Manage Azure identities and governance
AZ-104 · 40 questions
- Cascade Regional Airlines is onboarding 40 new gate agents at once ahead of a schedule expansion. The identity admin has a CSV with each agent's display name, user principal name, and department, and wants to create all the accounts in Microsoft Entra ID without opening the portal 40 times. Which approach should the admin use?
- A maintenance-records application at Cascade Regional Airlines needs a small team of mechanics and one external auditor from a certified inspection firm to co-edit a shared document library and receive a group mailbox for coordination emails. Which type of group best fits this need?
- Cascade Regional Airlines reorganizes its workforce so that every employee's department attribute in Microsoft Entra ID is kept accurate by HR. The identity admin wants a group of all Flight Operations employees to update itself automatically as people transfer in and out, without anyone manually adding or removing members. What should the admin configure?
- A service desk lead at Cascade Regional Airlines is designing self-service password reset (SSPR) for outstation employees so they can regain access to their accounts without calling the help desk after hours. Before enabling SSPR, what must the lead configure so users actually have a way to verify their identity during a reset?
- Cascade Regional Airlines runs a hybrid identity environment where employee accounts are synchronized from on-premises Active Directory to Microsoft Entra ID using Microsoft Entra Connect. The compliance officer wants an employee's self-service password reset in the cloud to also update their on-premises AD password, so a single password works everywhere. What must be enabled for this to work?
- Cascade Regional Airlines has a regional IT team responsible only for the accounts and devices at its three outstation offices, and must not be able to touch HQ or maintenance-base resources. The identity admin wants to delegate a limited set of administrative permissions scoped strictly to the outstation users and groups. What Microsoft Entra ID feature should the admin use?
- Cascade Regional Airlines just purchased Microsoft 365 E3 licenses for 200 new flight-planning staff. Rather than assigning a license to each user account individually, the identity admin wants new hires to automatically receive the correct license the moment they're added to the Flight Planning security group. Which licensing approach accomplishes this?
- Cascade Regional Airlines wants to require multi-factor authentication for all sign-ins to its crew-scheduling app using a conditional access policy, and also wants risk-based sign-in policies that automatically challenge users when Microsoft detects unusual sign-in behavior. Which Microsoft Entra ID licensing tier is the minimum needed to build these conditional access and risk-based policies?
- A contractor from an external staffing agency needs temporary access to Cascade Regional Airlines' shared maintenance-scheduling document library for a six-week engagement, but should never receive a company email mailbox or a full employee identity. What is the appropriate way to grant this access in Microsoft Entra ID?
- Cascade Regional Airlines equips its check-in kiosks with company-owned tablets that must be automatically enrolled in mobile device management and fully controlled by IT, with no personal Microsoft account ever touching them. Which Microsoft Entra device state matches this scenario?
- Cascade Regional Airlines' HQ desktops have been domain-joined to on-premises Active Directory for years, and the identity admin now wants those same machines to also register with Microsoft Entra ID so users can access cloud apps with conditional access enforced, without a disruptive re-image of every machine. What device join type describes the end state?
- During a bulk import of 60 new ramp-agent accounts, Cascade Regional Airlines' identity admin uploads a CSV to the Microsoft Entra ID bulk create tool, but the job reports that 5 rows failed while 55 succeeded. What should the admin do to identify exactly what went wrong with those 5 rows?
- Cascade Regional Airlines wants a Microsoft Entra ID group that automatically contains every corporate laptop enrolled through the company's device management program, so a security baseline policy can target exactly those machines without anyone manually adding devices. What should the identity admin configure?
- Cascade Regional Airlines' service desk lead is configuring self-service password reset policy and wants to require that a user register at least two different authentication methods, and that both methods be used together when performing a reset, for stronger assurance. Where is this requirement configured?
- Cascade Regional Airlines' compliance officer discovers that an administrative unit scoped to the outstation offices was assigned the Helpdesk Administrator role to a regional technician, but the technician is still able to reset the password of a HQ pilot's account, which should be out of scope. What is the most likely explanation for this scope violation?
- Cascade Regional Airlines wants every guest user invited from the external staffing agency to automatically land in a single review group so the compliance team can periodically audit all external access in one place, without anyone manually remembering to add each new guest. What should the identity admin configure?
- Cascade Regional Airlines assigns a Microsoft 365 E3 license to its Ground Operations security group using group-based licensing, but the identity admin notices the group has run out of available licenses in the pool, so several new members show a licensing error instead of receiving the license. What is the most appropriate way to resolve this?
- Cascade Regional Airlines' crew-scheduling application requires that only devices enrolled and marked compliant through device management can sign in, and the identity admin wants a conditional access policy to enforce this. Which Microsoft Entra ID device state must a device be in for a compliance status to exist and be evaluated by that policy?
- Cascade Regional Airlines' identity admin needs Privileged Identity Management to require just-in-time activation, approval workflows, and time-bound elevation for administrative roles, rather than granting those roles as permanent, always-on assignments. Which Microsoft Entra ID licensing tier is required to use Privileged Identity Management?
