Home / Community / Azure Administrator (AZ-104) - Identity, Governance & Virtual Networking
Public

Azure Administrator (AZ-104) - Identity, Governance & Virtual Networking

Master essential Azure Administrator (AZ-104) concepts with this high-yield flashcard deck, covering Microsoft Entra ID, robust governance with RBAC and Azure Policy, advanced virtual networking, and resilient storage strategies. Ace your exam by understanding core identity, security, and infrastructure management in Azure.

23 accessible of 23 cards

Card Preview

23 accessible of 23 cards

A quick, read-only look at the deck content.

Term

What is Microsoft Entra ID?

Definition

Microsoft Entra ID (formerly Azure Active Directory) is a cloud-based identity and access management service that helps employees sign in and access resources. It provides authentication, authorization, and single sign-on (SSO) capabilities for cloud and on-premises applications.

Term

How do you manage users and groups in Microsoft Entra ID?

Definition

Users and groups can be managed via the Azure portal, Azure CLI, Azure PowerShell, or Microsoft Graph API. Users can be internal (cloud-only, synced from on-premises AD) or external (guest users). Groups can be security groups or Microsoft 365 groups.

Term

What are Administrative Units in Microsoft Entra ID?

Definition

Administrative Units (AUs) are Entra ID resources that can contain users and groups. They allow for more granular delegation of administrative permissions, enabling administrators to manage a subset of users or groups within a larger Entra ID tenant.

Term

Explain Microsoft Entra ID Conditional Access.

Definition

Conditional Access is a feature that allows organizations to enforce policies based on specific conditions (e.g., user location, device state, application being accessed, sign-in risk). It helps protect resources by requiring additional authentication or blocking access when conditions are not met.

Term

What is the purpose of Azure Role-Based Access Control (RBAC)?

Definition

Azure RBAC provides fine-grained access management for Azure resources. It allows you to assign specific roles (e.g., Owner, Contributor, Reader, custom roles) to users, groups, service principals, or managed identities at different scopes (management group, subscription, resource group, resource).

Term

What is Azure Policy and its primary function?

Definition

Azure Policy helps enforce organizational standards and assess compliance at scale. It defines rules (policies) that describe the desired state of your Azure resources. Policies can prevent non-compliant resources from being created or modify existing non-compliant resources.

Term

Differentiate between Azure RBAC and Azure Policy.

Definition

RBAC focuses on who can do what (authorization) on specific resources, controlling management plane actions. Azure Policy focuses on what resources can or cannot be configured as (governance), enforcing rules and standards for resource properties. Analogy: RBAC is like giving someone a key to a specific room; Azure Policy is like setting rules for what furniture can be in that room.

Term

When would you use Azure RBAC over Azure Policy?

Definition

Use Azure RBAC when you need to control specific actions users or applications can perform on Azure resources (e.g., "User A can start/stop VMs in Resource Group X," "Service Principal Y can read secrets from Key Vault Z").