Azure AD Connect: Ensuring Group Owners Receive Monthly Group Membership Reports

Email Notifications for Group Owners

Question

Your network contains an on-premises Active Directory forest.

You discover that when users change jobs within your company, the membership of the user groups are not being updated. As a result, the users can access resources that are no longer relevant to their job.

You plan to integrate Active Directory and Azure Active Directory (Azure AD) by using Azure AD Connect.

You need to recommend a solution to ensure that group owners are emailed monthly about the group memberships they manage.

What should you include in the recommendation?

Answers

Explanations

Click on the arrows to vote for the correct answer

A. B. C. D.

B

https://docs.microsoft.com/en-us/azure/active-directory/governance/access-reviews-overview

The correct answer is B. Azure AD access reviews.

Explanation: To ensure that group owners are emailed monthly about the group memberships they manage, we need a solution that provides group membership visibility and sends reminders to group owners to review and update their memberships.

Azure AD access reviews provide a solution for this requirement. Access reviews allow administrators to create reviews for groups, applications, and Azure AD roles. These reviews can be scheduled to run at a frequency that fits the business needs, such as monthly. During the review, group owners receive an email notification asking them to review the group memberships they manage. They can then approve or deny access requests for the group, which updates the group membership accordingly.

Azure AD access reviews also provide reporting and auditing capabilities, allowing administrators to track the progress of the reviews and ensure that group owners are completing them in a timely manner.

Option A, Azure AD Identity Protection, is not related to this requirement. Azure AD Identity Protection provides advanced detection and remediation capabilities for identity-related risks.

Option C, Tenant Restrictions, is also not related to this requirement. Tenant Restrictions allow administrators to restrict access to Azure AD resources based on the location of the requesting user.

Option D, conditional access policies, are not related to this requirement. Conditional access policies allow administrators to control access to Azure AD resources based on various conditions, such as the user's location or device state.