Courseiva

AZ-305 Practice Question: Design identity, governance, and monitoring solutions

A multinational company uses Microsoft Entra ID with a custom domain. They need to implement a governance strategy for Microsoft 365 groups, ensuring that group expiration policies are enforced and that group owners receive renewal notifications. What should you configure?

⚠ Common exam trap

Candidates often confuse Microsoft Purview's data lifecycle management with group lifecycle management, or mistakenly think Intune or Sentinel can handle group expiration policies, when in fact only Microsoft Entra ID's group settings provide the specific expiration and renewal notification functionality.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Microsoft Entra ID – Group settings (Expiration policy)

Microsoft Entra ID's Group settings include an expiration policy specifically designed to enforce lifecycle management for Microsoft 365 groups. This policy allows administrators to set a group expiration period (e.g., 180, 365 days) and automatically sends renewal notification emails to group owners before expiration, enabling them to renew the group if needed. This directly meets the requirement for enforcing group expiration and renewal notifications.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Microsoft Purview compliance portal – Data Lifecycle Management

    Why it's wrong here

    Microsoft Purview compliance portal – Data Lifecycle Management is designed to govern the retention and deletion of organizational data across Microsoft 365 services like SharePoint, OneDrive, and Exchange. It applies retention labels and policies to files and messages, but it has no mechanism for configuring group expiration or automatically deactivating Microsoft 365 groups. Therefore, while it manages the lifecycle of data content, it does not manage the lifecycle of the groups that contain that data, making it irrelevant to the requirement for group expiration.

  • ✓

    Microsoft Entra ID – Group settings (Expiration policy)

    Why this is correct

    Microsoft Entra ID – Group settings (Expiration policy) is the correct administrative location because Microsoft 365 group expiration is a tenant-level policy that is enforced by Microsoft Entra ID. In the Entra admin center, you navigate to Identity > Groups > Group settings and configure the 'Expiration policy' to set a fixed validity period (e.g., 180 or 365 days) for all Microsoft 365 groups, with the option to send renewal notifications to group owners. This policy directly controls group lifecycle by automatically expiring inactive groups, and it can also be managed via Microsoft Graph or PowerShell (New-UnifiedGroupExpirationPolicy). This is the native mechanism provided by Microsoft for this exact scenario.

  • ✗

    Microsoft Intune – Device compliance policies

    Why it's wrong here

    Microsoft Intune – Device compliance policies are used to enforce security and compliance requirements on managed devices, such as requiring a minimum OS version, setting a device PIN, or detecting jailbroken/rooted devices. These policies are evaluated against devices and their results feed into conditional access and zero-trust decisions. Intune operates at the device layer and has no visibility or control over the existence, provisioning, or expiration of Microsoft 365 groups. Thus, it cannot be used to configure group expiration policies, making it an incorrect answer for this requirement.

  • ✗

    Microsoft Sentinel – Analytics rules

    Why it's wrong here

    Microsoft Sentinel – Analytics rules are part of a cloud-native SIEM and SOAR solution that collects security telemetry from various sources to detect and respond to threats. Analytics rules use KQL queries to generate alerts on suspicious activities such as anomalous sign-ins or potential data exfiltration. Sentinel is focused exclusively on security monitoring and incident response, not on administrative lifecycle management of Microsoft 365 groups. Configuring group expiration is an identity governance task, not a security analytics task, so Sentinel is not a valid place to set up group expiration policies.

About these practice questions

This AZ-305 question is part of Courseiva's 795-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AZ-305 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-305 exam.