Exam objective

AZ-104

Manage access to Azure resources

This objective sits in Manage Azure identities and governance, which carries 24% of the Azure Administrator exam. The questions below are original, written from the official objective title above, and each explanation cites the Microsoft Azure page it rests on.

Objective title verbatim from the official objectives. Microsoft Azure exam page ↗

A worked example

Shown solved, with the whole explanation open: this is what every question here carries.

Manage Azure identities and governance

An administrator assigns the Virtual Machine Contributor role to a user, with the scope set to the resource group ProjectA-RG. What is the effect of this role assignment?

The user can manage virtual machines in ProjectA-RG and any nested resource groupsAzure resource groups do not nest inside each other, so there is no nested scope to inherit.
The user can manage virtual machines across the entire subscriptionThis describes a subscription-level scope, which was not what was configured here.
The user can manage all resource types within ProjectA-RG, including storage accountsVirtual Machine Contributor grants permissions for virtual machine actions only, not all resource types.
The user can manage virtual networks across the entire subscriptionThis role grants virtual machine permissions, not virtual network permissions.
The user can manage virtual machines only within the ProjectA-RG resource groupCorrect · your answerCorrect: scope was explicitly set to the resource group, not the subscription.

Correct.

Checked against learn.microsoft.com, July 2026

Concept

A role assignment combines a security principal, a role definition, and a scope. The scope limits where the permissions granted by the role definition apply.

Why E

Because the scope is set to the ProjectA-RG resource group, the Virtual Machine Contributor permissions only apply to resources within that resource group, not beyond it.

Source

For example, the Virtual Machine Contributor role allows a user to create and manage virtual machines.... Scope is the set of resources that the access applies to. When you assign a role, you can further limit the actions allowed by defining a scope. This is helpful if you want to make someone a Website Contributor, but only for one resource group.

Azure RBAC overview, checked July 2026
#rbac#scope#role-assignment

Now you: practice questions

No account needed. The explanation opens when you answer.

Sample question 1 of 3

Manage Azure identities and governance

You need to delete an obsolete custom role and receive the error RoleDefinitionHasAssignments. What must happen before the deletion succeeds?

Sample question 2 of 3

Manage Azure identities and governance

An engineer's custom role must cover every current and future permission on Cost Management exports, and nothing else, without listing each one. Which action string should the engineer add?

Sample question 3 of 3

Manage Azure identities and governance

An organization has Prod and Dev management groups and wants one custom role assignable in both. Saving the role with both groups in AssignableScopes fails. What should the administrator do?

Full Azure Administrator question bank coming

We’re writing the complete bank from the official objectives right now. Leave your email and we’ll tell you when it ships, nothing else, ever.

Read the sources

These are the official pages the questions above cite. Reading them is studying the objective from the primary source, which is what the explanations point you toward anyway.

More objectives in Manage Azure identities and governance