Microsoft AZ-104 Entra Identity Management Practice Test
Topic 01 focuses on Microsoft Entra Users, Groups, Licensing, External Identities, and SSPR for the Microsoft Certified: Azure Administrator Associate certification and the AZ-104 exam, using Microsoft Azure administration scenarios. For broader exam preparation, review the Microsoft Azure Administrator AZ-104 Exam Dumps page. Each question includes a concise explanation of the correct answer and the technical reason the other choices are incorrect.
Question 1
To create and manage an Azure identity entirely in the cloud, which Azure configuration should be selected?
Correct Answer: A
Correct Answer
Answer A is correct because Cloud-only user is an identity created directly in Microsoft Entra ID rather than synchronized from an on-premises directory. It directly supports the requirement to create and manage an Azure identity entirely in the cloud.
Incorrect Answers
Answer B is incorrect because Self-service password reset (SSPR) is used to reduce help-desk password-reset work while requiring identity verification; it does not provide the capability described in the scenario.
Answer C is incorrect because Group-based licensing is used to administer licenses at scale by managing group membership instead of each user individually; it does not provide the capability described in the scenario.
Answer D is incorrect because Direct license assignment is used to license an individual user independently of group membership; it does not provide the capability described in the scenario.
Question 2
For Cloud-only user, which administrative outcome is expected?
Correct Answer: D
Correct Answer
Answer D is correct because Cloud-only user is an identity created directly in Microsoft Entra ID rather than synchronized from an on-premises directory. Its intended administrative use is to create and manage an Azure identity entirely in the cloud.
Incorrect Answers
Answer A is incorrect because that outcome belongs to Microsoft 365 group, which is used to support collaboration scenarios that need shared Microsoft 365 services; it is not the primary purpose of Cloud-only user.
Answer B is incorrect because that outcome belongs to User properties, which is used to maintain identity information that affects administration and access decisions; it is not the primary purpose of Cloud-only user.
Answer C is incorrect because that outcome belongs to Assigned group membership, which is used to control group membership manually when rule-based membership is not required; it is not the primary purpose of Cloud-only user.
Question 3
To support hybrid identity while keeping the authoritative user object on-premises, which Azure configuration should be selected?
Correct Answer: D
Correct Answer
Answer D is correct because Synchronized user is a Microsoft Entra user whose core identity originates in an on-premises directory and is synchronized to the cloud. It directly supports the requirement to support hybrid identity while keeping the authoritative user object on-premises.
Incorrect Answers
Answer A is incorrect because SSPR scope is used to control which users are permitted to use SSPR; it does not provide the capability described in the scenario.
Answer B is incorrect because User properties is used to maintain identity information that affects administration and access decisions; it does not provide the capability described in the scenario.
Answer C is incorrect because Security group is used to manage permissions for multiple identities as a single security principal; it does not provide the capability described in the scenario.
Question 4
For Synchronized user, which administrative outcome is expected?
Correct Answer: D
Correct Answer
Answer D is correct because Synchronized user is a Microsoft Entra user whose core identity originates in an on-premises directory and is synchronized to the cloud. Its intended administrative use is to support hybrid identity while keeping the authoritative user object on-premises.
Incorrect Answers
Answer A is incorrect because that outcome belongs to Usage location, which is used to provide the location value required for licensing decisions and service availability; it is not the primary purpose of Synchronized user.
Answer B is incorrect because that outcome belongs to Self-service password reset (SSPR), which is used to reduce help-desk password-reset work while requiring identity verification; it is not the primary purpose of Synchronized user.
Answer C is incorrect because that outcome belongs to Cloud-only user, which is used to create and manage an Azure identity entirely in the cloud; it is not the primary purpose of Synchronized user.
Question 5
To manage permissions for multiple identities as a single security principal, which Azure configuration should be selected?
Correct Answer: A
Correct Answer
Answer A is correct because Security group is a group that can be used to assign access to Azure resources and applications. It directly supports the requirement to manage permissions for multiple identities as a single security principal.
Incorrect Answers
Answer B is incorrect because Direct license assignment is used to license an individual user independently of group membership; it does not provide the capability described in the scenario.
