Microsoft Security, Compliance, and Identity Fundamentals (SC-900)Describe the capabilities of Microsoft EntraMedium

A security administrator needs to configure Microsoft Entra ID to automatically revoke access for users who have not accessed a specific application in the last 90 days. Additionally, they want to ensure that managers regularly review their team's access to sensitive resources. Which Microsoft Entra governance capability should be used?

  1. AMicrosoft Entra Identity Protection
  2. BMicrosoft Entra Entitlement Management
  3. CMicrosoft Entra Privileged Identity Management (PIM)
  4. DMicrosoft Entra Access Reviews
Show answer & explanation

Correct answer: D. Microsoft Entra Access Reviews

Microsoft Entra Access Reviews allow organizations to efficiently manage group memberships, access to enterprise applications, and role assignments by regularly reviewing who has access and automatically removing access for inactive users or those no longer needing it. This meets both requirements.

Why the other options are wrong

  • A. Microsoft Entra Identity Protection detects and remediates identity-based risks, which is not the primary function for access reviews or inactivity-based revocation.
  • B. Microsoft Entra Entitlement Management focuses on managing access lifecycles for external users and projects, not specifically for reviewing existing access and inactivity.
  • C. Microsoft Entra PIM manages privileged role assignments, not general user access to applications or inactivity-based revocation.

Microsoft Entra Access Reviews

Enable organizations to efficiently manage group memberships, access to enterprise applications, and role assignments by regularly reviewing who has access to what.

  • Automate access reviews for groups, applications, and roles
  • Can automatically revoke access for inactive users
  • Helps meet compliance requirements

Memory trick: Access Reviews: 'Who has what, and do they still need it?'

More Describe the capabilities of Microsoft Entra questions