AZ-104 - Manage Azure Identities and Governance - Section 1.2

Manage access to Azure resources using Azure role-based access control.

Understand how Azure RBAC role assignments grant permissions at a scope - management group, subscription, resource group, or resource - and how child scopes inherit assignments from parents. Distinguish between built-in roles such as Owner, Contributor, and Reader, and design custom roles when built-in definitions do not satisfy least-privilege requirements.

Azure RBACbuilt-in rolescustom rolesrole assignmentsscope hierarchy

Practice question for this objective

Free sampleManage Azure Identities and Governancehard

An administrator needs to delegate the ability to assign roles to other principals in Azure RBAC at a given scope. Which two built-in roles include the ability to assign roles in Azure RBAC? (Select 2 answers)

  • AUser Access Administrator Correct
  • BRole Based Access Control Administrator Correct
  • CVirtual Machine Contributor
  • DStorage Blob Data Contributor
  • EStorage Blob Data Owner
User Access Administrator and Role Based Access Control Administrator can assign roles in Azure RBAC, whereas job function and data roles such as Virtual Machine Contributor or Storage Blob Data The grounding lists both User Access Administrator and Role Based Access Control Administrator as privileged roles that manage user access and assign roles in Azure RBAC. Job function and data roles such as Virtual Machine Contributor and the storage data roles are not on that privileged list, so they cannot assign roles to other principals.

Why A is correct: Correct. User Access Administrator is one of the keyed answers. The grounding lists both User Access Administrator and Role Based Access Control Administrator as privileged roles that manage user access and assign roles in Azure RBAC.

Why B is correct: Correct. Role Based Access Control Administrator is one of the keyed answers. The grounding lists both User Access Administrator and Role Based Access Control Administrator as privileged roles that manage user access and assign roles in Azure RBAC.

Why C is wrong: Virtual Machine Contributor is a job function role for creating and managing virtual machines, and job function roles cannot assign roles in Azure RBAC.

Why D is wrong: Storage Blob Data Contributor grants access to blob data only, so it manages data rather than assigning roles in Azure RBAC to other principals.

Why E is wrong: Storage Blob Data Owner is administrator level for blob data but is not a privileged role that assigns roles in Azure RBAC, despite the word Owner in its name.

See more AZ-104 practice questions, answers explained.

More in this domain

Back to all Manage Azure Identities and Governance objectives, or the AZ-104 cert hub.

Examworthy is not affiliated with or endorsed by Microsoft. Original, blueprint-aligned practice material only.