AZ-305 Practice Question: Design identity, governance, and monitoring solutions
A company uses Microsoft Entra ID (Microsoft Entra ID). They need to grant temporary administrative roles to users for specific tasks. The process must require approval from a designated approver, and the access must automatically expire after a defined period. The company also needs audit logs of all role assignments and activations. Which Microsoft Entra ID feature should they implement?
⚠ Common exam trap
Many exam-takers confuse Entitlement Management (which handles access packages and reviews) with PIM (which specifically handles privileged role activation and approval workflows), leading candidates to pick Option B for its 'approval' and 'expiration' keywords.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Microsoft Entra ID Privileged Identity Management (PIM)
Microsoft Entra ID Privileged Identity Management (PIM) is the correct choice because it provides just-in-time (JIT) privileged access, requiring approval from designated approvers and automatically expiring role assignments after a defined duration. PIM also generates detailed audit logs for all role activations and assignments, meeting the compliance and monitoring requirements.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Microsoft Entra ID Privileged Identity Management (PIM)
Why this is correct
PIM is the correct choice because it provides just-in-time, time-bound administrative role activation (eligible vs. active) for Microsoft Entra ID roles and Azure resources. It supports approval workflows, MFA enforcement on activation, risk-based conditional access policies during activation, automatic expiration, and comprehensive audit logs, making it the dedicated tool for granting temporary privileged access. Unlike the other options, PIM directly addresses role governance and removes the need for standing admin privileges.
- ✗
Microsoft Entra ID Entitlement Management
Why it's wrong here
Entitlement Management creates access packages that govern a user's membership in groups, access to apps, and access to SharePoint sites, with approval requests and periodic access reviews. It can issue time-limited assignments, but it does so for business resources, not for administrative role activation like the 'Global Administrator' or 'Privileged Role Administrator' roles. Because the requirement is specifically to manage temporary entitlement to Microsoft Entra ID administrative roles, Entitlement Management cannot perform the binary eligible-to-active role activation and does not provide the dedicated role activation approval workflow that PIM offers.
- ✗
Microsoft Entra ID Identity Protection
Why it's wrong here
Identity Protection is a risk-detection and automated response engine that evaluates user and sign-in behavior, issuing risk levels (low/medium/high) and triggering conditional policies such as requiring password change or blocking authentication. It does not contain any mechanism for granting or activating administrative roles, nor does it support time-bound role assignments or approver workflows. While it can increase security around privileged access, it is not a privileged access management (PAM) solution and therefore cannot fulfill the need to assign temporary admin roles.
- ✗
Microsoft Entra ID Conditional Access
Why it's wrong here
Conditional Access is a policy engine that enforces control decisions (allow/deny, require MFA, accept use terms, or block access) on access to applications and resources based on signals like device compliance, location, and risk. It has no concept of role assignment, eligibility, or activation periods, and it cannot automatically grant a user a temporary administrative role with an approval chain. It could be used as part of a PIM activation policy (e.g., requiring MFA during role activation), but it is not a replacement for PIM’s role governance capabilities.
Go deeper
Related to this question
About these practice questions
This AZ-305 question is part of Courseiva's 795-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-305 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-305 exam.