production" where you could tag all your resources that are x x x x x x x x x x x
xin production. Tags applied to the resource group are not inherited by the
x x x x x x x x x x x x x
resources in that resource group. - correct answer ✔Tagging Resources
x x x x x x x x x
A service used to create, assign and manage different policies. These policies
x x x x x x x x x x x x
enforce different rules over your resources so they stay compliant with your
x x x x x x x x x x x x
corporate standards and service level agreements, The service does this by
x x x x x x x x x x x
running evaluations against your resources and scanning for those that are
x x x x x x x x x x x
not in compliance with your policies. - correct answer ✔Azure Policy
x x x x x x x x x x
A policy definition that has been assigned to take place within a specific
x x x x x x x x x x x x x
scope. This scope could range from a management group to a resource
x x x x x x x x x x x x
group. The term scope refers to all the resource groups, subscriptions, or
x x x x x x x x x x x x
management groups that the policy definition is assigned to. Policy x x x x x x x x x x
assignments are inherited by all child resources. This design means that a
x x x x x x x x x x x x
policy applied to a resource group is also applied to resources in that
x x x x x x x x x x x x x
resource group. However, you can exclude a sub-scope from the policy
x x x x x x x x x x x
assignment. - correct answer ✔Policy Assignment x x x x x