The blueprint
A mock exam here has 50 questions in 100 minutes, split across the domains in the same proportions as the official exam guide. The official pass mark is 700 of 1,000 (scaled). FixOps scores practice against a target of 72%.
-
01
Manage Azure Identities and Governance
-
02
Implement and Manage Storage
-
03
Deploy and Manage Azure Compute Resources
-
04
Implement and Manage Virtual Networking
-
05
Monitor and Maintain Azure Resources
Sample questions
Three of the 10 questions in the free diagnostic. Open one to see the answer and why.
An administrator must create 300 user accounts for new staff whose details are in a spreadsheet. Which approach in the Microsoft Entra admin center fits?
- Assign a licence to a group, which creates the accounts
- Bulk create, with the details in the CSV template
- Create a dynamic group whose rule names the new staff
- Invite each person as a guest user from the Users page
Answer: Bulk create, with the details in the CSV template. Bulk create takes a CSV file based on the downloadable template and creates one member account per row. Guest invitations are for people who keep an identity elsewhere, and neither groups nor licences create accounts: both only act on users that already exist.
A developer must create and manage every kind of resource in a resource group but must not be able to grant access to anyone. Which built-in role fits?
- Contributor
- Owner
- Reader
- User Access Administrator
Answer: Contributor. Contributor can manage all resources but cannot assign roles. Owner adds the right to assign roles, User Access Administrator manages access only, and Reader cannot change anything.
A storage account's firewall is set to allow selected networks. Virtual machines in subnet app-subnet must reach the account over its public endpoint. What must be in place on app-subnet before the subnet can be added as a network rule?
- A NAT gateway with a public IP prefix
- A delegation to Microsoft.Storage
- A route table with a route to the internet
- A service endpoint for Microsoft.Storage
Answer: A service endpoint for Microsoft.Storage. A virtual network rule on the storage firewall relies on the Microsoft.Storage service endpoint of the subnet, which lets the account see the subnet's identity instead of a public IP address. Routes, NAT gateways and delegations do not make a subnet eligible for a network rule.
Revision notes: Manage Azure Identities and Governance
The notes for one domain, free to read here and in the app. FixOps Pro has them for all 5 domains.
Who can sign in, what they may do to Azure resources, and how an organisation keeps subscriptions under control with policy, locks, tags, budgets and management groups.
Microsoft Entra users and groups
- Bulk create users from the CSV template; invite people from other organisations as guests (B2B), who sign in with their own account.
- A usage location must be set on a user before a licence is assigned directly.
- Dynamic membership groups follow a rule on user or device attributes and need Microsoft Entra ID P1. Members cannot be added by hand.
- With group-based licensing, users are licensed one by one; when licences run out the rest show an error on the group.
- A deleted user can be restored for 30 days with its object ID, groups and role assignments.
- Self-service password reset is enabled for None, Selected (one group) or All. Writing a reset back to on-premises AD needs password writeback and P1.
Azure role-based access control
- A role assignment is a security principal, a role definition and a scope. Scopes nest: management group, subscription, resource group, resource. Assignments are inherited downwards.
- Permissions are additive: the effective access is the sum of every assignment that applies.
- Owner manages resources and access. Contributor manages resources but cannot assign roles. User Access Administrator manages access only. Reader changes nothing.
- NotActions subtracts from the same role's Actions; it is not a deny. Only a deny assignment blocks an operation whatever roles grant.
- Reading or writing data inside a resource needs a data-plane role, such as Storage Blob Data Reader. Reader and Contributor cover the management plane.
- A custom role lists Actions, NotActions, DataActions and AssignableScopes.
- Microsoft Entra roles (for example Global Administrator, User Administrator) govern the directory, not Azure resources. A Global Administrator can elevate access to get User Access Administrator at root scope.
Azure Policy
- Policy evaluates resource properties against rules: Deny refuses a request, Audit reports, Modify and DeployIfNotExists change or add configuration.
- A new policy marks existing resources non-compliant but does not change, stop or delete them.
- DeployIfNotExists and Modify fix existing resources only through a remediation task, run with the assignment's managed identity.
- An initiative groups policies so that they are assigned and reported together. An assignment can exclude scopes beneath it.
Locks, tags and resource groups
- CanNotDelete allows changes but no deletion. ReadOnly also blocks changes, including POST operations such as listing storage keys.
- Locks apply to every user, are inherited by child resources and must be removed before a locked item can be deleted.
- Tags are not inherited from a resource group. A policy with the Modify effect can copy them down.
- Moving a resource to another resource group changes its resource ID, never its region. Both groups are locked for writes during the move.
- Deleting a resource group deletes everything in it.
Subscriptions, cost and management groups
- Management groups sit above subscriptions; a policy or role assigned there reaches every subscription below, including new ones.
- A budget notifies (or triggers an action group) at thresholds on actual or forecasted cost. It does not stop resources.
- Azure Advisor recommends cost savings such as resizing or shutting down underused virtual machines.
Easy to mix up
- Azure Policy decides what a resource may look like; RBAC decides who may act on it. An Owner is still bound by policy.
- Contributor cannot grant access; User Access Administrator can grant access but cannot manage resources.
- Reader on a storage account does not allow reading blobs: that needs a Storage Blob Data role.
- A budget is an alert, not a spending cap.