SC-300 Entitlement Management and Access Reviews 1 — Questions and Answers
Question 1: In Azure AD Entitlement Management, what is an 'access package'?
- A bundle of Azure subscription permissions
- A collection of resources (groups, apps, SharePoint sites) that can be requested and assigned together (Correct answer)
- A policy that blocks access to sensitive applications
- A compliance report of user access
Correct answer: A collection of resources (groups, apps, SharePoint sites) that can be requested and assigned together
An access package in Entitlement Management groups related resources into a single requestable unit, allowing users to request and receive access to multiple resources through a single workflow.
Question 2: Which role is required to create and manage access packages in Azure AD Entitlement Management?
- Security Administrator
- Identity Governance Administrator or catalog owner/access package manager (Correct answer)
- User Administrator
- Application Administrator
Correct answer: Identity Governance Administrator or catalog owner/access package manager
The Identity Governance Administrator can manage all entitlement management settings, while catalog owners and access package managers have delegated authority within their catalogs.
Question 3: What is a 'catalog' in Azure AD Entitlement Management?
- A list of all Azure AD users in the tenant
- A container for access packages and the resources they reference (Correct answer)
- An audit log of all access requests
- A policy set for external user collaboration
Correct answer: A container for access packages and the resources they reference
A catalog is a logical container that groups access packages and the resources they include, enabling delegation of access package management to specific catalog owners.
Question 4: An access package policy is configured with a 14-day expiration and no renewal. What happens to a user's access when the assignment expires?
- The user is prompted to re-request the access package
- Access is automatically removed from all resources included in the access package (Correct answer)
- The assignment is extended by another 14 days automatically
- The user's account is disabled
Correct answer: Access is automatically removed from all resources included in the access package
When an access package assignment expires, Entitlement Management automatically removes the user from all resource groups, apps, and sites included in that access package.
Question 5: Which Entitlement Management feature allows users from partner organizations with a different Azure AD tenant to request access packages?
- B2C external identities
- Connected organizations (Correct answer)
- Cross-tenant synchronization
- Azure AD guest invitation
Correct answer: Connected organizations
Connected organizations in Entitlement Management represent external Azure AD tenants or domains whose users can be approved to request access packages via self-service.
Question 6: What is the purpose of a 'policy' within an access package in Azure AD Entitlement Management?
- It defines the Azure RBAC roles assigned to the access package
- It defines who can request the access package, approval workflows, and assignment lifecycle settings (Correct answer)
- It lists all users currently assigned to the access package
- It configures MFA requirements for accessing resources in the package
Correct answer: It defines who can request the access package, approval workflows, and assignment lifecycle settings
An access package policy specifies the requestor scope, approvers, approval steps, access duration, and review requirements for assignments made through that policy.
In Azure AD Entitlement Management, what is an 'access package'?