Answer C is incorrect because B2B collaboration guest is used to grant controlled access to users from another organization without creating a normal internal workforce account; it does not provide the capability described in the scenario.
Answer D is incorrect because Microsoft 365 group is used to support collaboration scenarios that need shared Microsoft 365 services; it does not provide the capability described in the scenario.
Question 6
For Security group, which administrative outcome is expected?
Correct Answer: B
Correct Answer
Answer B is correct because Security group is a group that can be used to assign access to Azure resources and applications. Its intended administrative use is to manage permissions for multiple identities as a single security principal.
Incorrect Answers
Answer A is incorrect because that outcome belongs to Group owner, which is used to delegate routine group administration without granting broad directory-wide privileges; it is not the primary purpose of Security group.
Answer C is incorrect because that outcome belongs to Usage location, which is used to provide the location value required for licensing decisions and service availability; it is not the primary purpose of Security group.
Answer D is incorrect because that outcome belongs to Self-service password reset (SSPR), which is used to reduce help-desk password-reset work while requiring identity verification; it is not the primary purpose of Security group.
Question 7
To support collaboration scenarios that need shared Microsoft 365 services, which Azure configuration should be selected?
Correct Answer: B
Correct Answer
Answer B is correct because Microsoft 365 group is a collaboration-oriented group that can provide shared Microsoft 365 resources in addition to group membership. It directly supports the requirement to support collaboration scenarios that need shared Microsoft 365 services.
Incorrect Answers
Answer A is incorrect because Self-service password reset (SSPR) is used to reduce help-desk password-reset work while requiring identity verification; it does not provide the capability described in the scenario.
Answer C is incorrect because B2B collaboration guest is used to grant controlled access to users from another organization without creating a normal internal workforce account; it does not provide the capability described in the scenario.
Answer D is incorrect because Group owner is used to delegate routine group administration without granting broad directory-wide privileges; it does not provide the capability described in the scenario.
Question 8
For Microsoft 365 group, which administrative outcome is expected?
Correct Answer: B
Correct Answer
Answer B is correct because Microsoft 365 group is a collaboration-oriented group that can provide shared Microsoft 365 resources in addition to group membership. Its intended administrative use is to support collaboration scenarios that need shared Microsoft 365 services.
Incorrect Answers
Answer A is incorrect because that outcome belongs to Usage location, which is used to provide the location value required for licensing decisions and service availability; it is not the primary purpose of Microsoft 365 group.
Answer C is incorrect because that outcome belongs to SSPR scope, which is used to control which users are permitted to use SSPR; it is not the primary purpose of Microsoft 365 group.
Answer D is incorrect because that outcome belongs to Group-based licensing, which is used to administer licenses at scale by managing group membership instead of each user individually; it is not the primary purpose of Microsoft 365 group.
Question 9
To keep group membership aligned automatically with defined identity attributes, which Azure configuration should be selected?
Correct Answer: C
Correct Answer
Answer C is correct because Dynamic group membership is membership that Microsoft Entra ID evaluates automatically from user or device attribute rules. It directly supports the requirement to keep group membership aligned automatically with defined identity attributes.
Incorrect Answers
Answer A is incorrect because Security group is used to manage permissions for multiple identities as a single security principal; it does not provide the capability described in the scenario.
Answer B is incorrect because B2B collaboration guest is used to grant controlled access to users from another organization without creating a normal internal workforce account; it does not provide the capability described in the scenario.
Answer D is incorrect because Guest invitation redemption is used to complete onboarding of an invited external identity; it does not provide the capability described in the scenario.
Question 10
For Dynamic group membership, which administrative outcome is expected?
Correct Answer: C
Correct Answer
Answer C is correct because Dynamic group membership is membership that Microsoft Entra ID evaluates automatically from user or device attribute rules. Its intended administrative use is to keep group membership aligned automatically with defined identity attributes.
Incorrect Answers
Answer A is incorrect because that outcome belongs to B2B collaboration guest, which is used to grant controlled access to users from another organization without creating a normal internal workforce account; it is not the primary purpose of Dynamic group membership.
