BrainyBeeBrainyBee
ExploreBlogStart Studying
Home›Explore›Microsoft Azure Administrator (AZ-104)
🛠️

🔷 Microsoft Azure

Free Microsoft Azure Administrator (AZ-104) Study Resources

Administer Azure the way the exam tests it — identity and governance, storage, compute, virtual networking, and monitoring, mapped 1:1 to the official skills measured.

448
Practice Questions
6
Mock Exams
35
Study Notes
254
Flashcard Decks
154
Source Materials
Start Studying — Free

On This Page

  • Study Notes (35)
  • Practice Questions (15)
  • Flashcards (30)
  • Related Study Resources

Microsoft Azure Administrator (AZ-104) Study Notes & Guides

35 AI-generated study notes covering the full Microsoft Azure Administrator (AZ-104) curriculum. Showing 10 complete guides below.

Exam Map391 words

AZ-104 exam map

AZ-104

Read full article

AZ-104 exam map

What the exam states about itself

Skills measured as of
2026-04-17
Skill areas
5
Sub-areas
15
Objectives
82
Time
100 minutes
Passing score
700 of 1000

What AZ-104 certifies

AZ-104 certifies an administrator — somebody who operates an Azure estate rather than designing one. That shows up in the wording of the objectives: they are overwhelmingly verbs you perform, not judgements you defend. Configure, manage, create, troubleshoot, interpret. Where a design exam asks which architecture is right, this one asks which setting you would change and where you would change it.

Read that as a study instruction. Being able to describe a service is not the bar; being able to say which blade, scope or command changes its behaviour is.

The blueprint

Skill areaPublished rangeSub-areasObjectivesBank questions
1. Manage Azure identities and governance20–25%31599
2. Implement and manage storage15–20%31776
3. Deploy and manage Azure compute resources20–25%42499
4. Implement and manage virtual networking15–20%313107
5. Monitor and maintain Azure resources10–15%21367

Ranges, not points — and no published question count

Microsoft publishes each skill area as a RANGE, not a single percentage, and it does not publish how many questions the exam contains. Any source quoting an exact split or an exact question count for AZ-104 is estimating. This hive's practice papers use house point estimates that sit inside the published ranges, which is why a paper's mix will vary slightly from the ranges above.

The order worth taking

  1. Unit 1, identities and governance. Scope is the idea the rest of the exam assumes you already have.
  2. Unit 4, networking. It is the largest question surface in this bank and the one most often failed on a path question rather than a knowledge question.
  3. Unit 3, compute. The widest unit by objective count. Long, but each sub-area is self-contained.
  4. Unit 2, storage. Two clean families of question, quick to consolidate once units 1 and 4 are solid.
  5. Unit 5, monitoring and recovery. Smallest by weight, and the one candidates most often leave short.

Units 1 and 4 first is a deliberate inversion of the published order. Scope and network paths are the two ideas that other units silently depend on, so learning them late means re-reading everything that assumed them.

What this hive gives you

Study assets in this hive

Questions
448
Case-study questions
24, in 6 groups
Flashcards
254
Flashcard collections
82 — one per objective
Blueprint-weighted mocks
6, of 67 questions each

The flashcard deck pins to objective depth rather than topic depth, so coverage is verifiable one objective at a time — every one of the 82 has its own collection. The six mocks share no question with each other and each carries one complete case study, so they can be sat as six independent attempts.

Check yourself

Loading flashcards…

Traps that span the whole exam

Four habits that cost marks across every unit

Answering with the most capable service rather than the one the requirement asks for. Naming a correct setting at the wrong scope. Reading past a constraint stated once in the middle of a stem — a region, a team size, an existing resource that cannot move. Treating a service you have heard of as the answer to a requirement you have not fully read.

Every one of those is a reading failure rather than a knowledge failure, which is why working questions beats re-reading notes once you are past the first pass.

Unit Roadmap358 words

Unit 1 roadmap — Manage Azure identities and governance

AZ-104 › Unit 1

Read full article

Unit 1 roadmap — Manage Azure identities and governance

Unit 1 at a glance

Published range
20–25%
Sub-areas
3
Objectives
15
Bank questions
99
Flashcards
51

What this unit is really testing

Unit 1 is about who may act, where they may act, and what the platform will let them leave behind. Almost every question resolves to a scope question: an assignment made at the wrong level is the single most common way an administrator grants too much or too little. Read every stem for the scope first — management group, subscription, resource group, resource — and only then for the permission.

The order to work through it

  1. Start with identity objects, because everything else is granted to one: users, groups, and how membership is decided.
  2. Move to Azure role-based access control, and hold the distinction between directory roles and resource roles firmly. They are two systems that share a portal.
  3. Finish with governance, which is the widest surface: policy, locks, tags, resource groups, subscriptions, cost control and management groups.

Topic map

Every objective title below is quoted from Microsoft's skills-measured outline, as of 2026-04-17.

Manage Microsoft Entra users and groups

AZ104-U1.T1 · 5 objectives

  • Create users and groups
  • Manage user and group properties
  • Manage licenses in Microsoft Entra ID
  • Manage external users
  • Configure self-service password reset (SSPR)

Manage access to Azure resources

AZ104-U1.T2 · 3 objectives

  • Manage built-in Azure roles
  • Assign roles at different scopes
  • Interpret access assignments

Manage Azure subscriptions and governance

AZ104-U1.T3 · 7 objectives

  • Implement and manage Azure Policy
  • Configure resource locks
  • Apply and manage tags on resources
  • Manage resource groups
  • Manage subscriptions
  • Manage costs by using alerts, budgets, and Azure Advisor recommendations
  • Configure management groups

Traps

Where Unit 1 catches people

Treating Microsoft Entra roles and Azure resource roles as one system — they grant different things and are assigned in different places. Reaching for policy to grant access: policy governs what a resource may look like, not who may touch it. Expecting tags to reach child resources on their own. Reading a lock as a security control rather than a control-plane guard. Answering a scope question with the right permission at the wrong level.

Check yourself

Loading flashcards…

Are you ready to move on?

  • You can state this unit's published range without looking it up.
  • You can name every sub-area and say what separates it from its neighbours.
  • You can explain each trap above to somebody else, in your own words.
  • You have worked the unit's 99 bank questions and can say why the wrong options are wrong.

When all four are true, take a blueprint-weighted mock rather than more of this unit. A mock is the only asset here that tells you how this unit performs against the other four under time.

Unit Capstone810 words

Unit 1 capstone — Onboarding an acquired subsidiary

AZ-104 › Unit 1 › Capstone

Read full article

Unit 1 capstone — Onboarding an acquired subsidiary

Contoso acquires Northwind

Unit
AZ104-U1
Topics exercised
3
Objectives touched
15
Decisions
6
Time
25 minutes

The brief

Contoso has acquired Northwind, a 400-person business with its own Microsoft Entra tenant. Northwind's staff keep their existing sign-ins for at least a year. Their engineering contractors need to look at one Contoso resource group and nothing else. Contoso's own service desk must be able to grant access to Northwind staff — but only inside the subscription set aside for the integration, and without becoming able to change resources. Finance has been surprised by cloud spend twice this year and wants it not to happen again. Nothing in the production resource group may be deleted while the migration runs, and every resource created during it must be attributable to a cost centre.

What they need

  1. Northwind's 400 staff sign in with their existing credentials, without Contoso creating and managing 400 new accounts.
  2. Northwind's contractors can read one Contoso resource group and nothing else.
  3. The service desk can grant others access inside the integration subscription, but cannot change the resources in it.
  4. Every resource created in the integration subscription carries a cost-centre tag, whether or not the person creating it remembers.
  5. Nothing in the production resource group can be deleted during the migration.
  6. Finance is told when the integration subscription passes 80% of its monthly budget.

Commit before you read on

Write down your answer to each of the 6 numbered requirements above — the mechanism, and the scope you would apply it at. Then open the working below and compare. Reading the reasoning beside the question is the one way to feel like you knew it without having known it.

▶Show the working

1. 400 staff, their own credentials

B2B collaboration guests.

The partner uses their own identity management, so there is no account lifecycle for Contoso to run. Guests appear in the directory as user objects whose user principal name contains the #EXT# identifier. Note the side effect to control deliberately: by default every user in the organization, including existing guests, can invite more guests. If that is not wanted, external collaboration settings are the place to restrict it — not a role assignment.

2. Contractors read one resource group

Reader, assigned at the resource group scope.

Reader grants viewing and no changes. The examinable half is the scope: assign it at the resource group, not the subscription, because lower levels inherit from higher levels and there is no way to subtract an inherited assignment lower down. Assign to a group rather than to each contractor — a group is a security principal, so one assignment does the work of many.

3. Service desk grants access but cannot change resources

User Access Administrator at the subscription scope.

This is the requirement that eliminates the two obvious answers. Contributor grants full access to manage all resources but explicitly not the ability to assign roles — so it fails the first half. Owner grants full access including role assignment — so it fails the second. Only the role that separates access management from resource management satisfies both.

4. Every resource carries a cost-centre tag

An Azure Policy assignment that requires — or appends — the tag.

Tagging the resource group does nothing for its contents: resources don't inherit the tags you apply to a resource group or a subscription. Policy is the mechanism that makes a tag arrive on the resource. And note what policy is doing here — governing the state a resource may be in, not anybody's access.

5. Nothing deletable in production

A CanNotDelete lock at the resource group scope.

The portal calls it Delete; the command line calls it CanNotDelete. It lets authorized users read and modify but not delete, it is inherited by everything in the scope including resources added later, and the most restrictive lock in the chain wins. It is a control-plane guard, so it does not protect data inside a resource — which is not what was asked for here.

6. Finance told at 80% of budget

A budget with an alert at the 80% threshold.

And the sentence that decides the wrong answers: notifications are triggered when thresholds are exceeded, resources aren't affected, and consumption isn't stopped. A budget notifies. If the stem had said "prevent overspend", no budget would answer it. Budgets are evaluated every 24 hours, so this is not a real-time control either.

The reasoning this unit rewards

Four mechanisms, one English word

This unit keeps asking you to 'prevent' something, and four different mechanisms answer to that word. A lock prevents a control-plane change. A policy prevents a resource existing in a shape you disallow. A deny assignment prevents an action. A budget prevents nothing at all — it notifies. Decide which kind of prevention the requirement describes before you compare options.

Check yourself

Loading flashcards…

Where these figures come from

Every figure above was read from the raw documentation below on the day this sheet was written. The sha1 is git hash-object over the bytes as fetched, so a doc that changes underneath this sheet can be detected rather than assumed.

Documentsha1
B2B collaboration overviewb0768f637b07
Understand scope for Azure RBAC87e7f6fe1b69
Azure built-in roles068bc2c7255f
Use tags to organize your Azure resourcesb1d92e330865
Lock your Azure resources0a4f4f548288
Tutorial: Create and manage Azure budgets051db0341cf9
Build Lab166 words

Lab — A budget notifies and stops nothing

AZ-104 › Unit 1 › Lab

Read full article

Lab — A budget notifies and stops nothing

Lab brief

Node
AZ104-U1.T3
Time
15 minutes
Creates
A budget and an action group
Subscription
required
Difficulty
Foundational

The shortest lab in the set, and it exists for one sentence: resources aren't affected, and your consumption isn't stopped. Every learner nods at that and a third of them still answer 'budget' when a stem says 'prevent overspend'.

These commands have not been run

There is no Azure subscription in the environment this lab was written in, so not one of these commands has been executed. The syntax is derived from Microsoft's own CLI documentation, and the elements this lab asserts are quoted from it at the bottom of the page — but the specific invocations, with these names in this order, are unrun. Read each command before you run it, and expect to adjust names and regions. Treat the teardown as part of the lab, not an optional extra.

Before you start

A subscription you can read cost data on. A budget is a cost-management object and creates no billable resource.

Walkthrough

A budget notifies and stops nothing

  1. 1

    1. Create a budget below your current spend

    Set the amount deliberately low — below what the subscription has already used this period — so the threshold is already exceeded and you do not have to wait for reality to catch up.

Did it teach you what it was meant to?

Multiple choice · EasyWhat a budget does

Step 4 deployed a resource with the budget already exceeded. What does a budget do at that moment?

Multiple choice · MediumBudget evaluation timing

Why is a budget a poor answer to 'alert us the moment a runaway script starts spending'?

What goes wrong

What goes wrong

Setting a budget for the current period and expecting an immediate alert — the evaluation cycle is daily and the underlying data lags. Assuming a budget that has expired is still watching; it was deleted. And reading 'budget' as a cost control in an exam stem when it is a cost signal.

Tear it down

Run this whether or not the lab worked. Everything above was chosen to cost approximately nothing, and leaving it in place is how approximately nothing becomes something.

Teardown

  1. 1

    Delete the budget and the action group

    Neither costs anything, but a budget with a deliberately wrong amount left in place will keep emailing somebody every day, which is its own small punishment.

Where these figures come from

Every figure above was read from the raw documentation below on the day this sheet was written. The sha1 is git hash-object over the bytes as fetched, so a doc that changes underneath this sheet can be detected rather than assumed.

Documentsha1
Tutorial: Create and manage Azure budgets051db0341cf9
Build Lab212 words

Lab — Prove that inheritance only flows one way

AZ-104 › Unit 1 › Lab

Read full article

Lab — Prove that inheritance only flows one way

Lab brief

Node
AZ104-U1.T2
Time
25 minutes
Creates
Two resource groups, a role assignment, a custom role definition
Subscription
required
Difficulty
Core

The claim to make physical: you cannot narrow an inherited assignment from below. Everybody knows lower levels inherit from higher. Far fewer have watched an attempt to subtract fail.

These commands have not been run

There is no Azure subscription in the environment this lab was written in, so not one of these commands has been executed. The syntax is derived from Microsoft's own CLI documentation, and the elements this lab asserts are quoted from it at the bottom of the page — but the specific invocations, with these names in this order, are unrun. Read each command before you run it, and expect to adjust names and regions. Treat the teardown as part of the lab, not an optional extra.

Before you start

A subscription where you can create role assignments — that needs Owner or User Access Administrator on it. Resource groups and role definitions are free; nothing here deploys a billable resource.

Walkthrough

Prove that inheritance only flows one way

  1. 1

    1. Create two resource groups

    az group create --name bb-lab-rbac-a --location westeurope and again for bb-lab-rbac-b. A resource group holds metadata about resources, so its location is where that metadata lives — resources inside one may sit in different regions.

Did it teach you what it was meant to?

Multiple choice · HardScope and inheritance

A principal has Reader at the subscription. You need them to keep reading resource group A but lose access to B. What does step 3 show you must do?

Multiple choice · MediumBuilt-in roles

Step 5 showed the boundary between two built-in roles. Which requirement does Contributor fail?

What goes wrong

What goes wrong

Creating a role assignment needs Owner or User Access Administrator; Contributor cannot do it, which is the lab's own lesson arriving early. Assignments take a short while to take effect, so a failed read immediately after step 2 may just be propagation. And remember to delete the assignment in step 4 rather than layering another one on top.

Tear it down

Run this whether or not the lab worked. Everything above was chosen to cost approximately nothing, and leaving it in place is how approximately nothing becomes something.

Teardown

  1. 1

    Remove the assignment, then the resource groups

    az role assignment delete for anything left, then az group delete --name bb-lab-rbac-a and the same for bb-lab-rbac-b. Deleting the resource groups removes anything inside them.

Where these figures come from

Every figure above was read from the raw documentation below on the day this sheet was written. The sha1 is git hash-object over the bytes as fetched, so a doc that changes underneath this sheet can be detected rather than assumed.

Documentsha1
Manage Azure resource groups by using Azure CLIa3840d837a3d
Manage Azure resource groups by using the Azure portalc2bc52250166
Understand scope for Azure RBAC87e7f6fe1b69
Assign Azure roles using Azure CLIb29025fd43e6
Create or update Azure custom roles using Azure CLI7b5d855bd425
Azure built-in roles068bc2c7255f
List Azure deny assignmentsf4d5fba1f410
Build Lab204 words

Lab — Tags do not inherit, and a lock is not a permission

AZ-104 › Unit 1 › Lab

Read full article

Lab — Tags do not inherit, and a lock is not a permission

Lab brief

Node
AZ104-U1.T3
Time
25 minutes
Creates
A resource group, a tag, a policy assignment, a lock
Subscription
required
Difficulty
Core

Two claims in one sitting: resources do not inherit a resource group's tags, and a lock stops a delete even when your role permits it. Both are one command away from being obvious.

These commands have not been run

There is no Azure subscription in the environment this lab was written in, so not one of these commands has been executed. The syntax is derived from Microsoft's own CLI documentation, and the elements this lab asserts are quoted from it at the bottom of the page — but the specific invocations, with these names in this order, are unrun. Read each command before you run it, and expect to adjust names and regions. Treat the teardown as part of the lab, not an optional extra.

Before you start

A subscription and the ability to create policy assignments and locks on it. Everything created here is a governance object or an empty resource group; none of it is billable.

Walkthrough

Tags do not inherit, and a lock is not a permission

  1. 1

    1. Create a tagged resource group

    az group create --name bb-lab-gov --location westeurope --tags costCenter=1234. The tag is on the group.

Did it teach you what it was meant to?

Multiple choice · MediumTag inheritance

Step 2 showed an untagged resource inside a tagged resource group. What does that rule out as a design?

Multiple choice · HardLocks versus permissions

In step 5 the delete was refused although your role allows it. Which statement does that experiment support?

What goes wrong

What goes wrong

Policy assignments do not take effect instantly; give step 4 several minutes before deciding the assignment is wrong. The lock in step 5 is inherited by everything in the group, including anything you add afterwards, and the most restrictive lock in the chain wins — so remember it exists when the teardown refuses. And if step 2's storage account is more spend than you want, read it rather than run it.

Tear it down

Run this whether or not the lab worked. Everything above was chosen to cost approximately nothing, and leaving it in place is how approximately nothing becomes something.

Teardown

  1. 1

    Remove the lock first, then the assignment, then the group

    The order matters and it is the lab's last lesson: az lock delete for the lock, az policy assignment delete --name --scope $rgid for the assignment, then az group delete --name bb-lab-gov. With the lock still in place, the group delete is refused.

Where these figures come from

Every figure above was read from the raw documentation below on the day this sheet was written. The sha1 is git hash-object over the bytes as fetched, so a doc that changes underneath this sheet can be detected rather than assumed.

Documentsha1
Manage Azure resource groups by using Azure CLIa3840d837a3d
Use tags to organize your Azure resourcesb1d92e330865
Create a policy assignment with Azure CLI9adc3ee57e46
What is Azure Policy?0bc00fcd34d3
Lock your Azure resources0a4f4f548288
Build Lab183 words

Lab — Watch a dynamic group fill itself in

AZ-104 › Unit 1 › Lab

Read full article

Lab — Watch a dynamic group fill itself in

Lab brief

Node
AZ104-U1.T1
Time
20 minutes
Creates
Directory users and groups
Subscription
required
Difficulty
Core

The claim to make physical: membership type is decided once. A group that can carry Entra roles is forced to Assigned and can never become dynamic — and you find that out by trying it, not by reading it.

These commands have not been run

There is no Azure subscription in the environment this lab was written in, so not one of these commands has been executed. The syntax is derived from Microsoft's own CLI documentation, and the elements this lab asserts are quoted from it at the bottom of the page — but the specific invocations, with these names in this order, are unrun. Read each command before you run it, and expect to adjust names and regions. Treat the teardown as part of the lab, not an optional extra.

Before you start

An Azure subscription and the Groups Administrator or User Administrator role, which is what creating groups requires. Sign in with az login first. Directory objects are not billable resources.

Walkthrough

Watch a dynamic group fill itself in

  1. 1

    1. Create two users with different departments

    Use az ad user create twice, giving one user a department of Engineering and the other Finance. Note the object ids it returns; you will want them in step 4.

Did it teach you what it was meant to?

Multiple choice · MediumGroup membership types

You watched a user join a group in step 4 without anybody adding them, then watched the portal refuse to change membership type in step 5. Which requirement can a role-assignable group NOT satisfy?

Multiple choice · MediumDynamic membership licensing

Your tenant has 40 Microsoft Entra ID P1 licences and 250 users would match your dynamic rule. What does the documentation require?

What goes wrong

What goes wrong

Creating groups fails with an authorization error if you hold neither Groups Administrator nor User Administrator — that is the governance model, not a broken lab. Dynamic membership does not update instantly; give step 4 a few minutes before concluding the rule is wrong. And if your tenant has no P1 licences, step 3 is the one step you cannot run.

Tear it down

Run this whether or not the lab worked. Everything above was chosen to cost approximately nothing, and leaving it in place is how approximately nothing becomes something.

Teardown

  1. 1

    Delete the three groups, then the two users

    Use az ad group delete for each group and az ad user delete for each user. Directory objects cost nothing, but leaving test principals in a directory is how a stale account outlives the person who made it.

Where these figures come from

Every figure above was read from the raw documentation below on the day this sheet was written. The sha1 is git hash-object over the bytes as fetched, so a doc that changes underneath this sheet can be detected rather than assumed.

Documentsha1
Manage Microsoft Entra groups and group membership5e94c543e4b9
Dynamic membership rules for groupsc7bcd79f770a
Topic Cram Sheet447 words

Cram sheet — Manage access to Azure resources

AZ-104 › Unit 1 › Manage access to Azure resources

Read full article

Cram sheet — Manage access to Azure resources

Manage access to Azure resources

Node
AZ104-U1.T2
Objectives
3
Bank questions
25
Grounded documents
5

Three objectives, twenty-five bank questions, and almost all of them turn on one of two things: the scope an assignment was made at, or the difference between what a role grants and what something else takes away.

The anatomy of an assignment

  • A role assignment has exactly three elements: a security principal, a role definition, and a scope. Every RBAC question is really asking about one of the three.
  • A security principal is a user, a group, a service principal, or a managed identity.
  • Access is granted by creating an assignment and revoked by removing one. There is no deny switch in the middle of that, which is why the deny-assignment section below matters.

Scope: four levels, inherited downwards

  • Scope can be set at four levels: management group, subscription, resource group, and resource.
  • Lower levels inherit role permissions from higher levels. An assignment at the subscription reaches every resource group and resource beneath it, and there is no way to subtract from it with another role assignment.
  • Because inheritance only flows one way, the fix for over-broad access is always to move the assignment down, never to add a narrower one alongside it.

The three roles you must be able to separate

RoleWhat the documentation says it grants
OwnerFull access to manage all resources, including the ability to assign roles in Azure RBAC
ContributorFull access to manage all resources, but not the ability to assign roles, manage Blueprint assignments, or share image galleries
ReaderView all resources, but no changes

The line between Owner and Contributor is role assignment, and it is the single most-tested distinction in this topic. If a stem says somebody must grant access to others, Contributor is wrong.

Deny assignments and custom roles

  • A deny assignment blocks actions even if a role assignment grants them. Deny wins.
  • You cannot create deny assignments yourself. They are created and managed by Azure — a deployment stack's deny settings are the one way an administrator causes one to exist.
  • A tenant may hold up to 5,000 custom roles. (For Microsoft Azure operated by 21Vianet the limit is 2,000.) Custom roles can be shared between subscriptions that trust the same tenant.

Answer the scope before the permission

Almost every wrong answer in this topic is a correct permission at the wrong level. Read the stem for the boundary the requirement describes — one resource, one resource group, the whole subscription, several subscriptions — and eliminate on scope first. It usually leaves one option standing.

Traps

Where Unit 1 Topic 2 catches people

Offering Contributor where the requirement includes granting access to somebody else. Trying to narrow an inherited assignment by adding a more restrictive role lower down — inheritance does not work that way. Proposing to author a deny assignment, which no administrator can do directly. Forgetting that a group is a security principal, so the cleanest answer is often one assignment to a group rather than many to users.

Check yourself

Loading flashcards…

Where these figures come from

Every figure above was read from the raw documentation below on the day this sheet was written. The sha1 is git hash-object over the bytes as fetched, so a doc that changes underneath this sheet can be detected rather than assumed.

Documentsha1
What is Azure role-based access control?73aa4b760e7b
Understand scope for Azure RBAC87e7f6fe1b69
Azure built-in roles068bc2c7255f
List Azure deny assignmentsf4d5fba1f410
Azure custom rolesd5b6e14986be
Topic Cram Sheet841 words

Cram sheet — Manage Azure subscriptions and governance

AZ-104 › Unit 1 › Manage Azure subscriptions and governance

Read full article

Cram sheet — Manage Azure subscriptions and governance

Manage Azure subscriptions and governance

Node
AZ104-U1.T3
Objectives
7
Bank questions
59
Grounded documents
7

The heaviest topic in the bank — fifty-nine questions across seven objectives — and the one where exact numbers earn marks. Locks, tags and management groups all have published limits, and the command line uses names the portal does not.

Locks: two levels, two sets of names

Portal nameCommand-line nameWhat it allows
DeleteCanNotDeleteAuthorized users can read and modify the resource, but not delete it
Read-onlyReadOnlyAuthorized users can read it, but not delete or update it
  • Note the command-line spelling: CanNotDelete, with a capital N. It is a favourite of question writers precisely because the portal never shows it.
  • A ReadOnly lock is described as similar to restricting all authorized users to the permissions the Reader role provides.
  • Locks inherit downwards: apply one at a parent scope and every resource inside it inherits the same lock, including resources added later. The most restrictive lock in the chain takes precedence.
  • Locks are a control-plane control. They protect a resource from changes but do not restrict how it performs its function — a ReadOnly lock on a database server still permits data to be written inside its databases.

