exam questions

Exam AZ-104 All Questions

View all questions & answers for the AZ-104 exam

Exam AZ-104 topic 2 question 14 discussion

Actual exam question from Microsoft's AZ-104
Question #: 14
Topic #: 2
[All AZ-104 Questions]

HOTSPOT -
You have Azure Active Directory tenant named Contoso.com that includes following users:

Contoso.com includes following Windows 10 devices:

You create following security groups in Contoso.com:

For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point.
Hot Area:

Show Suggested Answer Hide Answer
Suggested Answer:

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Armina
Highly Voted 2 years, 11 months ago
User1 can add Device2 to Group1: No User2 can add Device1 to Group1: Yes User2 can add Device2 to Group2: No Explaination: Groups can contain both registered and joined devices as members. As a global administrator or cloud device administrator, you can manage the registered or joined devices. Intune Service administrators can update and delete devices. User administrator can manage users but not devices. User1 is a cloud device administrator. Users in this role can enable, disable, and delete devices in Azure AD and read Windows 10 BitLocker keys (if present) in the Azure portal. The role does not grant permissions to manage any other properties on the device. User2 is the owner of Group1. He can add Device1 to Group1. Group2 is configured for dynamic membership. The properties on which the membership of a device in a group of the type dynamic device are defined cannot be changed by either an end user or an user administrator. User2 cannot add any device to Group2.
upvoted 284 times
go4adil
1 year, 3 months ago
Correct; Answer is: User1 can add Device2 to Group1: No (because User1 is Cloud Device Admin and cannot change the group membership for Group1) User2 can add Device1 to Group1: Yes (because User2 is Group Owner which has the requisite authority for changing group membership. furthermore, Group1 has Assigned membership type) User2 can add Device2 to Group2: No (because though User2 is Group Owner with requisite rights but Group2 has Dynamic Device membership type) See below 'Tasks' with their 'Least Privileged Roles': https://learn.microsoft.com/en-us/entra/identity/role-based-access-control/delegate-by-task#groups
upvoted 8 times
...
klasbeatz
2 years, 10 months ago
But user 2 is the owner of the group? So because of the dynamic membership of the device this changes even abilities for the owner of the group?
upvoted 2 times
klasbeatz
2 years, 8 months ago
Found my answer : "With Cloud Device administrator role, you can Delete/Disable/Enable devices in Azure Active Directory but you cannot Add/Remove Users in the directory."
upvoted 6 times
klasbeatz
2 years, 7 months ago
Confusing you would think a cloud device admin could....Just reviewing this question again during my studies.
upvoted 2 times
...
...
...
Durden871
2 years, 1 month ago
1. Yes. Group 1 Owner - User 1. Group 1 membership type - assigned. User 1 can add the device to the group because they're the owner of said group. 2. Yes User 2 - Not the owner of group 1. However, User administrator role has the permission to update group membership. https://learn.microsoft.com/en-us/azure/active-directory/roles/permissions-reference 3. No Despite user 2 being an owner, they can't add dynamic devices to the group.
upvoted 12 times
Stunomatic
6 months, 1 week ago
I doesn't mean if I am the owner of certain group I can rule over any other device so Y Y N makes sense. but if (Cloud device admin cannot add/join devices) = True then NYN
upvoted 2 times
...
ChaBum
1 year, 7 months ago
User administrator role has the permission to update group membership, but only users, not devices.
upvoted 1 times
...
chair123
1 year, 7 months ago
it says Group 1 & 2 owner is User 12?.
upvoted 2 times
...
...
klexams
2 years, 10 months ago
User1 can add Device2 to Group1 should be YES coz User1 is the owner of Group1, the same statement you made for User2
upvoted 3 times
Chiboy
2 years, 10 months ago
Take a second look. User1 does not own any of the Groups. Answer is No.
upvoted 22 times
[Removed]
1 year, 3 months ago
But the answer says that User1 is Owner of Group1. So the question is wrong.
upvoted 1 times
jeru81
1 year, 2 months ago
How can be a question wrong? User2 is clearly Owner of both Groups. ANSWER is wrong.
upvoted 6 times
...
...
...
FabrityDev
1 year, 3 months ago