Answer B is incorrect because that outcome belongs to Usage location, which is used to provide the location value required for licensing decisions and service availability; it is not the primary purpose of Dynamic group membership.
Answer D is incorrect because that outcome belongs to User properties, which is used to maintain identity information that affects administration and access decisions; it is not the primary purpose of Dynamic group membership.
Question 11
To control group membership manually when rule-based membership is not required, which Azure configuration should be selected?
Correct Answer: D
Correct Answer
Answer D is correct because Assigned group membership is membership in which an administrator or group owner explicitly adds and removes members. It directly supports the requirement to control group membership manually when rule-based membership is not required.
Incorrect Answers
Answer A is incorrect because B2B collaboration guest is used to grant controlled access to users from another organization without creating a normal internal workforce account; it does not provide the capability described in the scenario.
Answer B is incorrect because Dynamic group membership is used to keep group membership aligned automatically with defined identity attributes; it does not provide the capability described in the scenario.
Answer C is incorrect because Self-service password reset (SSPR) is used to reduce help-desk password-reset work while requiring identity verification; it does not provide the capability described in the scenario.
Question 12
For Assigned group membership, which administrative outcome is expected?
Correct Answer: A
Correct Answer
Answer A is correct because Assigned group membership is membership in which an administrator or group owner explicitly adds and removes members. Its intended administrative use is to control group membership manually when rule-based membership is not required.
Incorrect Answers
Answer B is incorrect because that outcome belongs to Guest invitation redemption, which is used to complete onboarding of an invited external identity; it is not the primary purpose of Assigned group membership.
Answer C is incorrect because that outcome belongs to Self-service password reset (SSPR), which is used to reduce help-desk password-reset work while requiring identity verification; it is not the primary purpose of Assigned group membership.
Answer D is incorrect because that outcome belongs to Synchronized user, which is used to support hybrid identity while keeping the authoritative user object on-premises; it is not the primary purpose of Assigned group membership.
Question 13
To administer licenses at scale by managing group membership instead of each user individually, which Azure configuration should be selected?
Correct Answer: A
Correct Answer
Answer A is correct because Group-based licensing is license assignment applied to a group so eligible members inherit the licenses. It directly supports the requirement to administer licenses at scale by managing group membership instead of each user individually.
Incorrect Answers
Answer B is incorrect because Dynamic group membership is used to keep group membership aligned automatically with defined identity attributes; it does not provide the capability described in the scenario.
Answer C is incorrect because Direct license assignment is used to license an individual user independently of group membership; it does not provide the capability described in the scenario.
Answer D is incorrect because B2B collaboration guest is used to grant controlled access to users from another organization without creating a normal internal workforce account; it does not provide the capability described in the scenario.
Question 14
For Group-based licensing, which administrative outcome is expected?
Correct Answer: B
Correct Answer
Answer B is correct because Group-based licensing is license assignment applied to a group so eligible members inherit the licenses. Its intended administrative use is to administer licenses at scale by managing group membership instead of each user individually.
Incorrect Answers
Answer A is incorrect because that outcome belongs to Synchronized user, which is used to support hybrid identity while keeping the authoritative user object on-premises; it is not the primary purpose of Group-based licensing.
Answer C is incorrect because that outcome belongs to B2B collaboration guest, which is used to grant controlled access to users from another organization without creating a normal internal workforce account; it is not the primary purpose of Group-based licensing.
Answer D is incorrect because that outcome belongs to Security group, which is used to manage permissions for multiple identities as a single security principal; it is not the primary purpose of Group-based licensing.
Question 15
To license an individual user independently of group membership, which Azure configuration should be selected?
Correct Answer: C
Correct Answer
Answer C is correct because Direct license assignment is a product license assigned to a specific user object. It directly supports the requirement to license an individual user independently of group membership.
Incorrect Answers
Answer A is incorrect because Self-service password reset (SSPR) is used to reduce help-desk password-reset work while requiring identity verification; it does not provide the capability described in the scenario.
