anothercert

Your path to a cloud career starts here

A four-step learning path for Microsoft certifications: focused notes, spaced-repetition flashcards, quizzes and mock exams.

Free · No credit card · 4 certifications

Four steps

  1. Exam-focused notes

    Every exam objective explained with real-world examples. Focused on what the exam measures, so you don't waste time.

    AZ-104 / Manage Azure identities and governance / Manage Microsoft Entra users and groups

    Create users and groups in Microsoft Entra ID

    Every Azure subscription trusts a Microsoft Entra tenant to say who someone is. Two objects in that tenant do most of the day-to-day work: users (identities for people) and groups (collections of identities). Creating users gives people a sign-in. Creating groups lets you grant access to many of them in one step.

    Free sample, no account needed

    Create users and groups in Microsoft Entra ID

    Overview

    Every Azure subscription trusts a to say who someone is. Two objects in that tenant do most of the day-to-day work: users (identities for people) and groups (collections of identities). Creating users gives people a sign-in. Creating groups lets you grant access to many of them in one step.

    The problem groups solve is repetition. Without them, each permission is handed out person by person. With them, a resource owner or directory owner assigns a set of access permissions to every member of the group, instead of providing the rights one-by-one. Adding or removing one person then grants or revokes access with minimal effort.

    Entra ID can also fill groups for you. It supports defining membership based on rules, such as the department a user works in or their job title.

    Core concepts

    User. An identity in the tenant. Cloud users are created in the Microsoft Entra admin center under the Users area, where you supply details such as a user principal name and display name. The user can then be placed in groups.

    Group. A container that organizes users so permissions are easier to manage. Entra ID has two group types.

    Security group. The most common type, used to manage access to shared resources. Its members can be users, devices, and service principals. Example: a group called "Finance-Readers" that is given read access to a storage account, so every member gets that access at once. Creating this type requires a Microsoft Entra administrator.

    Microsoft 365 group. A collaboration group. Members get a shared mailbox, calendar, files, a site, and more. It can also give people outside the organization access, and it is available to both users and admins. Example: a project team that needs a shared mailbox and document library.

    Membership type. The second characteristic of a group, which controls how members are added. There are three values:

    • Assigned - members are added and maintained manually.
    • - users are added and removed automatically based on rules over user attributes such as department, job title, or location.
    • Dynamic Device - the same idea for devices. It applies to security groups only, because Microsoft 365 groups support dynamic users but not dynamic devices.

    Dynamic rule. The expression that decides membership. Example: all users whose Department attribute equals "Marketing" go into a Marketing security group.

    How it works

    1. Open the Groups item under Identity in the Microsoft Entra admin center to see existing groups. A brand-new deployment has none, so the list starts empty.

    Screenshot of the Microsoft Entra ID view all groups page. Shows a list of several groups.

    1. Create the group and choose its type: Security or Microsoft 365.
    2. Choose the membership type: Assigned, Dynamic User, or Dynamic Device.
    3. For an assigned group, add members by hand. For a dynamic group, build a rule with the membership rule generator, for example one that includes members from a specific place.

    Screenshot of the Dynamic Group membership rule generator. Set up a rule that includes members from a specific place.

    1. After that, Entra ID keeps membership current. When a member's attributes change, such as a move to another department, all dynamic membership rules in the tenant are reevaluated, and the user is added to or removed from groups accordingly.

    Dynamic membership requires a Microsoft Entra ID P1 license, or Intune for Education for device-based rules.

    Comparison

    AspectSecurity groupMicrosoft 365 group
    PurposeManage access to shared resourcesCollaboration: mailbox, calendar, files, SharePoint
    MembersUsers, devices, service principalsUsers (dynamic users supported)
    Who can createRequires an Entra administratorUsers and admins
    Dynamic DeviceSupportedNot supported
    Outside peopleNot described in the sourceCan be given access

    Scenario

    A company hires ten sales staff. The administrator wants them to reach a shared sales storage account without assigning rights ten times. They create a security group named "Sales-Staff" (a security group, since the goal is resource access, and an administrator is needed to create it). Because each new user has Department set to "Sales", they choose Dynamic User membership and write a rule on the Department attribute. This needs a Microsoft Entra ID P1 license. The permission is granted once to the group. When a sales employee moves to Marketing, the rules are reevaluated and the person leaves the group automatically.

    Exam traps

    • Dynamic Device membership is for security groups only. A Microsoft 365 group cannot use it.
    • Dynamic membership needs Microsoft Entra ID P1. A free tenant cannot use rules.
    • A security group needs a Microsoft Entra administrator to create it, while the Microsoft 365 option is open to users and admins.
    • Only Microsoft 365 groups come with a shared mailbox, calendar, and SharePoint site. Security groups are for access control.
    • Group type (Security or Microsoft 365) and membership type (Assigned, Dynamic User, Dynamic Device) are separate settings.
    • Members of a dynamic group are managed by the rule. Adding people by hand is the Assigned model.

    Original note written from Microsoft documentation. anothercert is not affiliated with Microsoft.

  2. Spaced-repetition flashcards

    Reviews scheduled right before you would forget, so knowledge stays after the exam.

    Why it works

    Memory fades without review. Each review pushes the next one further out.

    1 / 8 · AZ-104

    Click the card or press Space to flip it

  3. Quizzes

    Every topic has quiz questions on its most important points, with an explanation for each answer.

    Loading quiz…
  4. Mock exams

    Timed mock exams modeled on the Microsoft exam: questions are drawn in proportion to the official domain weights, and you get a score for every domain.

    Loading the exam…

Four steps, one goal: pass the exam and actually remember what you learned.

Create free account

Certifications

  • AZ-104

    Microsoft Certified: Azure Administrator Associate

    Topics
    82
    Flashcards
    484
    Questions
    406
  • AZ-305

    Designing Microsoft Azure Infrastructure Solutions

    Topics
    49
    Flashcards
    293
    Questions
    242
  • AZ-400

    Designing and Implementing Microsoft DevOps Solutions

    Topics
    86
    Flashcards
    511
    Questions
    421
  • AZ-900

    Microsoft Certified: Azure Fundamentals

    Topics
    57
    Flashcards
    328
    Questions
    284
See the full list

What makes it different

  • Based on Microsoft documentation

    Original notes, written from official Microsoft documentation.

  • Mapped to the exam

    Content is organized by the official skills outline, objective by objective.

  • Built for retention

    Flashcards and quizzes turn reading into knowledge that lasts.

FAQ

Is this official Microsoft material?

No. This is an independent study platform and is not affiliated with Microsoft.

Are the questions from the real exam?

No. All questions are written from the official skills outline. We never use leaked exam content.

Do I need an account?

Yes, a free account keeps your progress and flashcard schedule across devices.

How current is the content?

Each certification shows the date of the skills outline it is based on.

How do flashcards decide what to review?

They use FSRS, an open-source spaced-repetition algorithm that schedules each card right before you are likely to forget it.