Exam objective

AZ-104

Automate deployment of resources by using Azure Resource Manager (ARM) templates or Bicep files

This objective sits in Deploy and manage Azure compute resources, which carries 24% of the Azure Administrator exam. The questions below are original, written from the official objective title above, and each explanation cites the Microsoft Azure page it rests on.

Objective title verbatim from the official objectives. Microsoft Azure exam page ↗

A worked example

Shown solved, with the whole explanation open: this is what every question here carries.

Deploy and manage Azure compute resources

A CI/CD pipeline uses GitHub Actions to deploy Bicep files to an Azure subscription. The pipeline must authenticate without storing long-lived credentials. Which Microsoft Entra capability provides the identity needed for automated deployment?

Microsoft Entra ID Governance (automates access requests and reviews)This automates access requests, assignments, and reviews for human identity lifecycle, not pipeline identity.
Microsoft Entra Private Access (secures access to private corporate apps)This secures remote user access to internal corporate networks and printers, not pipeline authentication.
Microsoft Entra Workload ID (identity for apps, services, and containers)Correct · your answerCorrect: this is the identity and access management solution for workload identities like pipelines and services.
Microsoft Entra Verified ID (issues and verifies digital credentials)This issues and verifies digital credentials such as diplomas, unrelated to pipeline authentication.
Microsoft Entra Domain Services (managed LDAP and Kerberos authentication)This provides legacy Kerberos and LDAP authentication for domain-joined applications, not CI/CD identity.

Correct.

Checked against learn.microsoft.com, July 2026

Concept

Automated deployment pipelines that call Azure Resource Manager need a nonhuman identity that can be authenticated and authorized without stored secrets.

Why C

Microsoft Entra Workload ID is built for applications, services, and containers such as a GitHub Actions workflow that needs to authenticate to Azure subscriptions to run deployment workflows.

Source

Microsoft Entra Workload ID is the identity and access management solution for workload identities — applications, services, and containers that require authentication and authorization policies.... For example, GitHub Actions need a workload identity to access Azure subscriptions to automate, customize, and execute software development workflows.

Microsoft Entra overview, checked July 2026
#arm-templates#bicep#workload-identity#automation

Now you: practice questions

No account needed. The explanation opens when you answer.

Sample question 1 of 3

Deploy and manage Azure compute resources

A developer's Bicep deployment to create storage accounts in a resource group fails with an authorization error. The developer currently has only the Reader role assigned at the subscription scope. Which change resolves the failure while following least privilege?

Sample question 2 of 3

Deploy and manage Azure compute resources

An administrator redeploys an ARM template to a resource group. A storage account created manually in that group, never listed in the template, is gone. Which deployment setting caused this?

Sample question 3 of 3

Deploy and manage Azure compute resources

A team redeploys a Bicep file in incremental mode after deleting one property line from an existing resource's declaration. After deployment, the live resource's property reverts to its default. Why?

Full Azure Administrator question bank coming

We’re writing the complete bank from the official objectives right now. Leave your email and we’ll tell you when it ships, nothing else, ever.

Read the sources

These are the official pages the questions above cite. Reading them is studying the objective from the primary source, which is what the explanations point you toward anyway.

More objectives in Deploy and manage Azure compute resources