Microsoft Certified: Azure Administrator AssociateManage Azure identities and governanceMedium
A global organization uses Azure Active Directory (Azure AD) to manage its user accounts. Due to compliance requirements, all user accounts must have their licenses automatically assigned based on their department, and these licenses should be removed if a user leaves a specific department. Which Azure AD feature can automate this process?
- AAzure AD Group-based licensing
- BAzure AD Privileged Identity Management (PIM)
- CAzure AD Conditional Access
- DAzure AD Identity Protection
Show answer & explanationAnswer & explanation
Correct answer: A. Azure AD Group-based licensing
Azure AD Group-based licensing allows you to assign one or more product licenses to a security group. When users are added to or removed from the group, their licenses are automatically assigned or revoked, respectively, which aligns with the requirement for department-based license management.
Why the other options are wrong
- B. PIM manages just-in-time access for privileged roles, not for general user license assignment.
- C. Conditional Access enforces policies for accessing resources, not for automating license assignment.
- D. Identity Protection detects and remediates identity-based risks, not for license assignment.
Azure AD Group-based Licensing
A feature that automates the assignment and removal of Azure AD licenses to users based on their membership in specific security groups.
- Assigns licenses to security groups, not individual users directly
- Automatically assigns/removes licenses when users join/leave groups
- Simplifies license management at scale
Memory trick: Groups give licenses automatically, like a membership club.