Read the details carefully please before answering, you are causing confusion. User2 is the owner of both groups.
upvoted 8 times
...
...
...
Lazylinux
Highly Voted 2 years, 10 months ago
NO Cloud device admin cannot add/join devices YES: user admin can add device/user/groups NO: Dynamic groups dont require manual intervention, it uses criteria to add or remove devices/users/groups only assigned groups you can add
upvoted 127 times
Hyrydar
2 years, 7 months ago
the best and straight forward explanation lazylinux. good job
upvoted 3 times
...
micro9000
2 years, 3 months ago
I agreed on this answer (NYN) based on these documents: https://learn.microsoft.com/en-us/azure/active-directory/roles/permissions-reference#cloud-device-administrator 1. N - because adding or removing device actions aren't mention on the actions list 2. Y - because user 2 is the owner https://learn.microsoft.com/en-us/azure/active-directory/enterprise-users/groups-dynamic-membership 3. N - because You can't manually add or remove a member of a dynamic group.
upvoted 7 times
Durden871
2 years, 1 month ago
Careful, I believe the uploaded the question wrong. I believe group 1 SHOULD be User 1 is the owner of Group 1. If User 1 is the owner of Group 1: Y, Y, N If user 2 is the owner of both groups, NYN
upvoted 8 times
...
...
dc2k79
2 years, 6 months ago
User Admin CANNOT ADD devices.
upvoted 5 times
Asfajaf
2 years, 5 months ago
User2 is owner of Group2, User2 can add/remove members regardless of role
upvoted 6 times
darthfodio
2 years, 3 months ago
Group2 is dynamic, therefore no one, including the owner, can manually add an object.
upvoted 4 times
MeysamBayani
2 years, 2 months ago
but he/she can add new role for add devices. in question mention user2 can ...
upvoted 1 times
Durden871
2 years, 1 month ago
Based on the question, the answer for 3 is no. I'm cross-referencing with Udemy and the question on Udemy has "User 1 is the user of group 1" Which would make this question, "YYN". The way the question is loaded makes it "NYN".
upvoted 1 times
...
...
...
...
...
...
huyhq
Most Recent 1 month, 1 week ago
I think 1. User1 can add Device2 to Group1? No Group1 has Membership Type is "Assigned", so Owner Or Global Administrator has permission add device. User1 is a Cloud device administrator, but isn't owner Group1, so User1 don't add Device2 to Group1. 2. User2 can add Device1 to Group1? Yes User2 is Owner of Group1 and Group1 has Membership Type Assigned. User2 has permission for member management, So can add Device1 to Group1. 3. User2 can add Device2 to Group2? (No) Group2 has Membership Type is "Dynamic Device", so Azure AD automated member management based on predefined rules.. Users cannot manually add devices to Dynamic Device Groups, even if they are the group owners
upvoted 1 times
...
iamsks
1 month, 2 weeks ago
No No Yes
upvoted 1 times
iamsks
1 month, 1 week ago
I am correcting my previous response... No Yes No
upvoted 1 times
...
...
BWLZ
1 month, 3 weeks ago
User1 can add Device2 to Group1: No User1 is a Cloud Device Administrator and does not have permissions to manage group memberships. User2 can add Device1 to Group1: Yes User2 is a User Administrator and has the necessary permissions to manage group memberships, including adding devices to security groups. User2 can add Device2 to Group2: No Group2 is a Dynamic Device group, and User2, even as a User Administrator, cannot manually add devices to a dynamic group. Dynamic groups are managed automatically based on rules.
upvoted 1 times
...
Jay_D_Lincoln
2 months, 1 week ago
NYN As a cloud admin User1 do not have permission to add a device. However if User1 was the owner of Group1, then User1 would have full control of membership (which is not the case here)
upvoted 1 times
...
allinict_111
3 months ago
User2 cannot add Device2 to Group2 because it is a dynamic group
upvoted 1 times
...
GreenTick
5 months, 3 weeks ago
fundamentally bad and confusing azure architecture, when user and device "admin" can't add objects to AD group, unless the admin also has permission to modify the group.
upvoted 1 times
...
bacana
5 months, 4 weeks ago
From real life. User1 needs to be member of users administrator to add computer or user as member. As cloud device administrator he can't.
upvoted 1 times
...
LinuxLewis
6 months ago
for the question about user admins, as I thought they can only delegate user related queries and not to devices, however... https://learn.microsoft.com/en-us/answers/questions/1340769/can-an-user-with-user-administrator-role-add-an-az
