• Wrong document? Swap it for free
  • Written by students who passed
  • Immediately available after payment
  • Read online or as PDF
Sell
Where do you study
Your language
Document preview thumbnail
Preview 4 out of 47 pages
Exam (elaborations)

AZ-104 MICROSOFT AZURE ADMINISTRATOR ACTUAL EXAM 2026/2027 | Sample Questions & Answers | Verified | Pass Guaranteed - A+ Graded

Document preview thumbnail
Preview 4 out of 47 pages

Pass the AZ-104 Microsoft Azure Administrator exam with verified sample questions and answers. This A+ Graded resource is updated for 2026/2027 and covers all five core exam domains: Manage Azure identities and governance (20-25%), Implement and manage storage (15-20%), Deploy and manage Azure compute resources (20-25%), Implement and manage virtual networking (15-20%), and Monitor and maintain Azure resources (10-15%). Each question includes detailed rationales to strengthen understanding of key concepts like RBAC scopes, Azure Policy, storage redundancy (LRS/GRS/ZRS), ARM templates, VNet peering, and Azure Monitor alerts. With our Pass Guarantee, you have the definitive tool to pass on your first attempt. Download your complete AZ-104 exam guide instantly!

Content preview

AZ-104 Microsoft Azure Administrator Sample Exam | 2026/2027 150 Questions & Answers




AZ-104 MICROSOFT AZURE ADMINISTRATOR
Sample Questions & Answers
150 Sample Questions | 2026/2027 Updated Edition
Aligned with Microsoft Learn | Azure Best Practices | Current Exam Objectives



Total Questions 150 Sample Items

Sections 8 Domain Categories

Cognitive
30% Recall / 50% Application / 20% Analysis
Distribution

Question Style 75% Scenario-Based • 25% Direct Recall

Identities & Governance | Storage | Compute | Networking | Security &
Exam Blueprint
Monitoring | Backup & Cost | Automation | Troubleshooting




Section 1: Manage Azure Identities and Governance
Microsoft Entra ID, Users/Groups, RBAC, Subscriptions, & Azure Policy (Q1-Q24)

[Domain: Microsoft Entra ID - User Management]

Q1: You are an Azure administrator for Contoso Ltd. You need to create 500 new user accounts in Microsoft Entra
ID that represent temporary contractors. These accounts must automatically be disabled after 90 days without
manual intervention. Which approach minimizes administrative overhead and enforces the 90-day lifecycle?
A. Create each user individually in the Azure portal and set a calendar reminder to disable them after 90 days
B. Create a Microsoft Entra ID group named "Contractors" and add users; configure a dynamic group rule based on hire date
C. Use PowerShell with the Microsoft Graph module to bulk-create users with a "hireDate" attribute, then create a
dynamic group with an expiration rule [CORRECT]
D. Configure Microsoft Entra ID dynamic membership rules and assign a time-based access review that auto-disables the
user accounts
Correct Answer: C
Rationale: The most efficient approach combines bulk user creation via PowerShell/Microsoft Graph (setting the hireDate attribute)
with automation. While Entra ID Governance offers access reviews for group memberships, auto-disabling the underlying user account
after 90 days requires either Microsoft Entra ID Identity Protection risk policies, a Logic App triggered by the user lifecycle, or
Bicep/PowerShell automation. Option C reflects the realistic AZ-104 pattern: programmatically set hireDate, then use a scheduled
runbook or Lifecycle Workflow (Entra ID Governance) to disable accounts at hireDate+90. The other options either require manual
intervention (A, B) or confuse access review (which manages group membership expiration, not user account state) with account-disable
automation (D).

