AZ-305 Practice Question: Design identity, governance, and monitoring solutions
A company uses Microsoft Entra ID (Microsoft Entra ID). They need to allow external business partners to request access to a specific application. The access must be time-limited and require approval from the partner's manager. Additionally, access must automatically expire after the defined period. Which Microsoft Entra ID feature should they use?
⚠ Common exam trap
A common mix-up: candidates confuse Entitlement Management with PIM because both involve time-limited access, but PIM is strictly for privileged roles within the organization, not for external partner application access with manager approval.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Microsoft Entra ID Entitlement Management
Microsoft Entra ID Entitlement Management enables organizations to manage access for external business partners through access packages. These packages can enforce time-limited access, require manager approval, and automatically expire access after a defined period, directly meeting all the stated requirements.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Microsoft Entra ID Privileged Identity Management (PIM)
Why it's wrong here
Microsoft Entra ID Privileged Identity Management (PIM) is designed for just-in-time activation and time-bound assignments of highly privileged administrative roles, such as Global Administrator or Application Administrator, for internal user identities. It does not provide capabilities for external users to request access to line-of-business applications, nor does it include policy-driven approval workflows for app access requests or automatic removal of assignments based on application-specific access package policies. The requirement here is about granting and governing external access to applications, which is outside PIM's scope.
- ✓
Microsoft Entra ID Entitlement Management
Why this is correct
Microsoft Entra ID Entitlement Management is the correct solution because it is a feature of Microsoft Entra ID Identity Governance that lets administrators create access packages, which are bundles of resources such as groups, applications, and SharePoint sites. These access packages can be made available to external users via connected organizations, with customizable request policies that enforce approval workflows and define assignment duration—including automatic expiration and removal of access when the assignment ends. This directly matches the need to grant controlled, time-limited access to applications for external identities, while also supporting recurring access reviews as a complementary control.
- ✗
Microsoft Entra ID Identity Protection
Why it's wrong here
Microsoft Entra ID Identity Protection focuses on detecting potential vulnerabilities and risk events affecting identities, such as leaked credentials, impossible travel, or risky sign-in behavior, and automating conditional access responses to those risks. It does not provide an end-user-facing request mechanism, nor does it support catalogs of resources or scheduled expiration of access assignments for external users. Therefore, while it is important for security monitoring, it cannot fulfill the requirement for managing external access to applications with approval and lifecycle controls.
- ✗
Microsoft Entra ID Access Reviews
Why it's wrong here
Microsoft Entra ID Access Reviews are used to perform periodic recertification of existing access assignments by asking owners to confirm whether users still need their access, after which stale access can be removed. However, Access Reviews do not handle the initial request phase, meaning external users cannot submit a request, and they do not enforce automatic expiration based on a predefined time limit—access remains until a reviewer decides to remove it. In this scenario, you need a solution that both grants external access after approval and automatically expires it, which is not provided by Access Reviews alone.
Go deeper
Related to this question
About these practice questions
Courseiva writes every AZ-305 question from scratch — 795 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-305 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-305 exam.