DON'T WANT TO MISS A THING?

Certification Exam Passing Tips

Latest exam news and discount info

Curated and up-to-date by our experts

Yes, send me the newsletter

Free Microsoft AZ-104 Practice Questions & Answers 2026 Part3 | Microsoft Azure Administrator

Are you preparing for the Microsoft AZ-104 certification exam? SPOTO offers the Microsoft AZ-104 Premium File; all questions are aligned with the latest exam content and come with expert-provided answers. Our question banks cover the latest question types, core concepts, and detailed explanations, helping you familiarize yourself with the exam format and difficulty level. Whether you are reviewing core concepts or simulating a real exam environment, these resources will rapidly boost your confidence and readiness.
For over two decades, SPOTO has successfully helped numerous IT professionals secure their ideal positions at Fortune 500 companies. Download now to start practicing efficiently and ensure a high score on the actual exam. Don't miss this opportunity to pass your certification exam with ease!
Take other online exams

Question #1
Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.You have a Microsoft Entra tenant named contoso.com.You have a CSV file that contains the names and email addresses of 500 external users. You need to create a guest user account in contoso.com for each of the 500 external users.Solution: You create a PowerShell script that runs the New-MgInvitation cmdlet for each external user. Does this meet the goal?
A. Yes
B. No
View answer
Correct Answer: B

View The Updated AZ-104 Exam Questions

SPOTO Provides 100% Real AZ-104 Exam Questions for You to Pass Your AZ-104 Exam!

