🇺🇸 Microsoft Certified: Azure Administrator Associate · flashcards

Microsoft Certified: Azure Administrator Associate Manage Azure Identities and Governance Flashcards

54 question-and-answer cards covering Manage Azure Identities and Governance as it is examined in Microsoft Certified: Azure Administrator Associate. 24 of them are printed below, taken from across the deck — no signup, no paywall on the preview.

54Cards in deck
24Free preview
14Syllabus topics
~184Chars per answer
FreePrice

24 sample cards from the Manage Azure Identities and Governance deck

Sampled from the end of the deck, so these are different cards from the ones shown on the syllabus page.

  1. At what scopes do Microsoft Entra roles versus Azure RBAC roles apply?

    Entra roles apply at the tenant/directory level (some support administrative-unit scope); Azure RBAC roles apply at management group, subscription, resource group, or individual resource scope.

  2. Which role gives full control over Microsoft Entra ID, and which gives full control over Azure resources?

    Global Administrator (Entra role) gives full control over Microsoft Entra ID; Owner (Azure RBAC role) gives full control over Azure resources at its scope.

  3. How can a Global Administrator gain access to manage all Azure subscriptions?

    By toggling the 'Access management for Azure resources' setting in Entra ID, which grants them the User Access Administrator role at the root (/) scope of all subscriptions in the tenant.

  4. What does it mean to 'interpret effective permissions' in Azure, and what tool helps?

    It means determining the actual access a principal has by combining all role assignments and deny assignments across inherited scopes. The 'Check access' feature on a resource's Access control (IAM) blade shows a principal's effective access.

  5. If a user has Reader at the subscription and Contributor on a resource group within it, what are their effective permissions on that resource group?

    Contributor—because RBAC is additive and inherited, the union of Reader (subscription) and Contributor (resource group) results in Contributor-level access on that resource group.

  6. What is an Azure management group?

    A container above subscriptions used to organize multiple subscriptions and apply governance conditions (RBAC and Azure Policy) that are inherited by all subscriptions and resources beneath it.

  7. What is the root management group and key facts about the management group hierarchy?

    The root (Tenant Root Group) is the top-level management group automatically created per Entra tenant. The hierarchy supports up to 6 levels of depth (excluding root and subscription), and each MG/subscription has exactly one parent.

  8. What is the maximum number of management groups per Microsoft Entra tenant?

    Up to 10,000 management groups per tenant, with a hierarchy depth of up to 6 levels (not counting the root level or the subscription level).

  9. What is Azure Policy and what is its primary purpose?

    Azure Policy is a governance service that creates, assigns, and manages policies to enforce rules and effects on resources, ensuring they stay compliant with corporate standards and SLAs (e.g., allowed regions, required tags).

  10. Name five common effects available in Azure Policy.

    Deny, Audit, Append, Modify, DeployIfNotExists (others include AuditIfNotExists, Disabled, and Deny). Deny blocks non-compliant resources; Audit logs them as non-compliant.

  11. What is the difference between Azure Policy and Azure RBAC?

    Azure RBAC controls WHO can perform actions (authorization over principals); Azure Policy controls WHAT properties/configurations resources may have (enforcement over resource state), regardless of who creates them.

  12. What is an Azure Policy initiative (policy set)?

    A collection of multiple policy definitions grouped together and assigned as a single unit to achieve a broader compliance goal (e.g., a regulatory compliance baseline).

  13. What does Azure Policy 'remediation' do, and which effects support it?

    Remediation brings existing non-compliant resources into compliance by deploying or modifying configurations. It applies to deployIfNotExists and modify effects and uses a managed identity to perform the changes.

  14. What are the two types of Azure resource locks and what does each prevent?

    CanNotDelete (Delete lock): authorized users can read and modify but cannot delete the resource; ReadOnly: authorized users can read but cannot modify or delete the resource.

  15. At what scopes can Azure resource locks be applied and how do they inherit?

    Locks can be applied at subscription, resource group, or individual resource scope, and they are inherited by all child resources within that scope.

  16. Which RBAC permissions are required to create or delete Azure resource locks?

    Microsoft.Authorization/locks/* actions—provided by the Owner and User Access Administrator built-in roles.

  17. When multiple resource locks apply to a resource, which one takes precedence?

    The most restrictive lock wins—if both ReadOnly and CanNotDelete are inherited/applied, ReadOnly takes precedence and prevents modification.

  18. What is an Azure resource tag and what is its structure?

    A tag is metadata applied to Azure resources as a name/value pair (e.g., Environment=Production) used to organize resources logically for management, billing, and automation.

  19. Do Azure resource tags inherit from a resource group to its resources by default?

    No—tags are not inherited by default; a resource does not automatically receive its resource group's tags. Inheritance can be enforced using Azure Policy (modify/append effects).

  20. What are the limits on the number of tags per Azure resource and tag name/value length?

    Up to 50 tags per resource/resource group; tag name max 512 characters, tag value max 256 characters. (Storage accounts are limited to 128 characters for names.)

  21. How do resource tags support cost tracking in Azure?

    Tags appear in Cost Management and billing reports, letting you group, filter, and analyze costs by tag (e.g., by CostCenter, Department, or Environment) for chargeback and showback.

  22. What is Microsoft Cost Management and what does it provide?

    A suite of tools to monitor, allocate, analyze, and optimize Azure spending—offering cost analysis, budgets, alerts, recommendations, and exports across subscriptions and resource groups.

  23. What is an Azure budget in Cost Management and what happens when thresholds are reached?

    A budget sets a spending threshold over a time period (monthly, quarterly, annually). When actual or forecasted spend crosses a configured percentage threshold, it triggers alerts (email/action groups); budgets notify but do NOT automatically stop resources.

  24. What is the difference between 'actual' and 'forecasted' cost alerts in an Azure budget?

    Actual cost alerts fire when accrued spending reaches the threshold; forecasted alerts fire when Azure predicts spending will exceed the threshold by period end, allowing proactive action.

What this deck covers

The Manage Azure Identities and Governance deck follows the Microsoft Certified: Azure Administrator Associate Manage Azure Identities and Governance syllabus — 3 chapters and 14 topics — so questions land on material that is genuinely examinable rather than trivia around it. That works out to roughly 18.0 cards per chapter.

Answers are written to be recallable, not just readable — averaging about 184 characters, which is long enough to carry the reasoning and short enough to say out loud.

A deck like this earns its keep on the second and third pass. Read the syllabus first so you know the shape of the subject, then use the cards to find the specific facts that have not stuck.

Manage Azure Identities and Governance flashcards FAQ

How many Manage Azure Identities and Governance flashcards are in this Microsoft Certified: Azure Administrator Associate deck?

54 cards. This page previews 24 of them, sampled evenly across the deck so you can judge the difficulty before installing anything.

Are these Microsoft Certified: Azure Administrator Associate flashcards free?

Yes. The preview here is free to read with no signup, and the full 54-card deck is free inside the Examius app.

What do the Manage Azure Identities and Governance cards cover?

They follow the Microsoft Certified: Azure Administrator Associate Manage Azure Identities and Governance syllabus — 3 chapters and 14 topics — so the questions track what is actually examinable.

How should I use these flashcards?

Read the syllabus first so you know the shape of the subject, then drill the deck. Examius schedules each card with spaced repetition, so cards you keep missing come back sooner and ones you know drift further apart.