Courseiva

How to Configure Time-Limited External Access with Entitlement Management

Your organization uses Microsoft Entra ID and needs to ensure that external partners can access only specific applications for 30 days. What should you configure?

Quick Answer

The correct answer is entitlement management, specifically by creating an access package with a 30-day expiration. This works because entitlement management in Microsoft Entra ID is designed to govern external partner access through reusable catalogs of resources, and setting an expiration on the access package enforces the time-limited external access requirement, automatically removing the partner’s permissions after the defined period. On the Microsoft Cybersecurity Architect exam, this scenario tests your understanding of how to configure time-limited external access with entitlement management, often appearing as a scenario where you must distinguish between access packages, terms of use, and conditional access policies. A common trap is choosing a conditional access policy with a session timeout, but that controls session duration, not the overall access grant. Memory tip: think of an access package as a “guest pass” with an expiry date—once it expires, the pass is invalid, and the partner loses access to the specific applications.

⚠ Common exam trap

Many candidates confuse Conditional Access session controls (which manage sign-in frequency or app restrictions) with the ability to grant and expire access to specific applications, overlooking that entitlement management is the correct identity governance solution for time-limited external access.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Entitlement management and create an access package with an expiration of 30 days

Entitlement management in Microsoft Entra ID allows you to create access packages that govern external partner access to specific applications. By configuring an access package with a 30-day expiration, you enforce time-limited access, ensuring partners can only access the designated applications for the required duration. This directly meets the requirement of restricting access to specific apps with a defined expiry.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Entitlement management and create an access package with an expiration of 30 days

    Why this is correct

    Entitlement management access packages bundle specific application assignments with an expiry, directly satisfying the 30-day external partner constraint. Time-limited access packages automatically revoke access at expiration, unlike conditional access policies, which govern session conditions rather than provisioning and lifecycle.

  • ✗

    B2B direct connect

    Why it's wrong here

    B2B direct connect links two Microsoft Entra tenants for shared Teams channels, not time-limited access to specific applications; it grants mutual trust rather than per-app entitlement. It would suit ongoing cross-tenant Teams collaboration. External partners needing 30-day access to chosen apps require entitlement management access packages with expiry.

  • ✗

    Self-service group management

    Why it's wrong here

    Self-service group management lets users create and join groups; it neither restricts partners to named applications nor enforces a 30-day expiry. It is tempting because groups can grant app access, but entitlement management access packages provide the time-bound, application-scoped assignment the scenario requires.

  • ✗

    Conditional Access policy with session control

    Why it's wrong here

    Session controls govern in-session behaviour such as download, clipboard or sign-in frequency; they do not scope which applications a partner may reach or expire access after 30 days. It is tempting because Conditional Access targets external users, but entitlement management assignments handle application scoping and expiry.

About these practice questions

Courseiva writes every SC-100 question from scratch — 605 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

1 more way this is tested on SC-100

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. Your organization uses Microsoft Entra ID with external identities. You need to design a solution that allows partners to self-service sign up using their existing Azure AD or Microsoft account credentials, while preventing them from accessing other resources. What should you use?

hard
  • A.Microsoft Entra B2C
  • B.Microsoft Entra Identity Protection
  • ✓ C.Microsoft Entra B2B collaboration
  • D.Direct federation with partner's IdP

Why C: Microsoft Entra B2B collaboration is correct because it lets you invite external partners as guest users who can redeem invitations and sign in with their existing work/school account (Azure AD) or Microsoft account, while access is scoped only to the resources you explicitly share. Guest users in B2B are represented in your tenant and governed by Conditional Access and entitlement management, so they cannot access other resources by default. Entra B2C is for customer-facing apps with local or social identities, not partner collaboration in your corporate tenant. Identity Protection provides risk-based sign-in and user risk policies, not partner onboarding. Direct federation with a partner's IdP requires configuring a SAML/WS-Fed trust per partner and does not provide the self-service invitation and redemption model of B2B.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.