Microsoft Certified: Identity and Access Administrator AssociateImplement access governanceHard

A financial institution uses Microsoft Entra ID and has deployed entitlement management for various applications. They have an access package that grants access to sensitive financial reporting tools. Due to regulatory compliance, all users who are assigned this access package must also have a specific security attribute, 'ComplianceStatus: Approved', set on their user object in Microsoft Entra ID. If a user requests access and does not have this attribute, their request should be automatically denied. If the attribute is later removed from an assigned user, their access to the package should be revoked. How should this be configured in the access package policy?

  1. AAdd a connected organization for external users with the attribute.
  2. BSet a maximum assignment duration for the access package.
  3. CConfigure an access review for the access package annually.
  4. DAdd a 'Requestor must have attributes' condition to the policy, and enable 'Remove access if attributes change'.
Show answer & explanation

Correct answer: D. Add a 'Requestor must have attributes' condition to the policy, and enable 'Remove access if attributes change'.

To enforce attribute-based access at both request time and for ongoing assignments, you need to configure a 'Requestor must have attributes' condition in the policy's request settings and enable 'Remove access if attributes change' in the assignment lifecycle settings.

Why the other options are wrong

  • A. Connected organizations are for external users and don't directly enforce specific internal user attributes for access package policies.
  • B. Maximum assignment duration limits how long access is granted but doesn't dynamically revoke based on attribute changes.
  • C. Access reviews are periodic checks, not real-time enforcement of attribute conditions during request or on attribute change.

Attribute-Based Access in Entitlement Management

Using user attributes defined in Microsoft Entra ID as conditions for granting and maintaining access to an access package, allowing for dynamic policy enforcement.

  • Conditions can be set for requests (e.g., user must have attribute X).
  • Access can be automatically revoked if attributes change or are removed.
  • Enhances compliance and 'least privilege' by tying access to current user state.

Memory trick: Attributes are the access gatekeepers, changing them locks the door.

More Implement access governance questions