AZ-900 Describe Azure architecture and services Practice Question
Which Azure identity feature automatically assigns permissions when a user joins a specific group, and removes them when they leave?
⚠ Common exam trap
A common mix-up: candidates confuse Privileged Identity Management (PIM) with dynamic group membership because both involve 'automatic' actions, but PIM focuses on time-bound role activation, not attribute-driven group membership changes.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Azure AD Dynamic Groups
Azure AD Dynamic Groups automatically manage user membership based on rules defined using user or device attributes. When a user meets the rule criteria (e.g., department equals 'Sales'), they are added to the group and receive the associated permissions; when they no longer meet the criteria, they are removed, and permissions are revoked. This is the only Azure identity feature that directly ties group membership and permission assignment to attribute-based rules without manual intervention.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Azure AD Privileged Identity Management
Why it's wrong here
Azure AD Privileged Identity Management (PIM) is incorrect because it provides time-bound, just-in-time access to privileged roles such as Global Administrator or Azure AD role assignments, often with approvals or MFA requirements. PIM governs elevated access for administrators and does not modify group membership based on user attributes. While it can manage temporary activations for privileged groups, it is not a mechanism for automatically assigning permissions to regular users through group membership rules.
- ✓
Azure AD Dynamic Groups
Why this is correct
Azure AD Dynamic Groups are the correct choice because they automatically add or remove users from a group based on attribute rules, such as department, job title, or location. This rule-driven membership ensures that permissions and access rights are continuously aligned with each user's current profile, eliminating the need for manual updates. When an attribute changes, Azure AD evaluates the rule and updates group membership accordingly, which directly supports the scenario of automating permission assignment.
- ✗
Azure AD Conditional Access
Why it's wrong here
Azure AD Conditional Access is incorrect because it focuses on evaluating signals at sign-in time to enforce policies like multi-factor authentication, device compliance, or location restrictions. It does not manage group membership or automatically assign permissions based on attribute changes; rather, it decides whether an authenticated user can access a resource under specific conditions. The feature controls the access attempt itself, not the composition of groups that grant permissions.
- ✗
Azure AD Identity Protection
Why it's wrong here
Azure AD Identity Protection is incorrect because it is designed to detect risky sign-ins and user behavior, such as impossible travel, leaked credentials, or anonymous IP addresses, using machine learning. It can trigger automated responses like blocking access or requiring a password reset, but it does not add or remove users from groups. Its purpose is risk detection and remediation, not the attribute-based, lifecycle automation of group membership that dynamic groups provide.
Go deeper
Related to this question
Learn chapter
Azure Regions and Geographies
Key term
Feature
A feature is a distinct unit of functionality that delivers value to the user, often managed and tracked throughout the software development lifecycle.
Key term
Group
A group is a collection of users, devices, or other objects that are assigned permissions and policies together for simplified management in identity and governance systems like Microsoft Entra ID.
About these practice questions
Courseiva writes every AZ-900 question from scratch — 981 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-900 exam.