AZ-305 Practice Question: Design identity, governance, and monitoring solutions
Which TWO actions can be performed using Microsoft Entra ID Governance? (Choose two.)
⚠ Common exam trap
Candidates often confuse Entra ID Governance's access review capability (Option C) with a separate feature, but both B and C are correct; the question asks for two actions, and the trap is that some might think only one of these is valid, or they might incorrectly select A because synchronization is a common identity task, but it's not a governance action.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Manage access packages for internal and external users
Microsoft Entra ID Governance includes entitlement management, which allows administrators to create and manage access packages that bundle resources (like groups, apps, and SharePoint sites) and assign them to internal and external users. This enables automated lifecycle management of access, including expiration and renewal, making Option B correct.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Synchronize users from on-premises Active Directory
Why it's wrong here
Synchronizing users from on-premises Active Directory is a replication task performed by Microsoft Entra Connect or cloud sync, which copies identity objects (users, groups, passwords) into Microsoft Entra ID. While it is a prerequisite for enabling many identity scenarios, it does not enforce access policies, certify entitlements, or manage the access lifecycle. Governance is about arguably controlling who has what access after identities exist, not the act of ingesting those identities into the directory.
- ✓
Manage access packages for internal and external users
Why this is correct
Managing access packages is a flagship capability of Microsoft Entra ID Governance, delivered through Entitlement Management. It enables administrators to create catalogs of resources (groups, apps, sites), define request-and-approval workflows, set time-bound assignments, and handle automatic revocation. This feature is explicitly designed to govern access for both internal employees and external collaborators, ensuring access matches business need and is auditable.
- ✓
Perform access reviews of group memberships
Why this is correct
Performing access reviews of group memberships is another core Entra ID Governance feature. Access reviews allow administrators to invite group owners or other reviewers to periodically certify whether each member still needs access. The results can automatically remove non-approved users, which enforces least privilege and supports compliance with regulations like SOX or GDPR. This is a governance control that operates on existing membership, unlike syncing or provisioning, which are ingestion mechanisms.
- ✗
Configure network security group rules
Why it's wrong here
Configuring network security group (NSG) rules is an Azure networking function, not an identity governance task. NSGs contain security policies that allow or deny traffic to and from Azure resources based on source/destination IP addresses, ports, and protocols. These rules control at the network layer and have no bearing on user identities, roles, or access entitlements, so they fall entirely outside the scope of Microsoft Entra ID Governance.
- ✗
Deploy virtual machines in Azure
Why it's wrong here
Deploying virtual machines in Azure is a compute resource provisioning activity that creates infrastructure, not an identity governance operation. VM deployment involves selecting images, sizing, and network configuration, and it is performed via Azure Resource Manager, not Microsoft Entra ID. While those VMs might later be protected by identity controls, the act of deployment itself does not manage users, groups, or their access rights, and is unrelated to Entra ID Governance features.
Go deeper
Related to this question
About these practice questions
Courseiva writes every AZ-305 question from scratch — 795 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-305 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-305 exam.