A research institution uses Microsoft Entra ID and has implemented entitlement management. They have an access package for research data that contains highly confidential intellectual property. The institution needs to ensure that only full-time employees from the 'Research' department, who also possess a 'Security Clearance: Top Secret' attribute, are eligible to request this access package. Users outside this department or without the specific security clearance should not even see the option to request the package. Which combination of settings in the access package policy will achieve this visibility and eligibility control?
- AAdd 'Research' department to 'Users and groups' in request settings, and 'Security Clearance: Top Secret' to 'Requestor must have attributes' conditions.
- BConfigure an access review for the access package quarterly, and enable 'Remove access if attributes change'.
- CAdd 'Research' department to 'Connected organizations', and 'Security Clearance: Top Secret' to 'Custom extensions'.
- DSet 'Users and groups' in request settings to 'All users (including guests)', and add 'Security Clearance: Top Secret' to 'Approval settings'.
Show answer & explanationAnswer & explanation
Correct answer: A. Add 'Research' department to 'Users and groups' in request settings, and 'Security Clearance: Top Secret' to 'Requestor must have attributes' conditions.
To control both visibility and eligibility, the 'Users and groups' setting in the request policy should limit who can request (e.g., to a group containing 'Research' department members), and 'Requestor must have attributes' should enforce the 'Security Clearance: Top Secret' condition. This ensures only eligible users can even see and attempt to request the package.
Why the other options are wrong
- B. Access reviews and attribute change revocation are for ongoing access management, not for controlling who can initially request or see the package.
- C. Connected organizations are for external tenants/providers, not for internal department/attribute filtering. Custom extensions are for advanced workflow integration, not direct visibility/eligibility control at this level.
- D. Setting 'Users and groups' to 'All users' would make the package visible to everyone, contradicting the requirement to hide it from ineligible users. Approval settings are for after a request, not for initial eligibility/visibility.
Entitlement Policy Requestor Conditions
Settings within an Entitlement Management access package policy that define who is eligible to request access and what attributes they must possess to even see or submit a request.
- Controls both the visibility and eligibility of an access package.
- 'For users in your directory' specifies which internal users/groups can request.
- 'Requestor must have attributes' enforces specific user attribute conditions for requesting.
Memory trick: Request control: who sees, who qualifies, only the best get in.