Microsoft Azure Administrator Associate AZ-104 Practice Question
Your company needs a group of developers to manage virtual machines in a single Azure resource group. They must be able to start, stop, and restart VMs, but must not be able to delete them or assign roles to other identities. Which action should you take to meet the requirement using least-privilege access?
Assign the developers the Contributor role on the resource group.
Add the developers to a custom "Virtual Machine Operator" role at the subscription level.
Create a custom Azure RBAC role that includes only start, stop, and restart VM actions and assign it to the developers at the resource-group scope.
Create an Azure AD role with the required permissions and assign it to the developers.
Creating a custom Azure role that contains only the start, stop, and restart virtual-machine actions, then assigning that role at the resource-group scope, meets the requirement and respects least privilege.
The Contributor role includes the broad Microsoft.Compute/ permissions set, which allows deleting VMs as well as many other actions, so it grants excessive rights.
Azure AD administrative roles govern Microsoft Entra (Azure AD) objects- they do not provide permissions over Azure resources such as virtual machines, so they cannot solve this scenario.
Assigning a custom "Virtual Machine Operator" role (or any similar custom role) at the subscription level would satisfy the functional permissions but would expose every VM in the subscription, violating the stated scope limitation.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is an Azure RBAC role, and how does it work?
Open an interactive chat with Bash
How do you create a custom Azure RBAC role?
Open an interactive chat with Bash
What is the difference between a built-in role and a custom role in Azure RBAC?
Open an interactive chat with Bash
Microsoft Azure Administrator Associate AZ-104
Manage Azure identities and governance
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .