AZ-305 Practice Question: Design identity, governance, and monitoring solutions
A multinational company uses Microsoft Entra ID. The company has regional IT teams that need to manage users and groups within their respective regions. Each region has a distinct set of users in specific organizational units. The company wants to assign the User Administrator role to regional IT staff, but limit their scope to only the users in their region. Which Microsoft Entra ID feature should they use?
⚠ Common exam trap
Many exam-takers confuse Administrative Units with Dynamic Groups, thinking that group-based membership scoping is equivalent to role-based administrative scoping, but Dynamic Groups only control group membership, not administrative permissions.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Administrative Units
Administrative Units in Microsoft Entra ID allow you to delegate administrative roles, such as User Administrator, to a specific subset of users and groups defined by organizational boundaries (e.g., region). By creating an Administrative Unit for each region and adding the regional users and groups to it, you can assign the User Administrator role scoped to that unit, ensuring regional IT staff can only manage their own region's identities.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Administrative Units
Why this is correct
Administrative Units are the correct approach because they partition a tenant's users, groups, and devices into explicit management boundaries. An administrator can assign a built-in or custom role such as User Administrator or Helpdesk Administrator scoped to a specific Administrative Unit, so regional IT staff see and manage only the objects in their local unit. This gives the desired delegated administration while preventing tenant-wide access.
- ✗
Dynamic Groups
Why it's wrong here
Dynamic Groups address automatic group membership, not delegation of authority. A rule like 'Department equals Sales' determines who is added or removed from a group, but the resulting group does not have any administrative permissions over other users. Dynamic Groups cannot be used to restrict what an administrator is allowed to manage, because group membership and administrative scope are separate concepts.
- ✗
Microsoft Entra ID B2B
Why it's wrong here
Microsoft Entra ID B2B collaboration is designed for external collaboration, enabling guest users from other organizations to sign in with their own identity and access specific applications. It does not delegate administrative authority over internal directory objects to regional IT teams. Even if B2B guest accounts were assigned a role, that is not the mechanism for creating limited IT management scopes; Administrative Units serve that purpose.
- ✗
Microsoft Entra ID Identity Protection
Why it's wrong here
Microsoft Entra ID Identity Protection is a security monitoring and response service that evaluates risk signals like impossible travel, leaked credentials, and anomalous sign-ins to trigger conditional policies or require multi-factor authentication. It is operational security telemetry and automation, not a way to segment administration by geography or organizational unit. Identity Protection runs tenant-wide, so rejecting it is appropriate for this delegation scenario.
Go deeper
Related to this question
About these practice questions
One of 212 original AZ-305 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-305 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-305 exam.