Tags: the numbers

  • Maximum 50 tag name-value pairs per resource, resource group, and subscription — each, not combined.
  • Tag name limit 512 characters; tag value limit 256 characters. Storage accounts are the exception: their tag name limit is 128.
  • Resources do not inherit tags applied to a resource group or a subscription. If a stem asks for inherited tagging, the answer is a policy that applies them, not the tag itself.
  • Need more than 50? The documented workaround is a JSON string as a single tag value.

Management groups: the numbers

  • A single directory supports 10,000 management groups.
  • A management group tree supports up to six levels of depth — and that depth does not count the root.
  • Each management group and each subscription supports only one parent.
  • The root management group is named Tenant root group by default, its ID is the same value as the Microsoft Entra tenant ID, and it cannot be moved or deleted — unlike every other management group.

Resource groups hold metadata, not resources' locations

  • A resource group stores metadata about the resources, and the location you give it is where that metadata is stored — which is why the choice can matter for compliance.
  • Resources inside a resource group can be in different regions. A resource group is not a region boundary, and a stem that implies otherwise is testing exactly this.
  • Each resource belongs to exactly one resource group at a time; moving it is an explicit operation, not a property you edit.

Policy governs state; RBAC governs actions

This is the cleanest statement of the boundary, and it is worth memorising in the documentation's own terms:

  • Azure Policy ensures that resource state is compliant to your business rules without concern for who made the change or who has permission to make a change.
  • Azure RBAC focuses on managing user actions at different scopes.
  • And the sentence that decides the hardest questions in this topic: even if an individual has access to perform an action, if the result is a non-compliant resource, Azure Policy still blocks the create or update. Permission is not sufficient. Compliance is a second gate.

Policy effects are evaluated in order

The order matters because an earlier effect can prevent a later one from ever firing:

  1. disabled — checked first, to decide whether the rule is evaluated at all.
  2. append and modify — either can alter the request, and that change may stop an audit or deny from triggering.
  3. deny — evaluated before audit, which prevents double logging of a resource that was refused.
  4. audit, then manual, then auditIfNotExists.

A policy assignment governs the state a resource may be in. It never grants, denies or interprets a person's access — that is RBAC's job, and mixing them is the most common wrong answer in this topic.

Budgets do not stop anything

  • Notifications fire when a threshold is exceeded. Resources are not affected and consumption is not stopped. A budget is an alerting construct, not a spending cap.
  • Cost and usage data is typically available within 8 to 24 hours, and budgets are evaluated against it every 24 hours. A budget is not a real-time control either.
  • Budgets reset automatically at the end of each period — monthly, quarterly or annually — for the same amount. When a budget expires, it is automatically deleted.

When a stem says 'prevent', check what kind of prevention it means

A lock prevents a control-plane change. A policy prevents a resource from being created in a shape you disallow. A deny assignment prevents an action. A budget prevents nothing at all — it notifies. Four different mechanisms sharing one English word, and the exam knows it.

Traps

Where Unit 1 Topic 3 catches people

Expecting a budget to stop spending. Expecting tags on a resource group to appear on its resources. Reading a ReadOnly lock as protection for the data inside a resource rather than for the resource itself. Forgetting that the most restrictive inherited lock wins, so a lock two scopes up still blocks you. Reaching for Azure Policy to grant or deny somebody access.

Check yourself

Loading flashcards…

Where these figures come from

Every figure above was read from the raw documentation below on the day this sheet was written. The sha1 is git hash-object over the bytes as fetched, so a doc that changes underneath this sheet can be detected rather than assumed.

Documentsha1
Lock your Azure resources0a4f4f548288
Use tags to organize your Azure resourcesb1d92e330865
What are Azure management groups?d10ee6efe0ee
Manage Azure resource groups by using the Azure portalc2bc52250166
What is Azure Policy?0bc00fcd34d3
Understand Azure Policy effects6cb8a8ec40b0
Tutorial: Create and manage Azure budgets051db0341cf9
Topic Cram Sheet580 words

Cram sheet — Manage Microsoft Entra users and groups

AZ-104 › Unit 1 › Manage Microsoft Entra users and groups

Read full article

Cram sheet — Manage Microsoft Entra users and groups

Manage Microsoft Entra users and groups

Node
AZ104-U1.T1
Objectives
5
Bank questions
15
Grounded documents
5

The examinable detail in this topic is rarely what a group is. It is what the platform refuses to let you change afterwards, what a feature costs in licensing, and which default is already switched on in a tenant nobody has configured.

Four user types, not two

A workforce tenant distinguishes where the account lives from what privileges it carries, and those are two independent axes rather than one:

TypeAccount livesPrivileges
Internal memberIn your tenantMember
Internal guestIn your tenantGuest
External memberAuthenticates externallyMember
External guestAuthenticates externallyGuest

External member is the one people forget. Such users authenticate with an external account but hold member access to your tenant, which is common in multitenant organizations. Guest and external are not synonyms.

Groups: the settings you cannot take back

  • Creating a group needs at least the Groups Administrator or User Administrator role. Being a global reader or an owner of the resource is not enough.
  • Turning on Microsoft Entra roles can be assigned to the group automatically selects Assigned as the membership type — and once that option is enabled, the membership type can no longer be changed. A role-assignable group is therefore never a dynamic group.
  • Nesting is allowed for security groups, but a nested group does not gain access to resources and applications assigned to its parent. If the requirement is inherited access to an app, nesting is the wrong answer.

Dynamic membership is a licensed feature

  • Dynamic membership groups require Microsoft Entra ID P1 — or an Intune for Education licence — for each unique user who is a member of one or more of them.
  • The licences do not have to be assigned to those users individually; the organization simply has to hold enough of them to cover every such user. A thousand unique users across all dynamic groups means at least a thousand P1 licences.
  • Device-based dynamic groups need no licence for the devices themselves.

External users

  • A B2B guest signs in with their own credentials from their own organization, and appears in your directory as a user object whose user principal name contains the #EXT# identifier.
  • By default, every user in the organization — including existing guests — can invite more guests. Restricting that is a configuration change, not the starting state.
  • Two different settings are routinely confused. Cross-tenant access settings control whether users can authenticate with external Microsoft Entra tenants, inbound and outbound. External collaboration settings control which of your own users may send invitations at all.

Self-service password reset

  • SSPR is not enabled for administrators by default — the tenant setting is for end users.
  • If an Azure administrator role is assigned to the user, the strong two-gate password policy is enforced regardless of the tenant's own SSPR policy.
  • The policy decides how many registered methods a reset needs — one or two — and a user who has not registered enough of them is told to contact an administrator rather than being let through.

Read the question for the word that pins the answer

Role-assignable, dynamic, nested and guest are not descriptions in these stems — each one forecloses options. Role-assignable rules out dynamic membership. Nested rules out inherited application access. Dynamic brings a per-user licence requirement that a cost-constrained stem is usually testing.

Traps

Where Unit 1 Topic 1 catches people

Answering a dynamic-group question without the P1 licence consequence. Assuming a nested group inherits the parent's application access. Assuming guest invitation is restricted by default when it is open by default. Expecting SSPR to cover administrators because it is switched on for the tenant. Trying to change a role-assignable group's membership type after the fact.

Check yourself

Loading flashcards…

Where these figures come from

Every figure above was read from the raw documentation below on the day this sheet was written. The sha1 is git hash-object over the bytes as fetched, so a doc that changes underneath this sheet can be detected rather than assumed.

Documentsha1
Create, invite, and delete users7fa619c79ffb
Manage Microsoft Entra groups and group membership5e94c543e4b9
Dynamic membership rules for groupsc7bcd79f770a
B2B collaboration overviewb0768f637b07
How self-service password reset worksb614434fd03c

More Study Notes (25)

