Microsoft Certified: Identity and Access Administrator AssociateImplement access governanceEasy

A company uses Microsoft Entra ID (formerly Azure Active Directory) and has several business-critical applications. External vendors require temporary access to specific applications. The company wants to automate the process of granting and revoking access, ensuring that access is revoked automatically after a predefined period or when the vendor's contract ends. Which Microsoft Entra ID feature should the company implement to meet these requirements?

  1. AMicrosoft Entra Conditional Access
  2. BMicrosoft Entra Privileged Identity Management (PIM)
  3. CMicrosoft Entra entitlement management
  4. DMicrosoft Entra Identity Protection
Show answer & explanation

Correct answer: C. Microsoft Entra entitlement management

Microsoft Entra entitlement management is designed to automate access lifecycle management for both internal and external users, including granting temporary access and automatic revocation based on policies.

Why the other options are wrong

  • A. Conditional Access enforces policies based on conditions (e.g., location, device state) but does not automate access granting or revocation based on timeframes.
  • B. PIM manages just-in-time and just-enough access for privileged roles, not general application access for external vendors.
  • D. Identity Protection focuses on detecting and remediating identity-based risks, not managing access lifecycles.

Entitlement Management

A Microsoft Entra ID feature that enables organizations to manage identity and access lifecycle at scale by automating access requests, approvals, provisioning, and de-provisioning.

  • Automates access lifecycle for internal and external users.
  • Uses access packages to bundle resources.
  • Supports approval workflows and time-limited access.

Memory trick: Entitlement Management grants and revokes access like a meticulous librarian.

More Implement access governance questions