Microsoft 365 Certified: Administrator ExpertDeploy and manage a Microsoft 365 tenantMedium
A Microsoft 365 administrator is onboarding a new employee, Alex. Alex will be part of the Marketing department and requires access to all SharePoint sites and Microsoft Teams associated with Marketing. The administrator wants to automate Alex's access provisioning and ensure that Alex is automatically removed from these resources if they leave the Marketing department. Which feature should the administrator use to achieve this?
- AAzure AD Privileged Identity Management (PIM)
- BAzure AD Access Reviews
- CMicrosoft 365 Group Naming Policy
- DAzure AD Dynamic Groups
Show answer & explanationAnswer & explanation
Correct answer: D. Azure AD Dynamic Groups
Azure AD Dynamic Groups allow for automatic membership management based on user attributes. By defining a rule that includes users from the 'Marketing' department, Alex will automatically join (and leave) relevant groups and thus gain (and lose) access to associated resources.
Why the other options are wrong
- A. PIM manages just-in-time access for privileged roles, not general resource access based on departmental attributes.
- B. Access Reviews are for periodically reviewing group membership, not for automated provisioning/deprovisioning based on attributes.
- C. Group Naming Policy enforces naming conventions for Microsoft 365 Groups, not membership automation.
Azure AD Dynamic Groups
Groups in Azure Active Directory whose membership is automatically updated based on user or device attributes and defined rules, simplifying access management.
- Automates group membership lifecycle.
- Rules can be based on user attributes (e.g., department, job title).
- Supports both user and device dynamic groups.
Memory trick: Dynamic Groups: The group that sorts itself out.