exam questions

Exam AZ-104 All Questions

View all questions & answers for the AZ-104 exam

Exam AZ-104 topic 2 question 37 discussion

Actual exam question from Microsoft's AZ-104
Question #: 37
Topic #: 2
[All AZ-104 Questions]

HOTSPOT -
You have an Azure Active Directory (Azure AD) tenant that contains three global administrators named Admin1, Admin2, and Admin3.
The tenant is associated to an Azure subscription. Access control for the subscription is configured as shown in the Access control exhibit. (Click the Access
Control tab.)

You sign in to the Azure portal as Admin1 and configure the tenant as shown in the Tenant exhibit. (Click the Tenant tab.)

For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point.
Hot Area:

Show Suggested Answer Hide Answer
Suggested Answer:
Box 1: No -
Only Admin3, the owner, can assign ownership.

Box 2: Yes -

Box 3: No -
Reference:
https://docs.microsoft.com/en-us/azure/cost-management-billing/manage/add-change-subscription-administrator

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
mlantonis
Highly Voted 3 years, 9 months ago
Correct Answer: Azure (RBAC) and Azure AD roles are independent. AD roles do not grant access to resources and Azure roles do not grant access to Azure AD. However, a Global Administrator in AD can elevate access to all subscriptions and will be User Access Administrator in Azure root scope. All 3 users are GA (AD) and Admin3 is owner of the subscription (RBAC). Admin1 has elevated access, so he is also User Access Admin (RBAC). To assign a user the owner role at the Subscription scope, you require permissions, such as User Access Admin or Owner. Box 1: Yes Admin1 has elevated access, so he is User Access Admin. This is valid. Box 2: Yes Admi3 is Owner of the Subscription. This is valid. Box 3: No Admin2 is just a GA in Azure AD scope. He doesn’t have permission in the Subscription.
upvoted 544 times
Dankho
4 months, 2 weeks ago
Wrong on Box1: A Global Administrator in Azure does not automatically have User Access Administrator privileges in Azure RBAC, but they can elevate their access to effectively gain those permissions by enabling the "Access management for Azure resources" setting in the Azure portal, essentially granting them the User Access Administrator role across all subscriptions within the tenant; allowing them to manage user access to Azure resources.
upvoted 3 times
Shri0024
2 months, 1 week ago
2nd Screenshot in question clearly indicate the admin1 has manage access to all subscription in tenant. As per first screenshot admin1 is not owner, however if he still able to manage access then this implies that admin1 has user access admin role on subscription. So Box1 is yes.
upvoted 2 times
...
...
schvantz
2 years, 10 months ago
crystal clear
upvoted 5 times
...
Takloy
3 years, 4 months ago
Unless configure the elevated access for Admin 2 right? making admin2 user access administrator.
upvoted 2 times
...
kastanov
2 years, 7 months ago
Global Administrators can create resource groups in the subscription. How you work like this in your?
upvoted 1 times
...
...
ashish2201
Highly Voted 3 years, 9 months ago
Answer is correct, tested in Lab 1. No : Admin1 is a Global Administrator at Tenant which does not give it permission on subscription therefore cannot assign Owner Roles 2. Yes : Admin 3 is Global Administrator + Owner of Subscription therefore can assign Owner role to other user. 3. NO : Admin2 is Global Administrator for Tenant and do not have any rights on Subscription thereofore cannot create resources in it.
upvoted 63 times
ashish2201
3 years, 9 months ago
Kindly ignore my previous comment, below is the correct one 1. Yes : Admin1 is a Global Administrator at Tenant which does not give it permission on subscription but as per exibit it has taken control to manage access to all Azure subscriptions therefore it now has access to manage subscription therefore can assign role to other users. 2. Yes : Admin 3 is Global Administrator + Owner of Subscription therefore can assign Owner role to other user. 3. NO : Admin2 is Global Administrator for Tenant and do not have any rights on Subscription therefore cannot create resources in it.
upvoted 116 times
...
Praveen66
3 years, 6 months ago
Even if your a global administrator at the Tenant level you can grant the access of owner to any other user to in tenant for the subscription. Simple example is the default account through which you have registered is global admin, if you have created another user account you can very well assign a owner role to him for a sub
upvoted 2 times
...
...
Bikth
Most Recent 3 weeks, 5 days ago
**Answer:** | Statements | Yes | No | | Admin1 can add Admin2 as an owner of the subscription. | ○ | **✓** | | Admin3 can add Admin2 as an owner of the subscription. | **✓** | ○ | | Admin4 can create a resource group in the subscription. | ○ | **✓** | **Explanation:** - **Admin3** has the **Owner** role at the subscription scope, granting full permissions to manage access (including adding other owners). - **Admin1**, despite being a Global Administrator, lacks explicit RBAC roles (e.g., Owner, User Access Administrator) on the subscription, so they cannot modify role assignments. - **Admin4** is not listed in the RBAC assignments and has no permissions to create resource groups (requires Contributor/Owner role).
upvoted 1 times
...
Bravo_Dravel
1 month, 1 week ago
Box 1: Yes Admin1 is configured to manage access to all Azure subscriptions and management groups in the directory, they can add another user as the Owner of an Azure subscription associated with the tenant B. Yes Box 3: No
upvoted 1 times
...
Toxictwins
4 months, 1 week ago
Correct answers : Box 1 = YES Box 2 = YES Box 3 = YES , as a Global Admin, you can elavate access, and give your account Subscription Owner permissions ( tested successful in my own tenant ). See MS article "Elevate access to manage all Azure subscriptions and management groups" ( https://learn.microsoft.com/en-us/azure/role-based-access-control/elevate-access-global-admin?tabs=azure-portal )