[Domain: Microsoft Entra ID - Guest Users]

Q2: A partner organization (fabrikam.com) needs to collaborate on an Azure subscription. You invite 25 guest
users from Fabrikam into your Contoso Entra ID tenant. The guests must be able to access only one specific
application and must reauthenticate every 30 days. Which two configurations meet these requirements?
A. Configure Conditional Access policy scoped to "Guest users" requiring MFA, plus a B2B collaboration default policy
limiting guest access




Aligned with Microsoft Learn | Azure Best Practices Page 1

,AZ-104 Microsoft Azure Administrator Sample Exam | 2026/2027 150 Questions & Answers




B. Configure the "External collaboration settings" to restrict guest permissions, plus create a Conditional Access
policy with a session control to enforce sign-in frequency of 30 days scoped to the application [CORRECT]
C. Add guests to a security group and assign the "User" role, plus enable Entra ID Password Protection
D. Configure Azure AD B2C with a custom policy and a Conditional Access policy requiring MFA at every sign-in
Correct Answer: B
Rationale: Microsoft Entra ID External Collaboration settings (under "External identities > External collaboration settings") allow you to
restrict guest permissions (e.g., limit who guests can invite, what they can access). For session control (reauthentication frequency),
Conditional Access policies with the "Sign-in frequency" session control enforce reauthentication at a defined interval (e.g., 30 days). The
policy can be scoped to specific cloud apps. Option A describes guest MFA but does not enforce the 30-day reauth. Option C assigns
roles at the wrong scope. Option D describes B2C, which is for consumer identities, not B2B collaboration.

[Domain: Microsoft Entra ID - Self-Service Password Reset]

Q3: You configure Self-Service Password Reset (SSPR) for all users in your Entra ID tenant. The authentication
methods are set to require 2 methods to reset and the available methods are: mobile phone (SMS), office phone, and
security questions. A user reports that she cannot register her methods because she does not have a mobile phone
and her office phone is shared. What is the best solution?
A. Reduce the "number of methods required to reset" from 2 to 1, allowing her to use only security questions
B. Enable the "Email" authentication method in SSPR so users can verify via a personal email address
[CORRECT]
C. Assign the user the "Authentication Administrator" role so she can self-register without verification
D. Disable SSPR for this user account via the per-user MFA settings
Correct Answer: B
Rationale: Enabling the "Email" authentication method (registered under "Authentication methods > Policies") allows users to receive a
verification code at a non-Microsoft personal email address. Email is one of the supported methods for SSPR registration and
verification. Reducing the methods required to reset (option A) lowers security for the entire tenant and is not recommended. Option C is
incorrect because Authentication Administrators manage other users' credentials but cannot bypass their own registration. Option D is
undesirable because it removes SSPR for that user entirely.

[Domain: Microsoft Entra ID - Groups]

Q4: You have a Microsoft 365 group named "Marketing" that contains 250 members. The group is used to grant
access to a SharePoint site, a Teams team, and an Azure Resource Group via RBAC. The membership changes
frequently. You want to automate membership so that anyone with the "Marketing" department attribute in their
user profile is automatically added. Which group type and configuration should you use?
A. Convert the existing Microsoft 365 group to a Security group, then enable dynamic membership rules based on
user.department eq "Marketing"
B. Create a new Security group with dynamic membership (user.department -eq "Marketing"), and reassign RBAC and
resource access to the new group
C. Keep the Microsoft 365 group and enable dynamic membership on it using the rule user.department -eq
"Marketing" [CORRECT]
D. Create a dynamic distribution group in Exchange Online and use it for Azure RBAC assignment
Correct Answer: C
Rationale: Microsoft 365 groups support dynamic membership. You can change the membership type from "Assigned" to "Dynamic
User" on an existing M365 group, then define a rule such as user.department -eq "Marketing". The group retains its integration with
SharePoint, Teams, and Azure RBAC because it keeps the same object ID. Option A is wrong because you cannot "convert" an M365
group to a Security group; they are different group types with different capabilities. Option B discards the existing group integration.
Option D is incorrect because distribution groups are Exchange-only and cannot be assigned Azure RBAC roles.

