AZ-104 · Microsoft Entra users and groups
20 cards
Microsoft Entra Groups and Properties
-
Quick check
What does putting users in a group actually change about permission management?
AEvery member keeps their own individual permission set as before
The point of the group is that members stop needing individually granted rights for the shared resource.
BPermissions can be granted per person more quickly than before
Granting rights one by one is exactly the work that the group is meant to replace, not to speed up.
COne permission set reaches all members, and access changes become membership changes
Right. A group defines a security boundary, so one set of permissions covers its members and access is adjusted by adding or removing them.
2 / 20
-
Quick check
A project team needs a shared mailbox, a calendar, files and a SharePoint site, and outside collaborators must be included. Which group type fits?
AA Microsoft 365 group, which provides those collaboration resources
Right. Microsoft 365 groups exist to give members collaboration resources, and they can include people from outside the organization.
BA security group, which provides those collaboration resources
A security group manages access to shared resources; it is not what supplies a mailbox, calendar or SharePoint site.
CAssigned membership, which provides those collaboration resources
Assigned is a membership type, so it describes how a roster is filled rather than what the group provides.
4 / 20
-
Quick check
Which list contains only things that can be members of a security group?
AUsers, devices and service principals
Right. Security-group membership can include users, devices and service principals.
BShared mailboxes, calendars and SharePoint sites
Those are collaboration resources that a Microsoft 365 group provides to its members, not objects placed inside a security group.
CDepartments, job titles and work locations
Those are user attributes that a membership rule can evaluate; an attribute is not an object that joins a group.
6 / 20
-
Keep your progress in the app
That’s 3 of 10 quick checks. In the app they stay answered, and every lesson remembers where you left off.
-
Quick check
Which admin center path opens the creation of a group?
AIdentity, then Users and All users, then New user
That path creates a user object; it never reaches the group properties.
BIdentity, then Users and Deleted users, then Restore user
That path recovers an account deleted less than 30 days ago and creates nothing new.
CIdentity, then Groups and All groups, then New group
Right. New group is offered from the Groups surface and opens the form for group type, name, membership type, owners and members.
8 / 20
-
Quick check
Which membership type leaves the roster in the administrator's hands, to be added and maintained manually?
ADynamic User membership
Dynamic User fills the roster automatically from rules that read user attributes such as department or job title.
BAssigned membership
Right. Assigned means members are added and maintained manually rather than by a rule.
CDynamic Device membership
Dynamic Device fills the roster automatically from device attributes, and only for security groups.
10 / 20
-
Quick check
A user moves to a different department in a tenant that has dynamic membership rules. What happens next?
AExisting memberships stay fixed until an administrator edits each roster
Not needing that manual pass is the whole purpose of a rule-driven roster.
BThe group switches to Assigned membership and waits for an approval
A membership type is a property chosen for the group; an attribute change does not rewrite it.
CThe rules are reevaluated, and the user joins or leaves groups to match
Right. A change to a relevant attribute causes the dynamic rules to be reevaluated and the membership to follow the new value.
12 / 20
-
Quick check
What does dynamic membership for user-based rules require?
AA User Administrator role assignment
A directory role decides what an administrator may do; it does not license the dynamic membership feature.
BA Microsoft Entra ID P1 licence
Right. Dynamic membership requires Microsoft Entra ID P1, with Intune for Education as the alternative for device-based rules.
CA Windows Server AD identity source
That value describes where a synchronized identity originates and has nothing to do with licensing a membership rule.
14 / 20
-
Quick check
A team must control access to a shared resource, include devices selected by their attributes, and never update the roster by hand. Which configuration fits?
AA Microsoft 365 group with Dynamic User membership
A Microsoft 365 group is the collaboration type, and a user rule would not select devices by their attributes.
BA security group with Assigned membership
A security group is right, but an assigned roster is exactly the manual maintenance the team wants to avoid.
CA security group with Dynamic Device membership
Right. Access control selects the security group, and device attributes with no manual work select Dynamic Device.
16 / 20
-
Quick check
A project needs a shared mailbox and SharePoint site, must include external collaborators, and should add employees automatically when Department equals Marketing. What should be built?
AA security group using Dynamic User membership
The rule would work, but a security group does not provide the mailbox and SharePoint site the project asks for.
BA Microsoft 365 group using Dynamic User membership
Right. Collaboration resources and external participants select the Microsoft 365 group, and the Department rule selects Dynamic User.
CA Microsoft 365 group using Assigned membership
The group type is right, but an assigned roster would have to be maintained by hand instead of following the attribute.
18 / 20
-
Quick check
An access boundary must contain service principals, every membership change needs explicit approval, and the design must not depend on dynamic-rule licensing. What should be used?
AA security group with Assigned membership and a designated owner
Right. Security groups accept service principals and form access boundaries, and an assigned roster keeps every change manual and unlicensed.
BA security group with Dynamic Device membership and no manual roster
A device rule would populate the group automatically, which removes the explicit approval and needs the licence being avoided.
CA Microsoft 365 group with Assigned membership and shared files
A Microsoft 365 group is the collaboration type; it is not the access boundary described, and its members are not service principals.
20 / 20
-
10 quick checks · then the test
In the app, finishing the quick checks opens this lesson’s 10-question test, and the ones you miss come back exactly when you’re about to forget them.
The whole course, on your phone
Lessons you can read, audio you can listen to on the way to work, and practice that remembers what you got wrong.