- 477 Actual Exam Questions
- Compatible with all Devices
- Printable Format
- No Download Limits
- 90 Days Free Updates
Get All Microsoft Azure Administrator Exam Questions with Validated Answers
| Vendor: | Microsoft |
|---|---|
| Exam Code: | AZ-104 |
| Exam Name: | Microsoft Azure Administrator Exam |
| Exam Questions: | 477 |
| Last Updated: | August 8, 2026 |
| Related Certifications: | Azure Administrator Associate |
| Exam Tags: | Cloud Certifications, Microsoft Azure Certifications Intermediate Azure Administrators |
Looking for a hassle-free way to pass the Microsoft Azure Administrator Exam? DumpsProvider provides the most reliable Dumps Questions and Answers, designed by Microsoft certified experts to help you succeed in record time. Available in both PDF and Online Practice Test formats, our study materials cover every major exam topic, making it possible for you to pass potentially within just one day!
DumpsProvider is a leading provider of high-quality exam dumps, trusted by professionals worldwide. Our Microsoft AZ-104 exam questions give you the knowledge and confidence needed to succeed on the first attempt.
Train with our Microsoft AZ-104 exam practice tests, which simulate the actual exam environment. This real-test experience helps you get familiar with the format and timing of the exam, ensuring you're 100% prepared for exam day.
Your success is our commitment! That's why DumpsProvider offers a 100% money-back guarantee. If you don’t pass the Microsoft AZ-104 exam, we’ll refund your payment within 24 hours no questions asked.
Don’t waste time with unreliable exam prep resources. Get started with DumpsProvider’s Microsoft AZ-104 exam dumps today and achieve your certification effortlessly!
Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.
After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.
You have an Azure subscription that contains 10 virtual networks. The virtual networks are hosted in separate resource groups.
Another administrator plans to create several network security groups (NSGs) in the subscription.
You need to ensure that when an NSG is created, it automatically blocks TCP port 8080 between the virtual networks.
Solution: You configure a custom policy definition, and then you assign the policy to the subscription.
Does this meet the goal?
A custom policy definition is a way to define your own rules for using Azure resources. You can use custom policies to enforce compliance, security, cost management, or organization-specific requirements. However, a custom policy definition alone is not enough to meet the goal of automatically blocking TCP port 8080 between the virtual networks. You also need to create a policy assignment that applies the custom policy definition to the scope of the subscription. A policy assignment is the link between a policy definition and an Azure resource. Without a policy assignment, the custom policy definition will not take effect. Therefore, the solution does not meet the goal.
Tutorial: Create a custom policy definition
Create and manage policies to enforce compliance
You need to resolve the licensing issue before you attempt to assign the license again.
What should you do?
Scenario:Licensing Issue
1. You attempt to assign a license in Azure to several users and receive the following error message: 'Licenses not assigned. License agreement failed for one user.'
2. You verify that the Azure subscription has the available licenses.
Solution:
License cannot be assigned to a user without a usage location specified.
Some Microsoft services aren't available in all locations because of local laws and regulations. Before you can assign a license to a user, you must specify theUsage locationproperty for the user. You can specify the location under theUser>Profile>Settingssection in the Azure portal.
https://docs.microsoft.com/en-us/azure/active-directory/users-groups-roles/licensing-groups-resolve-problems
You have two Azure subscriptions named Sub1 and Sub2 that are linked to separate Microsoft Entra tenants.
You have the virtual networks shown in the following table.

You have two Azure subscriptions named Sub1 and Sub2 that are linked to separate Microsoft Entra tenants.
You have the virtual networks shown in the following table.
Which virtual networks can you peer with VNet1?
You need to implement the planned changes for the storage account content. Which containers and file shares can you use to organize the content?
In the scenario, storage1 is configured as StorageV2 with Hierarchical namespace = Yes, while storage2 is configured as StorageV2 with Hierarchical namespace = No.
From Microsoft's Azure Storage Documentation and AZ-104 Study Guide, the following principles apply:
A hierarchical namespace (enabled when the storage account has Azure Data Lake Storage Gen2 capabilities) allows the use of directories within containers to organize data.
The hierarchical namespace provides directory and file-level structure similar to a file system. This is supported only for blob containers, not for Azure Files.
Azure Files (file shares) do not depend on hierarchical namespaces and cannot have directories in the same way Data Lake Gen2 does --- directories can exist inside the share but not in the blob container sense.
The planned change states that you must use directories whenever possible to organize content. Therefore, only storage accounts with hierarchical namespace enabled can use directory structures --- that's storage1.
In this case:
storage1 (Hierarchical namespace = Yes) supports containers (like cont1) and file shares (like share1).
storage2 (Hierarchical namespace = No) does not support directories within blob containers (Data Lake structure).
Hence, you can use only cont1 (container in storage1) and share1 (file share in storage1) to organize content as required.
This is directly supported by the Microsoft documentation on Data Lake Storage Gen2:
''When you enable the hierarchical namespace for a storage account, you can organize objects into directories and subdirectories. This capability is available only for accounts configured for Data Lake Storage Gen2.''
Final Verified Answe r: B. cont1 and share1 only
You have an Azure subscription that contains 10 virtual networks. The virtual networks are hosted in separate resource groups.
Another administrator plans to create several network security groups (NSGs) in the subscription.
You need to ensure that when an NSG is created, it automatically blocks TCP port 8080 between the virtual networks.
Solution: You configure a custom policy definition, and then you assign the Azure policy to the subscription.
Does this meet the goal?
In Azure, Azure Policy is a governance tool used to enforce organizational standards and assess compliance across Azure resources. It allows administrators to define and assign policy definitions that automatically audit, deny, or modify resource configurations at deployment or runtime.
In this scenario, the requirement is that every time a Network Security Group (NSG) is created, it should automatically contain a rule that blocks TCP port 8080 traffic between virtual networks.
The Microsoft Azure Policy documentation confirms that you can create a custom policy definition using the Microsoft.Network/networkSecurityGroups/securityRules resource type. Within the policy's JSON definition, you can specify conditions such as:
The resource type to which the policy applies (networkSecurityGroups).
The enforcement mode (deny or deployIfNotExists).
The required configuration, such as a specific inbound or outbound rule (in this case, a rule denying TCP 8080).
By using the DeployIfNotExists effect in the policy, Azure automatically ensures that the NSG includes the required rule. If the rule does not exist, Azure deploys it automatically during resource creation.
Assigning this custom policy definition at the subscription level ensures it is inherited by all resource groups and applies to all virtual networks created in that subscription. This meets the goal because the requirement is to enforce a security configuration across all NSGs, regardless of which resource group or virtual network they belong to.
Therefore, configuring and assigning a custom Azure Policy to the subscription fully satisfies the requirement.
Security & Privacy
Satisfied Customers
Committed Service
Money Back Guranteed