OBJECTIVE ASSESSMENT - EXAM
AZ 104 Microsoft Azure
Administrator Associate
Exam Renewal 2026/2027
Official Exam | Grade A+ Verified
A+ Verified 2026/2027 70%
Answers Edition Passing Score
AZ 104 Microsoft Azure Administrator Associate Exam Renewal 2026/2027 COVER PAGE - 1
, SECTIONS COVERED
Section 1: Manage Azure Identities and Governance (20%)
Section 2: Implement and Manage Storage (20%)
Section 3: Deploy and Manage Azure Compute Resources (20%)
Section 4: Configure and Manage Virtual Networking (20%)
Section 5: Monitor and Back Up Azure Resources (20%)
Section 1: Manage Azure Identities and Governance Weight: 20%
Q1
An Azure administrator needs to ensure that only users from a specific on-premises Active Directory group can sign in to Azure
AD and access Microsoft 365 resources. The organization already has Azure AD Connect configured with password hash
synchronization. Which solution should the administrator implement to enforce this restriction?
A. Disable password hash synchronization and switch exclusively to federation with AD FS
B. Assign the Global Administrator role only to members of that on-premises group
C. Configure an Azure AD access review that removes all other users after 30 days
D. Create a Conditional Access policy that requires the user to be a member of the synchronized group
Correct Answer: D
Rationale:
Conditional Access can evaluate group membership from synchronized on-premises groups and block or allow sign-in accordingly. Switching
to federation is unnecessary when password hash sync already works; role assignment and access reviews do not enforce real-time sign-in
restrictions.
Q2
A company requires that guest users invited to Azure AD receive a temporary access pass that expires after 24 hours and
forces a password change on first use. The administrator must configure this capability with minimal ongoing management.
Which feature should be enabled?
A. Self-service password reset only for external users with a 24-hour password lifetime
B. Azure AD B2B direct federation with a custom invitation lifetime of one day
C. Privileged Identity Management eligible assignments for all guest accounts
D. Temporary Access Pass authentication method in Azure AD combined with guest user settings
Correct Answer: D
Rationale:
Temporary Access Pass (TAP) provides time-limited, one-time credentials ideal for guest onboarding. SSPR does not issue temporary
passes, B2B federation controls identity providers rather than pass lifetime, and PIM is designed for privileged role activation.
AZ 104 Azure Administrator Associate Exam Renewal 2026/2027 Page 2
, Q3
An organization wants to prevent accidental deletion of critical resource groups that contain production virtual machines and
storage accounts. The administrator must apply a protection mechanism that still allows authorized users to delete the groups
when necessary. Which Azure feature meets this requirement?
A. Read-only locks on every individual resource inside the groups
B. Management group hierarchy with deny assignments that cannot be overridden
C. Resource locks of type CanNotDelete applied to the resource groups, removable by users with Owner or User Access
Administrator roles
D. Azure Policy definitions that deny the Microsoft.Resources/subscriptions/resourceGroups/delete action permanently
Correct Answer: C
Rationale:
CanNotDelete locks prevent accidental deletion while still permitting authorized role holders to remove the lock when intentional deletion is
required. Permanent deny policies and unbreakable deny assignments make legitimate deletion impossible; resource-level locks alone do not
protect the group itself.
Q4
A finance team needs monthly reports showing the cost of all Azure resources tagged with CostCenter=Finance across three
subscriptions. The administrator must produce these reports without granting the team Owner rights on the subscriptions.
Which approach is most appropriate?
A. Assign the Owner role on each subscription and instruct the team to filter the Cost Management blade manually
B. Export usage data daily to a storage account and require the team to build custom Power BI reports from raw CSV files
C. Enable Azure Advisor cost recommendations and share the portal link with the finance team
D. Create a management group containing the three subscriptions, apply the tags, and grant the team Reader plus Cost
Management Reader roles at the management group scope
Correct Answer: D
Rationale:
Management group scope with Cost Management Reader provides aggregated cost visibility without excessive permissions. Owner is
over-privileged, raw CSV exports increase operational burden, and Advisor recommendations do not produce detailed tagged cost reports.
Q5
An administrator is configuring Azure AD Privileged Identity Management for the User Administrator role. The requirement is
that activation must require approval from a specific group and that activations last no longer than four hours. Which PIM
setting achieves both goals?
A. Configure a role assignment that is permanent and does not require activation
B. Use Azure AD access reviews alone to review role membership every 90 days
C. Require approval from the designated group and set the maximum activation duration to four hours
D. Enable just-in-time access without approval and set a permanent eligible assignment
Correct Answer: C
Rationale:
PIM activation settings allow both approval workflows and custom maximum duration. Permanent assignments and access reviews do not
provide time-limited, approved activation of privileged roles.
AZ 104 Azure Administrator Associate Exam Renewal 2026/2027 Page 3