Associate Renewal Assessment
2026/2027 | 100 Verified Questions &
Answers | Azure Admin Certification
Prep | 5 Core Domains | Instant
Download | rated 100% correct.
DOMAIN 1: MANAGE AZURE IDENTITIES AND
GOVERNANCE
1. You are the Azure Administrator for a company that uses Microsoft Entra
ID. A user reports that they have forgotten their password and cannot access
the Azure portal. You need to ensure the user can reset their own password.
Which Microsoft Entra ID feature should you configure?
A. Multi-Factor Authentication (MFA)
B. Conditional Access policies
C. Self-Service Password Reset (SSPR)
D. Privileged Identity Management (PIM)
Correct Answer: C (Self-Service Password Reset [SSPR])
Rationale: Self-Service Password Reset (SSPR) allows users to reset their
own passwords without contacting the helpdesk, reducing administrative
overhead. MFA adds verification but does not enable password resets.
Conditional Access controls access conditions, not password recovery. PIM
manages just-in-time access for privileged roles .
Teaching Point: Password recovery = SSPR.
Source: AZ-104 Renewal Exam Questions 2026/2027
2. Your company has a management group named MG-Production that
contains two subscriptions: Sub-A and Sub-B. You need to assign the Reader
,role to a user for both subscriptions with a single assignment. At which scope
should you assign the role?
A. Subscription scope for each subscription individually
B. Management group scope on MG-Production
C. Resource group scope on each resource group
D. Tenant scope
Correct Answer: B (Management group scope on MG-Production)
Rationale: Assigning the Reader role at the management group scope
automatically grants read access to all subscriptions and resource groups
within that management group. This follows the RBAC scope hierarchy:
Management Group → Subscription → Resource Group → Resource. Two
separate subscription assignments would be less efficient. Tenant scope
would grant access to all subscriptions in the entire tenant, exceeding
intended scope .
Teaching Point: Single assignment across subscriptions = management
group scope.
Source: AZ-104 Renewal Exam Questions 2026/2027
3. You need to prevent users from creating Azure storage accounts in the
East US region within your subscription. Which Azure Policy effect should you
use?
A. Audit
B. Deny
C. DeployIfNotExists
D. Append
Correct Answer: B (Deny)
Rationale: The Deny effect actively blocks resource creation that does not
comply with organizational standards. When a user attempts to create a
storage account in East US, the Deny policy rejects the request and returns
an error. Audit only logs a warning but allows creation. Append adds fields
during creation but cannot prevent it. DeployIfNotExists deploys required
configurations when a non-compliant resource is created, but does not
prevent initial creation .
Teaching Point: Block non-compliant resources = Deny effect.
Source: AZ-104 Renewal Exam Questions 2026/2027
, 4. A developer needs to upload files to an Azure Blob Storage container for 7
days with minimum required permissions. Which type of Shared Access
Signature (SAS) token should you create?
A. Account SAS with full service-level permissions
B. User delegation SAS with read and write permissions only
C. Service SAS with delete permissions included
D. Account SAS with object-level permissions only
Correct Answer: B (User delegation SAS with read and write
permissions only)
Rationale: A User Delegation SAS is secured by Microsoft Entra ID
credentials and provides the most granular, least-privilege access. It is
recommended for granting temporary access to blob storage because it does
not require the storage account key, reducing key compromise risk. An
Account SAS grants broader service-level access and requires the account
key. Including delete permissions would exceed minimum requirements .
Teaching Point: Least-privilege temporary blob access = User Delegation
SAS.
Source: AZ-104 Renewal Exam Questions 2026/2027
5. You need to ensure that when a network security group (NSG) is created,
it automatically blocks TCP port 8080 between virtual networks. What should
you configure?
A. A custom Azure Policy definition assigned to the subscription
B. An NSG inbound rule on each virtual network
C. Azure Firewall application rules
D. Route tables with custom routes
Correct Answer: A (A custom Azure Policy definition assigned to the
subscription)
Rationale: Azure Policy can enforce compliance rules across resources. A
custom policy definition can be created and assigned to the subscription to
automatically configure NSGs to block TCP port 8080 when they are created.
NSG rules would need to be manually configured on each NSG. Azure
Firewall and route tables serve different purposes .
Teaching Point: Automatic NSG configuration on creation = Azure Policy.
Source: Microsoft Certified Azure Administrator Associate Renewal
Assessment 2026