Your organization uses Microsoft Entra ID Governance. You need to automate the removal of access when an employee leaves the company. The identity lifecycle should trigger access reviews and automatic deprovisioning. What should you configure?
Microsoft Entra Lifecycle Workflows directly orchestrates joiner, mover, leaver, and post-arbitration workflows using built-in tasks arranged in a configurable schedule. For deprovisioning, it can trigger on an employee's leave date (for example, employeeLeaveDateTime) to disable the account, block sign-in, revoke sessions, remove licenses, and delete the user or send a manager email. Because it is event-driven by HR attributes and runs without manual intervention, it is the only option that automates the entire lifecycle from onboarding through offboarding.
Why this answer
Microsoft Entra Lifecycle Workflows is the correct choice because it is specifically designed to automate the entire identity lifecycle, including the removal of access when an employee leaves. It can trigger access reviews and automatically deprovision accounts and group memberships based on joiner, mover, and leaver scenarios, integrating with HR systems like Workday or SuccessFactors.
Exam trap
The trap here is that candidates often confuse Entitlement Management (which handles access packages) with Lifecycle Workflows (which handles the full lifecycle automation), or they think Access Reviews alone can automate deprovisioning, when in fact Access Reviews only provide attestation without execution of removal actions.
How to eliminate wrong answers
Option A is wrong because Microsoft Entra Entitlement Management manages access packages and approval workflows for resource access, but it does not automate the full identity lifecycle deprovisioning triggered by employee departure events. Option C is wrong because Microsoft Entra Access Reviews only provides periodic review and attestation of access, not automated deprovisioning or lifecycle triggers. Option D is wrong because Microsoft Entra Privileged Identity Management focuses on just-in-time privileged role activation and approval, not on automating the removal of all access for departing employees.