ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 4 - AZ-305 discussion

Report
Export

You have an Azure Active Directory (Azure AD) tenant named contoso.com that has a security group named Group'. Group i is configured Tor assigned membership. Group I has 50 members. including 20 guest users. You need To recommend a solution for evaluating the member ship of Group1. The solution must meet the following requirements:

• The evaluation must be repeated automatically every three months

• Every member must be able to report whether they need to be in Group1

• Users who report that they do not need to be in Group 1 must be removed from Group1 automatically

• Users who do not report whether they need to be m Group1 must be removed from Group1 automatically.

What should you include in me recommendation?

A.
implement Azure AU Identity Protection.
Answers
A.
implement Azure AU Identity Protection.
B.
Change the Membership type of Group1 to Dynamic User.
Answers
B.
Change the Membership type of Group1 to Dynamic User.
C.
Implement Azure AD Privileged Identity Management.
Answers
C.
Implement Azure AD Privileged Identity Management.
D.
Create an access review.
Answers
D.
Create an access review.
Suggested answer: D

Explanation:

https://docs.microsoft.com/en-us/azure/active-directory/governance/access-reviewsoverview#learn-about-access-reviewsHave reviews recur periodically: You can set up recurring access reviews of users at set frequenciessuch as weekly, monthly, quarterly or annually, and the reviewers will be notified at the start of eachreview. Reviewers can approve or deny access with a friendly interface and with the help of smartrecommendations. An administrator creates an access review of Group C with 50 member users and 25 guest users.

Makes it a self-review. 50 licenses for each user as self-reviewers.* https://docs.microsoft.com/enus/azure/active-directory/governance/access-reviews-overview#example-license-scenariosThere are 4 requirements and every single one is only met by access reviews.

https://docs.microsoft.com/en-us/azure/active-directory/governance/access-reviewsoverview#when-should-you-use-access-reviewsDynamic User is needed if a user must be automatically granted access on base of its attributes (department, jobtitle, location, etc.) https://techcommunity.microsoft.com/t5/itops-talkblog/dynamic-groups-in-azure-ad-and-microsoft-365/ba-p/2267494Implementing Azure AD PIM is no solution and absolutely not necessary for access reviews.

https://docs.microsoft.com/en-us/azure/active-directory/governance/access-reviewsoverview#where-do-you-create-reviews

asked 02/10/2024
Wislon Pereira
36 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first