Escrito por estudiantes que aprobaron Inmediatamente disponible después del pago Leer en línea o como PDF ¿Documento equivocado? Cámbialo gratis 4,6 TrustPilot
logo-home
Document preview thumbnail
Vista previa 4 fuera de 107 páginas
Examen

AZ-104 Azure Administrator Renewal Exam Prep 2026 | 300+ Practice Questions with Answers & Explanations | Microsoft Azure Certification

Document preview thumbnail
Vista previa 4 fuera de 107 páginas

AZ-104 Azure Administrator Renewal Exam Prep 2026 | 300+ Practice Questions with Answers & Explanations | Microsoft Azure Certification

Vista previa del contenido

AZ-104 Renewal Exam 2026 – Comprehensive Practice
Questions with Verified Answers

Domain 1: Manage Azure Identities and Governance (20-25%)



1. Your company is expanding globally and needs to organize its Azure subscriptions by department. You
have four departments: Finance, Marketing, HR, and IT. Each department requires its own set of Azure
policies and access control. What is the most efficient way to delegate Azure RBAC permissions to each
department in a new Azure tenant?



A) Assign each user the Contributor role at the root management group level.

B) Create a separate management group for each department, move each department’s subscriptions
under their respective management group, and assign RBAC roles at the appropriate scope.

C) Assign each user the Owner role at the root management group level.

D) Create a separate Azure Active Directory for each department and assign RBAC roles at the tenant
level.



Answer: B

Explanation: Management groups provide an efficient way to manage access, policies, and compliance
across multiple subscriptions. By creating a management group for each department and moving their
subscriptions under it, you can assign RBAC roles at the management group level, which inherits down
to all child subscriptions. This avoids assigning permissions at the individual subscription level or using a
single management group for all departments.




2. Your organization uses Microsoft Entra ID. You need to invite an external partner user so they can
collaborate on a specific Azure resource. The partner uses a Gmail account. What is the correct method
to create this guest user in the portal?



A) From Microsoft Entra ID → Users → All users → New user → Create new user → Enter their Gmail
address as the User name and select User type: Member.

B) From Microsoft Entra ID → Users → All users → New user → Invite external user → Enter the Gmail
address.

,C) From Microsoft Entra ID → Users → All users → New user → Create new user → Enter their Gmail
address as the User name and select User type: Guest.

D) From Microsoft Entra ID → Users → All users → New user → Bulk create → Upload a CSV with the
Gmail address.



Answer: B

Explanation: When inviting external users via the Azure portal, you must select "Invite external user"
and enter their email address. This creates a guest user account that maintains their own credentials
from their home identity provider. Option C would attempt to create a cloud-only account in your
tenant, which fails because the domain @gmail.com is not a verified domain in your tenant.




3. Your company has a Microsoft Entra tenant. You have a CSV file containing email addresses of 500
external partners. You need to invite them as guest users so they can access an Azure DevOps project.
All users must sign in with their existing corporate accounts. What is the most efficient method to
accomplish this?



A) Use a PowerShell script to invoke `New-AzureADUser` for each email address with `-UserType` set to
"Guest".

B) Use the "Bulk invite users" feature in the Microsoft Entra admin center by preparing a CSV file with
the email addresses.

C) Manually create each user as a new user in the portal with the "Guest" user type.

D) Send a mass email to the partners asking them to self-register using a link provided by Microsoft
Entra ID.



Answer: B

Explanation: The bulk invite feature in Microsoft Entra ID (formerly Azure AD) is designed specifically for
this scenario. You prepare a CSV with the user's email addresses and optional details, then upload it
through the portal. This sends invitations and creates guest accounts efficiently without scripting.
Manual creation would be inefficient, and the bulk create feature (Option C) is for creating cloud-only
users, not inviting external guests.

,4. You are a Global Administrator in a Microsoft Entra tenant. You need to ensure that all users in the
tenant register for MFA within 14 days of account creation. What Microsoft Entra feature should you
configure?



A) Identity Protection user risk policy

B) Conditional Access policy with a grant control for "Require multi-factor authentication" and a session
control for "Sign-in frequency"

C) MFA per-user settings enabled for all users

D) Azure AD Privileged Identity Management (PIM) assignment



Answer: B

Explanation: Conditional Access policies provide the most granular control for requiring MFA. By
creating a policy that applies to all users, includes all cloud apps, and uses "Require multi-factor
authentication" as a grant control, you can enforce MFA for all users. To implement a 14-day grace
period, you can combine this with a session control like "Require reauthentication every 14 days". Per-
user MFA settings are legacy and less flexible, and they lack the 14-day enforcement period.




5. Your organization uses Microsoft Entra ID. You need to manage the lifecycle of Azure resources. You
have been tasked with ensuring that all resources in a specific subscription have a "CostCenter" tag with
a value. What Azure service should you use to enforce this automatically?



A) Azure Policy

B) RBAC role assignment

C) Azure Blueprints

D) Management groups



Answer: A

Explanation: Azure Policy is the service that enforces organizational standards and assesses compliance
at scale. It provides built-in policies to enforce tagging on resource groups or individual resources.
Option B (RBAC) is for access control, Option C (Blueprints) is for orchestrating deployments, and Option
D (Management groups) is for organizing subscriptions hierarchically.

, 6. Your company has an Azure subscription. You have been assigned the Reader role at the subscription
scope. You need to grant a colleague access to manage virtual machines (start, stop, restart) in the
production resource group only. What is the minimal RBAC role you should assign to your colleague at
the production resource group scope?



A) Contributor

B) Reader

C) Virtual Machine Contributor

D) Owner



Answer: C

Explanation: The Virtual Machine Contributor role allows management of virtual machines (starting,
stopping, restarting) but does not grant access to the virtual network or storage account the VM uses,
and it cannot manage the resource group itself. Contributor would grant broader access than needed,
and Owner would grant full access including RBAC management.




7. You plan to implement role-based access control (RBAC). You have a resource group named RG1 that
contains multiple virtual machines. You need to assign a role to Development Team Lead so they can
manage the virtual machines and the virtual network within RG1. Which role should you assign at the
RG1 scope?



A) Owner

B) Contributor

C) Virtual Machine Contributor

D) Network Contributor



Answer: B

Información del documento

Subido en
4 de mayo de 2026
Número de páginas
107
Escrito en
2025/2026
Tipo
Examen
Contiene
Preguntas y respuestas
$28.49

¿Documento equivocado? Cámbialo gratis Dentro de los 14 días posteriores a la compra y antes de descargarlo, puedes elegir otro documento. Puedes gastar el importe de nuevo.
Escrito por estudiantes que aprobaron
Inmediatamente disponible después del pago
Leer en línea o como PDF

Seller avatar
francisndungu1
5.0
(1)
Vendido
7
Seguidores
0
Artículos
589
Última venta
3 días hace


Por qué los estudiantes eligen Stuvia

Creado por compañeros estudiantes, verificado por reseñas

Calidad en la que puedes confiar: escrito por estudiantes que aprobaron y evaluado por otros que han usado estos resúmenes.

¿No estás satisfecho? Elige otro documento

¡No te preocupes! Puedes elegir directamente otro documento que se ajuste mejor a lo que buscas.

Paga como quieras, empieza a estudiar al instante

Sin suscripción, sin compromisos. Paga como estés acostumbrado con tarjeta de crédito y descarga tu documento PDF inmediatamente.

Student with book image

“Comprado, descargado y aprobado. Así de fácil puede ser.”

Alisha Student

Preguntas frecuentes