Microsoft Security, Compliance, and Identity Fundamentals (SC-900)Describe the capabilities of Microsoft EntraMedium

A multinational corporation uses Microsoft Entra ID and has a complex organizational structure. They want to delegate the management of user access to specific resources (e.g., SharePoint sites, applications) to individual department managers, allowing them to approve or deny access requests without IT intervention. Which Microsoft Entra capability should be used?

  1. AMicrosoft Entra Identity Protection
  2. BMicrosoft Entra Privileged Identity Management (PIM)
  3. CMicrosoft Entra Entitlement Management
  4. DMicrosoft Entra Connect
Show answer & explanation

Correct answer: C. Microsoft Entra Entitlement Management

Microsoft Entra Entitlement Management allows organizations to manage identity and access lifecycle at scale by enabling delegated administration to non-IT managers. It automates access requests, approvals, provisioning, and deprovisioning.

Why the other options are wrong

  • A. Identity Protection detects and remediates identity risks, not for delegating access management.
  • B. PIM focuses on managing access to privileged roles, not general user access to resources delegated to managers.
  • D. Entra Connect synchronizes on-premises directories with Entra ID, which is unrelated to delegated access management.

Microsoft Entra Entitlement Management

A governance feature that enables organizations to manage identity and access lifecycle at scale, automating access requests, approvals, provisioning, and deprovisioning.

  • Delegates access approval to business owners
  • Automates access lifecycle for groups, applications, and sites
  • Ensures 'just-enough-access' and timely revocation

Memory trick: Empower managers to master access rights.

More Describe the capabilities of Microsoft Entra questions