Exam Tips & Pitfalls – Identities & Governance
The Identities & Governance section is one of the most tested areas in AZ-104. Questions are often trick-based, designed to test if you can tell the difference between similar features. Here are the key tips to keep in mind during the exam.
Biggest Pitfalls to Avoid
- Mixing up Authentication vs Authorization
– Authentication = proving identity (sign-in).
– Authorization = what you can do (permissions). - Confusing Entra Roles vs RBAC Roles
– Entra roles = tenant-wide (manage users, groups, licenses).
– RBAC roles = resource-level (manage VMs, Storage, etc.). - Misunderstanding Scope Inheritance
– Assigning a role at Subscription level flows down to all Resource Groups and resources.
– You cannot break inheritance — only refine with additional assignments lower down. - Over-licensing
– Always pick the minimum license tier required (P1 vs P2).
– Don’t jump to P2 unless the scenario mentions Identity Protection or PIM. - Guest vs Member
– Guest = external, authenticated by their own provider.
– Member = internal, part of your tenant.
– Guests don’t get default employee rights.
Quick Recall Hacks
- “Just-in-Time” → PIM
- “MFA, risky logins, device compliance” → Conditional Access
- “Reader, Contributor, Owner” → RBAC Roles
- “Global Admin, User Admin” → Entra Roles
- “External collaboration” → Guest / B2B Access
Exam Question Patterns
- Direct definition questions: “Which license is required for PIM?” → P2.
- Scenario-based RBAC: “User must manage VMs but not change permissions.” → Contributor.
- Scope trick: “Assign role at RG level but user sees nothing in another RG.” → Because RBAC is scoped.
- Licensing traps: “Company needs SSPR + Conditional Access.” → P1, not P2.
- Guest user scenario: “Partner logs in with Gmail.” → Guest B2B Access.
Final Exam Strategy
When reading identity-related questions:
1. Check if it’s about sign-in → Entra ID / Conditional Access.
2. Check if it’s about permissions on resources → RBAC.
3. Check if it’s about temporary elevation → PIM.
4. Check if it’s about external users → Guest Access.
5. Check if it’s about licensing → match feature to correct P1/P2 level.
What to Expect in the Exam
- Trick-heavy questions mixing RBAC vs Entra roles.
- At least 1–2 licensing questions (P1 vs P2).
- Scenario questions about scope and inheritance.
- Guest access collaboration scenario (B2B).