Courseiva
Describe Azure architecture and servicesmediumMultiple ChoiceObjective-mapped

AZ-900 Describe Azure architecture and services Practice Question

Which Azure identity feature automatically assigns permissions when a user joins a specific group, and removes them when they leave?

⚠ Common exam trap

A common mix-up: candidates confuse Privileged Identity Management (PIM) with dynamic group membership because both involve 'automatic' actions, but PIM focuses on time-bound role activation, not attribute-driven group membership changes.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Azure AD Dynamic Groups

Azure AD Dynamic Groups automatically manage user membership based on rules defined using user or device attributes. When a user meets the rule criteria (e.g., department equals 'Sales'), they are added to the group and receive the associated permissions; when they no longer meet the criteria, they are removed, and permissions are revoked. This is the only Azure identity feature that directly ties group membership and permission assignment to attribute-based rules without manual intervention.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Azure AD Privileged Identity Management

    Why it's wrong here

    Azure AD Privileged Identity Management (PIM) is incorrect because it provides time-bound, just-in-time access to privileged roles such as Global Administrator or Azure AD role assignments, often with approvals or MFA requirements. PIM governs elevated access for administrators and does not modify group membership based on user attributes. While it can manage temporary activations for privileged groups, it is not a mechanism for automatically assigning permissions to regular users through group membership rules.

  • Azure AD Dynamic Groups

    Why this is correct

    Azure AD Dynamic Groups are the correct choice because they automatically add or remove users from a group based on attribute rules, such as department, job title, or location. This rule-driven membership ensures that permissions and access rights are continuously aligned with each user's current profile, eliminating the need for manual updates. When an attribute changes, Azure AD evaluates the rule and updates group membership accordingly, which directly supports the scenario of automating permission assignment.

  • Azure AD Conditional Access

    Why it's wrong here

    Azure AD Conditional Access is incorrect because it focuses on evaluating signals at sign-in time to enforce policies like multi-factor authentication, device compliance, or location restrictions. It does not manage group membership or automatically assign permissions based on attribute changes; rather, it decides whether an authenticated user can access a resource under specific conditions. The feature controls the access attempt itself, not the composition of groups that grant permissions.

  • Azure AD Identity Protection

    Why it's wrong here

    Azure AD Identity Protection is incorrect because it is designed to detect risky sign-ins and user behavior, such as impossible travel, leaked credentials, or anonymous IP addresses, using machine learning. It can trigger automated responses like blocking access or requiring a password reset, but it does not add or remove users from groups. Its purpose is risk detection and remediation, not the attribute-based, lifecycle automation of group membership that dynamic groups provide.

About these practice questions

Courseiva writes every AZ-900 question from scratch — 981 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AZ-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-900 exam.