Medium1 markMultiple Choice
Domain 1.2: Authentication and AuthorizationDomain 1Authentication and AuthorizationIdentity GovernanceB2B

AZ-305 · Question 07 · Domain 1.2: Authentication and Authorization

A global logistics company frequently collaborates with hundreds of external partner organizations. Partners need access to specific internal web applications hosted on Azure App Service.

The company wants to use Microsoft Entra B2B collaboration. However, the IT department is concerned about 'guest account sprawl'—where partner accounts remain active long after a project ends, posing a security risk.

You need to design a solution that automatically asks internal project managers to verify if their external partners still need access every 90 days. If the manager does not respond, the partner's access should be automatically revoked.

Which Microsoft Entra feature should you recommend?

Answer options:

A.

Entitlement Management

B.

Access Reviews

C.

Privileged Identity Management (PIM)

D.

Conditional Access session controls

How to approach this question

Look for the feature specifically designed for periodic auditing and recertification of user access.

Full Answer

B.Access Reviews✓ Correct
Microsoft Entra Access Reviews (part of Identity Governance) enable organizations to periodically review users' access to resources. You can configure an access review to occur every 90 days, assign project managers as reviewers, and set the 'Upon completion settings' to automatically remove access if the reviewer does not respond.

Common mistakes

Selecting PIM. While PIM includes access reviews for admin roles, standard Access Reviews are used for application and group access lifecycle management.

Practice the full Azure Solutions Architect Expert AZ-305 Practice Exam 3

55 questions · hints · full answers · grading

More questions from this exam