hardMultiple Choice
MS-102 Practice Question: A company uses Microsoft Entra ID Governance to…
A company uses Microsoft Entra ID Governance to automate the lifecycle of user access. They want to automatically remove a user's group membership for a critical application 30 days after the user's employment end date is captured from the HR system. Which feature should be configured to meet this requirement?
⚠ Common exam trap
Test-takers frequently confuse Lifecycle Workflows (which handle HR-triggered automated actions with delays) with Entitlement management (which manages access packages and requests but lacks native HR event-driven scheduling).
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Lifecycle Workflows
Lifecycle Workflows (LCW) in Microsoft Entra ID Governance are specifically designed to automate joiner, mover, and leaver processes triggered by HR data. A 'leaver' workflow can be configured to remove group memberships a defined number of days after the employee's employment end date is captured from the HR system, meeting the 30-day requirement precisely.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Access Reviews
Why it's wrong here
Access Reviews are a governance control that relies on recurring human attestation. Reviewers periodically confirm or deny a user's access, and removal only occurs after a reviewer decision. They are not event-driven and do not automatically respond to an HR attribute such as a termination date, so they cannot autonomously remove group memberships based on lifecycle data.
- ✗
Entitlement management
Why it's wrong here
Entitlement management handles access packages with assigned expiration dates defined in the policy. While it can automatically remove assignments when the policy's duration ends, that trigger is a time-based or user-initiated event, not a direct HR event like termination. It also focuses on access packages rather than ad-hoc group memberships, so it is not the right tool for HR-driven lifecycle removal.
- ✓
Lifecycle Workflows
Why this is correct
Lifecycle Workflows are the correct answer because they are designed to automate identity lifecycle events using HR data from sources like Workday or SuccessFactors. When an HR event such as termination occurs, a workflow triggers tasks that can directly remove group memberships without human intervention. This approach specifically addresses the requirement to automate removal based on an HR attribute date.
- ✗
Privileged Identity Management
Why it's wrong here
Privileged Identity Management (PIM) provides just-in-time activation for privileged roles and includes approval workflows for role activation. Its scope is limited to privileged Microsoft Entra ID roles, not regular group memberships, and it does not respond to HR lifecycle events. PIM focuses on protecting administrative access, not on removing users from general groups based on employment status.
Go deeper
Related to this question
About these practice questions
Courseiva writes every MS-102 question from scratch — 712 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This MS-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-102 exam.