AZ-305 Practice Question: Design identity, governance, and monitoring solutions
Your company has a Microsoft Entra ID tenant with 10,000 users. You need to design a monitoring solution to detect when users are assigned to high-privilege roles (e.g., Global Administrator) and ensure that any such assignment triggers an automated investigation. Additionally, you need to monitor sign-in failures for guest users and automatically block accounts after 5 failed attempts within 10 minutes. You have the following requirements: 1) Use a cloud-native solution that minimizes administrative overhead. 2) Integrate with Microsoft Sentinel for incident response. 3) Use built-in features where possible. What should you do?
⚠ Common exam trap
The trap here is that candidates often over-engineer a solution with custom Logic Apps or KQL queries, overlooking the fact that PIM and Identity Protection already provide built-in alerting and automated blocking capabilities that natively integrate with Sentinel, satisfying the 'cloud-native' and 'minimize administrative overhead' requirements.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use Microsoft Entra Privileged Identity Management (PIM) alerts for role assignments and Microsoft Entra Identity Protection for sign-in risk policies; integrate both with Microsoft Sentinel.
Microsoft Entra Privileged Identity Management (PIM) provides built-in alerts for high-privilege role assignments, and Microsoft Entra Identity Protection offers risk-based policies for sign-in failures, including user risk policies that can automatically block accounts after a specified number of failures. Both services natively integrate with Microsoft Sentinel via built-in data connectors, enabling automated incident creation with minimal administrative overhead, meeting all requirements.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Use Microsoft Entra audit logs streamed to Log Analytics, create Azure Logic Apps to detect role assignments and sign-in failures, and trigger Sentinel incidents.
Why it's wrong here
Streaming Entra ID audit logs to Log Analytics is a sound detection baseline, but wrapping the analysis in Azure Logic Apps is a custom, code-heavy workaround that reinvents built-in functionality. Microsoft Entra already offers PIM alerts for role activation and Identity Protection for sign-in risk, both of which push native alerts to Sentinel without periodic polling or custom state management. Logic Apps also adds operational overhead (run history, failure handling, throttling) and still provides no preventive control, only post-hoc incident creation.
- ✗
Use Azure Policy to audit role assignments and create custom KQL functions in Log Analytics to detect sign-in failures, then forward to Sentinel.
Why it's wrong here
Azure Policy is an Azure resource governance tool that enforces rules on ARM templates, RBAC, and resource configuration; it cannot inspect or alert on Microsoft Entra ID role assignments or directory-level sign-in activity. Custom KQL functions in Log Analytics can query sign-in logs for patterns like repeated failures, but they are purely reactive—they detect anomalies after the fact and do not apply risk-based access policies or block access in real time. Furthermore, forwarding KQL results to Sentinel duplicates the native Microsoft Entra ID and Identity Protection connectors, which provide richer, pre-filtered signals.
- ✓
Use Microsoft Entra Privileged Identity Management (PIM) alerts for role assignments and Microsoft Entra Identity Protection for sign-in risk policies; integrate both with Microsoft Sentinel.
Why this is correct
This is the correct approach because it uses purpose-built Microsoft Entra security controls rather than custom or legacy tooling. PIM generates alerts on permanent role assignments and privileged role activations, enabling review of who has elevated access, while Identity Protection evaluates sign-in risk signals (e.g., password spray, impossible travel, anonymous IP) and can enforce policies to block sign-ins after repeated failures or require MFA. Both natively integrate with Microsoft Sentinel through out-of-the-box data connectors, giving security analysts a unified SIEM view without building custom orchestration logic.
- ✗
Deploy Microsoft Identity Manager (MIM) on-premises to monitor role changes, and use Microsoft Entra Connect Health for sign-in failures.
Why it's wrong here
MIM (Microsoft Identity Manager) is an on-premises identity lifecycle product, not a cloud-native monitoring service, so it lacks visibility into Microsoft Entra ID role assignments and would require extensive synchronization to even approximate this data. Microsoft Entra Connect Health monitors the health of Microsoft Entra Connect sync and on-premises AD FS infrastructure, but it does not track end-user sign-in failures or enforce risk-based policies—that is Identity Protection’s job. Relying on these legacy tools sidesteps the native Entra controls and introduces unnecessary infrastructure, making it both operationally complex and functionally inadequate.
Go deeper
Related to this question
About these practice questions
This AZ-305 question is part of Courseiva's 795-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-305 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-305 exam.