Microsoft Certified: Azure Administrator AssociateManage Azure identities and governanceEasy
A global company uses Azure Active Directory (Azure AD) to manage its user identities. Due to a recent internal audit, the security team has mandated that all guest user accounts must be reviewed and approved every 30 days to maintain access to critical applications. Which Azure AD feature should be implemented to meet this requirement with minimal administrative overhead?
- AManual review process with PowerShell scripts
- BAzure AD Conditional Access policies
- CAzure AD Identity Governance Access Reviews
- DAzure AD Privileged Identity Management (PIM)
Show answer & explanationAnswer & explanation
Correct answer: C. Azure AD Identity Governance Access Reviews
Azure AD Identity Governance Access Reviews allow organizations to manage group memberships, access to enterprise applications, and role assignments by creating recurring access reviews for users, including guests, to ensure they still need access.
Why the other options are wrong
- A. A manual process, even with scripting, would be highly inefficient and prone to errors for a recurring requirement across a large user base.
- B. Conditional Access policies enforce access controls at the time of sign-in but do not provide a recurring review and approval process for existing access.
- D. PIM manages just-in-time access for privileged roles, not recurring access reviews for all guest users.
Azure AD Identity Governance Access Reviews
A feature in Azure AD Identity Governance that enables organizations to manage group memberships, access to enterprise applications, and role assignments by creating recurring access reviews.
- Automates review of user access rights.
- Supports review of guest users, groups, and applications.
- Helps enforce compliance and reduce stale access permissions.
Memory trick: Guest access needs a regular check, like a revolving door of permissions.