Azure AD Core Concepts — AZ-104 Flashcards (Admin Units, Devices, Roles)

0.0(0)
studied byStudied by 0 people
learnLearn
examPractice Test
spaced repetitionSpaced Repetition
heart puzzleMatch
flashcardsFlashcards
Card Sorting

1/10

flashcard set

Earn XP

Description and Tags

Flashcards covering core Azure AD topics for the AZ-104 exam: including device types and management, administrative units, RBAC roles, and common exam scenarios. Designed using Dr. Justin Sung’s method — short prompts for active recall and conceptual understanding. Perfect for spaced repetition.

Study Analytics
Name
Mastery
Learn
Test
Matching
Spaced

No study sessions yet.

11 Terms

1
New cards

What’s the key difference between Azure AD Join and Azure AD Register?

Azure AD Join is for org-owned devices (like office desktops) logged in via domain or Autopilot. Azure AD Register is for BYOD — user’s personal devices logging into 365 services with conditional access and possibly MFA.

2
New cards

Why disable a device in Azure AD?

To revoke access, invalidate tokens, and prevent the device from authenticating again.

3
New cards

Which roles are needed to disable a device?

Global Admin, Intune Admin, Cloud Device Admin

4
New cards

What is enterprise state roaming?

A feature that syncs app data and settings across Azure AD-joined devices for roaming users.

5
New cards

Why download a device report as CSV?

For inventory tracking, audits, and reporting on device status or compliance.

6
New cards

How is an Azure AD Join different from a Register in terms of ownership?

Azure AD Join = company-owned, managed; Azure AD Register = user-owned (BYOD).

7
New cards

What are Administrative Units used for?

To scope admin privileges — like giving password reset rights to one HR admin without giving full org-wide access.

8
New cards

How does group membership affect Administrative Unit access?

Members of a group in an AU don’t automatically inherit access — you must add users individually if they need AU-specific roles.

9
New cards

Can you nest Administrative Units?

No — unlike on-premises OUs, Azure AD Administrative Units cannot be nested.

10
New cards

What’s the benefit of using dynamic groups?

Members are automatically added/removed based on attributes (like department or job title), reducing manual work.

11
New cards