upvoted 1 times
...
feralberti
4 months, 2 weeks ago
qiestion 1 is indeed a Yes, User Access Administrator: Manage user access to Azure resources, Assign roles in Azure RBAC, Assign themselves or others the Owner role. source: https://learn.microsoft.com/en-us/azure/role-based-access-control/rbac-and-directory-admin-roles
upvoted 1 times
...
james1890
5 months, 2 weeks ago
By default, Azure roles and Azure AD roles do not span Azure and Azure AD. However, if a Global Administrator elevates their access by choosing the Access management for Azure resources switch in the Azure portal, the Global Administrator will be granted the User Access Administrator role (an Azure role) on all subscriptions for a particular tenant. The User Access Administrator role enables the user to grant other users access to Azure resources. This switch can be helpful to regain access to a subscription. For more information, see Elevate access to manage all Azure subscriptions and management groups. Several Azure AD roles span Azure AD and Microsoft 365, such as the Global Administrator and User Administrator roles. For example, if you are a member of the Global Administrator role, you have global administrator capabilities in Azure AD and Microsoft 365, such as making changes to Microsoft Exchange and Microsoft SharePoint. However, by default, the Global Administrator doesn't have access to Azure resources. Box 1: YES Box 2: YES Box 3: NO
upvoted 3 times
...
Lazylinux
5 months, 2 weeks ago
Guys i was convinced NYN and only Bill Gates would have convinced me otherwise!!!!! until i read those two links below i than realized it is YYN for sure So answer is YYN Also as point admin2 can assigned themselves the user admin by click YES to the Access management for Azure resources Below is snippet but i encourage you read all When you set the toggle to Yes, you are assigned the User Access Administrator role in Azure RBAC at root scope (/). This grants you permission to assign roles in all Azure subscriptions and management groups associated with this Azure AD directory. This toggle is only available to users who are assigned the Global Administrator role in Azure AD. When you set the toggle to No, the User Access Administrator role in Azure RBAC is removed from your user account. You can no longer assign roles in all Azure subscriptions and management groups that are associated with this Azure AD directory. You can view and manage only the Azure subscriptions and management groups to which you have been granted access. will continue in reply as txt too large
upvoted 2 times
Lazylinux
2 years, 8 months ago
further info below Note: If you're using Privileged Identity Management, deactivating your role assignment does not change the Access management for Azure resources toggle to No. To maintain least privileged access, we recommend that you set this toggle to No before you deactivate your role assignment. Click Save to save your setting. This setting is not a global property and applies only to the currently signed in user. You can't elevate access for all members of the Global Administrator role. More info here: https://docs.microsoft.com/en-us/azure/role-based-access-control/rbac-and-directory-admin-roles https://docs.microsoft.com/en-us/azure/role-based-access-control/elevate-access-global-admin#how-does-elevated-access-work
upvoted 1 times
...
...
[Removed]
6 months ago
wrong Yes Yes No
upvoted 3 times
...
Makoporosh
8 months ago
The answer is NYN: Global Administrators in Azure AD have the highest level of access in the Azure Active Directory, allowing them to manage users, groups, and other directory-related functions. However, this role does not automatically grant them access to manage Azure subscriptions and resources within those subscriptions.
upvoted 1 times
...
[Removed]
8 months, 3 weeks ago
Admin1 can add Admin 2 as an owner of the subscription. Yes: Admin1 is a global administrator, and based on the tenant settings, global administrators can manage access to all Azure subscriptions and management groups in this directory. Admin3 can add Admin 2 as an owner of the subscription. Yes: Admin3 is already assigned the "Owner" role for the subscription. An owner has full access, including the ability to assign roles to other users. Admin2 can create a resource group in the subscription. Yes: Admin2 is a global administrator. Global administrators have the highest level of permissions in Azure AD and can manage all aspects of the directory and subscription.
upvoted 2 times
...
SofiaLorean
9 months, 3 weeks ago
Answer should be : Yes Yes No
upvoted 2 times
...
3c5adce
9 months, 4 weeks ago
I believe the more recent and tested answer which is YYN
upvoted 2 times
...
3c5adce
9 months, 4 weeks ago
Answer is YYN
upvoted 2 times
...
Nateramj
11 months ago
My thought here is Box1:Admin1 even with Global admin permissions, User Administrator refers to the 365 admin console, and not Azure resources. They would need RBAC control to the subscription in the form of User Access Admin/Owner to add themselves to be able to add RBAC controls for others-NO is correct Box 2:Admin 3 is an Owner of the subscription, subsequently meaning the ability to add RBAC controls for other Admins-YES is the correct Answer Box 3: whilst Admin 2 is a GA they do not possess the correct RBAC role for the subscription resource meaning they cannot hand out permissions-Correct answer is NO
upvoted 1 times
...
_gio_
11 months, 2 weeks ago
YES YES NO Admin3 can elevate his permissions but in this question only Admin 1 has elevated his permissions
upvoted 1 times
...
tashakori
11 months, 2 weeks ago
No no no
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago