Microsoft Certified: Identity and Access Administrator AssociateImplement access governanceHard
A software development company uses Microsoft Entra ID and has implemented entitlement management. They have an access package for their 'Developer Tools' which grants access to several critical applications and groups. The company needs to ensure that access to 'Developer Tools' is automatically revoked for users if they lose their 'Developer' attribute in Microsoft Entra ID. Which type of policy setting should be configured within the access package to achieve this?
- ALifecycle settings for assignments
- BRequestor conditions
- CConnected organization settings
- DApproval settings
Show answer & explanationAnswer & explanation
Correct answer: A. Lifecycle settings for assignments
To automatically revoke access based on a change in a user's attribute, you need to configure 'Lifecycle settings for assignments'. Specifically, you would set 'Access expiration' to 'Never' and then use 'Attribute-based access control (ABAC)' conditions within the policy to define when access should be revoked based on the 'Developer' attribute.
Why the other options are wrong
- B. Requestor conditions define who can *request* the access package, not when existing access is revoked.
- C. Connected organization settings define relationships with external tenants, not attribute-based access revocation for internal users.
- D. Approval settings manage the workflow for *granting* access, not for automatically revoking it based on attributes.
Entitlement Management Lifecycle Settings
Microsoft Entra entitlement management's lifecycle settings define how long assigned access remains valid and when it should be revoked, including options for attribute-based expiration.
- Manages when access assignments expire.
- Can be set to expire after a certain number of days, on a specific date, or 'Never'.
- Can leverage attribute-based conditions to automatically revoke access when user attributes change.
Memory trick: Lifecycle dictates when access dies; attributes trigger the end.