AZ-305 Practice Question: Design identity, governance, and monitoring solutions
A multinational company uses Microsoft Entra ID for identity. They need to grant external partners access to specific SharePoint Online sites. The access must be time-limited and require approval from a resource owner. Which Microsoft Entra ID feature should they use?
⚠ Common exam trap
A common mix-up: candidates confuse Entitlement Management (which handles external user access governance) with B2C (which is for customer-facing apps) or Conditional Access (which is a security policy layer, not a provisioning workflow).
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Microsoft Entra ID Entitlement Management.
Microsoft Entra ID Entitlement Management (A) is the correct feature because it enables organizations to manage external partner access to resources like SharePoint Online sites through access packages. These access packages can enforce time-limited access and require approval from designated resource owners, directly meeting the scenario's requirements.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Microsoft Entra ID Entitlement Management.
Why this is correct
Entitlement Management is an identity governance feature that lets administrators create access packages containing SharePoint Online sites, Teams, and other resources, and publish them to internal or external users. Policies within an access package define who can request access, who must approve, and when the access expires, enabling time-limited collaboration. For external partners, it supports Connected Organizations and identity providers including Google and Microsoft accounts, automatically removing access when the policy ends. This directly provides the request/approval/expiration workflow needed for the scenario.
- ✗
Microsoft Entra ID B2C.
Why it's wrong here
Entra ID B2C was built specifically for customer-facing applications, allowing users to authenticate with local accounts or social identity providers like Facebook and Google. It is a separate external identity service that runs in a dedicated B2C tenant, not the corporate tenant, and cannot issue tokens or entitlements that grant access to internal Microsoft 365 resources such as SharePoint Online. Because the goal is to administer partner access to your own Office 365 content, B2C's customer-centric scopes and tenant architecture are entirely the wrong fit, and it offers no access request or approval policies.
- ✗
Microsoft Entra ID Conditional Access.
Why it's wrong here
Conditional Access is a policy engine that evaluates real-time signals—such as user location, device compliance, sign-in risk, and application—and then grants or blocks authentication requests by enforcing controls like Multi-Factor Authentication. It does not contain any concept of a user initiating an access request, nor can it set an expiry date after which assigned permissions are automatically revoked. Even if a partner passes every CA policy, their role or group membership persists indefinitely unless another system explicitly removes it, so CA cannot alone deliver time-bound access. It is best used as a security overlay to protect the access Entitlement Management grants.
- ✗
Microsoft Entra ID Identity Protection.
Why it's wrong here
Identity Protection is a risk-detection layer that uses machine learning to flag risky users and sign-in events, then automatically takes remedial actions such as blocking the sign-in, forcing MFA, or prompting for password change. It performs continuous monitoring of credential compromises, but it has no capability to handle an access request, trigger an approval workflow, or assign a SharePoint Online site to an external user. Since it only reacts to authentication risk, it is orthogonal to the need for governing external resource access and would not solve the access request and expiration requirement.
Go deeper
Related to this question
About these practice questions
Courseiva writes every AZ-305 question from scratch — 795 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-305 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-305 exam.