AZ 104 RENEWAL EXAM QUESTION AND ANSWER UPDATED
2026/2027
110 Questions with High-Confidence Verified Rationales
Microsoft Azure Administrator (AZ-104) · Renewal Assessment · 2026/2027 Updates
Aligned with Microsoft Learn & Current Azure Service Updates
Total Questions 110 (EXACT) Cognitive Distribution 30% Recall | 50% Application | 20% Analysis
Sections 7 Azure Domain Areas Question Style 75% Scenario-based | 25% Direct Recall
Format MCQ, 4 options (A-D) Rationale Depth Azure Technical Reasoning + Best Practices
Exam Type Renewal Assessment Passing Standard Microsoft Azure Administrator Competency
Section 1: Identity and Governance Updates
Microsoft Entra ID, RBAC, Azure Policy, & Management Groups (Q1-16)
Q1: Your company recently renamed Azure Active Directory to Microsoft Entra ID. As the Azure administrator,
you need to grant a junior admin permissions to manage user accounts and group memberships but NOT to reset
passwords for privileged administrators. Which built-in role should you assign at the tenant scope?
A. Global Administrator
B. User Administrator [CORRECT]
C. Helpdesk Administrator
D. Authentication Administrator
Correct Answer: B
Rationale: The User Administrator role in Microsoft Entra ID can manage all aspects of users and groups, including
resetting passwords for non-administrator users, but cannot reset passwords for tenants' privileged administrator roles.
Global Administrator (A) is overprivileged — violates least-privilege. Helpdesk Administrator (C) can reset non-admin
passwords but cannot manage group memberships broadly. Authentication Administrator (D) is scoped to authentication
method management, not full user/group lifecycle.
Q2: A cloud engineer needs to invite an external consultant to collaborate on an Azure project. The consultant must
sign in with their own Gmail account without creating a new Microsoft account. Which feature should you
configure in Microsoft Entra ID?
A. Configure B2B collaboration and invite the consultant as a guest user using their Gmail address
[CORRECT]
B. Create a new member user in the tenant and require MFA on first login
C. Configure B2C with local email sign-in identity provider
D. Federate with Google Workspace using SAML and create a synced user
Correct Answer: A
Rationale: Microsoft Entra B2B collaboration lets you invite external users (including Gmail addresses) as guest users;
the invitee authenticates at their home identity provider and a verified one-time passcode flow is supported if they lack a
Microsoft account. Creating a new member user (B) requires the external consultant to manage new credentials. B2C (C)
is for customer-facing apps, not internal collaboration. SAML federation (D) is heavyweight and requires Google
Workspace admin consent; the simple B2B invitation flow is the right choice.
Page 1
,AZ-104 Renewal Exam — Question and Answer Updated 2026/2027 Microsoft Azure Administrator Renewal | High-Confidence Verified
Q3: Your organization requires self-service password reset (SSPR) for all users. Users must reset using BOTH their
mobile phone and an alternate email — and must not be allowed to use security questions. Which SSPR
configuration satisfies these requirements?
A. Set methods required to register = 1; authentication methods = mobile phone + email; security questions disabled
B. Set methods required to register = 2; authentication methods = mobile phone (SMS) + alternate email;
security questions disabled; require verification on reset [CORRECT]
C. Enable security questions as the primary method with mobile phone as fallback
D. Set methods required to reset = 1 and allow users to choose any combination
Correct Answer: B
Rationale: Microsoft Entra SSPR allows you to configure the number of methods required to register and reset, and which
methods are permitted. To enforce two specific methods (mobile phone + alternate email), set methods required to 2,
ensure those methods are enabled, disable security questions, and require verification at reset time. Choice A sets methods
to 1 — insufficient. Choice C allows security questions — explicitly forbidden. Choice D does not enforce the two
specific methods and lets the user choose — violates the requirement.
