Courseiva

AZ-305 Practice Question: Design identity, governance, and monitoring solutions

Which TWO are benefits of using Microsoft Entra ID Governance? (Choose two.)

⚠ Common exam trap

Watch out — candidates often confuse the overlapping capabilities of Microsoft Entra ID, Entra ID Governance, and Privileged Identity Management (PIM), mistakenly attributing JIT access or SSO to governance when they belong to separate services within the Microsoft Entra portfolio.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Automate the deprovisioning of user accounts when an employee leaves the organization

Option A is correct because Microsoft Entra ID Governance includes lifecycle workflows that automate the joiner-mover-leaver process, including automatically disabling or deleting user accounts and revoking access when an employee leaves the organization. Option B is correct because entitlement management is a core capability of Entra ID Governance, providing access packages, catalogs, and approval-based access request workflows so users can request and be granted time-bound access. Option C is not correct because just-in-time privileged access to Azure resources is delivered by Microsoft Entra Privileged Identity Management (PIM), which is a separate product from Entra ID Governance. Option D is not correct because single sign-on to SaaS applications is a core Microsoft Entra ID feature (via SAML/OIDC enterprise applications), not a specific benefit of Entra ID Governance. Option E is not correct because VPN connectivity for remote users is provided by Azure VPN Gateway or similar networking services, not by Entra ID Governance.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Automate the deprovisioning of user accounts when an employee leaves the organization

    Why this is correct

    Automating deprovisioning when an employee leaves is a core identity lifecycle workflow in Entra ID Governance. This workflow integrates with HR systems to trigger account and access removal in near real time, eliminating the risk of orphaned accounts and security breaches. It also generates audit logs for compliance, ensuring that departed staff cannot retain access to sensitive resources.

  • ✓

    Implement entitlement management for access request workflows

    Why this is correct

    Entitlement management enables controlled access requests through access packages and approval workflows. Administrators define policies that allow users to request access, with required approvers, time-bound assignments, and regular reviews. This centralizes access governance, ensures least privilege, and provides full auditability of who requested, approved, and received access.

  • ✗

    Enable just-in-time privileged access to Azure resources

    Why it's wrong here

    Just-in-time privileged access to Azure resources is a capability of Privileged Identity Management (PIM) rather than a core Entra ID Governance benefit. PIM allows time-bound elevation of roles, but the question's two primary governance benefits focus on identity lifecycle and entitlement management. Although PIM integrates with Entra ID, it belongs to the PIM service, not to governance's foundational capabilities.

  • ✗

    Provide single sign-on to all SaaS applications

    Why it's wrong here

    Single sign-on to all SaaS applications is an Entra ID authentication feature that uses protocols like SAML, OAuth 2.0, and OpenID Connect. It verifies a user's identity once and grants access to connected apps, but it does not manage the governance of who should have access or for how long. SSO is a prerequisite for governance, not a governance benefit itself.

  • ✗

    Provide VPN connectivity for remote users

    Why it's wrong here

    VPN connectivity for remote users is a network-level service, such as Azure Point-to-Site or Site-to-Site VPN, that establishes encrypted tunnels to corporate resources. Entra ID Governance operates at the identity layer, handling access requests, lifecycle workflows, and access reviews. It has no role in creating or managing VPN connections, which are infrastructure services.

About these practice questions

Courseiva writes every AZ-305 question from scratch — 795 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AZ-305 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-305 exam.