AZ-104 identities and governance explained
Manage Azure identities and governance is one of the two largest AZ-104 domains at 20–25%. It covers three things: users and groups in Microsoft Entra ID, access to Azure resources through role-based access control, and the governance tools that keep subscriptions tidy and affordable — Azure Policy, locks, tags, management groups, budgets and Advisor. Most questions are about scope: who gets what, and where it applies.
Microsoft Entra users and groups
Users and groups
You create users in the portal, with PowerShell or the CLI, or in bulk from a CSV file. Groups come in two types, security and Microsoft 365, and two membership styles:
| Membership | How members are added | Notes |
|---|---|---|
| Assigned | Manually by an owner or admin | Works on every licence tier |
| Dynamic user | A rule on user attributes, such as department -eq "Sales" | Needs an Entra ID P1 licence or higher |
| Dynamic device | A rule on device attributes | Security groups only |
A frequent exam scenario: a user’s department changes and they should lose access automatically. Dynamic membership is the answer; an assigned group would need someone to remember.
Licences and external users
Licences can be assigned per user or through group-based licensing, where every member of a group inherits the licence. A user without a usage location cannot receive a licence, which is the usual reason an assignment fails.
External users are invited as guests with B2B collaboration. They sign in with their own identity and appear in your directory with the user type Guest. External collaboration settings control who may invite them and which domains are allowed.
Self-service password reset
SSPR is enabled for none, a selected group, or all users. You choose how many authentication methods are required (one or two) and which methods count. A good exam habit: when a scenario says “pilot”, the answer is usually to scope SSPR to a selected group first.
Access to Azure resources
Entra roles versus Azure roles
This distinction is tested constantly. Entra roles, such as User Administrator or Global Administrator, manage the directory: users, groups, licences. Azure roles, such as Owner or Contributor, manage Azure resources. A Global Administrator does not automatically get access to subscriptions.
The four built-in roles to know cold
| Role | Manage resources | Grant access |
|---|---|---|
| Owner | Yes | Yes |
| Contributor | Yes | No |
| Reader | View only | No |
| User Access Administrator | No | Yes |
Beyond these, many services have their own roles, such as Virtual Machine Contributor or Storage Blob Data Reader. Note the split between control plane roles, which manage the resource, and data plane roles, which read or write its data. Contributor on a storage account does not by itself grant Storage Blob Data Reader.
Scopes and inheritance
Roles are assigned at four scopes: management group, subscription, resource group and resource. Assignments inherit downwards. The least-privilege answer is almost always the narrowest scope that still covers the requirement. To interpret access, use the Check access and Role assignments views on a resource’s Access control (IAM) blade, which also show inherited assignments.
Subscriptions and governance
Azure Policy
A policy definition describes a rule and its effect. An initiative groups several definitions. An assignment applies one of them to a scope, optionally with exclusions. Common effects:
- Deny blocks non-compliant creates and updates.
- Audit only reports.
- Modify and Append change the request, for example to add a tag.
- DeployIfNotExists deploys a related resource, such as a diagnostic setting.
Existing resources are not fixed automatically. Modify and DeployIfNotExists need a remediation task, which runs under a managed identity with the right roles.
Locks
| Lock | Effect |
|---|---|
| CanNotDelete | Resources can be changed but not deleted |
| ReadOnly | No changes and no deletes |
Locks inherit to child resources and apply to everyone, Owners included. A ReadOnly lock can cause surprises: on a storage account it blocks listing the access keys, because that is a write-type operation.
Tags
Tags are name-value pairs for cost reporting and organisation. They do not inherit from resource groups by default. To enforce or copy them, use Azure Policy, for example a Modify policy that inherits a tag from the resource group.
Resource groups, subscriptions and management groups
A resource belongs to exactly one resource group. Resources can move between resource groups and subscriptions, but dependent resources often have to move together, and the resource group’s region does not constrain the resources in it. Management groups sit above subscriptions and let you assign policy and RBAC once for many subscriptions.
Cost management
Budgets send alerts at thresholds you set; they do not stop resources. An action group on a budget can trigger automation if you need that. Azure Advisor gives cost recommendations, such as resizing or shutting down underused VMs.
Sample questions
Question 1. Every new resource in the subscription must carry a costCenter tag, and resources created without one must be blocked. Existing resources are not in scope. What should you implement?
- A. An Azure Policy assignment that denies resources without the costCenter tag
- B. A ReadOnly lock on the subscription
- C. A costCenter tag on each resource group
- D. A budget with an alert at 100%
Show answer
Answer: A
An Azure Policy assignment with the Deny effect on resources missing the tag blocks non-compliant creates. A resource lock prevents deletion or change but cannot check tags. Tags on the resource group are not inherited by resources. A budget reports cost and cannot block creation.
Want more questions like this? Full AZ-104 practice tests →
Question 2. A helpdesk team must reset passwords for users in Microsoft Entra ID. They must not be able to manage Azure virtual machines or any other Azure resource. What should you assign?
- A. Contributor on the subscription
- B. User Access Administrator on the subscription
- C. An Entra administrative role that allows password resets
- D. Owner on the root management group
Show answer
Answer: C
Password resets are a directory task, so the answer is an Entra role scoped to what the helpdesk needs, such as Helpdesk Administrator or User Administrator. Azure roles such as Contributor or Owner manage resources, not users, and User Access Administrator manages Azure role assignments rather than passwords.
Want more questions like this? Full AZ-104 practice tests →
Question 3. Engineers with the Owner role keep deleting a production virtual network by mistake. They still need to change its settings. What should you do?
- A. Apply a ReadOnly lock to the virtual network
- B. Assign an Azure Policy with the Audit effect
- C. Replace Owner with Reader for the engineers
- D. Apply a CanNotDelete lock to the virtual network
Show answer
Answer: D
A CanNotDelete lock stops deletion while allowing configuration changes, and it applies to Owners too. A ReadOnly lock would block the changes they need. Removing Owner changes much more than required, and an audit policy only reports after the fact.
Want more questions like this? Full AZ-104 practice tests →
What to practise
Build a small hierarchy: a management group, a subscription or two resource groups, a Deny policy on a missing tag, a CanNotDelete lock, a guest user with Reader on one resource group, and a budget with an alert. Then check each user’s effective access on the IAM blade. After that, most questions in this domain reduce to “which tool, at which scope”.