BrainyBeeBrainyBee
ExploreBlogStart Studying
HomeMicrosoft Azure Administrator (AZ-104)Cram sheet — Manage Microsoft Entra users and groups
Topic Cram Sheet580 words

Cram sheet — Manage Microsoft Entra users and groups

AZ-104 › Unit 1 › Manage Microsoft Entra users and groups

Cram sheet — Manage Microsoft Entra users and groups

Manage Microsoft Entra users and groups

Node
AZ104-U1.T1
Objectives
5
Bank questions
15
Grounded documents
5

The examinable detail in this topic is rarely what a group is. It is what the platform refuses to let you change afterwards, what a feature costs in licensing, and which default is already switched on in a tenant nobody has configured.

Four user types, not two

A workforce tenant distinguishes where the account lives from what privileges it carries, and those are two independent axes rather than one:

TypeAccount livesPrivileges
Internal memberIn your tenantMember
Internal guestIn your tenantGuest
External memberAuthenticates externallyMember
External guestAuthenticates externallyGuest

External member is the one people forget. Such users authenticate with an external account but hold member access to your tenant, which is common in multitenant organizations. Guest and external are not synonyms.

Groups: the settings you cannot take back

  • Creating a group needs at least the Groups Administrator or User Administrator role. Being a global reader or an owner of the resource is not enough.
  • Turning on Microsoft Entra roles can be assigned to the group automatically selects Assigned as the membership type — and once that option is enabled, the membership type can no longer be changed. A role-assignable group is therefore never a dynamic group.
  • Nesting is allowed for security groups, but a nested group does not gain access to resources and applications assigned to its parent. If the requirement is inherited access to an app, nesting is the wrong answer.

Dynamic membership is a licensed feature

  • Dynamic membership groups require Microsoft Entra ID P1 — or an Intune for Education licence — for each unique user who is a member of one or more of them.
  • The licences do not have to be assigned to those users individually; the organization simply has to hold enough of them to cover every such user. A thousand unique users across all dynamic groups means at least a thousand P1 licences.
  • Device-based dynamic groups need no licence for the devices themselves.

External users

  • A B2B guest signs in with their own credentials from their own organization, and appears in your directory as a user object whose user principal name contains the #EXT# identifier.
  • By default, every user in the organization — including existing guests — can invite more guests. Restricting that is a configuration change, not the starting state.
  • Two different settings are routinely confused. Cross-tenant access settings control whether users can authenticate with external Microsoft Entra tenants, inbound and outbound. External collaboration settings control which of your own users may send invitations at all.

Self-service password reset

  • SSPR is not enabled for administrators by default — the tenant setting is for end users.
  • If an Azure administrator role is assigned to the user, the strong two-gate password policy is enforced regardless of the tenant's own SSPR policy.
  • The policy decides how many registered methods a reset needs — one or two — and a user who has not registered enough of them is told to contact an administrator rather than being let through.

Read the question for the word that pins the answer

Role-assignable, dynamic, nested and guest are not descriptions in these stems — each one forecloses options. Role-assignable rules out dynamic membership. Nested rules out inherited application access. Dynamic brings a per-user licence requirement that a cost-constrained stem is usually testing.

Traps

Where Unit 1 Topic 1 catches people

Answering a dynamic-group question without the P1 licence consequence. Assuming a nested group inherits the parent's application access. Assuming guest invitation is restricted by default when it is open by default. Expecting SSPR to cover administrators because it is switched on for the tenant. Trying to change a role-assignable group's membership type after the fact.

Check yourself

Loading flashcards…

Where these figures come from

Every figure above was read from the raw documentation below on the day this sheet was written. The sha1 is git hash-object over the bytes as fetched, so a doc that changes underneath this sheet can be detected rather than assumed.

