Courseiva

AZ-305 Practice Question: Design identity, governance, and monitoring solutions

A company has Microsoft Entra ID Premium P2 licenses and wants to ensure that privileged roles (e.g., Global Administrator) are only activated when needed and with approval. They also need to regularly review who has access to these roles. Which combination of features should they use?

⚠ Common exam trap

Many exam-takers confuse Identity Protection (risk-based detection) with PIM (role activation and governance), leading them to select options that include Identity Protection instead of PIM for privileged role management.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Privileged Identity Management (PIM) and Microsoft Entra ID Access Reviews

Privileged Identity Management (PIM) provides just-in-time (JIT) activation of privileged roles with approval workflows, meeting the requirement for activation only when needed and with approval. Microsoft Entra ID Access Reviews then enable recurring certification of role assignments, ensuring that access is regularly reviewed and stale or inappropriate assignments are removed. Together, they form the correct combination for managing and governing privileged roles.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Privileged Identity Management (PIM) and Microsoft Entra ID Access Reviews

    Why this is correct

    PIM is the correct core service because it provides just-in-time, time-bound activation of privileged Microsoft Entra roles with approval workflows and audit trails, which directly satisfies the requirement to ensure privileged access is controlled. Access Reviews complements PIM by enabling recurring recertification of role assignments, so administrators can automatically remove or keep access based on attestation. Together they fulfill both activation governance and periodic review, making this combination the only one that fully addresses the stated requirement.

  • ✗

    Identity Protection and Conditional Access

    Why it's wrong here

    Identity Protection detects risks like leaked credentials and risky sign-ins, while Conditional Access enforces policies such as MFA or blocking access based on that risk. Neither service has any capability to manage privileged role activation, approval workflows, or time-bound assignments. Conditional Access operates at the authentication and session layer, not at the authorization layer for Entra roles, so this combination cannot ensure controlled privileged role usage.

  • ✗

    Entitlement Management and Conditional Access

    Why it's wrong here

    Entitlement Management manages access packages for applications, groups, and SharePoint sites, enabling self-service requests and approvals for those resources, but it does not govern Microsoft Entra ID privileged roles. Conditional Access only enforces sign-in policies and does not perform access reviews or role activation. This pairing addresses resource access governance, not the privileged role lifecycle that the requirement explicitly targets.

  • ✗

    Microsoft Entra ID Access Reviews and Identity Protection

    Why it's wrong here

    Access Reviews alone can review and recertify existing role assignments, but without PIM, there is no mechanism for just-in-time activation or approval for elevating into privileged roles. Identity Protection focuses on identity risk from sign-in behavior, not on delegated privileged role administration or access recertification. Therefore this combination fails to provide the required controlled activation workflow, making it an incomplete solution.

About these practice questions

Courseiva writes every AZ-305 question from scratch — 795 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AZ-305 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-305 exam.