Courseiva

AZ-305 Practice Question: Design identity, governance, and monitoring solutions

A company uses Microsoft Entra ID (Microsoft Entra ID). They need to automatically remove guest users who have not signed in for 60 days. Additionally, they must generate a report of all guest access for auditors. Which Microsoft Entra ID feature should they implement?

⚠ Common exam trap

Watch out — candidates often confuse Entitlement Management (which handles access packages) with Access Reviews (which handles periodic attestation and automated removal), missing that only Access Reviews directly support inactivity-based removal and audit reporting.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Access Reviews

Access Reviews in Microsoft Entra ID allow administrators to create recurring reviews that automatically remove guest users who have not signed in within a specified period (e.g., 60 days) by configuring the 'Inactive users (in days)' setting. Additionally, Access Reviews generate a detailed report of all guest access decisions, which can be exported for auditors, meeting both requirements directly.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Access Reviews

    Why this is correct

    Microsoft Entra Access Reviews are the right answer because they provide a recurring, attestation-based workflow to certify or deny access for users. You can scope a review to 'Guest users only' and set an inactivity threshold based on sign-in activity, so guests who haven't signed in by a certain date are automatically flagged and removed. When the review completes, you can auto-apply the results to remove denied guests from groups, applications, and directory roles, and every action is written to the Entra audit log for compliance evidence.

  • ✗

    Entitlement Management

    Why it's wrong here

    Entitlement Management is focused on the provisioning side of governance: it creates access packages that bundle roles and permissions for self-service requests, approval flows, and time-limited assignments. While access packages do support expiration policies that can automatically remove assignments at end of a duration, this removal is tied to the assignment lifecycle, not to actual user inactivity or large-scale guest attestation. Entitlement Management has no built-in capability to scan all guests, analyze their last sign-in date, and drive a multi-step review decision; that master-data-driven inactivity review is unique to Access Reviews.

  • ✗

    Identity Protection

    Why it's wrong here

    Identity Protection is a risk-detection engine that analyzes sign-in behaviors, such as impossible travel, password spray, anonymous IP addresses, and leaked credentials, and then maps those signals to user risk or sign-in risk levels. It can trigger Conditional Access policies to require step-up authentication or to block a risky sign-in, but it works at the authentication event, not at the directory object or membership level. Identity Protection cannot identify guests who are simply inactive, cannot create an attestation report listing all guest access, and cannot remove a guest from groups or applications; it is an antifraud tool, not a lifecycle governance tool.

  • ✗

    Terms of Use

    Why it's wrong here

    Terms of Use (ToU) in Microsoft Entra lets administrators publish PDF-based consent documents that users must accept before they are allowed to access certain apps, usually enforced through Conditional Access. ToU simply records acceptance or non-acceptance in the audit logs; it has no concept of user activity, inactivity thresholds, or access expiration. If a guest never accepts the ToU, Conditional Access blocks their initial sign-in, but the guest object and any existing group memberships remain untouched indefinitely. ToU can never generate a report of inactive guests that can be acted upon, and it cannot remove users from resources, so it is not a lifecycle or attestation solution.

About these practice questions

This AZ-305 question is part of Courseiva's 795-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AZ-305 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-305 exam.