AZ-104 sample questions with answers

10 free practice questions for the Microsoft Certified: Azure Administrator Associate exam. Try each one, then open the answer to see why the right option wins and every other option loses.

Question 1Manage Azure identities and governance

Humongous Insurance assigns a policy initiative at the tenant root management group that denies the creation of public IP addresses. A subscription named Sub-Lab is used for a proof of concept and must be allowed to create public IP addresses for the next 90 days only, after which the restriction must return automatically. You must not change what the assignment enforces anywhere else. What should you create?

  1. A.

    A second assignment of the same initiative on Sub-Lab with the effect set to Audit

  2. B.

    A new management group for Sub-Lab that has no policy assignment

  3. C.

    A policy exemption on Sub-Lab with an expiry date 90 days from now

  4. D.

    An excluded scope for Sub-Lab on the existing policy assignment

Show answer

Answer: C

Only a policy exemption supports an expiry date, so the restriction returns automatically after 90 days without anyone remembering to act.

  • A. A second assignment cannot weaken an inherited one; when several assignments apply, the most restrictive effect, Deny, wins.
  • B. Assignments made at the tenant root management group are inherited by every descendant, so a new management group would still inherit the Deny.
  • C. Exemptions are separate objects that support an expiresOn date, so enforcement resumes automatically when the waiver lapses.
  • D. An excluded scope has no expiry and requires editing the tenant root assignment, so the restriction would never return by itself.
Question 2Manage Azure identities and governance

Contoso uses group-based licensing to assign Microsoft 365 E3 to a group named All-Engineers. After 40 new engineers are added to the group, 12 of them show the licence assignment error "Usage location is not allowed" on the group's Licences page. The other 28 receive the licence normally. You must clear the errors with the least administrative effort. What should you do?

  1. A.

    Remove the 12 users from All-Engineers and assign the Microsoft 365 E3 licence to them directly

  2. B.

    Set the Usage location property of each affected user to a country where the service is available

  3. C.

    Turn off the unavailable service plans on the All-Engineers licence assignment

  4. D.

    Purchase additional Microsoft 365 E3 licences for the tenant

Show answer

Answer: B

The error names the cause: those users have a usage location where the product cannot be sold, so setting a supported usage location clears it.

  • A. Direct assignment enforces exactly the same usage location prerequisite, so the error would simply reappear, and it abandons group-based licensing for those users.
  • B. Usage location is the property the error names; setting it to a supported country lets Entra ID retry and complete the assignment automatically.
  • C. Disabling service plans changes the entitlement for every member of the group and does nothing about a missing or disallowed usage location.
  • D. Insufficient licences produce a different error; 28 members were licensed successfully, which proves the tenant still has available seats.
Question 3Manage Azure identities and governance

A subscription named Sub-Marketing is currently paid for by the IT department. From next quarter the marketing department must receive and pay the invoice instead. The resources in the subscription must not move and the administrators who manage them must keep their access. What should you do?

  1. A.

    Create a budget on Sub-Marketing scoped to the marketing department

  2. B.

    Change the Microsoft Entra directory that Sub-Marketing is associated with

  3. C.

    Move Sub-Marketing to a management group named MG-Marketing

  4. D.

    Transfer billing ownership of Sub-Marketing to the marketing department's billing account

Show answer

Answer: D

Transferring billing ownership changes who pays for the subscription while leaving the resources, the directory and the role assignments intact.

  • A. A budget monitors and alerts on spend against a threshold; it does not change the billing relationship.
  • B. Changing the directory permanently deletes all Azure role assignments and has no effect on who pays the invoice.
  • C. Management groups organise subscriptions for policy and access inheritance; they play no part in billing.
  • D. Billing ownership transfer changes who is invoiced while leaving resources, the directory and role assignments unchanged.
Question 4Manage Azure identities and governance

A budget of USD 20,000 a month exists on a subscription. The finance lead must be warned while there is still time to act, before the money is actually spent. Which budget alert condition should you use?

  1. A.

    Actual

  2. B.

    Credit

  3. C.

    Department spending quota

  4. D.

    Forecasted

Show answer

Answer: D

A Forecasted alert fires when the projected spend for the period will cross the threshold, giving warning before the money is spent.

  • A. Actual compares accumulated cost, so it can only fire after the money has already been spent.
  • B. Credit alerts fire automatically against an Azure Prepayment balance on an Enterprise Agreement; they are not a budget condition.
  • C. Department spending quota alerts apply to Enterprise Agreement departments and are not configured on a budget.
  • D. Forecasted evaluates the projected spend for the period, so the alert arrives before the threshold is actually reached.
Question 5Manage Azure identities and governance

Contoso Suites must give 180 support engineers the Virtual Machine Contributor role on the same resource group. Membership of the support team changes weekly. You must keep the number of role assignments in the subscription as low as possible and make joiner and leaver changes cheap. What should you do?

  1. A.

    Create a Microsoft Entra security group for the support engineers and create one Virtual Machine Contributor assignment for that group on the resource group

  2. B.

    Assign Virtual Machine Contributor to each engineer at the subscription and use a deny assignment to limit them to the resource group

  3. C.

    Create a custom role that lists the 180 engineers and assign it on the resource group

  4. D.

    Create a Virtual Machine Contributor assignment for each engineer on the resource group

Show answer

Answer: A

Assigning the role to one security group replaces 180 assignments with one, and membership changes then need no role assignment work at all.