[Domain: RBAC - Built-in Roles]

Q5: You need to grant a junior administrator the ability to restart Azure VMs in a specific resource group named
"prod-rg" but not allow them to delete or create VMs. Which built-in RBAC role should you assign at the resource


Aligned with Microsoft Learn | Azure Best Practices Page 2

,AZ-104 Microsoft Azure Administrator Sample Exam | 2026/2027 150 Questions & Answers




group scope?
A. Virtual Machine Contributor at the resource group scope
B. Virtual Machine User Login Login at the resource group scope
C. Reader at the resource group scope, plus a custom role with Microsoft.Compute/virtualMachines/restart/action
permission [CORRECT]
D. Owner at the resource group scope
Correct Answer: C
Rationale: The built-in "Virtual Machine Contributor" role (option A) allows create, delete, modify, and restart - too broad for this
scenario. "Virtual Machine User Login" (option B) is for OS-level login, not for restarting Azure VMs. "Owner" (option D) grants full
access including role assignment, which violates least-privilege. The correct approach is to combine Reader (for visibility) with a custom
role that includes only Microsoft.Compute/virtualMachines/restart/action and Microsoft.Compute/virtualMachines/start/action. This
demonstrates the AZ-104 emphasis on least-privilege custom roles when no built-in role fits.

[Domain: RBAC - Custom Roles]

Q6: You create a custom RBAC role in JSON format and attempt to deploy it via Azure CLI: az role definition
create --role-definition custom-role.json. The command fails with the error "The role definition is invalid. The role
definition must specify the scope for which it is usable." Which property is missing from your JSON file?
A. "Name": "Custom Role"
B. "AssignableScopes": ["/subscriptions/"] [CORRECT]
C. "Permissions": [{"Actions": ["*"]}]
D. "RoleName": "Custom Role"
Correct Answer: B
Rationale: Custom RBAC role definitions in JSON require the "AssignableScopes" property, which is an array specifying the scopes
where the role can be assigned (subscription, management group, or resource group). Without this property, the role definition is rejected
by Azure Resource Manager. The role also requires "Name" (a GUID), "Description", and "Actions"/"DataActions" arrays. Option C
describes the wrong property name ("Permissions" should be "Permissions" array, but each item is an object with "Actions"). Option D
("RoleName") is not a valid top-level property in the role definition JSON; the friendly name is in "roleName".

[Domain: RBAC - Scope Hierarchy]

Q7: A user is assigned the "Reader" role at the management group scope (root management group, "/"). The same
user is assigned the "Contributor" role at a subscription scope within that management group. What is the user's
effective permission on a resource group inside the subscription?
A. Reader only (management group scope overrides subscription scope)
B. Contributor only (lower scope overrides higher scope)
C. Contributor (RBAC is additive; the more permissive assignment wins) [CORRECT]
D. Reader and Contributor (both roles are granted simultaneously)
Correct Answer: C
Rationale: Azure RBAC is an additive model: assignments at higher scopes (management group, root) are inherited by lower scopes
(subscription, resource group, resource). When multiple roles are assigned at different scopes, the effective permission is the union of all
permissions. Since Contributor (full access except RBAC) is more permissive than Reader (read-only), the user effectively has
Contributor on the resource group. The exception is the "deny assignment" mechanism (e.g., used by Azure Blueprints and Managed
Apps) which overrides allow assignments. Option A is wrong because management group scope does not override subscription scope.
Option B is incorrect because both scopes contribute additively. Option D describes a permission union, but a user has one effective
permission set, not simultaneous separate permissions.

[Domain: Subscriptions - Management Groups]

Q8: Your organization has 25 Azure subscriptions. You want to apply a single Azure Policy across all current and
future subscriptions. Which approach is the most efficient and scalable?
A. Apply the policy assignment to each subscription individually



Aligned with Microsoft Learn | Azure Best Practices Page 3

, AZ-104 Microsoft Azure Administrator Sample Exam | 2026/2027 150 Questions & Answers




B. Create a management group hierarchy, place all subscriptions under one root management group, and assign the
policy at the management group scope [CORRECT]
C. Use Azure Blueprints to apply the policy as part of a blueprint assignment at each subscription
D. Use an Azure Policy Set Definition and assign it programmatically via Azure CLI to each subscription
Correct Answer: B
Rationale: Management groups allow you to manage multiple subscriptions as a single administrative unit. Any policy assignment, RBAC
role assignment, or Azure Policy initiative applied at the management group scope is inherited by all member subscriptions. This scales
automatically to future subscriptions added to the group. Option A does not scale and risks drift. Option C (Blueprints) is more complex
than necessary for a single policy and adds versioning overhead. Option D still requires per-subscription assignment and lacks centralized
governance.