upvoted 1 times
...
mwhooo
6 months ago
No one can add any device to group2 because its a dynamic group, Static members cant be added.
upvoted 1 times
...
Mshaty
7 months ago
i think the correct answer is Yes Yes No. User 1 is a cloud device administrator he can add a device to a group, User 2 is the owner of the Group so they can add members despite them being devices. Group 2 is a dynamic group hence you can not manually add a member
upvoted 2 times
...
cloudy_man
7 months, 1 week ago
(User administrator) can update the membership of both the groups, regardless of whether he is owner of the group or not because User administrator role has the permission to update group membership. He can add users, devices, other groups to any group in Azure AD. Below is the permission that user administrator role has: On the other hand Cloud Device administrator can add members to the Group of which he is the owner. and he can add users, devices and other groups only to that Group. With Cloud Device administrator role, you can Delete/Disable/Enable devices in Azure Active Directory but you cannot Add/Remove Users in the directory. With User administrator role, you can Add/Remove users in Azure AD but cannot Delete/Disable/Enable the devices. Hence, The answers are: No Yes No
upvoted 2 times
...
Navigati0n
7 months, 1 week ago
The access rights for User1 (Cloud Device Administrator) and User2 (User Administrator) in Azure AD, as well as the device status (Azure AD registered or Azure AD joined), will determine what actions each user can perform. >> User1 can add Device2 to Group1 - No. A Cloud Device Administrator can manage devices in Azure AD but cannot manage groups (including adding devices to a group). That task typically falls under the responsibilities of a User Administrator or a Group Owner. >> User2 can add Device1 to Group1 - Yes. As the owner of Group1 and a User Administrator, User2 has the rights to add devices to Group1. The fact that Device1 is Azure AD registered does not restrict it from being added to Group1. >> User2 can add Device2 to Group2 - No. User2 cannot manually add any device to Group2 because it is a dynamic device group. Memberships in dynamic device groups are determined by rules and conditions, rather than manual assignment. Even though User2 is a User Administrator and the owner of Group2, he cannot manually add devices to a dynamic device group.
upvoted 7 times
...
18c2076
7 months, 1 week ago
User1 can add Device2 to Group 1: NO - Explanation: Cloud Device Admins can enable/disable/delete devices in Azure. Cloud Device Admin DOES NOT grant permission to manage ANY other properties of these devices; Including group membership. User2 can add Device1 to Group1: YES Explanation: User2 is the OWNER of Group1. This user can add and remove membership to this group under any circumstance as the group membership type is ASSIGNED - Implying that any membership affiliation must be manually given to any given resource. User2 can add Device2 to Group2: NO Explanation: Group2 is stated to be a DYNAMIC membership assignment - This implies that any given resource MUST MEET the criteria/requirement outlined within the group dynamic membership scope to be added to this group as a member. The properties of dynamic group membership requirements CANNOT be changed by either end user nor user administrator. Additionally, Dynamic Groups feature require Entra ID Premium P1 or P2 licensing. Hope this helps. Happy studying!
upvoted 3 times
...
[Removed]
7 months, 2 weeks ago
Wrong No Yes No Owner = User2 User2 + Azure AD registered + Assigned
upvoted 1 times
...
lethuccrma
8 months, 1 week ago
ChatGPT answer: User1 can add device2 to group1: NO Reason: User1 is a Cloud Device Admin, but Group1 is an assigned group, and they are not listed as the owner of the group. Only the owner or a user with appropriate permissions (e.g., User admin) can assign devices to this group. User2 can add device1 to group1: YES Reason: User2 is a User Admin and the owner of Group1. As the group owner and with the User Admin role, they have the necessary permissions to add devices to Group1. User2 can add device2 to group2: NO Reason: Group2 is a Dynamic Device group, meaning its membership is determined automatically by rules based on device attributes. Devices cannot be manually added to dynamic groups, even by the owner.
upvoted 2 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago