Microsoft Certified: Azure Administrator AssociateManage Azure identities and governanceEasy
An administrator needs to create a new Azure AD user account for a contractor. The contractor requires temporary access to specific Azure resources for a period of 3 months. After this period, the account should automatically be disabled. Which setting should the administrator configure when creating the new user account in Azure AD?
- AAccount enabled (set to No)
- BBlock sign-in
- CUsage location
- DAccount expires on
Show answer & explanationAnswer & explanation
Correct answer: D. Account expires on
When creating a new user in Azure AD, the 'Account expires on' setting allows you to specify a future date after which the user account will automatically become disabled, perfectly suiting the requirement for temporary access for a contractor.
Why the other options are wrong
- A. Setting 'Account enabled' to 'No' immediately disables the account, not at a future date.
- B. Block sign-in immediately prevents the user from signing in; it doesn't allow for a future automatic disablement.
- C. Usage location is used for licensing and compliance, not for account expiration.
Azure AD User Account Expiration
A setting available when creating or managing Azure AD user accounts that allows an administrator to specify a future date on which the account will automatically be disabled.
- Useful for temporary users like contractors.
- Helps enforce least privilege and reduce stale accounts.
- Can be set via Azure portal or PowerShell.
Memory trick: For temporary users, set their expiration 'date' like a library book.