Microsoft Security, Compliance, and Identity Fundamentals (SC-900)Describe the capabilities of Microsoft EntraHard
A global organization uses Microsoft Entra ID and has a complex organizational structure with many departments and projects. They need a scalable solution to delegate the management of access to specific groups and applications to departmental managers, allowing them to approve or deny access requests from their team members. Which Microsoft Entra governance capability supports this delegated access management?
- AMicrosoft Entra Access Reviews
- BMicrosoft Entra Identity Protection
- CMicrosoft Entra Entitlement Management
- DMicrosoft Entra Privileged Identity Management (PIM)
Show answer & explanationAnswer & explanation
Correct answer: C. Microsoft Entra Entitlement Management
Microsoft Entra Entitlement Management enables organizations to manage identity and access lifecycle at scale, including delegating access management to non-IT managers, automating access requests, approvals, and lifecycle for groups, applications, and SharePoint sites.
Why the other options are wrong
- A. Access Reviews are for periodic re-certification, not for delegating day-to-day access requests.
- B. Identity Protection detects risks, not delegates access management.
- D. PIM manages privileged roles, not general user access to applications and groups via delegated approval workflows.
Microsoft Entra Entitlement Management
A Microsoft Entra ID governance capability that enables organizations to manage identity and access lifecycle at scale by automating access requests, approvals, provisioning, and deprovisioning.
- Allows delegation of access management to business owners.
- Uses 'access packages' to bundle resources (groups, apps, SharePoint).
- Automates access lifecycle for internal and external users.
Memory trick: Entitlement Management is like a self-service kiosk for access, with managers approving the orders.