Question #2
Note: The question is included in a number of questions that depicts the identical set-up. However, every question has a distinctive result. Establish if the solution satisfies the requirements.Your company has an Azure Active Directory (Azure AD) subscription.You want to implement an Azure AD conditional access policy.The policy must be configured to require members of the Global Administrators group to use Multi-Factor Authentication and an Azure AD-joined device when they connect to Azure AD from untrusted locations.Solution: You access the multi-factor authentication page to alter the user settings.Does the solution meet the goal?
A. es
B. o
View answer
Correct Answer: B
Question #3
Your on-premises network contains a VPN gateway.You have an Azure subscription that contains the resources shown in the following table.You need to ensure that all the traffic from VM1 to storage1 travels across the Microsoft backbone network. What should you configure?
A. Azure Application Gateway
B. private endpoints
C. a network security group (NSG)
D. Azure Virtual WAN
View answer
Correct Answer: B
Question #4
You have a Microsoft Entra tenant that contains the groups shown in the following table.You purchase Microsoft Entra ID P2 licenses. To which groups can you assign a license?
A. Group1 only
B. Group1 and Group3 only
C. Group3 and Group4 only
D. Group1, Group2, and Group3 only
E. Group1, Group2, Group3, and Group4
View answer
Correct Answer: B
Question #5
You have an Azure subscription that contains a virtual network named VNet1. VNet 1 has two subnets named Subnet1 and Subnet2. VNet1 is in the West Europe Azure region.The subscription contains the virtual machines in the following table.You need to deploy an application gateway named AppGW1 to VNet1.What should you do first?
A. ove VM3 to Subnet1
B. dd a virtual network
C. dd a service endpoint
D. top VM1 and VM2
View answer
Correct Answer: A
Question #6
Your company has virtual machines (VMs) hosted in Microsoft Azure. The VMs are located in a single Azure virtual network named VNet1.The company has users that work remotely. The remote workers require access to the VMs on VNet1. You need to provide access for the remote workers.What should you do?
A. Configure a Site-to-Site (S2S) VPN
B. Configure a VNet-toVNet VPN
C. Configure a Point-to-Site (P2S) VPN
D. Configure DirectAccess on a Windows Server 2012 server VM
E. Configure a Multi-Site VPN
View answer
Correct Answer: C
Question #7
You need to move the blueprint files to Azure.What should you do?
A. Generate a shared access signature (SAS)
B. Use the Azure Import/Export service
C. Generate an access key
D. Use Azure Storage Explorer to copy the files
View answer
Correct Answer: D
Question #8
Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.You have a Microsoft Entra tenant named contoso.com.You have a CSV file that contains the names and email addresses of 500 external users. You need to create a guest user account in contoso.com for each of the 500 external users. Solution: You create a PowerShell script that runs the New-MgUser cmdlet for each user.Does this meet the goal?
A. Yes
B. No
View answer
Correct Answer: B
Question #9
You have two Azure subscriptions named Sub1 and Sub2 that are linked to the same Microsoft Entra tenant.An administrator creates a custom role that has an assignable scope to a resource group named RG1 in Sub1.You need to ensure that you can apply the custom role to any resource group in Sub1 and Sub2. The solution must minimize administrative effort.What should you do?
A. Select the custom role and add Sub1 and Sub2 to the assignable scopes
B. Create a new custom role for Sub1
C. Create a new custom role for Sub1 and add Sub2 to the assignable scopes
D. Select the custom role and add Sub1 to the assignable scopes
View answer
Correct Answer: A
Question #10
Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.You have an Azure subscription that contains the following users in a Microsoft Entra tenant named contoso.onmicrosoft.com:User1 creates a new Microsoft Entra tenant named external.contoso.onmicrosoft.com. You need to create new user accounts in external.contoso.onmicrosoft.com.Solution: You instruct User4 to create the user accounts. Does that meet the goal?
A. Yes
B. No
View answer
Correct Answer: B
Question #11
Users are reporting that when they attempt to access myapps.microsoft.com, they are prompted multiple times to sign in and are forced to use an account name that ends with onmicrosoft.com. You discover that there is a UPN mismatch between Azure AD and the on-premises Active Directory. You need to ensure that the users can use single-sign-on (SSO) to access Azure resources. What should you do first?
A. From the on-premises network, request a new certificate that contains the Active Directory domain name
B. From the server that runs Azure AD Connect, modify the filtering options
C. From the on-premises network, deploy Active Directory Federation Services in a clustered environment
D. From Azure AD, add and verify a custom domain name
View answer
Correct Answer: D
Question #12
Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.You have an Azure subscription that contains the following users in a Microsoft Entra tenant named contoso.onmicrosoft.com:User1 creates a new Microsoft Entra tenant named external.contoso.onmicrosoft.com. You need to create new user accounts in external.contoso.onmicrosoft.com.Solution: You instruct User2 to create the user accounts. Does that meet the goal?
