Welcome to ExamTopics
ExamTopics Logo
- Expert Verified, Online, Free.
exam questions

Exam AZ-104 All Questions

View all questions & answers for the AZ-104 exam

Exam AZ-104 topic 2 question 66 discussion

Actual exam question from Microsoft's AZ-104
Question #: 66
Topic #: 2
[All AZ-104 Questions]

HOTSPOT
-

You have an Azure subscription that is linked to an Azure AD tenant. The tenant contains the custom role-based access control (RBAC) roles shown in the following table.



From the Azure portal, you need to create two custom roles named Role3 and Role4. Role3 will be an Azure subscription role. Role4 will be an Azure AD role.

Which roles can you clone to create the new roles? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

Show Suggested Answer Hide Answer
Suggested Answer:

Comments

Chosen Answer:
This is a voting comment (?) , you can switch to a simple comment.
Switch to a voting comment New
TorresW
Highly Voted 1 year, 9 months ago
https://www.examtopics.com/discussions/microsoft/view/57784-exam-az-500-topic-2-question-58-discussion/ i found similar questions in other page
upvoted 25 times
jimmyyml
1 year, 8 months ago
Thanks. Answer should be Role3: Role1 and built-in Azure subscription roles only Role4: Role2 only Explanation: You cannot clone built-in Azure AD role
upvoted 146 times
shandorcoachman
1 year, 7 months ago
What about this: https://learn.microsoft.com/en-us/azure/role-based-access-control/custom-roles-portal ? It seems you can.
upvoted 2 times
shandorcoachman
1 year, 7 months ago
Correcting myself, this is a subscription role.
upvoted 6 times
...
...
ChrisEkorhi
1 year, 3 months ago
This is the correct answers Role3: Role1 and built-in Azure subscription roles only Role4: Role2 only - For Azure AD role, you can only clone from custom role like Role 2 and connot clone from built-in role. Please ge test yourself using Azure free account.
upvoted 3 times
...
Paul_white
1 year, 7 months ago
This is the best answer here!!! https://www.examtopics.com/discussions/microsoft/view/57784-exam-az-500-topic-2-question-58-discussion/
upvoted 4 times
...
...
Panapi
1 year, 7 months ago
Answer is correcrt Valid! This question was on the exam 22/02/2023. Scored 920. Thanks guys!
upvoted 21 times
Sandip671
11 months, 3 weeks ago
Hiii my exam are in 10 days plz help me to make my concepts clear
upvoted 1 times
neolisto
11 months ago
Sandip671 how your exam? Did you pass it?
upvoted 3 times
...
ki01
9 months, 3 weeks ago
it's usually a bad idea to book an exam soon when you have very little idea of what you're doing....
upvoted 2 times
...
...
...
...
ElDakhli
Highly Voted 1 year, 9 months ago
Role3: Role1 and Azure subscription Roles only. Role4: Role2 only Explanation: There's a difference between Built-in AD roles and Built-in Subscription roles. **Built-in AD roles can't be cloned, but built-in subscription roles can be. Custom roles of either type can be cloned.** To clone the Bulit-in subscription Role, you open the subscription or the Resource group where you want to create the custom role and assign the permissions --> Go to Access Control (IAM) --> Roles tab --> Search for the subscription Role then clone it from the three dots in the right of the role. Reference: https://learn.microsoft.com/en-us/azure/role-based-access-control/custom-roles-portal
upvoted 23 times
Georgego
1 year, 8 months ago
Tested in LAB environment and can confirm Role3: Role1 and Azure subscription Roles only. Role4: Role2 only
upvoted 13 times
...
...
d7fb451
Most Recent 1 week ago
https://learn.microsoft.com/en-us/entra/identity/role-based-access-control/custom-create
upvoted 1 times
...
SeMo0o0o0o
1 month ago
WRONG Role3: Role1 and built-in Azure subscription roles only Role4: Role2 only
upvoted 1 times
...
certainly
1 month, 3 weeks ago