Unit 2 roadmap — Implement and manage storage

AZ-104 › Unit 2

375 words

Unit 2 capstone — A media archive on a budget

AZ-104 › Unit 2 › Capstone

808 words

Cram sheet — Configure access to storage

AZ-104 › Unit 2 › Configure access to storage

520 words

Cram sheet — Configure and manage storage accounts

AZ-104 › Unit 2 › Configure and manage storage accounts

421 words

Cram sheet — Configure Azure Files and Azure Blob Storage

AZ-104 › Unit 2 › Configure Azure Files and Azure Blob Storage

600 words

Lab — A lifecycle rule is a one-way door

AZ-104 › Unit 2 › Lab

180 words

Lab — Issue a signature you can actually revoke

AZ-104 › Unit 2 › Lab

216 words

Unit 3 roadmap — Deploy and manage Azure compute resources

AZ-104 › Unit 3

517 words

Cram sheet — Automate deployment by using ARM templates or Bicep files

AZ-104 › Unit 3 › Automate deployment by using ARM templates or Bicep files

398 words

Unit 3 capstone — Consolidating a mixed compute estate

AZ-104 › Unit 3 › Capstone

763 words

Cram sheet — Create and configure Azure App Service

AZ-104 › Unit 3 › Create and configure Azure App Service

577 words

Cram sheet — Create and configure virtual machines

AZ-104 › Unit 3 › Create and configure virtual machines

466 words

Lab — Watch an omitted property reset itself

AZ-104 › Unit 3 › Lab

186 words

Cram sheet — Provision and manage containers in the Azure portal

AZ-104 › Unit 3 › Provision and manage containers in the Azure portal

429 words

Unit 4 roadmap — Implement and manage virtual networking

AZ-104 › Unit 4

370 words

Unit 4 capstone — A hub-and-spoke that has to actually work

AZ-104 › Unit 4 › Capstone

763 words

Cram sheet — Configure and manage virtual networks in Azure

AZ-104 › Unit 4 › Configure and manage virtual networks in Azure

345 words

Cram sheet — Configure name resolution and load balancing

AZ-104 › Unit 4 › Configure name resolution and load balancing

394 words

Cram sheet — Configure secure access to virtual networks

AZ-104 › Unit 4 › Configure secure access to virtual networks

479 words

Lab — Prove a security group is stateful

AZ-104 › Unit 4 › Lab

190 words

Unit 5 roadmap — Monitor and maintain Azure resources

AZ-104 › Unit 5

389 words

Unit 5 capstone — The week after an incident

AZ-104 › Unit 5 › Capstone

711 words

Cram sheet — Implement backup and recovery

AZ-104 › Unit 5 › Implement backup and recovery

421 words

Lab — Find out what you can and cannot see about yesterday

AZ-104 › Unit 5 › Lab

196 words

Cram sheet — Monitor resources in Azure

AZ-104 › Unit 5 › Monitor resources in Azure

450 words

Ready to practice? Jump straight in — no sign-up needed.

Take practice tests, review flashcards, and read study notes right now.

Take a Practice Test

Microsoft Azure Administrator (AZ-104) Practice Questions

Try 15 sample questions from a bank of 448. Answers and detailed explanations included.

Q1medium

An operations lead assumes that configuring a budget will automatically shut down resources once spending crosses the limit. What does the documentation say?

A.

Budgets deallocate virtual machines at the 100% threshold by default

B.

Budgets pause the subscription until an administrator approves continued spending

C.

Thresholds trigger notifications only — resources aren't affected and consumption isn't stopped

D.

Budget enforcement applies only to Enterprise Agreement enrollments

Show answer & explanation

Correct Answer: C

The budget tutorial is explicit about scope of effect: "Notifications are triggered when the budget thresholds are exceeded. Resources aren't affected, and your consumption isn't stopped."

  • A — Incorrect. No built-in deallocation behavior exists; automation would require wiring an action group to Azure Functions/Logic Apps yourself.
  • B — Incorrect. No pausing mechanism accompanies budgets.
  • C — Correct. Verbatim documented behavior — budgets observe and notify, nothing more.
  • D — Incorrect. Budgets work at management group, subscription, and resource-group scopes across agreement types.

Answer: C

Q2easy

What is an Azure Resource Manager (ARM) template?

A.

A YAML manifest compiled into binaries at deploy time

B.

An imperative script that lists every API call in execution order

C.

A JSON file that defines the infrastructure and configuration for your project, written in declarative syntax

D.

A state file that tracks which resources were previously deployed

Show answer & explanation

Correct Answer: C

The documentation defines it directly: the template is a JavaScript Object Notation (JSON) file that defines the infrastructure and configuration for your project, and it uses declarative syntax — you state what you intend to deploy without writing the sequence of programming commands to create it.

  • A — Incorrect. ARM templates are JSON, not YAML, and nothing is compiled to binaries.
  • B — Incorrect. Imperative command sequences are exactly what declarative syntax avoids.
  • C — Correct. Verbatim definition.
  • D — Incorrect. Azure stores state server-side; there is no local state file to track.

Answer: C

Q3hard

One VM inside rg-app carries a CanNotDelete lock. An administrator issues a delete of the entire resource group. What happens?

A.

The resource group is deleted and the locked VM survives as an orphan

B.

Deletion proceeds because resource-group owners outrank locks

C.

The whole delete operation is blocked — a partial deletion is not possible

D.

Everything deletes except the locked VM's managed disk

Show answer & explanation

Correct Answer: C

The documentation addresses this scenario head-on: "If you have a Delete lock on a resource and attempt to delete its resource group, the feature blocks the whole delete operation. Even if the resource group or other resources in the resource group are unlocked, the deletion doesn't happen. A partial deletion isn't possible."

  • A — Incorrect. Orphaning is precisely what the lock prevents; the operation aborts wholesale.
  • B — Incorrect. "The lock overrides any user permissions."
  • C — Correct. Verbatim documented behavior — all-or-nothing.
  • D — Incorrect. There is no itemized carve-out; the delete never starts.

Answer: C

Q4medium

Since the September 30, 2025 deprecation took effect, where must authentication methods for SSPR be configured?

A.

In the converged Authentication methods policy.

B.

In each user's legacy per-user MFA enforcement settings.

C.

Through Conditional Access named locations.

D.

In the Registration tab of the Password reset pane.

Show answer & explanation

Correct Answer: A

Managing methods in the legacy MFA and SSPR policies ended on September 30, 2025 — the single remaining home for method configuration (which methods exist, targets, and SSPR/MFA enablement per method) is the Authentication methods policy.

  • A — Correct. Microsoft directed customers to migrate to the Authentication methods policy before the deprecation date.
  • B — Incorrect. Per-user legacy MFA management is part of what was deprecated.
  • C — Incorrect. Named locations shape Conditional Access decisions, not available authentication methods.
  • D — Incorrect. The Registration tab controls prompts/reconfirmation (e.g., the 180-day reconfirm interval), not which methods are allowed.

Answer: A

Q5medium

Every active download link for exports.zip came from service SAS tokens bound to stored policy p-share. You must invalidate all of them at once — without touching unrelated tokens. What do you do?

A.

Delete (or rename the ID of) the p-share stored access policy

B.

Regenerate both storage account access keys

C.

Shorten the SAS tokens' expiry via the policy, effective next calendar day

D.

Convert future links to user delegation SAS and wait for old ones to lapse

Show answer & explanation

Correct Answer: A

Revocation is a first-class capability of the construct: you can use a stored access policy to change the start time, expiry time, or permissions for a signature — and you can also use a stored access policy to revoke a signature, which deleting or renaming the policy accomplishes for everything signed under it.

  • A — Correct. Targeted revocation scoped exactly to the tokens hanging off p-share.
  • B — Incorrect. Works mechanically but is indiscriminate — every key-signed SAS account-wide dies too, violating the isolation requirement.
  • C — Incorrect. Policy edits can take up to 30 seconds to propagate but there is no next-calendar-day semantics; also editing expiry revokes rather than schedules.
  • D — Incorrect. Improves future hygiene but leaves the existing tokens live until natural expiry.

Answer: A

Q6easy

What hardware characteristic distinguishes Premium performance storage accounts from Standard ones?

A.

Magnetic spinning disks arranged in RAID sets

B.

In-memory caches fronting standard disks

C.

NVMe accelerators available only in paired regions

D.

Solid-state drives (SSDs) delivering low latency and high throughput

Show answer & explanation

Correct Answer: D

The documentation states it plainly: premium performance storage accounts use solid-state drives (SSDs) for low latency and high throughput.

  • A — Incorrect. Magnetic media describes nothing in the current account lineup.
  • D — Correct. Verbatim.
  • B — Incorrect. The distinction is disk class, not a caching layer.
  • C — Incorrect. Fabricated hardware detail.

Answer: D

Q7hard

A platform team is planning its governance estate. Per scope (management group or subscription), what is the maximum number of combined policy and initiative assignments?

A.

100

B.

250

C.

Unlimited — assignments are bounded only by subscription quotas

D.

200

Show answer & explanation

Correct Answer: D

The overview publishes Azure Policy object limits in a table. The relevant row reads: Scope — Policy or initiative assignments — maximum count 200.

  • A — Incorrect. 100 is not a published limit for assignments.
  • B — Incorrect. 250 appears nowhere in the limits table.
  • C — Incorrect. Assignments are explicitly capped per scope.
  • D — Correct. 200 assignments per scope, straight from the documented maximum counts. (For comparison: 500 policy definitions and 200 initiative definitions are allowed per scope.)

Answer: D

Q8medium

A route table holds a 10.0.0.0/24 route (next hop X) and a 10.0.0.0/16 route (next hop Y). Where does traffic for 10.0.0.5 go?

A.

To Y - broader prefixes take precedence

B.

Load-balanced across both routes

C.

Dropped - overlapping prefixes invalidate the table

D.

To X - the longest prefix (/24) matches and wins

Show answer & explanation

Correct Answer: D

Verbatim: Azure directs traffic destined for 10.0.0.5 to the next hop type specified in the route with the 10.0.0.0/24 address prefix. This process occurs because 10.0.0.0/24 is a longer prefix than 10.0.0.0/16, even though 10.0.0.5 falls within both address prefixes.

  • A - Incorrect. Broader never beats longer.
  • B - Incorrect. Route selection is deterministic, not distributed.
  • C - Incorrect. Overlap is normal; longest-prefix-match resolves it.
  • D - Correct. Longest prefix match sends 10.0.0.5 down the /24 route.

Answer: D

Q9medium

How does billing work for Azure Container Instances?

A.

Hourly rate per underlying VM size family, regardless of actual consumption

B.

A fixed monthly fee per container group

C.

Charged only while the container image is being pulled

D.

Per-second billing against the exact CPU-core and memory specifications you request

Show answer & explanation

Correct Answer: D

ACI lets you specify exact CPU cores and memory, and bills by the second based on what you request - so spend tracks actual need. (The restart-policy guidance repeats this: you are charged only for compute used while a task container runs.)

  • A - Incorrect. There is no VM-family hourly model; you never manage VMs.
  • B - Incorrect. No flat monthly group fee exists.
  • C - Incorrect. Pull time is not the billing unit.
  • D - Correct. Exact specification plus per-second billing.

Answer: D

Q10easy

Tailwind's region does not offer availability zones and the platform must survive planned maintenance under an availability SLA. What should the virtual machines be placed in?

A.

A proximity placement group, which guarantees maintenance is staggered

B.

An availability set holding two or more of the machines, which meets the 99.95% SLA at no extra cost

C.

A virtual machine scale set in a single zone, which is the only SLA-covered option

D.

Separate resource groups, so that maintenance events are scheduled independently

Show answer & explanation

Correct Answer: B

Availability sets exist for exactly this case — a region without zones — and the SLA attaches to having two or more machines in the set.

  • A — Incorrect. Proximity placement groups reduce latency; they do not stagger maintenance or carry this SLA.
  • B — Correct. Two or more VMs in an availability set, 99.95%, no extra cost for the set itself.
  • C — Incorrect. A single-zone scale set does not address a region without zones.
  • D — Incorrect. Resource groups are a management boundary and have no effect on maintenance.

Official doc: learn.microsoft.com/en-us/azure/virtual-machines/availability-set-overview — “Using two or more VMs in an availability set helps keep applications highly available and meets the 99.95% Azure service-level agreement (SLA).”

Answer: B

Q11medium

A UDR points at a firewall VM (virtual appliance) as next hop. Traffic arrives at the appliance but dies there. Which Azure setting did you most likely forget?

A.

Enable IP forwarding on the appliance network interface

B.

Disable BGP on the route table

C.

Set the appliance NIC to Static public IP allocation

D.

Enable accelerated networking on the workload VMs

Show answer & explanation

Correct Answer: A

Verbatim: Any network interface attached to a virtual machine that forwards network traffic to an address other than its own must have the Azure Enable IP forwarding option enabled for it. The setting disables the check of the source and destination for a network interface by Azure.

  • A - Correct. Without IP forwarding the platform drops packets whose destination differs from the NIC address - the classic dead-NVA symptom.
  • B - Incorrect. BGP state is irrelevant to a static UDR hop.
  • C - Incorrect. Public-IP allocation mode has no bearing on transit forwarding.
  • D - Incorrect. Accelerated networking speeds workloads; it does not authorize packet forwarding.

Answer: A

Q12medium

Northwind syncs its workforce from Windows Server Active Directory to Microsoft Entra ID with Microsoft Entra Connect. An administrator edits a synced employee's Job title directly in the Microsoft Entra admin center. What is the supported way to change this value?

A.

Change it in Windows Server Active Directory and wait for the next synchronization cycle to complete.

B.

Edit it in the Microsoft Entra admin center — Entra ID becomes the authoritative source for job information once saved.

C.

Delete and re-create the synchronized user with the corrected title.

D.

Assign the Hybrid Identity Administrator role, then the edit persists after the next sync.

Show answer & explanation

Correct Answer: A

For users sourced from Windows Server AD, identity, contact info, and job info are owned on-premises: edit them there and let Microsoft Entra Connect carry the change up on its next cycle.

  • A — Correct. The documentation states you "must use Windows Server Active Directory to update their identity, contact info, or job info" and wait for the next synchronization cycle.
  • B — Incorrect. Edits made in the cloud to these categories are overwritten on the next sync because the source of authority remains on-premises.
  • C — Incorrect. Re-creating a synced user is unnecessary and fights the connector.
  • D — Incorrect. No role makes a cloud-side job-info edit authoritative for a synced user.

Nuance the exam loves: some attributes remain Entra-owned even for synced users — notably Usage location, which you can still set in the admin center because licensing depends on it.

Answer: A

Q13medium

What are the documented scale-out instance maximums for the Basic, Standard, and Premium service plans (in that order)?

A.

10, 30, and 100 instances

B.

3, 30, and 100 instances

C.

5, 10, and 20 instances

D.

3, 10, and 30 instances

Show answer & explanation

Correct Answer: D

Verbatim: Basic, Standard, and Premium service plans scale out to as many as 3, 10, and 30 instances, respectively. Only App Service Environments in the Isolated tier push further, to 100 instances.

  • A - Incorrect. That sequence misassigns Basic to 10 and invents 100 for Premium; 100 is the ASE ceiling.
  • B - Incorrect. Basic caps at 3, not at 30 or 100.
  • C - Incorrect. Those numbers resemble slot counts and arbitrary mixes, not instance maxima.
  • D - Correct. 3 / 10 / 30 for Basic / Standard / Premium, exactly as documented.

Answer: D

Q14medium

What is the purpose of the cool-down period in an autoscale rule?

A.

After a scale action, the rule waits out its cool-down (five minutes by default) before triggering again, letting metrics stabilize and preventing repeated scaling for the same condition

B.

Cool-down pauses the entire application while new instances boot

C.

The default cool-down lasts 24 hours and applies only to scale-in rules

D.

Cool-down erases past scale events from the activity log

Show answer & explanation

Correct Answer: A

Verbatim: Autoscale evaluates the cool-down period configured on each candidate rule. After a scale operation, a rule is not eligible to initiate another scale action until its own cool-down period has elapsed. The cool-down period allows the metrics to stabilize and avoids scaling more than once for the same condition. The default cool-down period is five minutes.

  • A - Correct. Stabilization window, five-minute default, per-rule eligibility - all documented.
  • B - Incorrect. Cool-down throttles RULES, not applications; apps keep serving during scaling.
  • C - Incorrect. Five minutes, not 24 hours, and it applies to any rule that just fired.
  • D - Incorrect. Scale history lives in the activity log and Run history regardless of cool-down.

Answer: A

Q15medium

You plan to create a legacy managed image from an existing VM after running Sysprep. What limitation does the documentation attach to this flow?

A.

The VM must stay powered on throughout image creation

B.

Data disks are excluded from legacy managed images

C.

Images can only be created from Marketplace images, not custom VMs

D.

Once the VM is marked generalized, it cannot be restarted - and one managed image supports only up to 20 simultaneous deployments

Show answer & explanation

Correct Answer: D

Two constraints apply. First, once you mark a VM as generalized in Azure, you cannot restart the VM. Second, one managed image supports up to 20 simultaneous deployments - beyond that, provisioning timeouts can occur due to single-VHD storage limits, and the docs direct you to Azure Compute Gallery with roughly one replica per 20 concurrent deploys.

  • A - Incorrect. The capture flow requires the generalized VM to be deallocated.
  • B - Incorrect. Creating the image directly from the VM includes all associated disks, OS plus data.
  • C - Incorrect. Custom VMs are a supported source.
  • D - Correct. Both documented limitations stated.

Answer: D

These are 15 of 448 questions available. Take a practice test →

Microsoft Azure Administrator (AZ-104) Flashcards

254 flashcards for spaced-repetition study. Showing 30 sample cards below.

Apply and manage tags on resources(2 cards shown)

Question

How many tags can a resource, resource group or subscription carry?

Answer

50 tag name-value pairs, each.

If you need more, store a JSON string as a single tag value.

Question

Where do tags show up when you are analysing a bill?

Answer

In the Tags column of the cost view — for services that support tags with billing.

Assign roles at different scopes(5 cards shown)

Question

What are the four Azure scope levels, broadest to narrowest?

