Azure AD Identity Governance Configuration | SC-300 Exam Answer

Identity Governance Configuration for Azure Active Directory | SC-300 Exam Answer

Question

You have an Azure Active Directory (Azure AD) tenant named contoso.com.

You implement entitlement management to provide resource access to users at a company named Fabrikam, Inc.

Fabrikam uses a domain named fabrikam.com.

Fabrikam users must be removed automatically from the tenant when access is no longer required.

You need to configure the following settings: -> Block external user from signing in to this directory: No -> Remove external user: Yes -> Number of days before removing external user from this directory: 90 What should you configure on the Identity Governance blade?

Answers

Explanations

Click on the arrows to vote for the correct answer

A. B. C. D.

B.

https://docs.microsoft.com/en-us/azure/active-directory/governance/entitlement-management-external-users

To configure the desired settings, you need to access the Identity Governance blade in Azure Active Directory. The Identity Governance blade allows administrators to manage access to resources and govern access policies for users and groups in an organization.

The first setting that needs to be configured is "Block external user from signing in to this directory". This setting controls whether external users can sign in to the Azure AD tenant. Since Fabrikam users need access to the tenant, this setting should be set to "No".

The second setting that needs to be configured is "Remove external user". This setting controls whether external users are automatically removed from the tenant when their access is no longer required. Since Fabrikam users need to be removed automatically, this setting should be set to "Yes".

The third setting that needs to be configured is "Number of days before removing external user from this directory". This setting controls the number of days after which external users will be removed from the tenant if their access is no longer required. Since Fabrikam users need to be removed after 90 days, this setting should be set to "90".

Therefore, the correct answer to the question is D. Access reviews. Access reviews are used to periodically review and certify users' access to resources, and to remove access that is no longer required. By configuring the "Remove external user" and "Number of days before removing external user from this directory" settings in the Access reviews feature, you can ensure that Fabrikam users are automatically removed from the tenant when their access is no longer required.