Identity and governance guide
AZ-104 Identity and Governance: Entra ID, RBAC, Policies and Cost Control
AZ-104 identity and governance questions test whether you can control who has access, where controls apply and how resources stay organised. The official skills outline includes Microsoft Entra users and groups, Azure RBAC, subscriptions, resource groups, Azure Policy, locks, tags, budgets, Advisor recommendations and management groups.
Direct Answer
AZ-104 identity and governance questions test whether you can control who has access, where controls apply and how resources stay organised. The official skills outline includes Microsoft Entra users and groups, Azure RBAC, subscriptions, resource groups, Azure Policy, locks, tags, budgets, Advisor recommendations and management groups.
This domain is important because many Azure administration decisions begin with scope. A candidate who understands tenant, management group, subscription, resource group and resource scope can usually eliminate several wrong answers before touching the service details.
What to Know First
Use these quick points to frame your preparation before you start detailed practice.
Official weight
Manage Azure identities and governance is listed at 20-25%.
Most tested pattern
Choose between RBAC, policy, locks and tags based on the requirement.
Core habit
Always identify the scope before selecting the control.
Microsoft Entra Users and Groups
The study guide includes creating users and groups, managing properties, managing licenses, managing external users and configuring self-service password reset. For AZ-104, you should know how identity objects support Azure resource administration.
Practice questions often hide identity requirements inside operational wording. For example, if external contractors need temporary access to a resource group, the answer may involve external users and a scoped role assignment rather than broad subscription access.
Azure RBAC and Access Scope
RBAC is about permissions. You should know built-in roles, role assignment scopes and how to interpret access assignments. The common trap is assigning too much permission at too broad a scope.
When reviewing practice questions, ask what the user needs to do and where. A reader role at subscription scope is very different from a contributor role at resource-group scope.
Azure Policy, Locks, Tags and Management Groups
Azure Policy enforces rules or audits compliance. Resource locks help prevent accidental deletion or modification. Tags organise metadata for reporting and cost allocation. Management groups organise subscriptions for governance at scale.
These controls overlap in the way scenarios are written, but they do not do the same job. If the requirement is to require a tag, think policy. If the requirement is to prevent deletion, think lock. If the requirement is to let a user manage one resource group, think RBAC.
Governance Control Decision Table
Original Governance Scenario
A company has three subscriptions for development, test and production. Production resources must have cost-centre tags, accidental deletion must be prevented and developers should only manage development resources. A strong answer separates Azure Policy for tag enforcement, locks for deletion protection and RBAC for developer permissions.
This is the central identity and governance lesson: one scenario can require several controls, but each control solves a different problem.
Common Mistakes to Avoid
Using RBAC for everything
RBAC controls access. It does not enforce tags or prevent deletion by itself.
Forgetting management groups
Management groups are important when governance spans multiple subscriptions.
Confusing tags with policy
Tags store metadata; policy can require, add or audit tag rules depending on configuration.
How to Practise Scope Decisions
Build practice scenarios where the same permission is assigned at different scopes. Ask what changes if a role is assigned at the subscription, resource group or resource level. Then compare that with policy assignment at a management group or subscription level.
AZ-104 often tests this exact judgement. The control may be familiar, but the scope decides whether the answer is safe, excessive or ineffective.
Governance Patterns That Repeat
A tag requirement usually points toward Azure Policy. A permission requirement usually points toward RBAC. Deletion protection usually points toward a lock. Cost alerting points toward budgets, cost alerts or Advisor recommendations. Subscription organisation points toward management groups.
These patterns are simple, but they become powerful when you apply them before reading the answer choices. Decide what problem the prompt describes, then look for the Azure control that matches that problem.
Identity and Governance Practice Checklist
Before leaving this domain, make sure you can create users and groups, understand external users, describe SSPR, assign built-in roles, interpret access assignments, manage resource groups, apply tags, explain policy, configure locks and describe management-group purpose.
You should also be able to explain what each control cannot do. Knowing the boundary of a feature is often what separates the correct answer from the tempting distractor.
How to Use This Guide With AZ-104 Practice
Read the guide once for orientation, then turn it into active practice. Create a short list of decisions you should be able to make after studying this topic. For AZ-104 identity and governance, that means more than recognising terms. You should be able to read a scenario, identify the real requirement, choose the Azure control that fits, and explain why the nearby alternatives are weaker.
After each practice set, review missed questions in three layers. First, identify the domain: identity, governance, storage, compute, networking, monitoring or recovery. Second, identify the mistake type: knowledge gap, wrong scope, missed constraint, timing pressure or distractor confusion. Third, write one repair action that you can complete before the next session.
This is the difference between passive reading and exam preparation. Passive reading makes the topic feel familiar. Active practice makes the topic usable when a new question changes the wording, combines domains or hides the deciding detail near the end of the prompt.
How This Topic Connects to the Rest of AZ-104
No AZ-104 domain lives alone. A compute question may include networking constraints, identity permissions, storage access and monitoring requirements. A governance question may include cost control, management-group scope and resource locks. A storage question may depend on private endpoints, firewall rules, lifecycle management and backup expectations.
When reviewing AZ-104 Identity and Governance: Entra ID, RBAC, Policies and Cost Control, deliberately connect it to at least two other domains. Ask how the topic changes when security, cost, availability, deployment or recovery becomes the priority. This cross-domain thinking is what makes practice more realistic and prevents the exam from feeling like a set of disconnected trivia questions.
Turn This Guide Into Practice
Use realistic AZ-104 practice to turn knowledge into administrator decisions: read the scenario, identify the scope, choose the right Azure control and review every explanation.
Frequently Asked Questions
What is the difference between RBAC and Azure Policy?
RBAC controls who can perform actions. Azure Policy controls or audits resource compliance.
When should I use a resource lock?
Use a resource lock when the requirement is to prevent accidental deletion or modification.
Are tags tested in AZ-104?
Yes. The study guide includes applying and managing tags on resources.
Do I need to know Microsoft Entra ID?
Yes. The study guide includes users, groups, licenses, external users and SSPR.
Why are management groups important?
They help organise subscriptions so governance can be applied at scale.
Keep Building AZ-104 Readiness
Review the current Microsoft Learn study guide, practise with original scenarios, and use timed mixed sets when you are close to exam day.
Provider disclaimer: Heycademy is not affiliated with or endorsed by Microsoft. This page uses publicly available Microsoft Learn information for preparation guidance and original practice examples only.