MICROSOFT CERTIFIED AZ-104

Microsoft Azure Administrator

The core Azure operations certification: identities, governance, storage, compute, networking and monitoring.

Unlock AZ-104 - 90-day access

6 full-length premium mock exams with full explanations on every question, review mode, practice mode and unlimited retakes for 90 days. New exams added to this track during your window are included.

Pass guarantee: average 85%+ across this track's mocks, sit the real exam, and if you fail we refund you in full. 14-day money-back on top. Terms.

Start the free diagnostic - no account needed Create account

Free Diagnostic Exam Free

15 questions · 20 min · pass mark 70% · Find out if you'd pass AZ-104 today

Practice Exam 1 Premium

60 questions · 100 min · pass mark 70% · Full-length AZ-104 format: 60 questions in 100 minutes across all five domains. Case-study and drag-and-drop items are represented as scenario questions.

Practice Exam 2 Premium

60 questions · 100 min · pass mark 70% · Full-length AZ-104 format: 60 questions in 100 minutes across all five domains. Case-study and drag-and-drop items are represented as scenario questions.

Practice Exam 3 Premium

60 questions · 100 min · pass mark 70% · Full-length AZ-104 format: 60 questions in 100 minutes across all five domains. Case-study and drag-and-drop items are represented as scenario questions.

Practice Exam 4 Premium

60 questions · 100 min · pass mark 70% · Full-length AZ-104 format: 60 questions in 100 minutes across all five domains. Case-study and drag-and-drop items are represented as scenario questions.

Practice Exam 5 Premium

60 questions · 100 min · pass mark 70% · Full-length AZ-104 format: 60 questions in 100 minutes across all five domains. Case-study and drag-and-drop items are represented as scenario questions.

Practice Exam 6 Premium

60 questions · 100 min · pass mark 70% · Full-length AZ-104 format: 60 questions in 100 minutes across all five domains. Case-study and drag-and-drop items are represented as scenario questions.

Sample questions from this bank

Straight from the premium AZ-104 exams, explanation included. Judge the quality before you spend a cent.

Manage Azure Identities and Governance

A company wants members of a security group to be added and removed automatically whenever a user's department attribute changes to or from 'Engineering'. Which group configuration should an administrator use?

  • A An assigned security group with manual membership
  • B A dynamic device group filtered by device name
  • C A Microsoft 365 group with an assigned owner
  • D A dynamic user group with a membership rule on the department attribute
Show answer and explanation

Correct: D

A dynamic user group evaluates a membership rule (for example department equals Engineering) and adds or removes users automatically as their attributes change. An assigned group requires manual edits, a dynamic device group targets devices rather than users, and adding an owner to a Microsoft 365 group does not automate membership.

Reference: https://learn.microsoft.com/en-us/entra/identity/users/groups-dynamic-membership

Manage Azure Identities and Governance

A helpdesk team must be able to start, stop, restart, and resize existing virtual machines but must not be able to change the virtual network the VMs connect to or grant access to others. Which built-in role fits best?

  • A Virtual Machine Contributor
  • B Owner
  • C Contributor
  • D Network Contributor
Show answer and explanation

Correct: A

Virtual Machine Contributor lets a user manage virtual machines, including power and resize operations, but not the connected virtual network or storage and not role assignments. Contributor and Owner are far broader, and Network Contributor manages networking rather than VMs.

Reference: https://learn.microsoft.com/en-us/azure/role-based-access-control/built-in-roles

Manage Azure Identities and Governance

You are building a custom RBAC role that should permit every compute action except deleting virtual machines. Which element of the role definition should list the delete operation you want to block?

  • A Actions
  • B DataActions
  • C AssignableScopes
  • D NotActions
Show answer and explanation

Correct: D

NotActions lists operations subtracted from the permissions granted by Actions, so placing the VM delete operation there blocks it while still allowing the rest. Actions grants permissions, DataActions covers data-plane operations, and AssignableScopes defines where the role can be assigned.

Reference: https://learn.microsoft.com/en-us/azure/role-based-access-control/custom-roles

Every question in the bank ships with an explanation at this depth. See how our questions are made.

About the AZ-104 exam

What the real exam looks like and how PassForge gets you ready for it.

Format 40 to 60 questions, 100 minutes. Multiple choice, multiple response, case studies, and drag-and-drop.
Passing score 700 out of 1000. PassForge sets its pass mark at 70%.
Real exam cost 165 USD to sit the real exam.

Domains and official weights

Every PassForge mock in this track mirrors these proportions, so your practice score maps to the real one.

Manage Azure Identities and Governance 22%
Implement and Manage Storage 17%
Deploy and Manage Azure Compute Resources 27%
Implement and Manage Virtual Networking 20%
Monitor and Maintain Azure Resources 14%

How scoring works

AZ-104 is scored 1 to 1000 with a 700 pass line. Some questions sit inside a case study with shared context, and a few sections may not allow you to go back, so read carefully the first time on the real exam.

How to pass with PassForge

  1. Take the free diagnostic to see your per-domain breakdown.
  2. Review the explanation and reference on every miss.
  3. Drill Compute and Identity first, they are the largest domains.
  4. Run timed mocks until you clear 70% with time to spare.
  5. Book the real exam once you are steady above the bar.