Microsoft 365 FundamentalsDescribe security, compliance, privacy, and trust in Microsoft 365Medium

A multinational corporation uses Microsoft 365 for its global operations. They have a strict policy that all user accounts must be automatically disabled after 90 days of inactivity to reduce security risks. Which Microsoft 365 identity protection capability provides this functionality?

  1. AAzure AD Connect
  2. BAzure AD Access Reviews
  3. CAzure AD Identity Protection
  4. DAzure AD Conditional Access
Show answer & explanation

Correct answer: B. Azure AD Access Reviews

Azure AD Access Reviews allow organizations to manage group memberships, access to enterprise applications, and roles, including automatically removing users who no longer need access or are inactive, which aligns with the requirement to disable inactive accounts.

Why the other options are wrong

  • A. Azure AD Connect synchronizes on-premises directories with Azure AD but doesn't manage inactivity-based account disabling.
  • C. Azure AD Identity Protection detects and remediates identity-based risks like compromised credentials, not inactivity-based account management.
  • D. Azure AD Conditional Access enforces policies based on conditions like location or device, but not directly for disabling inactive accounts.

Azure AD Access Reviews

A capability in Azure Active Directory that enables organizations to efficiently manage group memberships, access to enterprise applications, and role assignments, ensuring appropriate access over time.

  • Automates review processes for access.
  • Helps remove stale or unnecessary access.
  • Can be configured for user inactivity.

Memory trick: Reviewing access is like checking attendance – who's still here and who's gone?

More Describe security, compliance, privacy, and trust in Microsoft 365 questions