Microsoft Security, Compliance, and Identity Fundamentals (SC-900)Describe the capabilities of Microsoft EntraMedium
A company wants to manage the lifecycle of user access to groups, applications, and SharePoint Online sites. They need a system that allows business owners to define access packages for resources and delegate approvals, while also ensuring that access is automatically removed when no longer needed. Which Microsoft Entra capability should they implement?
- AMicrosoft Entra Privileged Identity Management (PIM)
- BMicrosoft Entra Access Reviews
- CMicrosoft Entra Identity Protection
- DMicrosoft Entra Entitlement Management
Show answer & explanationAnswer & explanation
Correct answer: D. Microsoft Entra Entitlement Management
Microsoft Entra Entitlement Management is designed for managing identity and access lifecycle, allowing organizations to define access packages, delegate access requests and approvals to business owners, and automatically remove access based on policies and time limits.
Why the other options are wrong
- A. PIM focuses on managing privileged roles, not general user access lifecycle to applications and groups.
- B. Access Reviews help verify existing access, but don't manage the initial provisioning or lifecycle of access packages.
- C. Identity Protection detects and remediates identity-based risks, not general access lifecycle management.
Microsoft Entra Entitlement Management
An identity governance feature that enables organizations to manage identity and access lifecycle at scale by automating access requests, approvals, provisioning, and deprovisioning.
- Uses 'access packages' to group resources.
- Delegates access decisions to business owners.
- Automates access lifecycle, including expiration and removal.
- Supports internal and external users (B2B collaboration).
Memory trick: Entitlement Management: Easy access, easy exit, all automated.