Microsoft Certified: Identity and Access Administrator AssociateImplement access governanceEasy

A healthcare provider uses Microsoft Entra ID and has implemented entitlement management. They have an access package for 'Patient Data Access' that grants access to sensitive information. They need to ensure that only users from their 'Clinical Staff' security group can request this access package. Which policy setting within the access package should be configured?

  1. AApproval settings
  2. BRequestor conditions
  3. CLifecycle settings
  4. DConnected organizations
Show answer & explanation

Correct answer: B. Requestor conditions

To restrict who can request an access package, you configure 'Requestor conditions'. This allows you to specify specific users, groups, or connected organizations allowed to submit requests.

Why the other options are wrong

  • A. Approval settings define who approves access, not who can request it.
  • C. Lifecycle settings define when access expires or is reviewed, not who can initiate a request.
  • D. Connected organizations define external tenants allowed to request access, not specific internal groups.

Entitlement Management Requestor Conditions

A policy setting in Microsoft Entra entitlement management that defines which users are allowed to request access to an access package, enabling fine-grained control over access initiation.

  • Can specify individual users, security groups, or connected organizations.
  • Essential for controlling who can even see and apply for an access package.
  • Part of creating an access package policy.

Memory trick: Only authorized requestors can ask for the package.

More Implement access governance questions