A. Yes
B. No
View answer
Correct Answer: B
Question #13
Your company has two on-premises servers named SRV01 and SRV02. Developers have created an application that runs on SRV01. The application calls a service on SRV02 by IP address.You plan to migrate the application on Azure virtual machines (VMs). You have configured two VMs on a single subnet in an Azure virtual network.You need to configure the two VMs with static internal IP addresses. What should you do?
A. Run the New-AzureRMVMConfig PowerShell cmdlet
B. Run the Set-AzureSubnet PowerShell cmdlet
C. Modify the VM properties in the Azure Management Portal
D. Modify the IP properties in Windows Network and Sharing Center
E. Run the Set-AzureStaticVNetIP PowerShell cmdlet
View answer
Correct Answer: E
Question #14
You have an Azure Subscription that contains a storage account named storageacct1234 and two users named User1 and User2.You assign User1 the roles shown in the following exhibit.Which two actions can User1 perform? Each correct answer presents a complete solution.NOTE: Each correct selection is worth one point.
A. Assign roles to User2 for storageacct1234
B. Upload blob data to storageacct1234
C. Modify the firewall of storageacct1234
D. View blob data in storageacct1234
E. List files in file shares in storageacct1234
View answer
Correct Answer: BD
Question #15
You have an Azure subscription named Subscription1 that contains virtual network named VNet1. VNet1 is in a resource group named RG1.A user named User1 has the following roles for Subscription1: ReaderSecurity Admin Security ReaderYou need to ensure that User1 can assign the Reader role for VNet1 to other users. What should you do?
A. Assign User1 the Contributor role for VNet1
B. Assign User1 the Network Contributor role for VNet1
C. Assign User1 the User Access Administrator role for VNet1
D. Remove User1 from the Security Reader and Reader roles for Subscription1
View answer
Correct Answer: C
Question #16
Note: The question is included in a number of questions that depicts the identical set-up. However, every question has a distinctive result. Establish if the solution satisfies the requirements.Your company has an Azure Active Directory (Azure AD) tenant named weyland.com that is configured for hybrid coexistence with the on-premises ActiveDirectory domain.You have a server named DirSync1 that is configured as a DirSync server.You create a new user account in the on-premise Active Directory. You now need to replicate the user information to Azure AD immediately.Solution: You use Active Directory Sites and Services to force replication of the Global Catalog on a domain controller.Does the solution meet the goal?
A. es
B. o
View answer
Correct Answer: B
Question #17
You have 15 Azure subscriptions.You have a Microsoft Entra tenant that contains a security group named Group1. You plan to purchase additional Azure subscription.You need to ensure that Group1 can manage role assignments for the existing subscriptions and the planned subscriptions. The solution must meet the following requirements:Use the principle of least privilege. Minimize administrative effort.What should you do?
A. Assign Group1 the Owner role for the root management group
B. Assign Group1 the User Access Administrator role for the root management group
C. Create a new management group and assign Group1 the User Access Administrator role for the group
D. Create a new management group and assign Group1 the Owner role for the group
View answer
Correct Answer: B
Question #18
You have an Azure subscription named Subscription1 that contains a virtual network named VNet1. VNet1 is in a resource group named RG1.Subscription1 has a user named User1. User1 has the following roles: ReaderSecurity Admin Security ReaderYou need to ensure that User1 can assign the Reader role for VNet1 to other users. What should you do?
A. Remove User1 from the Security Reader role for Subscription1
B. Assign User1 the Access Administrator role for VNet1
C. Remove User1 from the Security Reader and Reader roles for Subscription1
D. Assign User1 the Network Contributor role for RG1
View answer
Correct Answer: B
Question #19
You have an Azure subscription.Users access the resources in the subscription from either home or from customer sites. From home, users must establish a point-to-site VPN to access the Azure resources. The users on the customer sites access the Azure resources by using site-to-site VPNs.You have a line-of-business-app named App1 that runs on several Azure virtual machine. The virtual machines run Windows Server.You need to ensure that the connections to App1 are spread across all the virtual machines.What are two possible Azure services that you can use? Each correct answer presents a complete solution.NOTE: Each correct selection is worth one point.
A. an internal load balancer
B. a public load balancer
C. an Azure Content Delivery Network (CDN)
D. Traffic Manager
E. an Azure Application Gateway
View answer
Correct Answer: AE
Question #20
You have a Microsoft Entra tenant that contains the groups shown in the following table.You purchase Microsoft Entra ID P2 licenses. To which groups can you assign a license?
A. Group1 only
B. Group1 and Group3 only
C. Group3 and Group4 only
D. Group1, Group2, and Group3 only
E. Group1, Group2, Group3, and Group4