Not sure if I am the only one being confused by the correct answer discussed here. Role3: Role1 and built-in Azure subscription roles only To create an Azure subscription role, you can clone existing Azure subscription roles Role1. it is a valid template. Built-in Azure subscription roles can also be used. But not neccessary cloning BOTH. So correct anwser should Role3: Role1 only Role4: Role2 only
upvoted 1 times
certainly
1 week, 5 days ago
nvm. i got it now. correct answer Role3: Role1 and Azure subscription Roles only. Role4: Role2 only
upvoted 1 times
...
...
CheMetto
2 months, 1 week ago
In other exam, i always answered custom role of azure + builtin, and custom role for entra id, but i found out is wrong on azure side, try it on your own! I created a custom role, even 2 days ago, then on IAM i search it and click on "Clone role". This role wasn't clonable, i could even find it on the search manually. So the answer is: Azure can copy only from built-in Azure Role, so is the second one. For Azure AD ( Entra ID ), you can copy only from custom role, so is the first one
upvoted 1 times
CheMetto
2 months, 1 week ago
You don't need to get a subscription to test it, just in portal.azure.com, search for management group -> create a new one -> access the new one -> go to IAM -> create a custom role -> try to clone it! You get what i'm talking about, nothing! I thought it was also an issue withing my tenant, so i decide to go on another oldest tenant... same issue! Can't clone a role which is not a built-in azure subscription role
upvoted 1 times
CheMetto
2 months, 1 week ago
i was wrong. it was a bug/issue of my tenant. i could do that on anothre one
upvoted 1 times
...
...
...
ajay01avhad
2 months, 1 week ago
For Role3, you should select: Role1 and built-in Azure subscription roles only For Role4, you should select: Role2 and built-in Azure AD roles only
upvoted 1 times
...
varinder82
4 months, 3 weeks ago
Final Answer: Role3: Role1 and built-in Azure subscription roles only Role4: Role2 only
upvoted 3 times
...
3c5adce
4 months, 4 weeks ago
Role3: Role1 and built-in Azure subscription roles only Role4: Role2 only Explanation: You cannot clone built-in Azure AD role
upvoted 1 times
...
Amir1909
7 months, 3 weeks ago
Role3: Role1 and built-in subscription roles only Role4: Role2 only
upvoted 4 times
...
mihir25
10 months, 3 weeks ago
Thanks. Answer should be Role3: Role1 and built-in Azure subscription roles only Role4: Role2 only Explanation: You cannot clone built-in Azure AD role I've done Scenraio and it's true that role 3 = role 1 + azure ad role role 4 = role 2
upvoted 1 times
...
pradeepbadisa
1 year ago
Built-in AD roles can't be cloned, but built-in subscription roles can be. Custom roles of either type can be cloned.
upvoted 1 times
...
Babustest
1 year ago
I have tested this in lab. Role4 can be cloned only from Role2. When I try to create a new AD role, it's giving only one option 'Clone from a custom role'.
upvoted 1 times
...
Prasis
1 year ago
Role3: Role1 and built-in Azure subscription roles only Role4: Role2 only https://www.youtube.com/watch?v=qbnuwEohUbo&list=PLlKA5U_Yqgof3H0YWhzvarFixW9QLTr4S&index=46
upvoted 4 times
...
SL4Y3R
1 year ago
Role3: Role1 and built-in Azure subscription roles only Role4: Role2 only
upvoted 2 times
...
oopspruu
1 year, 1 month ago
There is a difference between Azure Roles and Azure AD Roles. Their "cloning" rules are not the same. While you can clone an in-built Azure role, you CANNOT clone in-built Azure AD role. When creating a custom role in Azure AD, you can either choose a custom role already created OR start from scratch. So for 2nd, Answer should be Role2 only.
upvoted 1 times
...
zafara55
1 year, 2 months ago
All roles can be cloned. Customs and Built-in. So the answer is: Role3: Role 1 and built-in Azure subscription roles only Role4; Role 2 and built-in Azure AD roles only.
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...