Microsoft Azure Administrator (AZ-104) actual Exam 2026 questions
and well detailed answers
Question 1
You have an Azure Active Directory (Azure AD), now named Microsoft Entra ID,
tenant that syncs with an on-premises Active Directory domain. You need to
ensure that user passwords meet specific complexity requirements and block
common weak passwords. What should you implement?
• A. Azure AD Identity Protection
• B. Azure AD Password Protection
• C. Conditional Access policies
• D. Multi-Factor Authentication (MFA)
• Correct Answer: B
• Explanation: Microsoft Entra password protection applies global and
custom banned password lists to block weak passwords.
Question 2
Your company has multiple Azure subscriptions. You need to ensure that all
newly created resource groups are automatically tagged with a Department tag.
Which Azure feature should you use?
• A. Azure Policy
• B. Azure Role-Based Access Control (RBAC)
• C. Management Groups
• D. Azure Blueprints
• Correct Answer: A
• Explanation: Azure Policy allows you to audit and enforce resource
properties, including automatically adding or modifying tags upon creation
(modify effect).
Question 3
,Microsoft Azure Administrator (AZ-104) actual Exam 2026 questions
and well detailed answers
You need to assign a user the permission to restart virtual machines in a specific
resource group without giving them permissions to delete the resource group.
What should you do?
• A. Assign the Contributor role at the subscription level.
• B. Assign the Virtual Machine Contributor role at the resource group level.
• C. Assign the Owner role at the resource group level.
• D. Create a custom role with Microsoft.Compute/virtualMachines/write
only.
• Correct Answer: B
• Explanation: The Virtual Machine Contributor role allows you to manage
virtual machines, including restarting them, within the specified scope
(resource group) without granting administrative control over the entire
subscription or resource group deletion rights.
Question 4
An administrator needs to review sign-in logs for users who failed to log in due
to risky behavior. Which feature provides this capability?
• A. Azure Monitor Activity Logs
• B. Microsoft Entra ID Risk Detections and Sign-in logs
• C. Azure Cost Management
• D. Azure Advisor
• Correct Answer: B
• Explanation: Microsoft Entra ID provides risk detections and
interactive/non-interactive sign-in logs specifically for tracking
authentication attempts and security risks.
Question 5
,Microsoft Azure Administrator (AZ-104) actual Exam 2026 questions
and well detailed answers
You need to configure a management group hierarchy. What is the maximum
depth of the management group tree that you can create?
• A. 3
• B. 6
• C. 8
• D. 10
• Correct Answer: B
• Explanation: A management group tree can support up to 6 levels of depth
(excluding the root management group and the subscription level).
Question 6
Which Microsoft Entra ID edition is required to implement dynamic user groups
based on user attributes such as department?
• A. Free
• B. Microsoft Entra ID P1 or P2
• C. Office 365 Apps plan
• D. Basic
• Correct Answer: B
• Explanation: Dynamic groups require Microsoft Entra ID P1 or P2 licensing.
Question 7
You need to ensure that administrative access to Azure resources requires
approval and has a defined time limit. What should you implement?
• A. Azure AD Privileged Identity Management (PIM)
• B. Conditional Access Named Locations
• C. Azure Bastion
, Microsoft Azure Administrator (AZ-104) actual Exam 2026 questions
and well detailed answers
• D. Azure Security Center
• Correct Answer: A
• Explanation: PIM provides time-based and approval-based role activation
to mitigate risks of standing administrative access.
Question 8
An Azure subscription contains 50 resource groups. You need to apply a set of
governance rules to all resource groups within a specific subscription. Where
should you assign the Azure Policy?
• A. Management Group
• B. Subscription level
• C. Resource Group level
• D. Tenant root group
• Correct Answer: B
• Explanation: Assigning a policy at the subscription level applies it to all
resource groups and resources contained within that subscription.
Question 9
You need to allow external users from a partner organization to collaborate on
documents and access specific Azure apps without creating full member
accounts. What should you use?
