nerdexam
Microsoft

AZ-104 · Question #565

Hotspot Question You have an Azure AD tenant named contoso.com. You have two external partner organizations named fabrikam.com and litwareinc.com. Fabrikam.com is configured as a connected…

The correct answer is Require approval = No; Enabled = Yes; Require access reviews = No. Based on the configured Entitlement Management policies, Litwareinc users fall outside the request scope, while Fabrikam users will lose Group1 access when their assignment expires at 365 days and will be removed from the tenant 30 days later.

Submitted by layla.eg· Mar 4, 2026Manage identities and governance

Question

Hotspot Question You have an Azure AD tenant named contoso.com. You have two external partner organizations named fabrikam.com and litwareinc.com. Fabrikam.com is configured as a connected organization. You create an access package as shown in the Access package exhibit. You configure the external user lifecycle settings as shown in the Lifecycle exhibit. For each of the following statements, select Yes if the statement is true. Otherwise, select No. NOTE: Each correct selection is worth one point. Answer:

Exhibits

AZ-104 question #565 exhibit 1
AZ-104 question #565 exhibit 2
AZ-104 question #565 exhibit 3
AZ-104 question #565 exhibit 4
AZ-104 question #565 exhibit 5
AZ-104 question #565 exhibit 6

Answer Area

  • Require approvalNo
  • EnabledYes
  • Require access reviewsNo

Explanation

Based on the configured Entitlement Management policies, Litwareinc users fall outside the request scope, while Fabrikam users will lose Group1 access when their assignment expires at 365 days and will be removed from the tenant 30 days later.

Approach. Evaluate each statement based on the configured policies:

  1. Litwareinc.com users can be assigned to package1: NO. The access package is scoped only to 'All configured connected organizations'. Because Fabrikam is the only connected organization, Litwareinc users cannot request access under this policy.

  2. After 365 days, fabrikam.com users will be removed from Group1: YES. The access package specifically states 'Access package assignments expire: After 365 days'. When an assignment expires, Entitlement Management automatically revokes the user's access to the resources tied to that package, which removes them from Group1.

  3. After 395 days, fabrikam.com users will be removed from the contoso.com tenant: YES. The assignment expires at 365 days. Once the user loses this assignment, the external lifecycle policy takes over, waiting 30 days before removing the external user from the directory entirely (365 + 30 = 395 days).

Common mistakes.

  • common_mistake. A frequent error found in exam dumps (and partially reflected in the provided solution image) marks the second statement as 'No'. This is incorrect; Entitlement Management is designed to automatically remove resource memberships (like Group1) the moment an access package assignment expires, assuming no manual extension was requested.

Concept tested. Azure AD Entitlement Management, Access Package Expiration Policies, Connected Organizations, and External User Lifecycle Management.

Reference. https://learn.microsoft.com/en-us/entra/id-governance/entitlement-management-external-users

Topics

#Azure AD Access Packages#Azure AD Connected Organizations#Azure AD External Identities#Azure AD Lifecycle Management

Community Discussion

No community discussion yet for this question.

Full AZ-104 Practice