Answer B is incorrect because Guest invitation redemption is used to complete onboarding of an invited external identity; it does not provide the capability described in the scenario.
Answer D is incorrect because Group-based licensing is used to administer licenses at scale by managing group membership instead of each user individually; it does not provide the capability described in the scenario.
Question 16
For Direct license assignment, which administrative outcome is expected?
Correct Answer: C
Correct Answer
Answer C is correct because Direct license assignment is a product license assigned to a specific user object. Its intended administrative use is to license an individual user independently of group membership.
Incorrect Answers
Answer A is incorrect because that outcome belongs to Group owner, which is used to delegate routine group administration without granting broad directory-wide privileges; it is not the primary purpose of Direct license assignment.
Answer B is incorrect because that outcome belongs to Synchronized user, which is used to support hybrid identity while keeping the authoritative user object on-premises; it is not the primary purpose of Direct license assignment.
Answer D is incorrect because that outcome belongs to Assigned group membership, which is used to control group membership manually when rule-based membership is not required; it is not the primary purpose of Direct license assignment.
Question 17
To provide the location value required for licensing decisions and service availability, which Azure configuration should be selected?
Correct Answer: D
Correct Answer
Answer D is correct because Usage location is the user property that identifies the country or region used when determining service availability for licensing. It directly supports the requirement to provide the location value required for licensing decisions and service availability.
Incorrect Answers
Answer A is incorrect because Cloud-only user is used to create and manage an Azure identity entirely in the cloud; it does not provide the capability described in the scenario.
Answer B is incorrect because Dynamic group membership is used to keep group membership aligned automatically with defined identity attributes; it does not provide the capability described in the scenario.
Answer C is incorrect because User properties is used to maintain identity information that affects administration and access decisions; it does not provide the capability described in the scenario.
Question 18
For Usage location, which administrative outcome is expected?
Correct Answer: B
Correct Answer
Answer B is correct because Usage location is the user property that identifies the country or region used when determining service availability for licensing. Its intended administrative use is to provide the location value required for licensing decisions and service availability.
Incorrect Answers
Answer A is incorrect because that outcome belongs to Dynamic group membership, which is used to keep group membership aligned automatically with defined identity attributes; it is not the primary purpose of Usage location.
Answer C is incorrect because that outcome belongs to Synchronized user, which is used to support hybrid identity while keeping the authoritative user object on-premises; it is not the primary purpose of Usage location.
Answer D is incorrect because that outcome belongs to User properties, which is used to maintain identity information that affects administration and access decisions; it is not the primary purpose of Usage location.
Question 19
To grant controlled access to users from another organization without creating a normal internal workforce account, which Azure configuration should be selected?
Correct Answer: A
Correct Answer
Answer A is correct because B2B collaboration guest is an external identity represented in the tenant so a partner or other outside user can access shared resources. It directly supports the requirement to grant controlled access to users from another organization without creating a normal internal workforce account.
Incorrect Answers
Answer B is incorrect because Self-service password reset (SSPR) is used to reduce help-desk password-reset work while requiring identity verification; it does not provide the capability described in the scenario.
Answer C is incorrect because Microsoft 365 group is used to support collaboration scenarios that need shared Microsoft 365 services; it does not provide the capability described in the scenario.
Answer D is incorrect because Dynamic group membership is used to keep group membership aligned automatically with defined identity attributes; it does not provide the capability described in the scenario.
Question 20
For B2B collaboration guest, which administrative outcome is expected?
Correct Answer: B
Correct Answer
Answer B is correct because B2B collaboration guest is an external identity represented in the tenant so a partner or other outside user can access shared resources. Its intended administrative use is to grant controlled access to users from another organization without creating a normal internal workforce account.
Incorrect Answers
Answer A is incorrect because that outcome belongs to Microsoft 365 group, which is used to support collaboration scenarios that need shared Microsoft 365 services; it is not the primary purpose of B2B collaboration guest.
Answer C is incorrect because that outcome belongs to Guest invitation redemption, which is used to complete onboarding of an invited external identity; it is not the primary purpose of B2B collaboration guest.
