Microsoft Entra Users, Groups and Azure RBAC
Identity questions test users, groups, properties, licenses, external users, SSPR, built-in Azure roles, role assignments, scopes, and interpreting access.
How to study for AZ-104
Treat each AZ-104 item as an admin workflow: identify the scope, resource type, access boundary, deployment method, monitoring signal, or recovery requirement.
Core concepts
Concept 1
Microsoft Entra Users, Groups and Azure RBAC questions reward operational Azure administration judgment rather than simple service-name recall.
Exam cue: Identify the Azure scope: tenant, management group, subscription, resource group, resource, subnet, or identity.
Concept 2
The best answer identifies the scope, resource type, access path, deployment method, monitoring signal, and recovery requirement.
Exam cue: Match the tool to the administrative task: manage access, deploy, secure, monitor, back up, or troubleshoot.
Concept 3
Eliminate answers that confuse RBAC with policy, public access with private access, monitoring with backup, or templates with manual changes.
Exam cue: Prefer least privilege, repeatable deployment, protected storage, private networking, and validated recovery.
Risk pitfalls and guardrails
Using Azure Policy when the question asks who is allowed to perform an action.
Guardrail: Avoid answers that confuse RBAC with Policy, tags with network controls, dashboards with backup, or public exposure with secure private access.
Opening public access when private endpoints, service endpoints, or NSGs meet the requirement.
Guardrail: Avoid answers that confuse RBAC with Policy, tags with network controls, dashboards with backup, or public exposure with secure private access.
Assuming backup exists before checking vault, policy, retention, and restore validation.
Guardrail: Avoid answers that confuse RBAC with Policy, tags with network controls, dashboards with backup, or public exposure with secure private access.
Memory anchors
Microsoft Entra User
A Microsoft Entra user represents an identity that can authenticate to tenant resources.
Group
A group simplifies assignment of access, licenses, or management to multiple users.
License Assignment
License assignment enables users to access specific Microsoft cloud services.
External User
External users support collaboration with identities outside the tenant.
SSPR
Self-service password reset lets users reset passwords after meeting configured verification requirements.
Azure RBAC
Azure role-based access control assigns permissions to Azure resources using roles and scopes.
Built In Role
A built-in role provides predefined Azure management permissions.
Role Scope
Role scope controls whether permissions apply at management group, subscription, resource group, or resource level.
Access Assignment
An access assignment combines principal, role, and scope.
Least Privilege
Least privilege grants only the access needed for the approved task.
Checkpoint rule
Do the check-up only after you can summarize each concept in one sentence and identify one dangerous pitfall from memory.
Knowledge Check (after reading)
Short check-up to confirm understanding of this module.
Check-up Questions
A new support department needs 40 cloud-only identities with a common usage location and department value. Which approach minimizes repetitive portal work?
A dynamic Microsoft Entra group should include every user whose Department property equals Finance. A transferred employee remains in the group. What should the administrator do?
Answer all questions to submit.
Next step personalized recommendations
Continue learning
Move forward only after this module is stable.
What is Pass Harbor?
Completely free exam prep for 317 U.S. exams.
- Practice questions
- Flashcards
- Study guides
- Mock exams
- No registration
- No paywall
- Start instantly
“No more expensive exam prep. Quality study tools should be accessible to everyone.”