Q4: You assign a user the 'Virtual Machine Contributor' role at the resource group scope. The user attempts to
assign a managed identity to a VM in that resource group but receives a 403 Forbidden error. What is the
underlying cause, and what is the minimum change needed?
A. Virtual Machine Contributor role has been deprecated; assign 'Contributor' role
B. Assigning managed identities requires Microsoft.Authorization/*/Write permission, which is not in the
Virtual Machine Contributor role; assign 'Managed Identity Contributor' or create a custom role with
Microsoft.ManagedIdentity/identities/assign/action [CORRECT]
C. Move the VM to a different resource group
D. Enable managed identities for Azure resources at the subscription level
Correct Answer: B
Rationale: The 'Virtual Machine Contributor' built-in role allows VM lifecycle management but does not include the
permission to assign a managed identity to a VM (Microsoft.ManagedIdentity/identities/assign/action) or write role
assignments at the Authorization namespace. Assigning a managed identity is essentially a role assignment on the identity.
The least-privilege fix is to assign 'Managed Identity Contributor' or build a custom role that grants only the needed action.
Choice A is incorrect — VM Contributor is not deprecated and would still be over-broad. C and D do not address the
missing permission.
Q5: You need to deny resource creation in any region other than 'East US' and 'West Europe' across all
subscriptions in the management group 'CorpMG'. What is the most efficient way to enforce this?
A. Create a custom RBAC role with deny assignment and apply to each subscription
B. Create an Azure Policy definition 'Allowed Locations' and assign it at the management group 'CorpMG'
scope [CORRECT]
C. Apply resource locks to all non-compliant resource groups
D. Configure Azure Advisor recommendations on each subscription
Correct Answer: B
Rationale: Azure Policy is the governance tool for enforcing rules such as allowed locations. The 'Allowed Locations'
built-in policy definition can be assigned at the management group scope, automatically inheriting to all subscriptions
underneath. RBAC (A) is for access control, not allowed-locations enforcement. Resource locks (C) prevent
deletion/modification but do not control where resources are created. Azure Advisor (D) is advisory only —
non-enforcing.
Page 2
,AZ-104 Renewal Exam — Question and Answer Updated 2026/2027 Microsoft Azure Administrator Renewal | High-Confidence Verified
Q6: A developer needs read access to a single storage account but currently has the 'Reader' role at the subscription
scope. Following least-privilege principles, what is the BEST change?
A. Remove the Reader role at subscription scope and assign 'Storage Account Contributor' at the storage account
scope
B. Remove the Reader role at subscription scope and assign 'Reader and Data Access' at the storage account
scope [CORRECT]
C. Keep the Reader role at subscription scope and add 'Storage Account Contributor' at the storage account
D. Assign 'Storage Blob Data Reader' at the resource group scope
Correct Answer: B
Rationale: Least-privilege means scoping permissions as narrowly as possible. The developer needs only read access at
the storage account level. The 'Reader and Data Access' role provides read access to the storage account object AND read
access to data via Microsoft.Storage/storageAccounts/listKeys/action, which is exactly what a developer needing read
access would need. 'Storage Account Contributor' (A) gives management plane write — too much. Choice C leaves the
over-broad subscription Reader role in place. 'Storage Blob Data Reader' at the resource group scope (D) gives only blob
(container) data plane read; it would not let the user inspect the storage account management properties.
Q7: Your company has the following hierarchy: Root Management Group (Tenant Root Group) → 'Corp' →
'Prod' and 'Dev' → individual subscriptions. You need to apply a policy that ONLY affects 'Prod' subscriptions and
their descendants. Where should you assign the policy?
A. Tenant Root Group
B. 'Corp' management group
C. 'Prod' management group [CORRECT]
D. Each individual subscription under 'Prod'
Correct Answer: C
Rationale: Azure Policy is inherited downward. Assigning at the 'Prod' management group will apply to 'Prod' and all its
child subscriptions/resources — exactly what is needed. Assigning at the Tenant Root (A) or 'Corp' (B) would also affect
'Dev'. Assigning per subscription (D) works but is operationally inefficient and error-prone; management group
assignment is preferred for organizational governance.
