Microsoft Security, Compliance, and Identity Fundamentals (SC-900)Describe the capabilities of Microsoft EntraHard

An organization uses Microsoft Entra ID and wants to empower its department managers to approve or deny access requests for specific applications and groups without involving IT administrators. This delegation should also include automated expiration of access. Which Microsoft Entra capability supports this self-service access governance model?

  1. AMicrosoft Entra Identity Protection
  2. BMicrosoft Entra Privileged Identity Management (PIM)
  3. CMicrosoft Entra Access Reviews
  4. DMicrosoft Entra Entitlement Management
Show answer & explanation

Correct answer: D. Microsoft Entra Entitlement Management

Microsoft Entra Entitlement Management enables organizations to manage identity and access lifecycle at scale, empowering delegated non-IT users (like department managers) to approve access requests and automatically setting access expiration.

Why the other options are wrong

  • A. Identity Protection detects risks, not delegates access approval.
  • B. PIM manages privileged role access, not general application/group access for regular users.
  • C. Access Reviews are for periodic verification of existing access, not for initial requests and approvals.

Microsoft Entra Entitlement Management

An identity governance feature that enables organizations to manage identity and access lifecycle at scale.

  • Automates access request workflows, approvals, and provisioning.
  • Delegates access decisions to business owners.
  • Manages access for internal users, partners, and vendors.

Memory trick: Entitlement Management is like a self-service access vending machine with an expiry date.

More Describe the capabilities of Microsoft Entra questions