Microsoft Certified: Identity and Access Administrator AssociateImplement access governanceEasy
A retail company uses Microsoft Entra ID and has implemented entitlement management. They have an access package for their 'Marketing Team Resources' which includes access to several SharePoint sites and an internal application. The company wants to ensure that members of the Marketing Team automatically lose access to these resources if they leave the 'Marketing Team' Microsoft Entra security group. Which entitlement management lifecycle setting should be configured to achieve this?
- ARemove access when user leaves the source directory group
- BRemove access when user leaves the connected organization
- CExpiration date for assignments
- DRemove access when user's requestor-defined attribute changes
Show answer & explanationAnswer & explanation
Correct answer: A. Remove access when user leaves the source directory group
The 'Remove access when user leaves the source directory group' lifecycle setting ensures that if a user is assigned an access package based on their membership in a specific group (the source directory group), their access is automatically revoked when they are removed from that group.
Why the other options are wrong
- B. This applies to external users leaving a connected organization, not internal users leaving a group.
- C. Expiration date removes access after a fixed duration, not based on group membership changes.
- D. This is based on dynamic attributes, not direct group membership changes for access package assignments.
Entitlement Management Lifecycle Settings
Configurations within entitlement management that define how access package assignments are managed over time, including expiration and automatic removal based on conditions.
- Automates access removal.
- Can be based on time or group membership.
- Ensures least privilege over time.
Memory trick: Lifecycle Manages Access Automatically.