  • A. One assignment to a group covers all 180 engineers, and joiner and leaver changes become membership changes rather than assignment changes.
  • B. Deny assignments cannot be created directly; they are produced only by Azure Blueprints and Azure managed applications.
  • C. A custom role defines permissions, not membership; there is no list of users inside a role definition.
  • D. This creates 180 assignments against the subscription's limit and requires an assignment change for every joiner and leaver.
Question 6Manage Azure identities and governance

A colleague must be able to assign and remove product licences for users and groups in your Microsoft Entra tenant, and must be able to do nothing else. Which built-in Microsoft Entra role should you assign?

  1. A.

    License Administrator

  2. B.

    Global Administrator

  3. C.

    Billing Administrator

  4. D.

    User Administrator

Show answer

Answer: A

License Administrator is the least privileged built-in role that manages licence assignment and nothing else.

  • A. License Administrator assigns and removes licences for users and groups and sets usage location, with no other directory rights.
  • B. Global Administrator grants every permission in the tenant and should be reserved for emergency scenarios.
  • C. Billing Administrator buys subscriptions and seats but does not assign licences to users or groups.
  • D. User Administrator can assign licences but also creates and deletes users and manages groups, which exceeds the requirement.
Question 7Manage Azure identities and governance

Finance at Blue Yonder Airlines needs each month's Azure spend split by business unit. You tag every resource with a BusinessUnit tag on 14 May and then group the current month's costs by that tag in Cost analysis. Most of the month's cost appears under a group with no tag value. Why?

  1. A.

    Cost analysis can group by resource group but not by tag

  2. B.

    Tag values are case-sensitive, so the values were split into separate groups

  3. C.

    Cost data is not retagged retrospectively, so usage recorded before the tags were applied carries no tag value

  4. D.

    A resource must carry at least two tags before Cost analysis will group by either of them

Show answer

Answer: C

Tags are stamped onto usage records as the usage is emitted, so costs incurred before the tag existed are untagged for ever.

  • A. Cost analysis supports grouping and filtering by tag; that capability is one of the main purposes of tagging.
  • B. Case sensitivity is real but would produce several named groups rather than one large group with no tag value.
  • C. Tags are stamped onto usage records as they are emitted, so usage from before the tag was applied has no tag value and is never rewritten.
  • D. There is no minimum tag count; a single tag is enough to group by in Cost analysis.
Question 8Manage Azure identities and governance

When a colleague creates a resource group he is asked to choose a region, and he asks whether that choice restricts where the resources in the group can be deployed. What should you tell him?

  1. A.

    The region stores the resource group's metadata, and the group can contain resources from any region

  2. B.

    The region determines where the resources are billed from

  3. C.

    The region is only a label and has no effect at all

  4. D.

    The region restricts the group to resources deployed in that region

Show answer

Answer: A

A resource group's region holds only its metadata; the group can contain resources from any region.

  • A. The location stores the resource group's metadata only, and the group may contain resources from any Azure region.
  • B. Each resource is billed at the rates of the region it runs in, independently of the resource group's location.
  • C. It is not merely a label: it determines where the group's metadata resides, which matters for residency and for availability of management operations.
  • D. There is no such restriction; restricting deployment regions is what the Allowed locations policy definition is for.
Question 9Manage Azure identities and governance

An engineer must be able to create, rename and delete child management groups under a management group named MG-Corp. She must not be able to assign policies or roles at those management groups, and must not gain any ability to manage resources in the subscriptions beneath them. Which built-in role should you assign at MG-Corp?

  1. A.

    Management Group Reader

  2. B.

    Contributor

  3. C.

    Management Group Contributor

  4. D.

    Resource Policy Contributor

Show answer

Answer: C

Management Group Contributor acts only on management group objects, so it creates, renames, moves and deletes them without touching resources, policy or access.

  • A. Management Group Reader can view the hierarchy but cannot create, rename or delete management groups.
  • B. Contributor at a management group inherits full resource management to every subscription beneath it, which the requirement forbids.
  • C. Management Group Contributor creates, renames, moves and deletes management groups only, granting no policy, access or resource rights.
  • D. Resource Policy Contributor manages policy objects, which is exactly the capability the requirement excludes.
Question 10Manage Azure identities and governance

You attempt to move a virtual machine from a resource group in one subscription to a resource group in another subscription. Validation fails with the error code MissingMoveDependentResources. What should you do?

  1. A.

    Delete the virtual machine's diagnostic settings and retry the move

  2. B.

    Include the virtual machine's managed disks, network interface, virtual network and other dependent resources in the same move request

  3. C.

    Deallocate the virtual machine and retry the move

  4. D.

    Register the Microsoft.Compute and Microsoft.Network resource providers in the source subscription, and then run the move validation again

Show answer

Answer: B

A cross-subscription move must include every dependent resource, and MissingMoveDependentResources names the ones that were left out.

  • A. Diagnostic settings are extension resources that move with their parent and do not block the operation.
  • B. The error means a dependency was omitted; the virtual machine and every resource it depends on must move together in one request.
  • C. A virtual machine does not need to be deallocated to move, and its power state is unrelated to this error.
  • D. An unregistered provider raises a different error, and it is the destination subscription that must be registered for the resource type.

Keep going with 562 more AZ-104 questions

Free papers every day, in the real exam formats, with progress by exam domain. Unlock every paper and timed mock exam when you are ready.

AZ-104 sample questions with answers (10 free) · CertifyCloudx