Answer

Management group → subscription → resource group → resource.

Question

How many custom roles can a tenant hold?

Answer

5,000.

Question

What are the three restrictions on a custom role's AssignableScopes?

Answer

  • It cannot be the root scope "/"
  • It cannot use wildcards (*)
  • It can name only one management group

Question

At which scope can a custom role containing DataActions never be assigned?

Answer

Management group scope. Custom roles with DataActions can't be assigned there.

Question

What must you do before a custom role can be deleted?

Answer

Remove every role assignment that uses it.

Otherwise the delete fails with There are existing role assignments referencing role (code: RoleDefinitionHasAssignments).

Configure and interpret backup reports and alerts(2 cards shown)

Question

Where do you find backup alerts, jobs, security and usage without configuring anything?

Answer

In the Overview pane of Resiliency, the Recovery Services vault and the Backup vault — available by default.

Question

What three protections does Azure Files backup give you?

Answer

  • Instant restore — file share snapshots, so you restore just the files you want
  • Soft delete enabled at the storage account level, 14-day retention
  • A lease on snapshots taken by backup jobs, locking them against accidental deletion

Configure an internal or public load balancer(3 cards shown)

Question

At which OSI layer does Azure Load Balancer operate, and what traffic does it distribute?

Answer

Layer 4. Use it to distribute TCP or UDP traffic across VMs or scale sets — it is the single point of contact for clients.

Question

What is Azure Load Balancer's default distribution mode, and what makes up the hash?

Answer

Five-tuple hash — source IP, source port, destination IP, destination port, and protocol type.

Question

How many tuples does each session persistence mode use?

Answer

modetupleseffect
Nonefivesame client IP → any healthy instance
Client IPtwosame client IP → same instance
Client IP and protocolthreesame client IP and protocol → same instance

Configure Azure DNS(4 cards shown)

Question

What must you do to resolve a private DNS zone's records from a virtual network?

Answer

Link the virtual network to the zone.

The zone data is stored as a global resource, so it isn't tied to any one virtual network or region.

Question

Do two virtual networks need to be peered to resolve names across them?

Answer

No. Cross-virtual-network DNS resolution has no explicit dependency on the networks being peered.

Question

How many private DNS zones can a virtual network link to with autoregistration enabled?

Answer

One. A virtual network links to only one zone when autoregistration is on — though many virtual networks can link to a single zone.

Question

What does DNS autoregistration not cover?

Answer

  • Non-VM resources such as internal load balancers — create those records manually
  • Secondary NICs — only the primary NIC gets a record
  • Reverse (PTR) records — not supported at all

Records are removed when the VM is deleted or stopped.

Configure Azure Site Recovery for Azure resources(3 cards shown)

Question

What does Azure Site Recovery do?

Answer

Replicates workloads running on physical and virtual machines from a primary site to a secondary location, keeping business apps running during outages.

Question

What does a recovery plan define, and how many instances can it hold?

Answer

How machines fail over and the sequence in which they start afterwards, by gathering them into recovery groups.

Up to 100 protected instances per plan, usable for both failover to and failback from Azure.

Question

Which network should a test failover use, and why?

Answer

One isolated from the production recovery site network, set per VM in Compute and Network settings — so the drill can't disturb production.

Configure Azure Storage firewalls and virtual networks(3 cards shown)

Question

What network access does a brand-new storage account allow?

Answer

Connections from any network. Storage accounts allow this by default — restricting access is something you turn on.

Question

How many virtual network rules and IP network rules can one storage account hold?

Answer

400 of each — up to 400 virtual network rules and up to 400 IP network rules per storage account.

Question

You enable a service endpoint on a subnet. What happens to the IP rules that used to permit that subnet?

Answer

They stop having any effect.

Traffic from a service-endpoint subnet no longer uses a public IP address to reach the storage account, so an IP rule has nothing left to match.

Configure Azure Storage redundancy(5 cards shown)

Question

What does LRS replicate across, and what durability does it give?

Answer

A single physical datacenter in the primary region — and at least 99.999999999% (11 nines) durability over a year.

Question

What does ZRS copy across, and is the write synchronous?

Answer

Three or more availability zones in the primary region, and yes — synchronously.

A ZRS write returns successfully only after the data is written to all replicas across the three zones.

Question

With plain GRS, can you read the secondary copy?

Answer

No — not unless a failover happens.

For read access to the secondary you need RA-GRS or RA-GZRS. Geo-redundancy and read access are two separate purchases.

Question

What is the only difference between GRS and GZRS?

Answer

How the data is replicated in the primary region — LRS for GRS, ZRS for GZRS.

In the secondary region both are identical: always replicated synchronously using LRS.

Question

Which redundancy option does Azure Files not support?

Answer

RA-GRS and RA-GZRS — the read-access variants.

Configure backup for an App Service(3 cards shown)

Question

Which tiers support App Service backup, and what is special about Basic?

Answer

Basic, Standard, Premium and Isolated.

On Basic you can only back up and restore the production slot.

Question

What is the maximum size of a custom App Service backup?

Answer

10 GB, of which at most 4 GB can be the linked database.

Exceed 10 GB of content and the backup fails — that is the maximum you can back up at a time.

Question

How often can custom backups run, and what constrains a restore target?

Answer

Every 2 hours minimum, up to 12 backups per day (manual plus scheduled).

Backups restore only to a target app on the same OS platform as the source.

Showing 30 of 254 flashcards. Study all flashcards →

Related Study Resources

Explore other free certification prep and study materials on BrainyBee.

AWS Certified Cloud Practitioner (CLF-C02)

854 questions · 163 notes

AWS Certified Solutions Architect - Associate (SAA-C03)

1408 questions · 204 notes

AWS Certified Machine Learning Engineer - Associate (MLA-C01)

724 questions · 160 notes

AWS Certified CloudOps Engineer - Associate (SOA-C03)

840 questions · 148 notes

AWS Certified Security - Specialty (SCS-C03)

980 questions · 130 notes

AWS Certified AI Practitioner (AIF-C01)

353 questions · 145 notes

AWS Certified Advanced Networking - Specialty (ANS-C01)

1156 questions · 231 notes

Microsoft Azure AI Fundamentals (AI-901)

663 questions · 89 notes

Ready to ace Microsoft Azure Administrator (AZ-104)?

Access all 448 practice questions, 6 timed mock exams, study notes, and flashcards — no sign-up required.

Start Studying — Free
Explore All HivesBlogHome

© 2026 BrainyBee. Free AI-powered exam prep.

Blueprint retrieval

Card 1 of 3

Front of flashcard 1 of 3

Which two skill areas carry the highest published range, and what is it?

medium

Manage Azure identities and governance, and Deploy and manage Azure compute resources — both 20–25%.

az-104az104:exam-mapretrieval

Blueprint retrieval

Card 1

Front

Which two skill areas carry the highest published range, and what is it?

Back

Manage Azure identities and governance, and Deploy and manage Azure compute resources — both 20–25%.

Card 2

Front

How many questions does the AZ-104 exam contain?

Back

Microsoft does not publish a question count. Any specific number you see quoted is an estimate.

Card 3

Front

What is the passing score, and on what scale?

Back

700, on a scale of 1000 — a scaled score, not a percentage of questions answered correctly.

Blueprint retrieval

Card 1

Front

Which two skill areas carry the highest published range, and what is it?

Back

Manage Azure identities and governance, and Deploy and manage Azure compute resources — both 20–25%.

Card 2

Front

How many questions does the AZ-104 exam contain?

Back

Microsoft does not publish a question count. Any specific number you see quoted is an estimate.

Card 3

Front

What is the passing score, and on what scale?

Back

700, on a scale of 1000 — a scaled score, not a percentage of questions answered correctly.

Unit 1 retrieval check

Card 1 of 3

Front of flashcard 1 of 3

In one sentence, what is Unit 1 really testing?

easy

Whether you can put the right permission or control at the right SCOPE — management group, subscription, resource group, or resource.

az-104az104:unit:1retrieval

Unit 1 retrieval check

Card 1

Front

In one sentence, what is Unit 1 really testing?

Back

Whether you can put the right permission or control at the right SCOPE — management group, subscription, resource group, or resource.

Card 2

Front

Which two access systems does this unit deliberately keep separate?

Back

Microsoft Entra directory roles, which govern the directory, and Azure role-based access control, which governs resources.

Card 3

Front

What does Azure Policy govern, and what does it NOT govern?

Back

It governs the state a resource is allowed to be in. It does not grant, deny or interpret anyone's access.

Unit 1 retrieval check

Card 1

Front

In one sentence, what is Unit 1 really testing?

Back

Whether you can put the right permission or control at the right SCOPE — management group, subscription, resource group, or resource.

