Microsoft Certified: Identity and Access Administrator AssociateImplement access governanceEasy

A company uses Microsoft Entra ID (formerly Azure Active Directory) and has implemented entitlement management. They have a business-critical application that requires highly sensitive data access. The security team wants to ensure that access to this application is reviewed by at least two separate managers before it is granted, to minimize the risk of unauthorized access. Which feature in an entitlement management access package policy should be configured to meet this requirement?

  1. AMulti-stage approval
  2. BAutomatic request approval
  3. CExpiration settings
  4. DGuest user self-service
Show answer & explanation

Correct answer: A. Multi-stage approval

Multi-stage approval allows you to define multiple stages of approval for access requests, with different approvers or groups of approvers for each stage, directly addressing the need for two separate managers.

Why the other options are wrong

  • B. Automatic request approval grants access without any human intervention, which is contrary to the requirement.
  • C. Expiration settings define how long access is granted, not how it is approved.
  • D. Guest user self-service relates to how guest users request access, not the approval process itself.

Multi-stage Approval

A feature in Microsoft Entra entitlement management policies that requires multiple distinct approvals for an access request to be granted.

  • Enhances security for sensitive resources.
  • Allows different approvers or groups at each stage.
  • Configurable within access package policies.

Memory trick: Many managers make sure it's right, two locks for sensitive light.

More Implement access governance questions