Microsoft Certified: Identity and Access Administrator AssociateImplement an identity management solutionMedium
A company wants to ensure that all guest user accounts in their Azure AD tenant are regularly reviewed to confirm their continued need for access. They need to automate this review process and involve the guest users' sponsors in the approval decisions. Which Azure AD Identity Governance feature should be used?
- AAccess reviews
- BPrivileged Identity Management (PIM)
- CEntitlement management
- DTerms of use
Show answer & explanationAnswer & explanation
Correct answer: A. Access reviews
Azure AD access reviews enable organizations to efficiently manage group memberships, access to enterprise applications, and role assignments by automating the process of reviewing and certifying user access on a recurring basis, often involving resource owners or sponsors.
Why the other options are wrong
- B. Privileged Identity Management (PIM) focuses on managing, controlling, and monitoring access to important resources, specifically for privileged roles, not general guest user access reviews.
- C. Entitlement management helps organize resources into access packages and define policies for requesting and approving access, but access reviews are for periodic re-certification of existing access.
- D. Terms of use allow organizations to present information to users before they access resources, but it doesn't automate the review of existing access.
Azure AD Access Reviews
An Azure AD Identity Governance feature that enables organizations to manage group memberships, access to enterprise applications, and role assignments by automating the process of reviewing and certifying user access.
- Automates recurring access reviews.
- Reviewers can be group owners, managers, or self-review.
- Helps enforce least privilege and compliance.
Memory trick: Review access, renew trust.