View answer
Correct Answer: B
Question #21
You have an Azure subscription that contains the resources shown in the following table.You need to assign Workspace1 a role to allow read, write, and delete operations for the data stored in the containers of storage1.Which role should you assign?
A. Storage Account Contributor
B. Contributor
C. Storage Blob Data Contributor
D. Reader and Data Access
View answer
Correct Answer: C
Question #22
You have an Azure subscription named Subscription1 that contains virtual network named VNet1. VNet1 is in a resource group named RG1.A user named User1 has the following roles for Subscription1: ReaderSecurity Admin Security ReaderYou need to ensure that User1 can assign the Reader role for VNet1 to other users. What should you do?
A. Remove User1 from the Security Reader and Reader roles for Subscription1
B. Assign User1 the Contributor role for VNet1
C. Assign User1 the Owner role for VNet1
D. Assign User1 the Network Contributor role for RG1
View answer
Correct Answer: C
Question #23
Note: The question is included in a number of questions that depicts the identical set-up. However, every question has a distinctive result. Establish ifthe solution satisfies the requirements.Your company's Azure solution makes use of Multi-Factor Authentication for when users are not in the office. The Per Authentication option has been configuredas the usage model.After the acquisition of a smaller business and the addition of the new staff to Azure Active Directory (Azure AD) obtains a different company and adding the newemployees to Azure Active Directory (Azure AD), you are informed that these employees should also make use of Multi-Factor Authentication.To achieve this, the Per Enabled User setting must be set for the usage model.Solution: You reconfigure the existing usage model via the Azure CLI.Does the solution meet the goal?
A. Yes
B. No
View answer
Correct Answer: B
Question #24
Note: The question is included in a number of questions that depicts the identical set-up. However, every question has a distinctive result. Establish ifthe solution satisfies the requirements.Your company has an Azure Active Directory (Azure AD) subscription.You want to implement an Azure AD conditional access policy.The policy must be configured to require members of the Global Administrators group to use Multi-Factor Authentication and an Azure AD-joined device when theyconnect to Azure AD from untrusted locations.Solution: You access the Azure portal to alter the grant control of the Azure AD conditional access policy.Does the solution meet the goal?
A. Yes
B. No
View answer
Correct Answer: A
Question #25
You have an Azure subscription named Subscription1 that contains a virtual network named VNet1. VNet1 is in a resource group named RG1. Subscription1 has a user named User1. User1 has the following roles; * Reader * Security Admin * Security Reader You need to ensure that User1 can assign the Reader role for VNet1 to other users. What should you do?
A. AAssign User1 the Contributor role for VNet1
B. BRemove User from the Security Reader and Reader roles tot Subscription1
C. CAssign User1 the Network Contributor role for VNet1
D. DAssign User1 the User Access Administrator role for VNet1
View answer
Correct Answer: D
Question #26
You have an Azure subscription named Subscription1. Subscription1 contains the resource groups in the following table.RG1 has a web app named WebApp1. WebApp1 is located in West Europe. You move WebApp1 to RG2.What is the effect of the move?
A. The App Service plan for WebApp1 remains in West Europe
B. The App Service plan for WebApp1 moves to North Europe
C. The App Service plan for WebApp1 remains in West Europe
D. The App Service plan for WebApp1 moves to North Europe
View answer
Correct Answer: A
Question #27
You need to recommend a solution to automate the configuration for the finance department users. The solution must meet the technical requirements. What should you include in the recommended?
A. Azure AP B2C
B. Azure AD Identity Protection
C. an Azure logic app and the Microsoft Identity Management (MIM) client
D. dynamic groups and conditional access policies
View answer
Correct Answer: C
Question #28
Note: The question is included in a number of questions that depicts the identical set-up. However, every question has a distinctive result. Establish if the solution satisfies the requirements.Your company's Azure solution makes use of Multi-Factor Authentication for when users are not in the office. The Per Authentication option has been configured as the usage model.After the acquisition of a smaller business and the addition of the new staff to Azure Active Directory (Azure AD) obtains a different company and adding the new employees to Azure Active Directory (Azure AD), you are informed that these employees should also make use of Multi-Factor Authentication.To achieve this, the Per Enabled User setting must be set for the usage model.Solution: You create a new Multi-Factor Authentication provider with a backup from the existing Multi-Factor Authentication provider data.Does the solution meet the goal?
A. es
B. o
View answer
Correct Answer: B
Question #29
You are planning to deploy an Ubuntu Server virtual machine to your company's Azure subscription.You are required to implement a custom deployment that includes adding a particular trusted root certification authority (CA).Which of the following should you use to create the virtual machine?
