SC-900 Describe the capabilities of Microsoft Entra Practice Question
Your organization has implemented Microsoft Entra ID Governance. You need to review and attest to the access rights of users in a specific group every quarter. The group contains both direct members and members from nested groups. Which Microsoft Entra feature should you use to automate this review?
⚠ Common exam trap
A common mix-up: candidates confuse Entitlement Management (which handles access requests and packages) with Access Reviews (which handle periodic attestation), leading candidates to pick D when the question explicitly requires a recurring review and attestation workflow.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Access reviews
Access Reviews in Microsoft Entra ID Governance allow you to create recurring reviews of group membership, including both direct members and transitive members from nested groups. This feature automates the attestation process by sending reviewers notifications and tracking their decisions, ensuring compliance with quarterly review requirements.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Lifecycle workflows
Why it's wrong here
Lifecycle workflows in Microsoft Entra ID Governance are designed to automate tasks associated with a user's identity lifecycle, such as onboarding, offboarding, or moving within an organization. These workflows trigger actions based on user attribute changes or scheduled events related to their employment status. They are not intended for the periodic review of existing access entitlements, like group memberships, which require a separate attestation process to validate continued need.
- ✓
Access reviews
Why this is correct
Microsoft Entra access reviews are a critical component of identity governance, specifically designed to enable organizations to efficiently manage access by regularly reviewing who has access to what resources. They allow designated reviewers, such as group owners or managers, to periodically attest to the continued necessity of access for users to groups, applications, or roles. This process ensures that access remains appropriate, adheres to the principle of least privilege, and helps maintain compliance with organizational policies and regulatory requirements.
- ✗
Privileged Identity Management
Why it's wrong here
Microsoft Entra Privileged Identity Management (PIM) focuses on managing, controlling, and monitoring access to important organizational resources by providing just-in-time (JIT) and just-enough-access (JEA) for privileged roles and resources. While PIM does include access review capabilities, these are specifically for PIM-eligible roles and groups, ensuring that only necessary privileged access is maintained. It is not the general solution for routine, periodic reviews of all group memberships across an organization, which are typically handled by broader access review features.
- ✗
Entitlement management
Why it's wrong here
Microsoft Entra entitlement management streamlines how organizations manage access to groups, applications, and SharePoint sites by bundling resources into "access packages" and defining policies for requesting and approving access. Its primary function is to govern the access request and provisioning process, allowing users to self-service access based on predefined rules. Although access packages can incorporate access reviews as part of their lifecycle, entitlement management itself is not the dedicated service for conducting periodic reviews of existing, already provisioned group memberships outside the context of an access package.
Go deeper
Related to this question
Learn chapter
Compliance Concepts
Key term
Compliance
Compliance is the process of ensuring that an organization follows laws, regulations, standards, and internal policies that apply to its operations and data handling.
Key term
Group
A group is a collection of users, devices, or other objects that are assigned permissions and policies together for simplified management in identity and governance systems like Microsoft Entra ID.
About these practice questions
One of 1,250 original SC-900 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.