Q8: An administrator accidentally deleted a production resource group. The deletion occurred 5 days ago. The
resource group was NOT protected by a resource lock. Which statement is TRUE?
A. The resource group can be restored from Azure Backup if Recovery Services Vault was configured in the same
region
B. Soft delete for Azure Resource Manager allows recovery of the deleted resource group within the retention
window (default 14 days) using the subscription's 'Restore' operation [CORRECT]
C. The resource group cannot be recovered; only individual resources within have soft delete
D. Restoration requires opening a Microsoft support ticket within 7 days
Correct Answer: B
Rationale: Azure Resource Manager (ARM) soft delete for resource groups was rolled out in 2024 and is enabled by
default at the subscription level. Deleted resource groups can be recovered via the 'Validate' and 'Restore' operations
within a configurable retention window (default 14 days, extendable). Resource-level soft delete (e.g., for storage
accounts) is separate and different from resource group recovery. Azure Backup (A) protects data, not resource group
objects. Opening a support ticket (D) is no longer required for the standard recovery flow.
Page 3
, AZ-104 Renewal Exam — Question and Answer Updated 2026/2027 Microsoft Azure Administrator Renewal | High-Confidence Verified
Q9: You have an existing custom Azure role defined in JSON. You need to update the role definition to add a new
permission. After updating the JSON, which Azure CLI command applies the change?
A. az role definition create --role-definition updated-role.json
B. az role definition update --role-definition updated-role.json [CORRECT]
C. az role assignment create --role updated-role.json
D. az role definition apply --role-definition updated-role.json
Correct Answer: B
Rationale: Existing custom Azure roles are updated with 'az role definition update --role-definition <file>.json'. Use 'az
role definition create' only for new role definitions; create will fail on an existing role name/ID. Role assignment (C) is
unrelated to role definition modification. 'az role definition apply' (D) is not a valid CLI verb for this operation.
Q10: You need to tag all resources in a subscription with their cost center and environment automatically when
created, and remediate existing resources. Which combination of Azure services should you use?
A. Azure Policy with 'Modify' effect and a remediation task; policy assigned at the subscription scope
[CORRECT]
B. Azure Advisor cost recommendations applied manually
C. Azure Resource Manager template with tag values hardcoded in each template
D. Azure CLI script run nightly from Azure Automation to add missing tags
Correct Answer: A
Rationale: Azure Policy with the 'Modify' effect can append or replace tags on both new resources (deny/audit if
non-compliant) and existing resources (via a remediation task). The 'Modify' effect can also be used to enforce tag
inheritance from the resource group. Advisor (B) is advisory only. ARM templates (C) only affect resources deployed
through that template, not pre-existing resources. A nightly CLI script (D) is brittle, requires a service principal with
contributor rights, and is not policy-enforced.
Q11: A user has both 'Reader' (assigned at subscription scope) and 'Contributor' (assigned at resource group
scope) on the same resource. When the user attempts to write to a resource in that resource group, what is the
effective permission?
A. Reader only; the most restrictive role always wins
B. Contributor; Azure RBAC is additive — the union of permissions across all applicable assignments is the
effective permission [CORRECT]
C. The user cannot write because Reader denies writes
D. The user must explicitly select the Contributor role in the portal before performing writes
Correct Answer: B
Rationale: Azure RBAC is an additive allow-only model; the effective permission is the union of all assigned roles across
all scopes that apply to the resource. There are no 'deny' permissions in built-in roles. Reader provides read; Contributor
provides read/write on the resource group. The user can write to resources in that resource group because Contributor
grants Write. Choice A is wrong — RBAC is not 'most restrictive wins'. Choice C is wrong — Reader does not 'deny'; it
just doesn't grant write. Choice D is wrong — no role selection is needed; the user authenticates and gets the union of all
assigned roles.
Page 4