Microsoft Certified: Azure Administrator AssociateManage Azure identities and governanceMedium

A company uses Azure Active Directory (Azure AD) to manage its user identities. Due to a recent internal audit, they need to ensure that all users who have not logged in for more than 90 days are automatically disabled within Azure AD. Which Azure AD feature should the administrator configure to meet this requirement?

  1. AAzure AD user lifecycle workflows
  2. BAzure AD Conditional Access policies
  3. CAzure AD Identity Protection
  4. DAzure AD PIM (Privileged Identity Management)
Show answer & explanation

Correct answer: A. Azure AD user lifecycle workflows

Azure AD user lifecycle workflows allow administrators to automate tasks such as disabling inactive user accounts based on specific conditions like inactivity. This feature directly addresses the requirement for automatically disabling users after 90 days of inactivity.

Why the other options are wrong

  • B. Azure AD Conditional Access policies control access to resources based on conditions but do not automate user account status changes like disabling for inactivity.
  • C. Azure AD Identity Protection focuses on detecting and remediating identity-based risks, not on automatically disabling inactive users.
  • D. Azure AD PIM manages just-in-time access for privileged roles and does not handle general user account inactivity policies.

Azure AD User Lifecycle Workflows

Azure AD user lifecycle workflows automate identity governance processes for users joining, moving, or leaving an organization, including managing user account states based on conditions.

  • Automates tasks like onboarding, offboarding, and access management.
  • Can be triggered by events or scheduled based on conditions (e.g., inactivity).
  • Requires Azure AD Premium P2 license.

Memory trick: Workflows manage the user's journey, making sure they're active or archived.

More Manage Azure identities and governance questions