TechNuggets Academy

Plan and automate identity governance

Free Microsoft Certified: Identity and Access Administrator Associate practice — 6 questions on Plan and automate identity governance, with explanations. No sign-up. Full 12-question mixed test →

Question 1 of 6 · Plan and automate identity governance
An organization uses Microsoft Entra entitlement management. They want to prevent any user who already has the 'Finance-Sensitive' access package from also being granted the 'Marketing-External' access package, due to a conflict-of-interest policy, without requiring manual review of every request. Which feature should be configured?
Separation of duties (SoD) checks in entitlement management let you designate an incompatible access package or group; the system automatically blocks a request if the requester already holds the conflicting access, enforced at request time with no manual review needed.
Question 2 of 6 · Plan and automate identity governance
A company wants a lifecycle workflow to run automatically and immediately whenever a user's employeeType attribute value changes from 'Employee' to 'Contractor', rather than waiting for the next scheduled execution. Which trigger type should the workflow use?
The 'Attribute changed' trigger type in Microsoft Entra ID Governance lifecycle workflows fires a workflow automatically as soon as a specified attribute (such as employeeType) changes on a user object, without needing a scheduled run.
Question 3 of 6 · Plan and automate identity governance
An administrator creates a recurring access review for members of a role that is eligible in PIM. The administrator wants the review's outcome (removing denied users) to be implemented automatically once the review period ends, without requiring anyone to manually apply the results. Which setting accomplishes this?
The 'Auto apply results to resource' setting on an access review automatically implements the review outcome (e.g., removing a user whose access was denied or not reviewed) at the end of the review period, eliminating the need for manual application.
Question 4 of 6 · Plan and automate identity governance
A compliance requirement states that all users must re-accept a specific Terms of Use policy every 90 days, even if they accepted the current version previously. Which Terms of Use configuration satisfies this requirement without publishing a new document version each time?
Terms of use policies include an 'Expire consents' option that forces users to re-accept the same terms after a defined number of days, meeting recurring re-acceptance requirements without needing to publish a new document version.
Question 5 of 6 · Plan and automate identity governance
An organization wants employees to be able to consent to apps that request only low-impact permissions such as sign-in and basic profile read, while blocking consent for apps requesting high-impact permissions like full mailbox access — without turning off user consent entirely. Which configuration meets this requirement?
The recommended user consent setting, 'Allow user consent for apps from verified publishers, for selected permissions,' combined with permission classifications (marking specific permissions as low impact), lets users consent only to apps requesting those classified low-impact permissions while blocking consent for apps requesting anything else.
Question 6 of 6 · Plan and automate identity governance
A company requires that requests for a specific access package go through two sequential levels of approval — first a manager, then a resource owner — before access is granted. Which capability supports this requirement?
Entitlement management access package request policies support configuring up to two sequential approval stages, each with its own set of approvers (e.g., manager for stage one, resource owner for stage two), satisfying multi-level sequential approval.
Ready for the real thing?

The full course has two full-length practice tests, video lessons for every exam domain, hands-on labs and detailed answer explanations.

Start my full course on Udemy →