SaveMyCert
Log in
5 of 5 free questions left today·for 30 a day
AZ-104 · Domain 1

Manage Azure identities and governance practice questions

Manage Azure identities and governance is worth 24% of the AZ-104 exam — the heaviest of the 5 domains. Microsoft Entra users and groups, access to Azure resources, and subscription-level governance. Official weighting 20–25%. 6 fully worked examples are further down this page, answers included.

Exam weight
24%
the heaviest of the 5 domains
Questions
60
across 3 topics
Free, no account
5/day
sign up free to remove the cap
Explanations
Every option
right and wrong

Build a practice session

5 free questions left today.

Domains

How many?

Mode

Ready when you are

10 fresh questions drawn across 1 of 5 domains, in Learn mode.

Focused review

Every question you answer incorrectly, and every question you flag while practising, is saved here automatically. Finish a session and you can come back to re-drill just those.

6 sample Manage Azure identities and governance questions, fully explained

Questions from the AZ-104 bank mapped to domain 1, with the answer key and the reasoning behind every option. None of them repeat the examples on the main AZ-104 practice page.

Question 1Manage Azure identities and governance

An administrator must onboard 200 new full-time employees into Microsoft Entra ID as member accounts as quickly as possible. Which approach is the most efficient?

Choose one.

  • a
    Use Bulk invite to send each employee a B2B invitation

    Bulk invite creates external guest accounts, which is wrong for your own internal full-time employees.

  • b
    Use Bulk create on the Users blade with a completed CSV template Correct

    Bulk create uploads one CSV row per member account, provisioning hundreds of users in a single background operation.

  • c
    Create each user individually with Create new user

    Creating 200 accounts one at a time is exactly what bulk operations exist to avoid.

  • d
    Create a dynamic group so the 200 users are added automatically

    A dynamic group manages membership of accounts that already exist; it does not create the user accounts.

The concept

Large-scale user provisioning uses CSV-driven bulk operations, not manual creation or scripting.

Why that’s the answer

Bulk create provisions many member accounts from one CSV upload, the fastest path for 200 employees. Bulk invite (A) makes guests, not members. Creating each user (C) is the slow manual approach bulk operations replace. A dynamic group (D) only manages membership of existing accounts and creates none.

How to reason it out
  1. Recognize the accounts are internal members, so use bulk create rather than bulk invite.
  2. Download the CSV template and fill one row per employee.
  3. Upload it with Bulk create and track the result under Bulk operation results.

Exam tip: Provisioning many internal accounts at once is a CSV Bulk create operation.

Manage Microsoft Entra Users and Groups (AZ-104) — the lesson that teaches this.

Question 2Manage Azure identities and governance

A project team needs a shared mailbox, a shared calendar, a SharePoint site, and a Microsoft Teams workspace provisioned together. Which type of object should the administrator create in Microsoft Entra ID?

Choose one.

  • a
    A Microsoft 365 group Correct

    Creating a Microsoft 365 group provisions a shared mailbox, calendar, SharePoint site, and Teams-ready workspace for collaboration.

  • b
    A security group

    A security group grants access, roles, and licenses but does not provision shared collaboration resources like a mailbox or Teams site.

  • c
    An administrative unit

    An administrative unit scopes directory administration to a subset of users; it provides no shared collaboration resources.

  • d
    A dynamic device group

    A dynamic device group collects devices by rule and offers no mailbox, SharePoint site, or Teams workspace.

The concept

Security groups grant access; Microsoft 365 groups add shared collaboration resources.

Why that’s the answer

A Microsoft 365 group exists precisely to provision shared collaboration tools — mailbox, calendar, SharePoint, Teams. A security group (B) manages permissions, not collaboration resources. An administrative unit (C) scopes admin duties, not collaboration. A dynamic device group (D) manages devices and provisions nothing shared.

