← All AZ-305 Flashcard Decks

Azure Identity and Access Management Design Flashcards

6 cards from real AZ-305 practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 6 Azure Identity and Access Management Design flashcards as text
  1. Which Azure AD feature would you use to automatically grant or revoke users' access to applications based on their job role attributes?

    Answer: Entitlement Management access packages

    Entitlement Management access packages bundle resources and define policies for who can request them and how long they retain access.

  2. A multi-tenant SaaS application needs to authenticate users from thousands of different Azure AD tenants. What is the recommended design?

    Answer: Register the app as a multi-tenant application in Azure AD

    Registering an app as multi-tenant allows users from any Azure AD tenant to consent and sign in without requiring guest account creation.

  3. Your security team requires that stale guest accounts be automatically removed after 90 days of inactivity. Which feature enables this?

    Answer: Azure AD Access Reviews

    Azure AD Access Reviews can be configured to periodically evaluate guest account activity and automatically remove inactive accounts.

  4. Which Azure AD license tier is required to use both Privileged Identity Management and Identity Protection features?

    Answer: Azure AD Premium P2

    Both PIM and Identity Protection are Azure AD Premium P2 features that require that specific license tier.

  5. A company wants to prevent users from enrolling personal devices in Azure AD and require only compliant corporate devices for cloud app access. Which two features should you combine?

    Answer: Intune device compliance policies + Conditional Access

    Intune enforces device compliance standards and Conditional Access can then require a compliant device before granting access to cloud apps.

  6. You need to design an identity solution for a consumer-facing mobile application where users can sign in with Google or Facebook. Which service is most appropriate?

    Answer: Azure AD B2C

    Azure AD B2C is designed for customer-facing applications and supports social identity providers like Google and Facebook out of the box.