Microsoft Certified: Azure Administrator AssociateManage Azure identities and governanceHard
A global organization uses Azure AD to manage its user accounts. Due to compliance requirements, all user accounts created for contractors must be automatically disabled after their contract ends. The contracts typically last for 6 months. You need to implement a solution that ensures these contractor accounts are automatically disabled after 180 days from their creation date without manual intervention. How should you configure these user accounts?
- AImplement a custom Azure Automation runbook to disable accounts based on a date tag.
- BSet an Azure AD Conditional Access policy to block sign-ins after 180 days.
- CConfigure the 'accountExpires' attribute for the user accounts in Azure AD.
- DUse Azure AD Identity Governance to schedule access reviews for contractor accounts.
Show answer & explanationAnswer & explanation
Correct answer: C. Configure the 'accountExpires' attribute for the user accounts in Azure AD.
Azure AD user accounts have an 'accountExpires' attribute (also known as 'Account expiration date') that can be set. When this date passes, the account is automatically disabled, preventing sign-in. This is the native and most direct way to achieve automatic account disabling based on a specific date in Azure AD, aligning with the requirement for no manual intervention.
Why the other options are wrong
- A. While an automation runbook could achieve this, it's a custom solution that requires development and maintenance. The 'accountExpires' attribute is a built-in, native feature for this purpose, making it the preferred solution.
- B. Conditional Access can block sign-ins but doesn't natively disable the account based on an expiration date without a custom attribute or other trigger.
- D. Access reviews are for periodic validation of access, not for automatic disabling of accounts based on a fixed expiration date.
Azure AD Account Expiration
Azure AD user accounts can have an 'accountExpires' attribute set, which automatically disables the account on the specified date, preventing further sign-ins.
- Native feature for automatic account disabling.
- Useful for temporary users like contractors.
- Can be set via PowerShell, Graph API, or Azure AD Connect (if synced).
Memory trick: AccountExpires is the 'E' for 'End date' of access.