Courseiva

AZ-305 Practice Question: Design identity, governance, and monitoring solutions

Your company uses Microsoft Entra ID. You need to implement a governance strategy for guest users. Which TWO actions should you take? (Choose two.)

⚠ Common exam trap

Many candidates confuse blocking or disabling guest access (Options B and C) with governance, when the correct approach involves reviewing and managing guest access through reviews and entitlement management.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Create access reviews for guest users

Access reviews for guest users (Option A) are a core governance control in Microsoft Entra ID, allowing administrators to periodically review and confirm or revoke guest access. This ensures that guest accounts remain necessary and compliant with security policies, directly addressing the governance requirement.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Create access reviews for guest users

    Why this is correct

    Access reviews in Microsoft Entra ID provide a planned, recurring recertification workflow for guest users, forcing owners to confirm or revoke each guest's access to sensitive resources. By assigning reviewers per access package or application, you can automatically remove stale or unauthorized external accounts, satisfying compliance requirements and enforcing the principle of least privilege. This is a core governance control because it operationalizes periodic oversight rather than relying on one-time provisioning decisions.

  • ✗

    Disable external identities

    Why it's wrong here

    Disabling external identities, typically by turning off the B2B collaboration invitation feature, is a tenant-wide setting that prevents any new guest users from being invited but does nothing to audit, review, or clean up existing guest accounts. It is a blunt operational shutdown, not a governance strategy, and it eliminates the ability to collaborate with external partners altogether, which is usually unacceptable for a business. Governance requires ongoing monitoring and lifecycle management, not simply closing the door to future invitations.

  • ✗

    Block all guest user access

    Why it's wrong here

    Blocking all guest user access, for instance by applying a Conditional Access policy that denies any guest account, halts current guest access to all applications and data but leaves the guest objects in the directory unprotected from future policy gaps. This approach is both disruptive, because it kills legitimate external collaboration, and incomplete, because it does not require any human review of whether access is still appropriate. A governance framework should selectively revoke access based on periodic validation, not indiscriminately deny every external identity without context.

  • ✗

    Enable self-service sign-up for guest users

    Why it's wrong here

    Enabling self-service sign-up for guest users in Microsoft Entra ID allows external individuals to create accounts and request access to resources without any IT intervention or approval workflow, which is the opposite of governance. Self-service sign-up bypasses controlled onboarding processes, leading to unvetted identities that are not tracked by the organization and may not be included in future access reviews or lifecycle policies. It undermines the ability to maintain an accurate inventory of who has access and why, creating shadow identities that increase risk and audit complexity.

  • ✓

    Configure Microsoft Entra entitlement management

    Why this is correct

    Configuring Microsoft Entra entitlement management gives you the tools to create access packages for guests, including approval chains, separation-of-duties checks, and expiration policies that automatically revoke access after a defined period. Entitlement management is correct governance because it packages onboarding, approval, and time-bound access together, making guest identity lifecycle proactive rather than ad hoc. It also integrates directly with access reviews, allowing you to combine initial controlled provisioning with recurrent recertification, so this is a valid approach if the goal is a comprehensive external identity governance program.

About these practice questions

Courseiva writes every AZ-305 question from scratch — 795 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AZ-305 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-305 exam.