Answer D is incorrect because that outcome belongs to Synchronized user, which is used to support hybrid identity while keeping the authoritative user object on-premises; it is not the primary purpose of B2B collaboration guest.
Question 21
To complete onboarding of an invited external identity, which Azure configuration should be selected?
Correct Answer: C
Correct Answer
Answer C is correct because Guest invitation redemption is the process by which an invited external user accepts the invitation and establishes access to the resource tenant. It directly supports the requirement to complete onboarding of an invited external identity.
Incorrect Answers
Answer A is incorrect because Synchronized user is used to support hybrid identity while keeping the authoritative user object on-premises; it does not provide the capability described in the scenario.
Answer B is incorrect because Dynamic group membership is used to keep group membership aligned automatically with defined identity attributes; it does not provide the capability described in the scenario.
Answer D is incorrect because User properties is used to maintain identity information that affects administration and access decisions; it does not provide the capability described in the scenario.
Question 22
For Guest invitation redemption, which administrative outcome is expected?
Correct Answer: D
Correct Answer
Answer D is correct because Guest invitation redemption is the process by which an invited external user accepts the invitation and establishes access to the resource tenant. Its intended administrative use is to complete onboarding of an invited external identity.
Incorrect Answers
Answer A is incorrect because that outcome belongs to SSPR scope, which is used to control which users are permitted to use SSPR; it is not the primary purpose of Guest invitation redemption.
Answer B is incorrect because that outcome belongs to Group-based licensing, which is used to administer licenses at scale by managing group membership instead of each user individually; it is not the primary purpose of Guest invitation redemption.
Answer C is incorrect because that outcome belongs to B2B collaboration guest, which is used to grant controlled access to users from another organization without creating a normal internal workforce account; it is not the primary purpose of Guest invitation redemption.
Question 23
To maintain identity information that affects administration and access decisions, which Azure configuration should be selected?
Correct Answer: B
Correct Answer
Answer B is correct because User properties is attributes such as display name, job information, usage location, and account state stored on a Microsoft Entra user object. It directly supports the requirement to maintain identity information that affects administration and access decisions.
Incorrect Answers
Answer A is incorrect because Group-based licensing is used to administer licenses at scale by managing group membership instead of each user individually; it does not provide the capability described in the scenario.
Answer C is incorrect because Guest invitation redemption is used to complete onboarding of an invited external identity; it does not provide the capability described in the scenario.
Answer D is incorrect because Direct license assignment is used to license an individual user independently of group membership; it does not provide the capability described in the scenario.
Question 24
For User properties, which administrative outcome is expected?
Correct Answer: A
Correct Answer
Answer A is correct because User properties is attributes such as display name, job information, usage location, and account state stored on a Microsoft Entra user object. Its intended administrative use is to maintain identity information that affects administration and access decisions.
Incorrect Answers
Answer B is incorrect because that outcome belongs to Dynamic group membership, which is used to keep group membership aligned automatically with defined identity attributes; it is not the primary purpose of User properties.
Answer C is incorrect because that outcome belongs to Self-service password reset (SSPR), which is used to reduce help-desk password-reset work while requiring identity verification; it is not the primary purpose of User properties.
Answer D is incorrect because that outcome belongs to Group-based licensing, which is used to administer licenses at scale by managing group membership instead of each user individually; it is not the primary purpose of User properties.
Question 25
To delegate routine group administration without granting broad directory-wide privileges, which Azure configuration should be selected?
Correct Answer: B
Correct Answer
Answer B is correct because Group owner is an identity delegated the ability to manage membership and selected settings for a group. It directly supports the requirement to delegate routine group administration without granting broad directory-wide privileges.
Incorrect Answers
Answer A is incorrect because Dynamic group membership is used to keep group membership aligned automatically with defined identity attributes; it does not provide the capability described in the scenario.
Answer C is incorrect because Guest invitation redemption is used to complete onboarding of an invited external identity; it does not provide the capability described in the scenario.
Answer D is incorrect because Assigned group membership is used to control group membership manually when rule-based membership is not required; it does not provide the capability described in the scenario.
Question 26
For Group owner, which administrative outcome is expected?
