Courseiva

AZ-305 Practice Question: Design identity, governance, and monitoring solutions

You are designing an identity lifecycle management solution for a multinational company. Employees frequently change departments, and you need to automate the assignment and removal of application access based on their current department. Which THREE Microsoft Entra features should you use?

⚠ Common exam trap

Candidates often confuse Privileged Identity Management (PIM) with lifecycle management—PIM handles temporary elevation for admin roles, not the ongoing assignment of application access based on user attribute changes.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Dynamic membership groups

Dynamic membership groups (A) are correct because they automatically add or remove users based on attribute values like 'department'. When an employee changes departments, their department attribute is updated, and the group membership is recalculated, granting or revoking access to applications assigned to that group. This is the core mechanism for automating access changes based on user attributes.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Dynamic membership groups

    Why this is correct

    Dynamic membership groups in Microsoft Entra ID automatically add and remove user accounts based on rule expressions evaluated against attributes like department, jobTitle, or country. Because membership is recalculated whenever an attribute changes or a user signs in, access to the group's linked applications is granted or revoked immediately without manual intervention. For an identity lifecycle solution centered on automating access based on organizational attributes, dynamic groups are the most direct choice.

  • Microsoft Entra Privileged Identity Management

    Why it's wrong here

    Microsoft Entra Privileged Identity Management (PIM) provides just-in-time, time-bound activation of privileged roles such as Global Administrator or Application Administrator, along with access reviews and alerts for those roles. It is not designed to manage the general application-access lifecycle of regular, non-privileged users. While PIM is an important security control in Entra ID, it does not fulfill the requirement to automatically add or remove standard employee access based on lifecycle changes.

  • Microsoft Entra access reviews

    Why this is correct

    Microsoft Entra access reviews let you create recurring attestation campaigns in which designated reviewers confirm whether each user still needs access to a group, application, or role. When the review finishes, decisions can be applied automatically to remove stale or unauthorized access. This supports identity lifecycle by ensuring departing users, role changes, or unused permissions do not linger, but it is a periodic, reviewer-driven process rather than an immediate, attribute-based rule, so it is not the primary mechanism for automatic lifecycle-driven membership.

  • Microsoft Entra entitlement management

    Why this is correct

    Microsoft Entra entitlement management enables you to bundle resources (groups, apps, and SharePoint sites) into access packages that enforce policies for request, approval, duration, and expiration. It automates assignment, periodic renewal, and removal of entitlements, making it a powerful tool for time-bound or request-based access. However, the described scenario centers on continuous, attribute-driven membership updates (for example, department changes), which dynamic membership groups handle more directly; entitlement management complements this by governing who can request or be assigned those packages.

  • Microsoft Entra self-service password reset

    Why it's wrong here

    Microsoft Entra self-service password reset (SSPR) allows users to reset or unlock their own passwords securely without contacting IT. It addresses credential management and authentication, not the lifecycle of application access, group membership, or resource entitlements. Since the design objective is to automate granting and revoking access as a user's attributes or roles change, SSPR is unrelated to this identity lifecycle requirement.

About these practice questions

One of 212 original AZ-305 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AZ-305 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-305 exam.