Microsoft Azure Administrator Associate AZ-104 Practice Question
As an Azure administrator, you need to provide a set of users with the ability to manage virtual machines but not to modify network settings. What is the BEST method to achieve this?
Edit an existing role to remove networking permissions and assign it to users
Create a custom role by copying an existing role that manages virtual machines and removing permissions related to networking
Assign multiple built-in roles to users to provide the required permissions
Assign the 'Contributor' role to users and block network access using Azure Policy