Correct Answer: A
Correct Answer
Answer A is correct because Group owner is an identity delegated the ability to manage membership and selected settings for a group. Its intended administrative use is to delegate routine group administration without granting broad directory-wide privileges.
Incorrect Answers
Answer B is incorrect because that outcome belongs to Usage location, which is used to provide the location value required for licensing decisions and service availability; it is not the primary purpose of Group owner.
Answer C is incorrect because that outcome belongs to Assigned group membership, which is used to control group membership manually when rule-based membership is not required; it is not the primary purpose of Group owner.
Answer D is incorrect because that outcome belongs to Dynamic group membership, which is used to keep group membership aligned automatically with defined identity attributes; it is not the primary purpose of Group owner.
Question 27
To reduce help-desk password-reset work while requiring identity verification, which Azure configuration should be selected?
Correct Answer: A
Correct Answer
Answer A is correct because Self-service password reset (SSPR) is a Microsoft Entra capability that lets enabled users reset or unlock their password after satisfying configured verification requirements. It directly supports the requirement to reduce help-desk password-reset work while requiring identity verification.
Incorrect Answers
Answer B is incorrect because Security group is used to manage permissions for multiple identities as a single security principal; it does not provide the capability described in the scenario.
Answer C is incorrect because SSPR scope is used to control which users are permitted to use SSPR; it does not provide the capability described in the scenario.
Answer D is incorrect because Group-based licensing is used to administer licenses at scale by managing group membership instead of each user individually; it does not provide the capability described in the scenario.
Question 28
For Self-service password reset (SSPR), which administrative outcome is expected?
Correct Answer: C
Correct Answer
Answer C is correct because Self-service password reset (SSPR) is a Microsoft Entra capability that lets enabled users reset or unlock their password after satisfying configured verification requirements. Its intended administrative use is to reduce help-desk password-reset work while requiring identity verification.
Incorrect Answers
Answer A is incorrect because that outcome belongs to Guest invitation redemption, which is used to complete onboarding of an invited external identity; it is not the primary purpose of Self-service password reset (SSPR).
Answer B is incorrect because that outcome belongs to Synchronized user, which is used to support hybrid identity while keeping the authoritative user object on-premises; it is not the primary purpose of Self-service password reset (SSPR).
Answer D is incorrect because that outcome belongs to B2B collaboration guest, which is used to grant controlled access to users from another organization without creating a normal internal workforce account; it is not the primary purpose of Self-service password reset (SSPR).
Question 29
To control which users are permitted to use SSPR, which Azure configuration should be selected?
Correct Answer: C
Correct Answer
Answer C is correct because SSPR scope is the setting that determines whether self-service password reset is disabled, enabled for selected groups, or enabled for all users. It directly supports the requirement to control which users are permitted to use SSPR.
Incorrect Answers
Answer A is incorrect because Group-based licensing is used to administer licenses at scale by managing group membership instead of each user individually; it does not provide the capability described in the scenario.
Answer B is incorrect because User properties is used to maintain identity information that affects administration and access decisions; it does not provide the capability described in the scenario.
Answer D is incorrect because Assigned group membership is used to control group membership manually when rule-based membership is not required; it does not provide the capability described in the scenario.
Question 30
For SSPR scope, which administrative outcome is expected?
Correct Answer: D
Correct Answer
Answer D is correct because SSPR scope is the setting that determines whether self-service password reset is disabled, enabled for selected groups, or enabled for all users. Its intended administrative use is to control which users are permitted to use SSPR.
Incorrect Answers
Answer A is incorrect because that outcome belongs to User properties, which is used to maintain identity information that affects administration and access decisions; it is not the primary purpose of SSPR scope.
Answer B is incorrect because that outcome belongs to Self-service password reset (SSPR), which is used to reduce help-desk password-reset work while requiring identity verification; it is not the primary purpose of SSPR scope.
Answer C is incorrect because that outcome belongs to Group owner, which is used to delegate routine group administration without granting broad directory-wide privileges; it is not the primary purpose of SSPR scope.
Popular posts
Recent Posts