Documentsha1
Create, invite, and delete users7fa619c79ffb
Manage Microsoft Entra groups and group membership5e94c543e4b9
Dynamic membership rules for groupsc7bcd79f770a
B2B collaboration overviewb0768f637b07
How self-service password reset worksb614434fd03c
All Microsoft Azure Administrator (AZ-104) Study Resources

Related Notes

  • AZ-104 exam map391 words
  • Unit 1 roadmap — Manage Azure identities and governance358 words
  • Unit 1 capstone — Onboarding an acquired subsidiary810 words
  • Lab — A budget notifies and stops nothing166 words
  • Lab — Prove that inheritance only flows one way212 words
  • Lab — Tags do not inherit, and a lock is not a permission204 words
  • Lab — Watch a dynamic group fill itself in183 words
  • Cram sheet — Manage access to Azure resources447 words
  • Cram sheet — Manage Azure subscriptions and governance841 words
  • Unit 2 roadmap — Implement and manage storage375 words
  • Unit 2 capstone — A media archive on a budget808 words
  • Cram sheet — Configure access to storage520 words

Ready to study Microsoft Azure Administrator (AZ-104)?

Practice tests, flashcards, and all study notes — free, no sign-up.

Start Studying

Ready to study Microsoft Azure Administrator (AZ-104)?

Practice tests, flashcards, and all study notes — free, no sign-up needed.

Start Studying — Free
Microsoft Azure Administrator (AZ-104) ResourcesExplore All HivesBlogHome

© 2026 BrainyBee. Free AI-powered exam prep.

Cram check — Manage Microsoft Entra users and groups

Card 1 of 6

Front of flashcard 1 of 6

Are 'external' and 'guest' the same thing in a workforce tenant?

hard

No. An EXTERNAL MEMBER authenticates with an external account but holds member access. Where the account lives and what it may do are independent.

az-104az104:unit:1cram

Cram check — Manage Microsoft Entra users and groups

Card 1

Front

Are 'external' and 'guest' the same thing in a workforce tenant?

Back

No. An EXTERNAL MEMBER authenticates with an external account but holds member access. Where the account lives and what it may do are independent.

Card 2

Front

What does enabling 'Microsoft Entra roles can be assigned to the group' do to membership type?

Back

It selects Assigned automatically, and the membership type can no longer be changed. So a role-assignable group is never dynamic.

Card 3

Front

Who needs a Microsoft Entra ID P1 licence for dynamic membership groups?

Back

Every unique USER who is a member of one or more of them. Devices in device-based dynamic groups need none.

Card 4

Front

By default, who can invite B2B guests?

Back

All users in the organization, including existing B2B guest users. Restricting it is a change you make, not the default.

Card 5

Front

Does a nested group inherit the parent group's access to an application?

Back

No. Nested groups do not gain access to shared resources and applications assigned to the parent group.

Card 6

Front

Is SSPR on for administrators by default?

Back

No — the tenant setting is for end users. And where an Azure administrator role is assigned, the strong two-gate policy applies.

Cram check — Manage Microsoft Entra users and groups

Card 1

Front

Are 'external' and 'guest' the same thing in a workforce tenant?

Back

No. An EXTERNAL MEMBER authenticates with an external account but holds member access. Where the account lives and what it may do are independent.

Card 2

Front

What does enabling 'Microsoft Entra roles can be assigned to the group' do to membership type?

Back

It selects Assigned automatically, and the membership type can no longer be changed. So a role-assignable group is never dynamic.

Card 3

Front

Who needs a Microsoft Entra ID P1 licence for dynamic membership groups?

Back

Every unique USER who is a member of one or more of them. Devices in device-based dynamic groups need none.

Card 4

Front

By default, who can invite B2B guests?

Back

All users in the organization, including existing B2B guest users. Restricting it is a change you make, not the default.

Card 5

Front

Does a nested group inherit the parent group's access to an application?

Back

No. Nested groups do not gain access to shared resources and applications assigned to the parent group.

Card 6

Front

Is SSPR on for administrators by default?

Back

No — the tenant setting is for end users. And where an Azure administrator role is assigned, the strong two-gate policy applies.