How to reason it out
  1. Note the requirement is shared collaboration resources, not permissions.
  2. Map shared mailbox, SharePoint, and Teams to a Microsoft 365 group.
  3. Create the Microsoft 365 group so the resources are provisioned automatically.

Exam tip: A shared mailbox, SharePoint site, and Teams workspace means a Microsoft 365 group.

Manage Microsoft Entra Users and Groups (AZ-104) — the lesson that teaches this.

Question 3Manage Azure identities and governance

An administrator wants a security group whose membership always contains exactly the users whose department is Sales, updating automatically as people join or leave the department. Which membership type and rule should be configured?

Choose one.

  • a
    Membership type Assigned, adding each Sales user by hand

    Assigned membership requires manual maintenance and will not update automatically when the department attribute changes.

  • b
    Membership type Dynamic User with the rule user.department -eq "Sales" Correct

    A Dynamic User group evaluates each user's attributes and automatically adds anyone whose department equals Sales and removes anyone who changes.

  • c
    Membership type Dynamic Device with the rule device.department -eq "Sales"

    Dynamic Device evaluates device attributes, not user department, so it cannot track Sales people.

  • d
    Membership type Assigned with a Conditional Access policy scoped to Sales

    Conditional Access controls sign-in conditions; it does not populate a group's membership by attribute.

The concept

Dynamic membership adds and removes members automatically from an attribute-based rule.

Why that’s the answer

Dynamic User with user.department -eq "Sales" auto-includes everyone in Sales and drops them when the attribute changes. Assigned (A) needs manual upkeep. Dynamic Device (C) reads device attributes, not user department. Conditional Access (D) governs sign-in, not group membership.

How to reason it out
  1. The phrase updates automatically by attribute signals dynamic membership.
  2. The subject is users, so choose Dynamic User (not Dynamic Device).
  3. Enter the rule user.department -eq "Sales".

Exam tip: Auto-add users by department is a Dynamic User group with user.department -eq "Sales".

Manage Microsoft Entra Users and Groups (AZ-104) — the lesson that teaches this.

Question 4Manage Azure identities and governance

Before configuring dynamic membership for several security groups, an administrator must confirm the tenant is correctly licensed. Which Microsoft Entra license is required for dynamic group membership?

Choose one.

  • a
    Microsoft Entra ID Free

    The free tier supports assigned membership only; dynamic rules are a premium feature.

  • b
    Microsoft Entra ID P2 is mandatory, and P1 will not work

    P2 includes the capability, but P1 is the minimum required; claiming P1 is insufficient is incorrect.

  • c
    Microsoft Entra ID P1 Correct

    Dynamic membership requires a Microsoft Entra ID P1 license for each user the rule evaluates.

  • d
    No paid license is required for dynamic membership

    Dynamic membership is a premium feature and does require a paid P1 (or higher) license per evaluated member.

The concept

Dynamic membership, group-based licensing, and SSPR for cloud users all require Microsoft Entra ID P1.

Why that’s the answer

Dynamic group membership needs at least Microsoft Entra ID P1 for each evaluated member. Free (A) supports only assigned membership. P2 (B) works but is not the minimum, so calling P1 insufficient is wrong. A paid license is required (D is false).

How to reason it out
  1. Identify dynamic membership as a premium capability.
  2. Recall the minimum edition that unlocks it is P1.
  3. Confirm P1 licensing per evaluated member before building the rules.

Exam tip: Dynamic membership requires at least Microsoft Entra ID P1.

Manage Microsoft Entra Users and Groups (AZ-104) — the lesson that teaches this.

Question 5Manage Azure identities and governance

An administrator must ensure every member of a 400-person department receives the same Microsoft 365 license, with licenses removed automatically when someone leaves the department. Which feature accomplishes this with the least ongoing effort?

Choose one.

  • a
    Group-based licensing, assigning the product license to the department's group Correct

    Assigning a license to a group makes every member inherit it and releases it automatically when a user leaves the group.

