exam questions

Exam AZ-104 All Questions

View all questions & answers for the AZ-104 exam

Exam AZ-104 topic 6 question 5 discussion

Actual exam question from Microsoft's AZ-104
Question #: 5
Topic #: 6
[All AZ-104 Questions]

You have an Azure subscription that contains the identities shown in the following table.

User1, Principal1, and Group1 are assigned the Monitoring Reader role.
An action group named AG1 has the Email Azure Resource Manager Role notification type and is configured to email the Monitoring Reader role.
You create an alert rule named Alert1 that uses AG1.
You need to identity who will receive an email notification when Alert1 is triggered.
Who should you identify?

  • A. User1 and Principal1 only
  • B. User1, User2, Principal1, and Principal2
  • C. User1 only
  • D. User1 and User2 only
Show Suggested Answer Hide Answer
Suggested Answer: D 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
mlantonis
Highly Voted 4 years, 1 month ago
Correct Answer: C Email will only be sent to Azure AD user members of the Monitoring Reader role. Email will not be sent to Azure AD groups or service principals. Reference: https://docs.microsoft.com/en-us/azure/azure-monitor/platform/action-groups https://docs.microsoft.com/en-us/azure/azure-monitor/alerts/action-groups#email-azure-resource-manager-role
upvoted 177 times
c75e123
6 months, 1 week ago
Answer is: D When you use Azure Resource Manager for email notifications, you can send email to the members of a subscription's role. Email is sent to Microsoft Entra ID user or group members of the role. https://learn.microsoft.com/en-us/azure/azure-monitor/alerts/action-groups#email-azure-resource-manager
upvoted 2 times
...
rawrkadia
4 years ago
Did you actually test this? The question doesn't involve sending an email to a group but is instead concerned with role assignment inheritance from the group. The link you're all posting isn't necessarily relevant. User 2 should inherit the role assignment from the group, you can easily validate that in the portal. I am waiting out the 24hr lag period before testing. Alert group scoped to email on VM creation or deletion, one user assigned role directly and one via group. Will report back.
upvoted 15 times
panjie_s
3 years, 9 months ago
result?
upvoted 9 times
...
...
suriyaswamy
3 years, 11 months ago
Thanks for this Info
upvoted 2 times
...
Chole22
3 years, 4 months ago
Agree answer C: Email Azure Resource Manager Role Send email to the members of the subscription's role. Email will only be sent to Azure AD user members of the role. Email won't be sent to Azure AD groups or service principals.
upvoted 3 times
...
...
[Removed]
Highly Voted 4 years, 1 month ago
Answer is D. AG sends to users that have 'reader' role, User2 inherits that role through Group1 membership.
upvoted 61 times
NotMeAnyWay
2 years, 12 months ago
Anwser c: User1 only Can't be true, just send 10 seconds reading this from MS Docs: https://docs.microsoft.com/en-us/azure/azure-monitor/alerts/action-groups#email-azure-resource-manager-role Only the users in the Manager Role receive the email alert, not the group members or Principals.
upvoted 14 times
Razvan123
2 years, 11 months ago
You should not confuse group email (generated on group creation) with individual emails for group members.
upvoted 3 times
...
Babushka
2 years, 7 months ago
Folks that do say it's D are saying that's the answer because User 2 inherits Manager Role through Group 1. The AG is configured to send alert on the role which User 2 will have.
upvoted 2 times
...
garmatey
2 years ago
why does this have 6 upvotes?
upvoted 2 times
garmatey
2 years ago
Now 8? Yall, this person is wrong. No where in that documentation does it say "not the group ***members*** or Principals." It does however say "The email is only sent to Azure Active Directory user members of the selected role, not to Azure AD ***groups*** or service principals."
upvoted 2 times
...
...
...
green_arrow
4 years ago
I'm agree
upvoted 5 times
efla
1 year ago
Hello agree. Hope you're doing well.
upvoted 7 times
...
...
...
8ac3742
Most Recent 2 months, 4 weeks ago
Selected Answer: C
"Email ARM Role" notification type can be only received by direct AAD user, not by indirect user under one group which has the target role of the AG as well as the Service Principal like managed identity
upvoted 1 times
...
HawkesLager
8 months, 1 week ago
https://learn.microsoft.com/en-us/azure/azure-monitor/alerts/action-groups#email-azure-resource-manager When you use Azure Resource Manager for email notifications, you can send email to the members of a subscription's role. Email is sent to Microsoft Entra ID user or group members of the role. This includes support for roles assigned through Azure Lighthouse. Note Action Groups only supports emailing the following roles: Owner, Contributor, Reader, Monitoring Contributor, Monitoring Reader.
upvoted 1 times
...
itismadu
9 months, 2 weeks ago
Selected Answer: D
