nerdexam
Microsoft

AZ-104 · Question #382

Hotspot Question You have an Azure Active Directory (Azure AD) tenant that contains three global administrators named Admin1, Admin2, and Admin3. The tenant is associated to an Azure subscription…

The correct answer is Admin1 can add Admin2 as an owner of the subscription. = Yes; Admin2 can add Admin1 as an owner of the subscription. = No; Admin2 can create a resource group in the subscription. = No. Admin1 has elevated their access to become a User Access Administrator at the root scope (tenant level) by enabling 'Access management for Azure resources' in the Azure AD tenant settings. This grants Admin1 the ability to manage access across all Azure subscriptions in the…

Submitted by obi.ng· Mar 4, 2026Manage identity and access - specifically the elevation of Azure AD Global Administrators to User Access Administrator at the root scope, and the distinction between Azure AD roles and Azure subscription RBAC roles.

Question

Hotspot Question You have an Azure Active Directory (Azure AD) tenant that contains three global administrators named Admin1, Admin2, and Admin3. The tenant is associated to an Azure subscription. Access control for the subscription is configured as shown in the Access control exhibit. (Click the Exhibit tab.) You sign in to the Azure portal as Admin1 and configure the tenant as shown in the Tenant exhibit. (Click the Exhibit tab.) For each of the following statements, select Yes if the statement is true. Otherwise, select No. NOTE: Each correct selection is worth one point. Answer:

Exhibits

AZ-104 question #382 exhibit 1
AZ-104 question #382 exhibit 2
AZ-104 question #382 exhibit 3
AZ-104 question #382 exhibit 4
AZ-104 question #382 exhibit 5
AZ-104 question #382 exhibit 6

Answer Area

  • Admin1 can add Admin2 as an owner of the subscription.Yes
  • Admin2 can add Admin1 as an owner of the subscription.No
  • Admin2 can create a resource group in the subscription.No

Explanation

Admin1 has elevated their access to become a User Access Administrator at the root scope (tenant level) by enabling 'Access management for Azure resources' in the Azure AD tenant settings. This grants Admin1 the ability to manage access across all Azure subscriptions in the tenant, including assigning Admin2 as an owner of the subscription. Admin2, however, has no elevated permissions beyond being a Global Administrator in Azure AD - Global Admin role does not automatically grant Azure subscription RBAC permissions, so Admin2 cannot add owners or create resource groups in the subscription.

Topics

#Azure AD Global Administrator#User Access Administrator#Azure RBAC#Access Management for Azure Resources

Community Discussion

No community discussion yet for this question.

Full AZ-104 Practice