Microsoft Certified: Identity and Access Administrator AssociateImplement an identity management solutionMedium
A company uses Azure AD for identity management. They have several guest users from partner organizations who need access to specific applications. The security team wants to ensure that these guest users are automatically removed from Azure AD after 90 days of inactivity. Which feature should be configured to achieve this?
- AAzure AD Privileged Identity Management (PIM)
- BAzure AD Identity Protection policies
- CAzure AD Conditional Access policies
- DAzure AD Access Reviews
Show answer & explanationAnswer & explanation
Correct answer: D. Azure AD Access Reviews
Azure AD Access Reviews allow you to manage group memberships, application access, and role assignments for users, including guest users, by automating review cycles and actions like removal for inactive users.
Why the other options are wrong
- A. PIM manages just-in-time access for privileged roles, not general guest user lifecycle management.
- B. Identity Protection focuses on detecting and remediating identity-based risks, not managing inactivity for guest user cleanup.
- C. Conditional Access policies enforce access controls based on conditions at the time of sign-in, not for managing long-term inactivity.
Azure AD Access Reviews
A feature in Azure AD that enables organizations to manage group memberships, application access, and role assignments by automating review cycles.
- Helps ensure that only authorized users have access to resources.
- Can automate actions like removing inactive users or denying access.
- Supports reviewing access for internal users, guest users, and privileged roles.
Memory trick: Govern access: Review, Entitle, PIM, and Terms are key.