[Domain: Azure Policy - Definitions]

Q9: You apply the built-in Azure Policy "Require a tag and its value on resources" at a subscription scope with
parameters: tagName="environment", tagValue="production". What happens when a user creates a new storage
account in the subscription without specifying the environment tag?
A. The storage account is created without the tag and a compliance warning appears in the portal 24 hours later
B. The storage account creation is blocked by Azure Resource Manager and the user receives a 403 Forbidden error
C. The storage account is created without the tag, the policy records it as non-compliant, and a remediation task can
auto-add the tag [CORRECT]
D. Azure Policy automatically adds the environment=production tag to the resource at creation time
Correct Answer: C
Rationale: The "Require a tag and its value on resources" policy uses the "audit" effect by default, which evaluates resources for
compliance but does not block creation. Non-compliant resources are flagged in the compliance dashboard. To automatically add the
missing tag, you must create a remediation task that uses a managed identity with contributor permissions on the resource. To block
creation, you would need a policy with the "deny" effect. Option A is wrong because compliance evaluation is near-real-time (within
~5-15 minutes), not 24 hours. Option B (403) is the behavior of a deny-effect policy, not the default audit effect. Option D is incorrect
because Azure Policy does not automatically add tags without a remediation task.

[Domain: Azure Policy - Effects]

Q10: You need to enforce that all storage accounts created in your subscription must allow only HTTPS traffic
(require secure transfer). Which Azure Policy effect should you use to PREVENT the creation of non-compliant
storage accounts?
A. Audit
B. Deny [CORRECT]
C. Append
D. Disabled
Correct Answer: B
Rationale: The "Deny" effect prevents non-compliant resources from being created or updated. Azure Resource Manager rejects the
request before the resource is committed. The "Audit" effect allows creation but flags it as non-compliant. The "Append" effect
(deprecated for most uses) adds fields to a resource during creation/update but does not block creation. "Disabled" turns off the policy
evaluation. For hard enforcement (preventive control), use Deny. For detective control (monitoring), use Audit. AZ-104 emphasizes
understanding policy effects: Audit, Deny, AuditIfNotExists, DeployIfNotExists, Disabled, Modify, Append.

[Domain: Azure Policy - Initiatives]

Q11: You need to apply a set of 12 Azure Policy definitions to a management group. Some definitions have
parameters that vary per subscription. What is the most efficient way to manage these policies?
A. Assign each policy definition individually at the management group scope
B. Create a policy initiative (policy set definition) that includes all 12 policies, define parameters at the initiative
level, and assign the initiative at the management group scope [CORRECT]
C. Create an Azure Blueprint that includes all 12 policies as artifacts and assign the blueprint to each subscription


Aligned with Microsoft Learn | Azure Best Practices Page 4

Document information

Uploaded on
September 29, 2026
Number of pages
47
Written in
2026/2027
Type
Exam (elaborations)
Contains
Questions & answers
$18.50

Wrong document? Swap it for free Within 14 days of purchase and before downloading, you can choose a different document. You can simply spend the amount again.
Written by students who passed
Immediately available after payment
Read online or as PDF

Seller avatar
Reputation scores are based on the amount of documents a seller has sold for a fee and the reviews they have received for those documents. There are three levels: Bronze, Silver and Gold. The better the reputation, the more your can rely on the quality of the sellers work.
NURSEEXAMITY
3.4
(110)
Sold
597
Followers
275
Items
6880
Last sold
18 hours ago




Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Working on your references?

Create accurate citations in APA, MLA and Harvard with our free citation generator.

Working on your references?

Frequently asked questions