  • b
    Assign the license directly to each of the 400 users

    Per-user assignment for 400 people is heavy manual work and does not auto-remove licenses on departure.

  • c
    Use Bulk create to re-provision the users with the license attached

    Bulk create provisions accounts; it is not a licensing mechanism and does not manage license removal.

  • d
    Create a dynamic device group and license the devices

    Licenses are assigned to users, not devices, so licensing a device group does not license the people.

The concept

Group-based licensing assigns product licenses to a group so members inherit them.

Why that’s the answer

Group-based licensing gives every group member the license and reclaims it when they leave — ideal at scale. Direct per-user assignment (B) is manual and does not auto-remove. Bulk create (C) provisions accounts, not licenses. A device group (D) cannot license people because licenses attach to users.

How to reason it out
  1. Recognize the need to license many users and auto-remove on departure.
  2. Assign the product license to a group under Billing > Licenses.
  3. Members inherit the license; leaving the group releases it to the pool.

Exam tip: Licensing many users at scale is group-based licensing, not per-user assignment.

Manage Microsoft Entra Users and Groups (AZ-104) — the lesson that teaches this.

Question 6Manage Azure identities and governance

After setting up group-based licensing, an administrator notices that several users in the group failed to receive their Microsoft 365 license. Which user property is most likely missing and causing the licensing failure?

Choose one.

  • a
    Usage location Correct

    Some services are not available in every region, so a user with no usage location set fails license assignment.

  • b
    Job title

    Job title is informational metadata and does not affect whether a license can be assigned.

  • c
    Department

    Department can drive dynamic membership but is not required for a license to be assigned successfully.

  • d
    User principal name (UPN)

    Every user already has a UPN as their sign-in identifier; a missing UPN would prevent the account existing, not just licensing.

The concept

A user without a usage location set will fail licensing because some services are region-restricted.

Why that’s the answer

Usage location is required so Microsoft can honor regional service availability; without it the license assignment fails. Job title (B) and department (C) do not block licensing. UPN (D) is mandatory for the account to exist at all, so it is not the missing licensing property.

How to reason it out
  1. Note licenses were assigned but did not apply.
  2. Recall that licensing checks the user's usage location for regional availability.
  3. Set usage location on the affected users to clear the error.

Exam tip: Missing usage location causes license assignment to fail.

Manage Microsoft Entra Users and Groups (AZ-104) — the lesson that teaches this.

What AZ-104 domain 1 tests, topic by topic

The official exam guide breaks Manage Azure identities and governance into 3 topics. The question bank follows the same split, so a weak topic shows up as a cluster of misses you can go back and read.

Published AZ-104 practice questions per topic in Manage Azure identities and governance
TopicWhat it coversQuestions
Manage Microsoft Entra users and groupsSkills outline section (AZ-104, as of April 17, 2026). Creating users and groups; managing user and group properties; managing licenses in Microsoft Entra ID; managing external users; configuring self-service password reset (SSPR).20
Manage access to Azure resourcesSkills outline section (AZ-104, as of April 17, 2026). Managing built-in Azure roles; assigning roles at different scopes; interpreting access assignments.20
Manage Azure subscriptions and governanceSkills outline section (AZ-104, as of April 17, 2026). Implementing and managing Azure Policy; configuring resource locks; applying and managing tags on resources; managing resource groups and subscriptions; managing costs by using alerts, budgets, and Azure Advisor recommendations; configuring management groups.20
Total60

Revise Manage Azure identities and governance before you drill it

Other AZ-104 domains

Manage Azure identities and governance: your questions

Manage Azure identities and governance is domain 1 of the AZ-104 exam guide and carries 24% of the scored content — the heaviest of the 5 domains. On a 50-question paper that works out to roughly 12 questions, though Microsoft Azure does not publish an exact per-domain count and individual exam forms vary.

Source

The domain weight and topic list on this page come from the official AZ-104 exam guide.