Microsoft Certified: Azure Administrator AssociateManage Azure identities and governanceEasy

An administrator needs to create a new Azure AD user account for a contractor. The contractor requires temporary access to specific Azure resources for a period of 3 months. After this period, the account should automatically be disabled. Which setting should the administrator configure when creating the new user account in Azure AD?

  1. AAccount enabled (set to No)
  2. BBlock sign-in
  3. CUsage location
  4. DAccount expires on
Show answer & explanation

Correct answer: D. Account expires on

When creating a new user in Azure AD, the 'Account expires on' setting allows you to specify a future date after which the user account will automatically become disabled, perfectly suiting the requirement for temporary access for a contractor.

Why the other options are wrong

  • A. Setting 'Account enabled' to 'No' immediately disables the account, not at a future date.
  • B. Block sign-in immediately prevents the user from signing in; it doesn't allow for a future automatic disablement.
  • C. Usage location is used for licensing and compliance, not for account expiration.

Azure AD User Account Expiration

A setting available when creating or managing Azure AD user accounts that allows an administrator to specify a future date on which the account will automatically be disabled.

  • Useful for temporary users like contractors.
  • Helps enforce least privilege and reduce stale accounts.
  • Can be set via Azure portal or PowerShell.

Memory trick: For temporary users, set their expiration 'date' like a library book.

More Manage Azure identities and governance questions