AZ-305 Practice Question: Design identity, governance, and monitoring solutions
Which THREE capabilities are provided by Microsoft Entra ID Identity Governance? (Select THREE.)
⚠ Common exam trap
Many exam-takers confuse Conditional Access and Identity Protection (which are security-focused features) with Identity Governance capabilities, but the exam specifically tests that governance includes entitlement management, access reviews, and PIM as the three core pillars.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Entitlement management
Microsoft Entra ID Identity Governance is a suite of capabilities designed to help organizations manage and govern access to resources. Entitlement management (A) enables the creation of access packages to automate access requests, approvals, and assignments. Access reviews (B) allow periodic recertification of group memberships and application access to ensure only the right users have access. Privileged Identity Management (C) provides just-in-time privileged access and role activation workflows for Microsoft Entra ID roles and Azure resources, directly supporting governance of elevated access.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Entitlement management
Why this is correct
Entitlement management is a core identity governance capability in Microsoft Entra ID that operationalizes access lifecycle management through access packages. These packages bundle resources such as groups, apps, and SharePoint sites, and enforce policies for request, approval, and automatic expiration or removal of access. This enables self-service access requests while ensuring that assignments are time-bound and auditable, directly satisfying least-privilege and compliance requirements.
- ✓
Access reviews
Why this is correct
Access reviews provide a formal recertification mechanism for existing access assignments, allowing designated reviewers to periodically validate group memberships and application entitlements. By automating review cycles and requiring explicit approval or removal decisions, it prevents ‘permission creep’ and helps meet regulatory audit standards. This is a distinct governance capability because it focuses on the ongoing validation of access rights, not on granting initial access or enforcing real-time security controls.
- ✓
Privileged Identity Management
Why this is correct
Privileged Identity Management (PIM) governs privileged roles through just-in-time activation, enabling users to obtain elevated permissions only for a limited, authorized window. It enforces activation rules such as approval workflows, multi-factor authentication, and justification, while also generating detailed audit logs for every elevation event. This is a governance function because it controls the lifecycle of high-risk access rather than providing continuous standing privileges, making it essential for securing administrative accounts.
- ✗
Conditional Access
Why it's wrong here
Conditional Access is a real-time access control engine that evaluates signals like user location, device compliance, risk level, and application sensitivity to decide whether to allow or block authentication. Although it is a critical security feature of Microsoft Entra ID, it does not manage the lifecycle of access assignments, such as requesting, approving, reviewing, or removing entitlements. Since identity governance is specifically about structured processes for managing access over time, Conditional Access does not belong to the set of three governance capabilities.
- ✗
Identity Protection
Why it's wrong here
Identity Protection uses algorithmic risk detection to identify compromised accounts and suspicious sign-in behaviors, triggering policies that require password changes or block access. It is concerned with the security of authentication events, not with the governance of access rights themselves. Governance capabilities like entitlement management, access reviews, and PIM handle who should get access, why, and for how long—whereas Identity Protection reacts to potential threats, making it a security tool rather than an identity governance feature.
Go deeper
Related to this question
About these practice questions
One of 795 original AZ-305 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-305 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-305 exam.