Courseiva

AZ-305 Practice Question: Design identity, governance, and monitoring solutions

Your organization plans to deploy Microsoft Entra ID Governance. You need to ensure that access to critical applications is reviewed quarterly by the application owners. Which Microsoft Entra ID feature should you use?

⚠ Common exam trap

Many candidates confuse Entitlement Management (which includes access packages and can trigger reviews) with the dedicated Access Reviews feature, but the question explicitly asks for the feature that ensures reviews are conducted quarterly by application owners, which is the core purpose of Access Reviews, not a secondary function of Entitlement Management.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Microsoft Entra ID Access Reviews

Microsoft Entra ID Access Reviews (Option D) is the correct feature because it enables recurring, delegated review of user access to applications, groups, or roles. By configuring an access review with quarterly frequency and assigning application owners as reviewers, you directly meet the requirement for periodic attestation of access to critical applications. This is the specific Entra ID capability designed for governance-driven access recertification.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Microsoft Entra ID Privileged Identity Management

    Why it's wrong here

    Microsoft Entra ID Privileged Identity Management (PIM) is not the correct service because it is scoped to governing time-bound activation and approval for highly privileged directory roles such as Global Administrator, not to periodic attestation of whether regular users still need access to business applications. PIM provides just-in-time access elevation and audit history for role assignments, but it does not generate recurring reviews answered by resource owners or automatically remove stale assignments for non-privileged application permissions. A recurring access review could be configured to include privileged roles, but PIM itself lacks the review workflow engine that schedules, sends reminders, and collects owner decisions.

  • ✗

    Microsoft Entra ID Entitlement Management

    Why it's wrong here

    Microsoft Entra ID Entitlement Management is not the correct service because it focuses on automating the request, approval, and assignment lifecycle of access packages, not on the ongoing attestation of existing access. While Entitlement Management includes connected organizations and policies that expire or revoke assignments based on defined criteria, it does not by default run periodic reviews where access owners must explicitly re-certify that a user's current access is still appropriate. Its primary mechanism is governing how access is granted, whereas Access Reviews governs whether access should be retained after it has already been granted.

  • ✗

    Microsoft Entra ID Terms of Use

    Why it's wrong here

    Microsoft Entra ID Terms of Use is not the correct service because it only presents a policy document that users must acknowledge before accessing an application, and it tracks consent rather than evaluating the appropriateness of existing access. Terms of Use can be configured to require re-acceptance on a schedule, but that re-acceptance is simply an acknowledgment from the user and does not involve an independent owner or manager attesting to the necessity of the user's permissions. It provides no workflow for a reviewer to deny or remove access based on the attestation result, so it cannot satisfy a periodic access certification requirement.

  • ✓

    Microsoft Entra ID Access Reviews

    Why this is correct

    Microsoft Entra ID Access Reviews is the correct service because it provides recurring, owner-driven attestation workflows where designated reviewers—such as application owners or managers—are asked to confirm whether a user, group, or application role assignment should continue. Administrators can configure the review frequency (e.g., weekly, monthly, quarterly), specify the scope to all users or only guest users, and enable auto-apply settings that remove denied access automatically after the review period ends. It also supports self-review and multi-stage reviews, giving organizations a complete control loop for regularly proving that access is still necessary. In this scenario, the requirement for owners to periodically attest to whether users still need access directly maps to Access Reviews, not to a request, consent, or privileged-role feature.

About these practice questions

Courseiva writes every AZ-305 question from scratch — 795 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AZ-305 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-305 exam.