AZ-104 - Manage Azure Identities and Governance (23% of the exam) - Section 1.1

Manage Microsoft Entra users and groups.

Create and manage Microsoft Entra ID user accounts, distinguish between security groups and Microsoft 365 groups, and configure dynamic membership rules that automatically assign users based on attributes. Apply bulk operations to create or update large sets of users efficiently, and recognise when dynamic membership is appropriate versus direct assignment.

Microsoft Entra IDuser accountsgroup typesdynamic membershipbulk operations

Practice question for this objective

Free sampleManage Azure Identities and Governancemedium

An administrator needs to assign and unassign Microsoft Entra licenses to users and groups for the tenant. Which management surface does Microsoft direct administrators to use for these license assignments?

  • AThe Azure billing portal for assigning and unassigning user and group licenses
  • BThe Microsoft 365 admin center for assigning and unassigning user and group licenses Correct
  • CThe Microsoft Entra pricing page for assigning and unassigning user and group licenses
  • DThe Microsoft Defender portal for assigning and unassigning user and group licenses
Assign and unassign Microsoft Entra user and group licenses in the Microsoft 365 admin center. User and group license assignments are managed through the Microsoft 365 admin center, per the licensing documentation.

Why A is wrong: Billing handles invoices and subscriptions, not the per-identity license assignment task.

Why B is correct: Correct. User and group license assignments are managed through the Microsoft 365 admin center, per the licensing documentation.

Why C is wrong: The pricing page compares plans and does not perform license assignment.

Why D is wrong: Defender manages security workloads and is not the documented license assignment surface.

See more AZ-104 practice questions, answers explained.

Exam traps in Manage Azure Identities and Governance

Answers that look right on this material and are not. Each one is a distractor from a different question in the AZ-104 bank for this domain.

  • Yes

    Why it is wrong: You can create dynamic membership groups for users or devices, but you can't create a rule that contains both users and devices. Security groups can include either devices or users, so the combined-rule design is not allowed and the work must be split across two groups.

  • Guest Inviter

    Why it is wrong: Guest Inviter is the least-privileged role for inviting an external guest, not for creating a new internal user.

  • At least the User Administrator role

    Why it is wrong: User Administrator manages users and is valid for many group tasks, but the documented pause-and-resume control names Groups Administrator.

Examworthy is not affiliated with or endorsed by Microsoft. Original, blueprint-aligned practice material only.