Microsoft Certified: Azure Administrator AssociateManage Azure identities and governanceHard

A company uses Azure Active Directory (Azure AD) to manage its user accounts. They have a new requirement to ensure that all user accounts are automatically removed from all groups and their licenses are revoked when their employee status changes to 'Terminated' in the HR system. This process must be automated and efficient. Which Azure AD feature is best suited for this task?

  1. AAzure AD PIM (Privileged Identity Management)
  2. BAzure AD Identity Governance with user provisioning
  3. CAzure AD Conditional Access policies
  4. DAzure AD Connect with custom synchronization rules
Show answer & explanation

Correct answer: B. Azure AD Identity Governance with user provisioning

Azure AD Identity Governance, specifically its user provisioning capabilities, is designed to automate the lifecycle of user identities. It can integrate with HR systems (like Workday or SuccessFactors) to automatically update user attributes, manage group memberships, and revoke licenses based on changes in employee status, such as 'Terminated'.

Why the other options are wrong

  • A. Azure AD PIM manages just-in-time access for privileged roles and does not handle general user lifecycle events like termination-driven group/license management.
  • C. Azure AD Conditional Access policies control access based on conditions but do not automate user account lifecycle management like group removal or license revocation.
  • D. Azure AD Connect primarily synchronizes attributes and password hashes from on-premises AD DS. While it can be customized, directly managing group memberships and license revocation based on an HR system 'Terminated' status is not its primary or most efficient use case compared to Identity Governance.

Azure AD Identity Governance (User Provisioning)

Azure AD Identity Governance, through its user provisioning capabilities, automates the creation, maintenance, and removal of user identities across various systems, often integrating with HR systems for lifecycle management.

  • Automates user lifecycle from joiner to leaver.
  • Can provision users to Azure AD, SaaS apps, and on-premises systems.
  • Integrates with HR systems (e.g., Workday, SuccessFactors) as a source of truth.
  • Manages group memberships and license assignments automatically.

Memory trick: Identity Governance is the HR manager for your digital workforce, automating joiners and leavers.

More Manage Azure identities and governance questions