Courseiva

AZ-305 Practice Question: Design identity, governance, and monitoring solutions

A company uses Microsoft Entra ID (Microsoft Entra ID). They want to provide external business partners with access to an internal application. The access must be time-limited to 60 days, approved by a manager within the partner company, and automatically expire. The company also needs to generate reports of who has access. Which Microsoft Entra ID feature should they implement?

⚠ Common exam trap

Watch out — candidates often confuse Identity Governance with Privileged Identity Management (PIM) — PIM is for privileged roles, not for managing external partner access with time-limited, approved, and expiring access packages.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Microsoft Entra ID B2B collaboration with entitlement management

Microsoft Entra ID B2B collaboration with entitlement management allows you to invite external users from partner companies and manage their access through access packages. These packages can enforce time-limited access (e.g., 60 days), require approval from the partner's manager, and automatically expire. Entitlement management also provides built-in reporting to track who has access, meeting all stated requirements.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Microsoft Entra ID B2B collaboration with entitlement management

    Why this is correct

    Microsoft Entra ID B2B collaboration with entitlement management is correct because it specifically addresses granting external partners access to internal applications with time-bound, approval-based access packages. Entitlement management enables admins to create access packages that include multiple assignments, require approvals, set expiration dates, and provide access reviews, while B2B collaboration supplies the necessary identity lifecycle and authentication for external users. This combination delivers governed, auditable, and expiring access for 10 partners, aligning with the requirement for approval and time-bound access.

  • ✗

    Microsoft Entra ID B2C custom policies

    Why it's wrong here

    Microsoft Entra ID B2C custom policies are designed for customer-facing identity and access management, not for partner access to internal enterprise applications. B2C is built to handle consumer identities (e.g., social or local accounts) with customizable sign-up and sign-in experiences, but it does not integrate with access packages, approval workflows, or entitlement management. Because the requirement is about granting external business partners access to corporate apps, B2C's customer authentication model does not provide the necessary governance or time-bound access controls.

  • ✗

    Microsoft Entra ID Identity Governance with Privileged Identity Management (PIM)

    Why it's wrong here

    Microsoft Entra ID Identity Governance with Privileged Identity Management (PIM) is focused on managing and governing privileged administrative roles, such as Global Administrator or Application Administrator, not on granting general external user access to applications. While PIM provides just-in-time access, approvals, and time-bound assignments, it applies to role activations for elevated permissions in Entra ID, not to end-user application access. Therefore, PIM is not a viable solution for managing partner access to internal apps, as it lacks the access package and assignment capabilities needed for external collaboration.

  • ✗

    Microsoft Entra ID Conditional Access with session controls

    Why it's wrong here

    Microsoft Entra ID Conditional Access with session controls is an access control layer that evaluates conditions—such as user location, device compliance, or risk—and can enforce session policies like sign-in frequency or app restrictions. It does not include approval workflows, access packages, or lifecycle management for external users, and it cannot independently provide time-bound access or expiration for guest accounts. While Conditional Access could be used alongside an access package solution to enforce security policies, it is not designed to manage the approval and expiration requirements described in the scenario.

About these practice questions

This AZ-305 question is part of Courseiva's 795-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AZ-305 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-305 exam.