- Cascade Regional Airlines' cloud administrator is auditing external access and finds that the tenant's external collaboration settings allow any employee to invite guests from any domain with no restrictions, which the compliance officer considers too permissive for an airline handling sensitive maintenance data. What should the administrator do to tighten this while still allowing legitimate B2B collaboration?
- Cascade Regional Airlines' cloud administrator assigns the Contributor role to the maintenance-records support team at the resource group scope that holds their virtual machines and storage account. A new storage account is then created in a different resource group in the same subscription. What can the maintenance-records team do with the new storage account?
- Support engineers on Cascade Regional Airlines' crew-scheduling application need to restart the app's underlying App Service and read its diagnostic logs, but the built-in Contributor role also lets them delete the resource, and the built-in Reader role cannot perform the restart. What should the subscription owner do to give the engineers exactly the access they need?
- A FinOps analyst at Cascade Regional Airlines needs to stop virtual machines from ever being created with unapproved SKUs at the outstation offices, before the deployment can complete. Which Azure Policy effect accomplishes this?
- A compliance officer at Cascade Regional Airlines must apply a consistent bundle of about fifteen related governance policies, covering tagging, allowed regions, and allowed VM SKUs, to every current and future outstation-office subscription. What is the most efficient way to do this?
- Cascade Regional Airlines' cloud administrator holds the Owner role on the maintenance-records resource group and applies a CanNotDelete resource lock to protect its production database from accidental removal. Later, the same administrator attempts to delete the entire resource group. What happens?
- Cascade Regional Airlines is reorganizing its management group hierarchy and moves the Kiosk-Ops subscription out of the Corporate management group and into the Outstations management group, which carries stricter Azure Policy assignments. What is the immediate effect on resources in the Kiosk-Ops subscription?
- A FinOps analyst at Cascade Regional Airlines configures a monthly Cost Management budget with an alert set to fire at 90% of the cap for the crew-scheduling subscription, notifying stakeholders by email as spend approaches the limit. If actual spend exceeds the budget, what happens to further resource deployments in that subscription?
- A helpdesk technician at Cascade Regional Airlines needs the ability to reset passwords for user accounts belonging to the airport kiosk fleet support staff in Microsoft Entra ID. Which type of role should the cloud administrator assign?
- A compliance officer at Cascade Regional Airlines wants every resource created at outstation offices to be tagged with the correct cost-center value automatically, rather than relying on staff to remember and finance correcting mistakes after the fact. What should the compliance officer configure?
- Cascade Regional Airlines' subscription owner assigns an Azure Policy with the DeployIfNotExists effect requiring diagnostic settings on all maintenance-records storage accounts. Storage accounts created before the assignment now show as non-compliant. Without recreating them, how can the owner bring the existing accounts into compliance?
- At Cascade Regional Airlines, a cloud administrator is assigned the Reader role at the management group level and separately assigned the Contributor role directly at the maintenance-records resource group beneath that management group. What is the administrator's effective permission on resources inside the maintenance-records resource group?
- A FinOps analyst at Cascade Regional Airlines moves several virtual machines from the Kiosk-Pilot resource group into the Kiosk-Prod resource group within the same subscription. What should the analyst expect regarding any RBAC role assignments that were scoped directly to Kiosk-Pilot?
- A compliance officer at Cascade Regional Airlines applies a ReadOnly resource lock to the crew-scheduling production App Service to preserve its configuration during an audit. A developer who holds the Contributor role then attempts to restart the App Service. What happens?
- A cloud administrator at Cascade Regional Airlines wants visibility into which outstation-office virtual machines are running on unapproved SKUs before deciding whether to fully enforce an approved-SKU standard, without disrupting any current operations. Which Azure Policy effect fits this goal?
- Cascade Regional Airlines' management group hierarchy has a single root management group, Cascade-Root, containing all current subscriptions for HQ, Outstations, and Kiosk-Ops. The subscription owner wants one "require approved regions" Azure Policy enforced across every current subscription and any subscription added in the future, using a single assignment. Where should the policy be assigned?
- A FinOps analyst at Cascade Regional Airlines has been asked to grant other engineers appropriate RBAC roles on the crew-scheduling resource group, but the analyst has no need to create, modify, or delete the resources themselves. Which built-in Azure role best matches this responsibility?
- A compliance officer at Cascade Regional Airlines applies a CanNotDelete resource lock at the subscription level covering the entire Outstations subscription. Can a resource group owner within that subscription, who holds the Owner role on just their own resource group, delete that resource group?
- Cascade Regional Airlines' cloud administrator wants a single Azure Policy initiative definition for "allowed locations," but HQ should only permit resources in one region while a separate outstation-office subscription should only permit resources in a different region. How can the administrator achieve this using one initiative definition?
- A subscription owner at Cascade Regional Airlines wants to track spending specifically for the maintenance-records resource group, separately from the rest of the spend happening elsewhere in the same subscription. How should the owner set this up in Cost Management?
- Cascade Regional Airlines' compliance officer wants the Kiosk-Ops subscription to inherit governance from both the Outstations management group and the Finance management group at the same time, and attempts to place Kiosk-Ops as a child of both. Is this possible in Azure's management group hierarchy?