Welcome to ExamTopics
ExamTopics Logo
- Expert Verified, Online, Free.
exam questions

Exam AZ-104 All Questions

View all questions & answers for the AZ-104 exam

Exam AZ-104 topic 2 question 14 discussion

Actual exam question from Microsoft's AZ-104
Question #: 14
Topic #: 2
[All AZ-104 Questions]

HOTSPOT -
You have Azure Active Directory tenant named Contoso.com that includes following users:

Contoso.com includes following Windows 10 devices:

You create following security groups in Contoso.com:

For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point.
Hot Area:

Show Suggested Answer Hide Answer
Suggested Answer:
Box 1: Yes -
User1 is a Cloud Device Administrator.
Device2 is Azure AD joined.
Group1 has the assigned to join type. User1 is the owner of Group1.
Note: Assigned groups - Manually add users or devices into a static group.
Azure AD joined or hybrid Azure AD joined devices utilize an organizational account in Azure AD

Box 2: No -
User2 is a User Administrator.
Device1 is Azure AD registered.
Group1 has the assigned join type, and the owner is User1.
Note: Azure AD registered devices utilize an account managed by the end user, this account is either a Microsoft account or another locally managed credential.

Box 3: Yes -
User2 is a User Administrator.
Device2 is Azure AD joined.
Group2 has the Dynamic Device join type, and the owner is User2.
Reference:
https://docs.microsoft.com/en-us/azure/active-directory/devices/overview