user 1 and user 2 User 2 because its also a member of a group that has the rights Email Azure Resource Manager When you use Azure Resource Manager for email notifications, you can send email to the members of a subscription's role. Email is sent to Microsoft Entra ID user or group members of the role. This includes support for roles assigned through Azure Lighthouse. Note Action Groups only supports emailing the following roles: Owner, Contributor, Reader, Monitoring Contributor, Monitoring Reader. https://learn.microsoft.com/en-us/azure/azure-monitor/alerts/action-groups#email-azure-resource-manager
upvoted 3 times
...
Honey918
11 months, 1 week ago
Correct Ans: D When you use Azure Resource Manager for email notifications, you can send email to the members of a subscription's role. Email is sent to Microsoft Entra ID **user** or **group** members of the role. This includes support for roles assigned through Azure Lighthouse. https://learn.microsoft.com/en-us/azure/azure-monitor/alerts/action-groups#email-azure-resource-manager
upvoted 1 times
...
a6bd45e
12 months ago
Selected Answer: D
This might have changed or is depricated, but now for Entra it is "Email Azure Resource Manager When you use Azure Resource Manager for email notifications, you can send email to the members of a subscription's role. Email is sent to Microsoft Entra ID user or group members of the role. This includes support for roles assigned through Azure Lighthouse." https://learn.microsoft.com/en-us/azure/azure-monitor/alerts/action-groups
upvoted 5 times
...
enklau
1 year ago
When you use Azure Resource Manager for email notifications, you can send email to the members of a subscription's role. Email is sent to Microsoft Entra ID user or group members of the role. https://learn.microsoft.com/en-us/azure/azure-monitor/alerts/action-groups#email-azure-resource-manager
upvoted 1 times
...
23169fd
1 year, 1 month ago
Selected Answer: D
Managed identities (such as Principal1 and Principal2) do not have associated email addresses and cannot receive email notifications. Therefore, only Azure AD users who are part of the Monitoring Reader role and have valid email addresses will receive the email notifications.
upvoted 3 times
...
WeepingMaplte
1 year, 1 month ago
Selected Answer: C
Email Azure Resource Manager role - Send an email to the subscription members, based on their role. A notification email is sent only to the primary email address configured for the Microsoft Entra user. - The email is only sent to Microsoft Entra ID user members of the selected role, not to Microsoft Entra groups or service principals. https://learn.microsoft.com/en-us/azure/azure-monitor/alerts/action-groups#email-azure-resource-manager-role:~:text=Fields-,Email%20Azure%20Resource%20Manager%20role,-Send%20an%20email https://learn.microsoft.com/en-us/azure/role-based-access-control/built-in-roles/monitor#monitoring-reader
upvoted 2 times
...
a3432e2
1 year, 2 months ago
C is correct Check mlantonis links. Email will only be sent to Azure AD user members of the Monitoring Reader role. Email will not be sent to Azure AD groups or service principals. A user has to be assigned that role hence User 1 is. User 2 (We are not told that this user was assigned) is a member of a group that has the role enabled, but that doesn't mean that User 2 has that role.
upvoted 1 times
...
bobothewiseman
1 year, 3 months ago
Selected Answer: D
Tested in lab, correct answer is D.
upvoted 7 times
...
tashakori
1 year, 3 months ago
D is correct
upvoted 2 times
...
WEIJIAN
1 year, 3 months ago
Selected Answer: D
mail will only be sent to Azure AD user members of the Monitoring Reader role. Email will not be sent to Azure AD groups or service principals.
upvoted 2 times
...
Candybar
1 year, 4 months ago
Selected Answer: C
Makes sure the email addresses added to the group are AAD user members not any groups, see Email Azure Resource Manager role for more info. If the members not receiving emails are not in a group and indeed member roles at the subscription level, then your issue will require more investigation.
upvoted 1 times
...
neolisto
1 year, 7 months ago
Selected Answer: D
Correct answer is D. I have tested it in a lab. Logic of this alert is very simple. User1 received an email because he is directly assigned to the Monitoring Reader role (which is in Action group). User2 received alert because he has the same role as a User1, because he inherited this role from the Group1 assignment. It means, that notification was received not because Group1 was selected as a target of notifications in AG1 (1. Cuz it's not; 2. Group can't be assigned as an email receiver, because groups physically have no emails. Service Principals also can't have email address), but because of AG1 condition is set for Monitoring Reader role. Email was sent to User2, because User2 has the same role as a User1. Even if User1 is assigned directly and User2 inherit this role from his Group in AAD.
upvoted 14 times
...
ImpulseEEE
1 year, 7 months ago
Selected Answer: C
mlantonis Highly Voted 2 years, 6 months ago Correct Answer: C Email will only be sent to Azure AD user members of the Monitoring Reader role. Email will not be sent to Azure AD groups or service principals.
upvoted 2 times
SamCook101
1 year, 6 months ago
Things changes alot in Azure within 2 years, Im still confused whether its C or D but since someone has more like doesn't mean right answer .
upvoted 1 times
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...