• A. Microsoft Entra B2B collaboration
• B. Microsoft Entra B2C directory
• C. Active Directory Federation Services (AD FS)
• D. Managed Identities
• Correct Answer: A
and well detailed answers
Question 1
You have an Azure Active Directory (Azure AD), now named Microsoft Entra ID,
tenant that syncs with an on-premises Active Directory domain. You need to
ensure that user passwords meet specific complexity requirements and block
common weak passwords. What should you implement?
• A. Azure AD Identity Protection
• B. Azure AD Password Protection
• C. Conditional Access policies
• D. Multi-Factor Authentication (MFA)
• Correct Answer: B
• Explanation: Microsoft Entra password protection applies global and
custom banned password lists to block weak passwords.
Question 2
Your company has multiple Azure subscriptions. You need to ensure that all
newly created resource groups are automatically tagged with a Department tag.
Which Azure feature should you use?
• A. Azure Policy
• B. Azure Role-Based Access Control (RBAC)
• C. Management Groups
• D. Azure Blueprints
• Correct Answer: A
• Explanation: Azure Policy allows you to audit and enforce resource
properties, including automatically adding or modifying tags upon creation
(modify effect).
Question 3
,Microsoft Azure Administrator (AZ-104) actual Exam 2026 questions
and well detailed answers
You need to assign a user the permission to restart virtual machines in a specific
resource group without giving them permissions to delete the resource group.
What should you do?
• A. Assign the Contributor role at the subscription level.
• B. Assign the Virtual Machine Contributor role at the resource group level.
• C. Assign the Owner role at the resource group level.
• D. Create a custom role with Microsoft.Compute/virtualMachines/write
only.
• Correct Answer: B
• Explanation: The Virtual Machine Contributor role allows you to manage
virtual machines, including restarting them, within the specified scope
(resource group) without granting administrative control over the entire
subscription or resource group deletion rights.
Question 4
An administrator needs to review sign-in logs for users who failed to log in due
to risky behavior. Which feature provides this capability?
• A. Azure Monitor Activity Logs
• B. Microsoft Entra ID Risk Detections and Sign-in logs
• C. Azure Cost Management
• D. Azure Advisor
• Correct Answer: B
• Explanation: Microsoft Entra ID provides risk detections and
interactive/non-interactive sign-in logs specifically for tracking
authentication attempts and security risks.
Question 5
,Microsoft Azure Administrator (AZ-104) actual Exam 2026 questions
and well detailed answers
You need to configure a management group hierarchy. What is the maximum
depth of the management group tree that you can create?
• A. 3
• B. 6
• C. 8
• D. 10
• Correct Answer: B
• Explanation: A management group tree can support up to 6 levels of depth
(excluding the root management group and the subscription level).
Question 6
Which Microsoft Entra ID edition is required to implement dynamic user groups
based on user attributes such as department?
• A. Free
• B. Microsoft Entra ID P1 or P2
• C. Office 365 Apps plan
• D. Basic
• Correct Answer: B
• Explanation: Dynamic groups require Microsoft Entra ID P1 or P2 licensing.
Question 7
You need to ensure that administrative access to Azure resources requires
approval and has a defined time limit. What should you implement?
• A. Azure AD Privileged Identity Management (PIM)
• B. Conditional Access Named Locations
• C. Azure Bastion
, Microsoft Azure Administrator (AZ-104) actual Exam 2026 questions
and well detailed answers
• D. Azure Security Center
• Correct Answer: A
• Explanation: PIM provides time-based and approval-based role activation
to mitigate risks of standing administrative access.
Question 8
An Azure subscription contains 50 resource groups. You need to apply a set of
governance rules to all resource groups within a specific subscription. Where
should you assign the Azure Policy?
• A. Management Group
• B. Subscription level
• C. Resource Group level
• D. Tenant root group
• Correct Answer: B
• Explanation: Assigning a policy at the subscription level applies it to all
resource groups and resources contained within that subscription.
Question 9
You need to allow external users from a partner organization to collaborate on
documents and access specific Azure apps without creating full member
accounts. What should you use?
• A. Microsoft Entra B2B collaboration
• B. Microsoft Entra B2C directory
• C. Active Directory Federation Services (AD FS)
• D. Managed Identities
• Correct Answer: A