Microsoft Certified: Identity and Access Administrator AssociateImplement an identity management solutionEasy
A company uses Azure AD for identity management. They have several guest users from partner organizations who regularly access specific SharePoint Online sites. The security team mandates that these guest users' access rights must be periodically reviewed and confirmed by the site owners. Which Azure AD feature should be used to automate this process?
- AAzure AD Conditional Access policies
- BAzure AD Identity Protection
- CAzure AD B2B Direct Connect
- DAzure AD Access Reviews
Show answer & explanationAnswer & explanation
Correct answer: D. Azure AD Access Reviews
Azure AD Access Reviews allow organizations to efficiently manage group memberships, access to enterprise applications, and roles, ensuring that only necessary access is maintained. It's ideal for periodic review of guest user access.
Why the other options are wrong
- A. Conditional Access policies control *how* and *when* users access resources, not *who* should have access.
- B. Identity Protection focuses on detecting and remediating identity-based risks, not access re-certification.
- C. B2B Direct Connect enables seamless collaboration but doesn't provide access review capabilities.
Azure AD Access Reviews
A feature in Azure AD Identity Governance that enables organizations to efficiently manage group memberships, access to enterprise applications, and role assignments. It helps ensure that only necessary access is maintained.
- Automates periodic review of access rights.
- Can be configured for groups, applications, or roles.
- Reviewers can approve, deny, or recommend access.
Memory trick: Guest access needs a gatekeeper, not just a guest list.