Microsoft Certified: Identity and Access Administrator AssociateImplement access governanceEasy
A company uses Microsoft Entra ID (formerly Azure Active Directory) and has implemented entitlement management to control access to various resources. They have a critical application that requires highly sensitive data. You need to ensure that specific users can request access to this application, and their requests are automatically approved if they meet certain criteria, without requiring manual intervention from a manager or resource owner. Which entitlement management setting should you configure for the access package policy?
- AAllow users to request access with justification
- BRequire access reviews for assignments
- CRequire approval from a designated approver
- DEnable automatic request approval if specific conditions are met
Show answer & explanationAnswer & explanation
Correct answer: D. Enable automatic request approval if specific conditions are met
Automatic request approval, based on specific conditions, allows for streamlined access provisioning without manual intervention, which aligns with the requirement for automatic approval if criteria are met.
Why the other options are wrong
- A. While justification can be required, it does not enable automatic approval and still implies a review process.
- B. Access reviews are for re-validating existing access, not for initial request approval.
- C. This option requires manual intervention, which contradicts the requirement for automatic approval.
Automatic Request Approval (Entitlement Management)
A feature in Entitlement Management that allows access requests to be automatically approved if the requesting user meets predefined conditions within the access package policy.
- Eliminates manual approval steps for compliant requests.
- Conditions can include department, user attributes, or group membership.
- Streamlines access provisioning for well-defined scenarios.
Memory trick: Entitlement policies: conditions grant keys automatically.