AZ-500 Secure identity and access Practice Question
Your organization uses Microsoft Entra ID and requires that all accesses to sensitive applications be approved by the application owner. You need to implement a solution where users can request access to these applications, and the request is automatically routed to the owner for approval. What should you configure?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Entitlement management access packages
Entitlement management access packages in Microsoft Entra ID are the correct choice because they let you bundle resources such as sensitive applications into an access package with an approval policy, so users request access through the My Access portal and the request is automatically routed to the designated approver (the application owner) before access is granted. This directly satisfies the requirement for owner-approved, request-based access to applications. Option A (Entra roles and administrative units) governs role assignments and scoping, not user access-request approval workflows for applications. Option C (Privileged Identity Management for groups) handles just-in-time activation of privileged group membership, not application access requests with owner approval. Option D (cross-tenant access settings) controls collaboration and trust with external Entra tenants, which is unrelated to internal application access approvals.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Microsoft Entra roles and administrative units
Why it's wrong here
Microsoft Entra roles and administrative units are designed to manage and scope administrative permissions, not end-user access requests to applications. Administrative units let you restrict the scope of role assignments to specific directory objects, such as users or groups, for delegated administration. They do not provide request/approval workflows or lifecycle policies for granting access to business applications.
- ✓
Entitlement management access packages
Why this is correct
Entitlement management access packages are the correct identity governance solution because they bundle resources such as applications, groups, and SharePoint sites into packages that users can request. Access package policies can require specified custom approvers, define approval stages, set access durations, and trigger recurring access reviews. This directly satisfies the requirement for user-driven application access requests with custom approvals.
- ✗
Privileged Identity Management for groups
Why it's wrong here
Privileged Identity Management (PIM) for groups focuses on just-in-time activation of Microsoft Entra ID roles or Azure resource roles for members of role-assignable groups. It governs when users can activate their already-assigned privileged role memberships, not how users request access to an application. PIM for groups does not provide the custom approval workflow for non-privileged application access requests that entitlement management offers.
- ✗
Cross-tenant access settings
Why it's wrong here
Cross-tenant access settings manage inbound and outbound B2B collaboration with external organizations, including policies for external users, tenant restrictions, and trust settings. They are used to control whether users from other tenants can sign in to your tenant or access resources, not to enable internal users to request access to an application. This option is unrelated to custom approval workflows for application access requests.
Visual reference
Go deeper
Related to this question
About these practice questions
This AZ-500 question is part of Courseiva's 617-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-500 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-500 exam.