Objective access.to-azure-resourcesAZ-104

Manage access to Azure resources

Objective access.to-azure-resources sits in Manage Azure identities and governance, which carries 24% of the Azure Administrator exam. The questions below are original, written from the official objective title above, and each explanation cites the Microsoft Azure page it rests on.

Objective title verbatim from the official objectives. Microsoft Azure exam page

A worked example

Shown solved, with the whole explanation open: this is what every question here carries.

Manage Azure identities and governanceModerate

An administrator assigns the Virtual Machine Contributor role to a user, with the scope set to the resource group ProjectA-RG. What is the effect of this role assignment?

Correct.

The concept

A role assignment combines a security principal, a role definition, and a scope. The scope limits where the permissions granted by the role definition apply.

Why this answer

Because the scope is set to the ProjectA-RG resource group, the Virtual Machine Contributor permissions only apply to resources within that resource group, not beyond it.

  • Correct: scope was explicitly set to the resource group, not the subscription.
  • BThis describes a subscription-level scope, which was not what was configured here.
  • CVirtual Machine Contributor grants permissions for virtual machine actions only, not all resource types.
  • DAzure resource groups do not nest inside each other, so there is no nested scope to inherit.
  • EThis role grants virtual machine permissions, not virtual network permissions.
Read the sourceAzure RBAC overview
Verified against learn.microsoft.com · 2026-07-28
rbacscoperole-assignment

Now you: objective access.to-azure-resources questions

No account needed. The explanation opens when you answer.

Sample question 1 of 3

Manage Azure identities and governanceEasy

An Azure role assignment is being created. Which three elements does it consist of?

Sample question 2 of 3

Manage Azure identities and governanceModerate

Which objects can be named as the security principal in an Azure role assignment?

Sample question 3 of 3

Manage Azure identities and governanceModerate

A DBA group should manage SQL databases across a whole subscription but nothing else. Which part of the assignment expresses the boundary?

Full Azure Administrator question bank coming

We’re writing the complete bank from the official objectives right now. Leave your email and we’ll tell you when it ships, nothing else, ever.

Read the sources

These are the official pages the questions above cite. Reading them is studying the objective from the primary source, which is what the explanations point you toward anyway.

More objectives in Manage Azure identities and governance