AZ-104 - Manage Azure Identities and Governance (23% of the exam) - Section 1.3

Manage Azure subscriptions and governance using tags, policies, resource locks, and Cost Management.

Configure Azure Policy definitions and assignments to enforce compliance, apply resource tags to organise and allocate costs, and use management groups to apply governance consistently across multiple subscriptions. Distinguish between ReadOnly and CanNotDelete resource locks, and use Azure Cost Management to analyse spending and set budgets.

Azure Policyresource tagsresource locksmanagement groupsAzure Cost Management

Practice question for this objective

Free sampleManage Azure Identities and Governancemedium

An architect wants to apply a consistent tag set across a management group, a subscription, a resource group, and individual resources for cost reporting. At which scope can tags NOT be applied directly?

  • ASubscriptions
  • BResource groups
  • CIndividual resources
  • DManagement groups Correct
Tags apply to resources, resource groups, and subscriptions, but never to management groups. You can apply tags to Azure resources, resource groups, and subscriptions but not to management groups.

Why A is wrong: Tags can be applied to subscriptions.

Why B is wrong: Tags can be applied to resource groups.

Why C is wrong: Tags can be applied to individual resources.

Why D is correct: Correct. You can apply tags to Azure resources, resource groups, and subscriptions but not to management groups.

See more AZ-104 practice questions, answers explained.

Exam traps in Manage Azure Identities and Governance

Answers that look right on this material and are not. Each one is a distractor from a different question in the AZ-104 bank for this domain.

  • A policy assignment, which the SDK refers to as a PolicyScope

    Why it is wrong: An assignment binds a definition to a scope; it is not the grouping object, and PolicyScope is not the SDK term.

  • Yes

    Why it is wrong: Although a policy can be assigned at the management group level, only resources at the subscription or resource group level are evaluated, so assuming Yes would misjudge the scope of evaluation.

  • Tags propagate after a delay, so the administrator should wait and refresh the view

    Why it is wrong: There is no propagation delay; resources simply do not inherit group tags at all.

Examworthy is not affiliated with or endorsed by Microsoft. Original, blueprint-aligned practice material only.