Card 2

Front

Which two access systems does this unit deliberately keep separate?

Back

Microsoft Entra directory roles, which govern the directory, and Azure role-based access control, which governs resources.

Card 3

Front

What does Azure Policy govern, and what does it NOT govern?

Back

It governs the state a resource is allowed to be in. It does not grant, deny or interpret anyone's access.

Unit 1 capstone review

Card 1 of 3

Front of flashcard 1 of 3

Grant access to others, but change nothing. Which role?

hard

User Access Administrator. Contributor cannot assign roles; Owner can change resources too.

az-104az104:unit:1capstone

Unit 1 capstone review

Card 1

Front

Grant access to others, but change nothing. Which role?

Back

User Access Administrator. Contributor cannot assign roles; Owner can change resources too.

Card 2

Front

A resource group is tagged. Are its resources?

Back

No. Resources do not inherit tags from a resource group or subscription — use a policy to apply them.

Card 3

Front

Finance wants spending stopped at a threshold. Can a budget do that?

Back

No. It notifies; resources are not affected and consumption is not stopped.

Unit 1 capstone review

Card 1

Front

Grant access to others, but change nothing. Which role?

Back

User Access Administrator. Contributor cannot assign roles; Owner can change resources too.

Card 2

Front

A resource group is tagged. Are its resources?

Back

No. Resources do not inherit tags from a resource group or subscription — use a policy to apply them.

Card 3

Front

Finance wants spending stopped at a threshold. Can a budget do that?

Back

No. It notifies; resources are not affected and consumption is not stopped.

Cram check — Manage access to Azure resources

Card 1 of 5

Front of flashcard 1 of 5

What are the three elements of a role assignment?

easy

A security principal, a role definition, and a scope.

az-104az104:unit:1cram

Cram check — Manage access to Azure resources

Card 1

Front

What are the three elements of a role assignment?

Back

A security principal, a role definition, and a scope.

Card 2

Front

What are the four scope levels, and which way does inheritance flow?

Back

Management group, subscription, resource group, resource. Lower levels inherit permissions from higher levels — downwards only.

Card 3

Front

What separates Owner from Contributor?

Back

The ability to assign roles in Azure RBAC. Contributor manages everything else but cannot grant access to others.

Card 4

Front

Can you create a deny assignment?

Back

Not directly — Azure creates and manages them. They block actions even when a role assignment grants them.

Card 5

Front

How many custom roles may one tenant hold?

Back

5,000. For Microsoft Azure operated by 21Vianet, the limit is 2,000.

Cram check — Manage access to Azure resources

Card 1

Front

What are the three elements of a role assignment?

Back

A security principal, a role definition, and a scope.

Card 2

Front

What are the four scope levels, and which way does inheritance flow?

Back

Management group, subscription, resource group, resource. Lower levels inherit permissions from higher levels — downwards only.

Card 3

Front

What separates Owner from Contributor?

Back

The ability to assign roles in Azure RBAC. Contributor manages everything else but cannot grant access to others.

Card 4

Front

Can you create a deny assignment?

Back

Not directly — Azure creates and manages them. They block actions even when a role assignment grants them.

Card 5

Front

How many custom roles may one tenant hold?

Back

5,000. For Microsoft Azure operated by 21Vianet, the limit is 2,000.

Cram check — Manage Azure subscriptions and governance

Card 1 of 8

Front of flashcard 1 of 8

What are the two lock levels called on the command line?

medium

CanNotDelete and ReadOnly — the portal calls the same two Delete and Read-only.

az-104az104:unit:1cram

Cram check — Manage Azure subscriptions and governance

Card 1

Front

What are the two lock levels called on the command line?

Back

CanNotDelete and ReadOnly — the portal calls the same two Delete and Read-only.

Card 2

Front

How many tags can one resource carry, and are they inherited?

Back

50 name-value pairs, and no — resources do not inherit tags from a resource group or subscription. Use a policy to apply them.

Card 3

Front

How deep can a management group tree go, and how many parents may a subscription have?

Back

Six levels of depth, and exactly one parent.

Card 4

Front

Does exceeding a budget stop consumption?

Back

No. Notifications are triggered; resources are not affected and consumption is not stopped. Budgets are evaluated every 24 hours.

Card 5

Front

Which policy effect is evaluated first, and why does the order matter?

Back

disabled, to decide whether the rule runs at all. Order matters because append and modify can alter a request enough to stop deny or audit from firing.

Card 6

Front

Must every resource in a resource group be in the same region as the group?

Back

No. The group's location is where its METADATA lives; resources inside it can be in different regions.

Card 7

Front

Someone has permission to create a resource, but policy says the result is non-compliant. What happens?

Back

Policy still blocks the create or update. Permission is not sufficient — compliance is a second, independent gate.

Card 8

Front

Which lock wins when two are inherited?

Back

The most restrictive lock in the inheritance chain takes precedence.

Cram check — Manage Azure subscriptions and governance

Card 1

Front

What are the two lock levels called on the command line?

Back

CanNotDelete and ReadOnly — the portal calls the same two Delete and Read-only.

Card 2

Front

How many tags can one resource carry, and are they inherited?

Back

50 name-value pairs, and no — resources do not inherit tags from a resource group or subscription. Use a policy to apply them.

Card 3

Front

How deep can a management group tree go, and how many parents may a subscription have?

Back

Six levels of depth, and exactly one parent.

Card 4

Front

Does exceeding a budget stop consumption?

Back

No. Notifications are triggered; resources are not affected and consumption is not stopped. Budgets are evaluated every 24 hours.

Card 5

Front

Which policy effect is evaluated first, and why does the order matter?

Back

disabled, to decide whether the rule runs at all. Order matters because append and modify can alter a request enough to stop deny or audit from firing.

Card 6

Front

Must every resource in a resource group be in the same region as the group?

Back

No. The group's location is where its METADATA lives; resources inside it can be in different regions.

Card 7

Front

Someone has permission to create a resource, but policy says the result is non-compliant. What happens?

Back

Policy still blocks the create or update. Permission is not sufficient — compliance is a second, independent gate.

Card 8

Front

Which lock wins when two are inherited?

Back

The most restrictive lock in the inheritance chain takes precedence.

Cram check — Manage Microsoft Entra users and groups

Card 1 of 6

Front of flashcard 1 of 6

Are 'external' and 'guest' the same thing in a workforce tenant?

hard

No. An EXTERNAL MEMBER authenticates with an external account but holds member access. Where the account lives and what it may do are independent.

az-104az104:unit:1cram

Cram check — Manage Microsoft Entra users and groups

Card 1

Front

Are 'external' and 'guest' the same thing in a workforce tenant?

Back

No. An EXTERNAL MEMBER authenticates with an external account but holds member access. Where the account lives and what it may do are independent.

Card 2

Front

What does enabling 'Microsoft Entra roles can be assigned to the group' do to membership type?

Back

It selects Assigned automatically, and the membership type can no longer be changed. So a role-assignable group is never dynamic.

Card 3

Front

Who needs a Microsoft Entra ID P1 licence for dynamic membership groups?

Back

Every unique USER who is a member of one or more of them. Devices in device-based dynamic groups need none.

Card 4

Front

By default, who can invite B2B guests?

Back

All users in the organization, including existing B2B guest users. Restricting it is a change you make, not the default.

Card 5

Front

Does a nested group inherit the parent group's access to an application?

Back

No. Nested groups do not gain access to shared resources and applications assigned to the parent group.

Card 6

Front

Is SSPR on for administrators by default?

Back

No — the tenant setting is for end users. And where an Azure administrator role is assigned, the strong two-gate policy applies.

Cram check — Manage Microsoft Entra users and groups

Card 1

Front

Are 'external' and 'guest' the same thing in a workforce tenant?

Back

No. An EXTERNAL MEMBER authenticates with an external account but holds member access. Where the account lives and what it may do are independent.

Card 2

Front

What does enabling 'Microsoft Entra roles can be assigned to the group' do to membership type?

Back

It selects Assigned automatically, and the membership type can no longer be changed. So a role-assignable group is never dynamic.

Card 3

Front

Who needs a Microsoft Entra ID P1 licence for dynamic membership groups?

Back

Every unique USER who is a member of one or more of them. Devices in device-based dynamic groups need none.

Card 4

Front

By default, who can invite B2B guests?

Back

All users in the organization, including existing B2B guest users. Restricting it is a change you make, not the default.

Card 5

Front

Does a nested group inherit the parent group's access to an application?

Back

No. Nested groups do not gain access to shared resources and applications assigned to the parent group.

Card 6

Front

Is SSPR on for administrators by default?

Back

No — the tenant setting is for end users. And where an Azure administrator role is assigned, the strong two-gate policy applies.