Top 3 Microsoft Entra ID Governance Features for Access Recertification and Lifecycle Management
You are deploying Microsoft Entra ID Governance. Which THREE capabilities should you include to meet compliance requirements for access recertification and lifecycle management?
Quick Answer
The answer is Entitlement Management, Access Reviews, and Lifecycle Management workflows. These three capabilities form the core of Microsoft Entra ID Governance for access recertification and lifecycle management because they automate the entire process from provisioning to periodic attestation and deprovisioning. Entitlement Management enables governed access packages and automated assignment, while Access Reviews provide recurring attestation workflows for group memberships, application roles, and privileged groups, creating a clear audit trail for compliance with regulations like SOX, GDPR, or HIPAA. Lifecycle Management workflows handle joiner-mover-leaver scenarios, ensuring access is automatically granted or revoked based on HR triggers. On the MS-102 exam, this question tests your ability to distinguish governance features from broader identity features like Conditional Access or Identity Protection—a common trap is selecting Azure AD roles or PIM instead of Lifecycle Management. Remember the mnemonic "EAL" for Entitlement, Access Reviews, and Lifecycle Management to lock in the three pillars of recertification and lifecycle control.
⚠ Common exam trap
Watch out — candidates often confuse Identity Protection's risk-based conditional access with governance recertification, or assume B2B Collaboration covers lifecycle management, when in fact only Access Reviews, Lifecycle Workflows, and Entitlement Management directly address compliance-driven access recertification and lifecycle automation.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Access Reviews
Access Reviews (B) is correct because it is the Entra ID Governance capability that drives access recertification, letting reviewers periodically attest to group memberships, application assignments, and privileged role assignments so stale or excessive access is removed. Lifecycle Workflows (D) is correct because it automates joiner, mover, and leaver tasks—such as pre-hire provisioning, attribute-based updates, and post-termination access removal—which is exactly the lifecycle management requirement. Entitlement Management (E) is correct because access packages, catalogs, and assignment policies govern who can request and retain access, with expiration and approval controls that support recertification and lifecycle governance. Identity Protection (A) is not included because it is a risk-detection and conditional access signal service, not a recertification or lifecycle tool, and B2B Collaboration (C) is not included because it only enables external guest access rather than providing the required governance capabilities.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Identity Protection
Why it's wrong here
Identity Protection detects risky sign-ins and compromised credentials; it does not schedule access reviews or automate joiner-mover-leaver tasks. Access recertification needs access reviews, and lifecycle management needs entitlement management and lifecycle workflows. Identity Protection is correct when the requirement is risk-based Conditional Access.
- ✓
Access Reviews
Why this is correct
Access Reviews periodically recertify group membership, application access and privileged role assignments, producing reviewer decisions and audit records. This directly satisfies the compliance requirement for access recertification within Microsoft Entra ID Governance, complementing entitlement management and lifecycle workflows.
- ✗
B2B Collaboration
Why it's wrong here
B2B Collaboration governs how external partners are invited and granted access to resources; it does not run recurring access reviews or automate lifecycle transitions. Recertification requires access reviews, and lifecycle management requires entitlement management and lifecycle workflows. B2B Collaboration is correct when onboarding guest users from partner organisations.
- ✓
Lifecycle Workflows
Why this is correct
Lifecycle Workflows automates joiner-mover-leaver tasks, such as triggering access reviews when a user changes department or leaves. This directly satisfies the stem's lifecycle management requirement by removing manual provisioning, while complementing access reviews to enforce recertification at defined events.
- ✓
Entitlement Management
Why this is correct
Entitlement management delivers access packages with assignment policies and recurring access reviews, directly satisfying the recertification and lifecycle requirements. It automates granting, revoking and reviewing access for internal and external users, so periodic attestation and joiner-mover-leaver lifecycle tasks are enforced rather than handled manually.
Go deeper
Related to this question
Learn chapter
Entra ID Governance Portal
Key term
Guest access
Guest access allows a user to temporarily connect to a network, application, or shared resource with limited permissions, without being a permanent member of the organization.
Key term
Microsoft Entra ID
Microsoft Entra ID is a cloud-based identity and access management service that lets employees sign in and access resources both inside and outside of your organization.
About these practice questions
This MS-102 question is part of Courseiva's 712-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on MS-102
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. Which THREE are features of Microsoft Entra ID Governance? (Choose three.)
hard- A.Password protection
- ✓ B.Entitlement management
- C.Conditional access policies
- ✓ D.Access reviews
- ✓ E.Privileged Identity Management (PIM)
Why B: Entitlement management is a core feature of Microsoft Entra ID Governance that enables organizations to manage the lifecycle of access for internal and external users through access packages, catalogs, and policies. It automates access requests, approvals, and assignments, ensuring users have the right access to resources like groups, apps, and SharePoint sites.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This MS-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-102 exam.