AZ-305 Practice Question: Design identity, governance, and monitoring solutions
You are designing identity governance for a company that uses Microsoft Entra ID. The company wants to grant external partners access to an internal application for 90 days. After 90 days, access must be automatically removed. Additionally, the application requires that users have multi-factor authentication (MFA) and a compliant device. You need to design a solution that meets these requirements with minimal administrative effort. What should you do?
⚠ Common exam trap
It's easy for candidates to confuse Privileged Identity Management (PIM) with entitlement management, thinking PIM's time-limited role activation can be applied to application access, but PIM is for Microsoft Entra ID roles and Azure resource roles, not for granting external user access to applications with conditional access enforcement.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create an access package in Microsoft Entra entitlement management with a 90-day policy and conditional access policies for MFA and device compliance.
Microsoft Entra entitlement management allows you to create an access package that automatically grants external partners access to the application for exactly 90 days, after which access is automatically removed via an expiration policy. Additionally, you can enforce multi-factor authentication (MFA) and device compliance by configuring conditional access policies that are applied to the access package, meeting all requirements with minimal administrative effort through automation.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Create an access package in Microsoft Entra entitlement management with a 90-day policy and conditional access policies for MFA and device compliance.
Why this is correct
An access package in Microsoft Entra entitlement management is the correct approach because it creates a time-boxed assignment with a 90-day access policy that triggers automatic expiration and can require access reviews. When combined with conditional access policies enforcing MFA and device compliance, it ensures that only compliant, authenticated users can gain access, and because the assignment lifecycle is managed by Entra Identity Governance, it removes the need for manual cleanup. The access package also supports per-assignment expiration that applies to guest and internal users alike.
- ✗
Manually create guest user accounts, assign app, and set calendar reminder to delete after 90 days.
Why it's wrong here
Manually creating guest accounts and relying on a calendar reminder to delete them after the 90-day window is not a governance control—it depends on an individual remembering to take action, which is error-prone and leaves orphaned accounts if missed. This approach lacks automated lifecycle management, access reviews, and audit trails tied to the original policy, so it cannot enforce consistent revocation across the organization. In a real-world environment, manual entries also risk breaking compliance with least-privilege principles because the account remains active until someone manually removes it.
- ✗
Create a dynamic group in Microsoft Entra ID that includes partners and assign the app; use a scheduled script to remove membership after 90 days.
Why it's wrong here
A dynamic group in Microsoft Entra ID includes partners based on an attribute rule, but dynamic groups cannot natively enforce a time-limited access duration because membership is continuously re-evaluated against the rule—once user attributes remain unchanged, the user stays in the group. Adding a scheduled script to remove membership after 90 days fights the dynamic group engine: if the user still matches the rule, the group will automatically re-add them on the next evaluation, making the script ineffective. Even if you change the rule to exclude them, that becomes a manual rule change that does not scale or provide per-access-package expiry visibility.
- ✗
Use Microsoft Entra Privileged Identity Management to grant just-in-time access for 90 days.
Why it's wrong here
Microsoft Entra Privileged Identity Management (PIM) is designed to provide just-in-time access to privileged roles such as Global Administrator, Security Administrator, or Azure resource roles—not to grant a general business application to external partners. While PIM can provide time-limited access, it is scoped to role activation, not to application assignments, and it would require making users eligible for a role that grants access to that app, which is an incorrect and insecure pattern. Additionally, PIM does not automatically enforce MFA or device compliance as a condition of the application access itself; it applies to role activation.
Go deeper
Related to this question
About these practice questions
This AZ-305 question is part of Courseiva's 795-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-305 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-305 exam.