AZ-305 Practice Question: Design identity, governance, and monitoring solutions
A company uses Microsoft Entra ID (Microsoft Entra ID). They need to grant external partners access to an internal application for a limited time (30 days). The access request must be approved by a manager from the partner's organization, and after 30 days the access must automatically expire. They also want to send email reminders 7 days before expiration. Which Microsoft Entra ID feature should they use?
⚠ Common exam trap
Many exam-takers confuse PIM (which handles privileged role activation for internal admins) with Entitlement Management (which handles external partner access with full lifecycle governance), or assume B2B with Conditional Access alone can enforce time limits and reminders without the access package framework.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Microsoft Entra ID Entitlement Management
Microsoft Entra ID Entitlement Management enables organizations to manage access for external partners through access packages, which can include time-limited assignments, approval workflows (including manager approval from the partner's organization), and automatic expiration with email notifications. This directly meets the requirement for a 30-day access period with manager approval and 7-day reminder emails.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Microsoft Entra ID Identity Protection
Why it's wrong here
Microsoft Entra ID Identity Protection is a risk-detection engine that analyzes signals such as impossible travel, anonymous IP addresses, leaked credentials, and sign-ins from malware-linked devices to generate risk scores and trigger conditional access controls like MFA prompts or blocked sign-ins. However, it focuses exclusively on detecting and responding to compromised identities or risky behavior, not on governing who can access which applications for how long. It contains no concept of access packages, approval workflows, or automatic expiration for external partner assignments, so it cannot satisfy the requirement for time-limited external access with approvals.
- ✗
Microsoft Entra ID Privileged Identity Management (PIM)
Why it's wrong here
Microsoft Entra ID Privileged Identity Management (PIM) provides just-in-time and time-bound activation for highly privileged directory roles such as Global Administrator, Privileged Role Administrator, and Azure resource roles, complete with activation approvals, audit logs, and access reviews. Its core purpose is managing and securing privileged administrative access within the organization, not granting external partners access to business applications through an approval-and-expiration lifecycle. While a guest could theoretically be assigned a role via PIM, PIM does not offer a self-service request portal for partners to request access to application packages, nor does it provide per-entitlement expiration for non-privileged application access.
- ✓
Microsoft Entra ID Entitlement Management
Why this is correct
Microsoft Entra ID Entitlement Management is the correct choice because it is specifically built to govern access to applications, groups, and SharePoint sites through access packages. Administrators can create access packages that include a partner's required app, define an approval workflow, and set an expiration date for each assignment, at which point access is automatically removed with optional reminder emails before expiry. External users from connected organizations can request access through the Microsoft Entra myaccess portal, and access reviews ensure continued need, making this the only option among those listed that fully supports time-limited external access with approvals and lifecycle governance.
- ✗
Microsoft Entra ID B2B with Conditional Access
Why it's wrong here
Microsoft Entra ID B2B allows external users to be invited, but it does not provide built-in approval workflows or automatic time-bound access with expiration reminders. Conditional Access enforces policies but does not manage the lifecycle of external access.
Go deeper
Related to this question
About these practice questions
This AZ-305 question is part of Courseiva's 795-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-305 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-305 exam.