A. he New-AzureRmVm cmdlet
B. he New-AzVM cmdlet
C. he Create-AzVM cmdlet
D. he az vm create command
View answer
Correct Answer: D
Question #30
You have an Azure subscription named Subscription1 that contains a virtual network named VNet1. VNet1 is in a resource group named RG1.Subscription1 has a user named User1. User1 has the following roles: ReaderSecurity Admin Security ReaderYou need to ensure that User1 can assign the Reader role for VNet1 to other users. What should you do?
A. Remove User1 from the Security Reader role for Subscription1
B. Assign User1 the Owner role for VNet1
C. Assign User1 the Contributor role for VNet1
D. Assign User1 the Network Contributor role for VNet1
View answer
Correct Answer: B
Question #31
Which of the following charts is not supported by the query language?
A. linechart
B. barchart
C. areachart
D. piechart
View answer
Correct Answer: A
Question #32
Note: The question is included in a number of questions that depicts the identical set-up. However, every question has a distinctive result. Establish if the solution satisfies the requirements.Your company’s Azure subscription includes two Azure networks named VirtualNetworkA and VirtualNetworkB.VirtualNetworkA includes a VPN gateway that is configured to make use of static routing. Also, a site-to-site VPN connection exists between your company’s on-premises network and VirtualNetworkA.You have configured a point-to-site VPN connection to VirtualNetworkA from a workstation running Windows10. After configuring virtual network peering between VirtualNetworkA and VirtualNetworkB, you confirm that you are able to access VirtualNetworkB from the company’s on-premises network. However, you find that you cannot establish a connection to VirtualNetworkB from the Windows 10 workstation.You have to make sure that a connection to VirtualNetworkB can be established from the Windows 10 workstation.Solution: You choose the Allow gateway transit setting on VirtualNetworkB. Does the solution meet the goal?
A. Yes
B. No
View answer
Correct Answer: B
Question #33
You have the Azure virtual machines shown in the following table.A DNS service is installed on VM1.You configure the DNS servers settings for each virtual network as shown in the following exhibit.You need to ensure that all the virtual machines can resolve DNS names by using the DNS service on VM1.What should you do?
A. onfigure a conditional forwarder on VM1
B. dd service endpoints on VNET1
C. dd service endpoints on VNET2 and VNET3
D. onfigure peering between VNET1, VNET2, and VNET3
View answer
Correct Answer: D
Question #34
Note: The question is included in a number of questions that depicts the identical set-up. However, every question has a distinctive result. Establish ifthe solution satisfies the requirements.Your company's Azure solution makes use of Multi-Factor Authentication for when users are not in the office. The Per Authentication option has been configuredas the usage model.After the acquisition of a smaller business and the addition of the new staff to Azure Active Directory (Azure AD) obtains a different company and adding the newemployees to Azure Active Directory (Azure AD), you are informed that these employees should also make use of Multi-Factor Authentication.To achieve this, the Per Enabled User setting must be set for the usage model.Solution: You create a new Multi-Factor Authentication provider with a backup from the existing Multi-Factor Authentication provider data.Does the solution meet the goal?
A. Yes
B. No
View answer
Correct Answer: B
Question #35
You have an Azure subscription named Subscription1 that contains a virtual network named VNet1. VNet1 is in a resource group named RG1.Subscription1 has a user named User1. User1 has the following roles: ReaderSecurity Admin Security ReaderYou need to ensure that User1 can assign the Reader role for VNet1 to other users. What should you do?
A. Assign User1 the Network Contributor role for VNet1
B. Remove User1 from the Security Reader role for Subscription1
C. Assign User1 the Owner role for VNet1
D. Assign User1 the Network Contributor role for RG1
View answer
Correct Answer: C
Question #36
Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.You have a Microsoft Entra tenant named contoso.com.You have a CSV file that contains the names and email addresses of 500 external users. You need to create a guest user account in contoso.com for each of the 500 external users. Solution: You create a PowerShell script that runs the New-MgUser cmdlet for each user.Does this meet the goal?
A. Yes
B. No
View answer
Correct Answer: B
Question #37
You have an Azure subscription that contains the resources shown in the following table.You need to assign Workspace1 a role to allow read, write, and delete operations for the data stored in the containers of storage1.Which role should you assign?
A. Storage Account Contributor
B. Contributor
C. Storage Blob Data Contributor
D. Reader and Data Access
View answer
Correct Answer: C

View The Updated Microsoft Exam Questions

SPOTO Provides 100% Real Microsoft Exam Questions for You to Pass Your Microsoft Exam!

View Answers after Submission

Please submit your email and WhatsApp to get the answers of questions.

Note: Please make sure your email ID and Whatsapp are valid so that you can get the correct exam results.

Email:
Whatsapp/phone number:
Contact Us