Comments

Chosen Answer:
This is a voting comment (?) , you can switch to a simple comment.
Switch to a voting comment New
Armina
Highly Voted 2 years, 4 months ago
User1 can add Device2 to Group1: No User2 can add Device1 to Group1: Yes User2 can add Device2 to Group2: No Explaination: Groups can contain both registered and joined devices as members. As a global administrator or cloud device administrator, you can manage the registered or joined devices. Intune Service administrators can update and delete devices. User administrator can manage users but not devices. User1 is a cloud device administrator. Users in this role can enable, disable, and delete devices in Azure AD and read Windows 10 BitLocker keys (if present) in the Azure portal. The role does not grant permissions to manage any other properties on the device. User2 is the owner of Group1. He can add Device1 to Group1. Group2 is configured for dynamic membership. The properties on which the membership of a device in a group of the type dynamic device are defined cannot be changed by either an end user or an user administrator. User2 cannot add any device to Group2.
upvoted 263 times
go4adil
8 months, 3 weeks ago
Correct; Answer is: User1 can add Device2 to Group1: No (because User1 is Cloud Device Admin and cannot change the group membership for Group1) User2 can add Device1 to Group1: Yes (because User2 is Group Owner which has the requisite authority for changing group membership. furthermore, Group1 has Assigned membership type) User2 can add Device2 to Group2: No (because though User2 is Group Owner with requisite rights but Group2 has Dynamic Device membership type) See below 'Tasks' with their 'Least Privileged Roles': https://learn.microsoft.com/en-us/entra/identity/role-based-access-control/delegate-by-task#groups
upvoted 4 times
...
Durden871
1 year, 7 months ago
1. Yes. Group 1 Owner - User 1. Group 1 membership type - assigned. User 1 can add the device to the group because they're the owner of said group. 2. Yes User 2 - Not the owner of group 1. However, User administrator role has the permission to update group membership. https://learn.microsoft.com/en-us/azure/active-directory/roles/permissions-reference 3. No Despite user 2 being an owner, they can't add dynamic devices to the group.
upvoted 12 times
ChaBum
1 year ago
User administrator role has the permission to update group membership, but only users, not devices.
upvoted 1 times
...
chair123
1 year ago
it says Group 1 & 2 owner is User 12?.
upvoted 2 times
...
Durden871
1 year, 7 months ago
Disregard, kind of. I'm cross-referencing with Udemy and see the question is slightly altered. In this question, user 2 is the owner of both groups. In the question I'm cross-referencing, User 1 is the owner of group 1.
upvoted 8 times
...
...
klasbeatz
2 years, 3 months ago
But user 2 is the owner of the group? So because of the dynamic membership of the device this changes even abilities for the owner of the group?
upvoted 1 times
klasbeatz
2 years, 1 month ago
Found my answer : "With Cloud Device administrator role, you can Delete/Disable/Enable devices in Azure Active Directory but you cannot Add/Remove Users in the directory."
upvoted 6 times
klasbeatz
2 years ago
Confusing you would think a cloud device admin could....Just reviewing this question again during my studies.
upvoted 2 times
...
...
...
klexams
2 years, 4 months ago
User1 can add Device2 to Group1 should be YES coz User1 is the owner of Group1, the same statement you made for User2
upvoted 3 times
Chiboy
2 years, 3 months ago
Take a second look. User1 does not own any of the Groups. Answer is No.
upvoted 20 times
mnasiban
8 months, 4 weeks ago
But the answer says that User1 is Owner of Group1. So the question is wrong.
upvoted 1 times
jeru81
8 months ago
How can be a question wrong? User2 is clearly Owner of both Groups. ANSWER is wrong.
upvoted 4 times
...
...
...
FabrityDev
9 months, 1 week ago
Read the details carefully please before answering, you are causing confusion. User2 is the owner of both groups.
upvoted 6 times
...
...
...
Lazylinux
Highly Voted 2 years, 3 months ago
NO Cloud device admin cannot add/join devices YES: user admin can add device/user/groups NO: Dynamic groups dont require manual intervention, it uses criteria to add or remove devices/users/groups only assigned groups you can add
upvoted 118 times
Hyrydar
2 years, 1 month ago
the best and straight forward explanation lazylinux. good job
upvoted 2 times
...
micro9000
1 year, 9 months ago
I agreed on this answer (NYN) based on these documents: https://learn.microsoft.com/en-us/azure/active-directory/roles/permissions-reference#cloud-device-administrator 1. N - because adding or removing device actions aren't mention on the actions list 2. Y - because user 2 is the owner https://learn.microsoft.com/en-us/azure/active-directory/enterprise-users/groups-dynamic-membership 3. N - because You can't manually add or remove a member of a dynamic group.
upvoted 7 times
Durden871
1 year, 7 months ago
Careful, I believe the uploaded the question wrong. I believe group 1 SHOULD be User 1 is the owner of Group 1. If User 1 is the owner of Group 1: Y, Y, N If user 2 is the owner of both groups, NYN
upvoted 8 times
...
...
dc2k79
1 year, 11 months ago
User Admin CANNOT ADD devices.
upvoted 5 times
Asfajaf
1 year, 11 months ago
User2 is owner of Group2, User2 can add/remove members regardless of role
upvoted 6 times
darthfodio
1 year, 9 months ago
Group2 is dynamic, therefore no one, including the owner, can manually add an object.
upvoted 4 times
MeysamBayani
1 year, 8 months ago
but he/she can add new role for add devices. in question mention user2 can ...
upvoted 1 times
Durden871
1 year, 7 months ago
Based on the question, the answer for 3 is no. I'm cross-referencing with Udemy and the question on Udemy has "User 1 is the user of group 1" Which would make this question, "YYN". The way the question is loaded makes it "NYN".
upvoted 1 times
...
...
...
...
...
...
Mshaty
Most Recent 1 week, 3 days ago
i think the correct answer is Yes Yes No. User 1 is a cloud device administrator he can add a device to a group, User 2 is the owner of the Group so they can add members despite them being devices. Group 2 is a dynamic group hence you can not manually add a member
upvoted 1 times
...
cloudy_man
2 weeks, 2 days ago
(User administrator) can update the membership of both the groups, regardless of whether he is owner of the group or not because User administrator role has the permission to update group membership. He can add users, devices, other groups to any group in Azure AD. Below is the permission that user administrator role has: On the other hand Cloud Device administrator can add members to the Group of which he is the owner. and he can add users, devices and other groups only to that Group. With Cloud Device administrator role, you can Delete/Disable/Enable devices in Azure Active Directory but you cannot Add/Remove Users in the directory. With User administrator role, you can Add/Remove users in Azure AD but cannot Delete/Disable/Enable the devices. Hence, The answers are: No Yes No
upvoted 2 times
...
Navigati0n
2 weeks, 2 days ago
The access rights for User1 (Cloud Device Administrator) and User2 (User Administrator) in Azure AD, as well as the device status (Azure AD registered or Azure AD joined), will determine what actions each user can perform. >> User1 can add Device2 to Group1 - No. A Cloud Device Administrator can manage devices in Azure AD but cannot manage groups (including adding devices to a group). That task typically falls under the responsibilities of a User Administrator or a Group Owner. >> User2 can add Device1 to Group1 - Yes. As the owner of Group1 and a User Administrator, User2 has the rights to add devices to Group1. The fact that Device1 is Azure AD registered does not restrict it from being added to Group1. >> User2 can add Device2 to Group2 - No. User2 cannot manually add any device to Group2 because it is a dynamic device group. Memberships in dynamic device groups are determined by rules and conditions, rather than manual assignment. Even though User2 is a User Administrator and the owner of Group2, he cannot manually add devices to a dynamic device group.
upvoted 7 times
...
18c2076
2 weeks, 2 days ago
User1 can add Device2 to Group 1: NO - Explanation: Cloud Device Admins can enable/disable/delete devices in Azure. Cloud Device Admin DOES NOT grant permission to manage ANY other properties of these devices; Including group membership. User2 can add Device1 to Group1: YES Explanation: User2 is the OWNER of Group1. This user can add and remove membership to this group under any circumstance as the group membership type is ASSIGNED - Implying that any membership affiliation must be manually given to any given resource. User2 can add Device2 to Group2: NO Explanation: Group2 is stated to be a DYNAMIC membership assignment - This implies that any given resource MUST MEET the criteria/requirement outlined within the group dynamic membership scope to be added to this group as a member. The properties of dynamic group membership requirements CANNOT be changed by either end user nor user administrator. Additionally, Dynamic Groups feature require Entra ID Premium P1 or P2 licensing. Hope this helps. Happy studying!
upvoted 3 times
...
SeMo0o0o0o
3 weeks, 3 days ago
Wrong No Yes No Owner = User2 User2 + Azure AD registered + Assigned
upvoted 1 times
...
lethuccrma
1 month, 2 weeks ago
ChatGPT answer: User1 can add device2 to group1: NO Reason: User1 is a Cloud Device Admin, but Group1 is an assigned group, and they are not listed as the owner of the group. Only the owner or a user with appropriate permissions (e.g., User admin) can assign devices to this group. User2 can add device1 to group1: YES Reason: User2 is a User Admin and the owner of Group1. As the group owner and with the User Admin role, they have the necessary permissions to add devices to Group1. User2 can add device2 to group2: NO Reason: Group2 is a Dynamic Device group, meaning its membership is determined automatically by rules based on device attributes. Devices cannot be manually added to dynamic groups, even by the owner.
upvoted 1 times
...
DJHASH786
2 months, 1 week ago
NYN Generally registered devices would be users personal devices, mobile phones or laptops etc.. they log into the device with their personal credentials. An Entra ID joined device is connected to your organization, and users can log into the devices with their work account.
upvoted 1 times
...
76d5e04
4 months ago
Conflicting with the question. In question User2 is the owner of Group1 & 2 but in the answer section it is mentioned "Group1 has the assigned join type, and the owner is User1." Examtopics in-charge please fix the contents as we rely on the details mentioned here
upvoted 1 times
...
varinder82
4 months, 2 weeks ago
Final Answer : N Y N
upvoted 1 times
...
3c5adce
4 months, 4 weeks ago
Going to go with NYN
upvoted 1 times
3c5adce
4 months, 3 weeks ago
Retracting and going with this one instead: NNY User1 can add Device2 to Group1: No User2 can add Device1 to Group1: No User2 can add Device2 to Group2: Yes
upvoted 1 times
...
...
varinder82
5 months, 1 week ago
Final Answer : No Yes No
upvoted 1 times
...
tashakori
6 months, 3 weeks ago
Yes Yes No
upvoted 3 times
...
AAlmani
7 months, 2 weeks ago
No Yes No User1 (Cloud Device administrator) should be an owner of group1 to add users or devices User 2 (User administrator) can update the membership of any assigned group, regardless of whether he is owner of the group or not because User administrator role has the permission to update group membership. He can add users, devices, to any assigned group in Azure AD. User 1&2 can't manually add or remove a member of a dynamic group.
upvoted 2 times
...
Amir1909
7 months, 3 weeks ago
No Yes No
upvoted 2 times
...
RichTsung
8 months, 3 weeks ago
It looks like someone answered this question on Microsoft Learn: https://learn.microsoft.com/en-us/answers/questions/40861/azure-ad-device-management Based on the given scenario, the answers are: N: User1 is NOT the owner of Group1 Y: User 2 is a user admin N: You can't manually add into a dynamic group
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...