Microsoft AZ-104: Azure Active Directory and Identity Management — Study Guide

Part of the Microsoft Azure Administrator Associate AZ-104 — Study Guide. Practice with verified answers in the Microsoft exam hub, or take timed practice tests on ExamRoll.io.

Overview

Azure Active Directory (Azure AD) is the identity control plane for Microsoft cloud services. A tenant is a dedicated, trusted identity directory that contains users, groups, applications, devices, and policies. A subscription is a billing container for Azure resources and is associated with exactly one Azure AD tenant for identity and access; a single tenant can hold multiple subscriptions. Role assignments for Azure resources (Azure RBAC) come from the tenant associated with the subscription. Users authenticate against their home tenant and can be granted access to resources in any subscription that trusts that tenant. Identity governance and security policies (for example, Conditional Access) apply at the tenant layer and drive how identities consume services across subscriptions.

Identities, Groups, and Licensing

Azure AD user accounts fall into three categories that influence lifecycle, authentication, and administration:

Groups provide scalable authorization and licensing. Assigned membership is explicitly managed. Dynamic membership (Azure AD Premium P1) evaluates rules against user or device attributes and automatically maintains membership in near real-time, ideal for employee type, department, or device compliance scenarios. Group-based licensing assigns product SKUs (for example, Microsoft 365 E5, Azure AD Premium) to security groups; Azure AD calculates effective license assignment, honors service plan disables, and surfaces conflicts. Dynamic groups pair well with group-based licensing to automatically license populations based on attributes.

Hybrid Identity with Azure AD Connect

Azure AD Connect establishes identity sync and sign-in patterns for hybrid environments:

Synchronization runs on a scheduler (default 30-minute cycle). Use Start-ADSyncSyncCycle -PolicyType Delta to immediately push recent changes such as new users, group membership, and attribute updates. Run -PolicyType Initial only for first-time or topology/schema changes (it performs full import, sync, and export and is slower). Forcing AD replication, restarting NetLogon, or manipulating the Global Catalog does not trigger Azure AD Connect export; the supported method is the PowerShell sync cycle or Synchronization Service Manager operations. Scope sync with OU and attribute filtering. For password writeback and SSPR integration to on-premises, enable the writeback feature in Azure AD Connect and grant the necessary on-premises permissions.

Access Decisions: Conditional Access, MFA, SSPR, and Identity Protection

Conditional Access (Azure AD Premium P1/P2) evaluates signals and enforces real-time controls at sign-in and token issuance. A policy targets users, groups, or directory roles; cloud apps or user actions; and conditions such as sign-in risk, device platform, client apps (legacy vs modern), and locations. Named locations tag trusted IP ranges or countries/regions and allow explicit include/exclude logic. Grant controls enforce requirements such as:

Multi-factor authentication can be enforced via:

Azure AD Identity Protection (Azure AD Premium P2) detects and responds to risk using telemetry such as leaked credentials, atypical travel, malware-linked IPs, and unfamiliar sign-in properties:

Administrative Roles and B2B Governance

Administrative roles scope control within Azure AD and should follow least privilege:

B2B collaboration lets external users access apps and resources without duplicating identities. The process includes:

Practical Problem Scenario

Contoso Ltd. has a hybrid identity deployment and must reduce risk for privileged access while onboarding a partner’s users to specific applications. The Azure administrator is tasked with enforcing MFA and device trust for Global Administrators from untrusted networks, accelerating on-premises-to-cloud user sync during a merger, and governing partner guest access to a SharePoint Online site and an internal line-of-business app.

Step-by-step approach:

  1. Model identities and trust
  1. Optimize hybrid sign-in and sync
  1. Enforce privileged access controls
  1. Standardize MFA and SSPR
  1. Onboard partner users with B2B and govern access

Why these services:


All domains · Azure Subscriptions

Practice these questions → · Timed practice on ExamRoll.io →

Pass the whole exam — not just this question

You found this answer. Get every verified question and explanation in one place, and save hours of prep. Free to start.

Pass your exam →

Browse Microsoft →

Related guides

All-in-one access

One subscription. Every exam.

Every plan unlocks unlimited answer search, practice tests, AI explanations, and the full resource library — in 20+ languages.

Monthly
24.87
Just €0.83/day
Everything included:
  • Unlimited answer search
  • Unlimited practice tests
  • AI-powered explanations
  • Full resource library
  • 20+ languages
  • Weekly content updates
  • Rewards & referrals
  • Priority support
Start free trial

No credit card required*

Best value
12 months
179.87
Just €0.49/daySave 40%
Everything included:
  • Unlimited answer search
  • Unlimited practice tests
  • AI-powered explanations
  • Full resource library
  • 20+ languages
  • Weekly content updates
  • Rewards & referrals
  • Priority support
Start free trial

No credit card required*

✓ Free plan included · ✓ Cancel anytime · ✓ All plans unlock the full product