You are deploying Microsoft Entra ID Governance. Which THREE capabilities should you include to meet compliance requirements for access recertification and lifecycle management?
Access Reviews periodically recertify group membership, application access and privileged role assignments, producing reviewer decisions and audit records. This directly satisfies the compliance requirement for access recertification within Microsoft Entra ID Governance, complementing entitlement management and lifecycle workflows.
Why this answer
Access Reviews (B) is correct because it is the Entra ID Governance capability that drives access recertification, letting reviewers periodically attest to group memberships, application assignments, and privileged role assignments so stale or excessive access is removed. Lifecycle Workflows (D) is correct because it automates joiner, mover, and leaver tasks—such as pre-hire provisioning, attribute-based updates, and post-termination access removal—which is exactly the lifecycle management requirement. Entitlement Management (E) is correct because access packages, catalogs, and assignment policies govern who can request and retain access, with expiration and approval controls that support recertification and lifecycle governance.
Identity Protection (A) is not included because it is a risk-detection and conditional access signal service, not a recertification or lifecycle tool, and B2B Collaboration (C) is not included because it only enables external guest access rather than providing the required governance capabilities.
Exam trap
The trap here is that candidates often confuse Identity Protection's risk-based conditional access with governance recertification, or assume B2B Collaboration covers lifecycle management, when in fact only Access Reviews, Lifecycle Workflows, and Entitlement Management directly address compliance-driven access recertification and lifecycle automation.