Microsoft AZ-104 Exam
Microsoft Azure Administrator (Page 7 )

Updated On: 12-Jan-2026

HOTSPOT (Drag and Drop is not supported)
You have an Azure subscription named Subscription1 that has a subscription ID of c276fc76-9cd4-44c9-99a7- 4fd71546436e.
You need to create a custom RBAC role named CR1 that meets the following requirements: Can be assigned only to the resource groups in Subscription1
Prevents the management of the access permissions for the resource groups
Allows the viewing, creating, modifying, and deleting of resources within the resource groups
What should you specify in the assignable scopes and the permission elements of the definition of CR1? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
Hot Area:

  1. See Explanation section for answer.

Answer(s): A

Explanation:


Reference:

https://docs.microsoft.com/en-us/azure/role-based-access-control/custom-roles
https://docs.microsoft.com/en-us/azure/role-based-access-control/resource-provider- operations#microsoftresources



You have an Azure subscription.
Users access the resources in the subscription from either home or from customer sites. From home, users must establish a point-to-site VPN to access the Azure resources. The users on the customer sites access the Azure resources by using site-to-site VPNs.
You have a line-of-business-app named App1 that runs on several Azure virtual machine. The virtual machines run Windows Server.
You need to ensure that the connections to App1 are spread across all the virtual machines.
What are two possible Azure services that you can use? Each correct answer presents a complete solution.
NOTE: Each correct selection is worth one point.

  1. an internal load balancer
  2. a public load balancer
  3. an Azure Content Delivery Network (CDN)
  4. Traffic Manager
  5. an Azure Application Gateway

Answer(s): A,E

Explanation:

Network traffic from the VPN gateway is routed to the cloud application through an internal load balancer. The load balancer is located in the front-end subnet of the application.


Reference:

https://docs.microsoft.com/en-us/azure/architecture/reference-architectures/hybrid-networking/vpn https://docs.microsoft.com/en-us/azure/load-balancer/load-balancer-overview https://docs.microsoft.com/en-us/azure/application-gateway/overview



You have an Azure subscription.
You have 100 Azure virtual machines.
You need to quickly identify underutilized virtual machines that can have their service tier changed to a less expensive offering.
Which blade should you use?

  1. Monitor
  2. Advisor
  3. Metrics
  4. Customer insights

Answer(s): B

Explanation:

Correct:
Advisor
Advisor helps you optimize and reduce your overall Azure spend by identifying idle and underutilized resources. You can get cost recommendations from the Cost tab on the Advisor dashboard.
Incorrect:
* Customer insights
* Metrics
* Monitor


Reference:

https://docs.microsoft.com/en-us/azure/advisor/advisor-cost-recommendations



HOTSPOT (Drag and Drop is not supported)
You have a Microsoft Entra tenant.
You need to create a conditional access policy that requires all users to use multi-factor authentication when they access the Azure portal.
Which three settings should you configure? To answer, select the appropriate settings in the answer area.
NOTE: Each correct selection is worth one point.
Hot Area:

  1. See Explanation section for answer.

Answer(s): A

Explanation:


Reference:

https://docs.microsoft.com/en-us/azure/active-directory/conditional-access/app-based-mfa



You have a Microsoft Entra tenant named contoso.onmicrosoft.com. The User administrator role is assigned to a user named Admin1.
An external partner has a Microsoft account that uses the user1@outlook.com sign in.
Admin1 attempts to invite the external partner to sign in to the Microsoft Entra tenant and receives the following error message: “Unable to invite user user1@outlook.com – Generic authorization exception.”
You need to ensure that Admin1 can invite the external partner to sign in to the Microsoft Entra tenant. What should you do?

  1. From the Users settings blade, modify the External collaboration settings.
  2. From the Custom domain names blade, add a custom domain.
  3. From the Organizational relationships blade, add an identity provider.
  4. From the Roles and administrators blade, assign the Security administrator role to Admin1.

Answer(s): A

Explanation:


Reference:

https://techcommunity.microsoft.com/t5/Azure-Active-Directory/Generic-authorization-exception-inviting-Azure- AD-gests/td-p/274742



Viewing page 7 of 110
Viewing questions 25 - 28 out of 553 questions



Post your Comments and Discuss Microsoft AZ-104 exam prep with other Community members:

Join the AZ-104 Discussion