AZ-104 · Question #565
Hotspot Question You have an Azure AD tenant named contoso.com. You have two external partner organizations named fabrikam.com and litwareinc.com. Fabrikam.com is configured as a connected…
The correct answer is Require approval = No; Enabled = Yes; Require access reviews = No. Based on the configured Entitlement Management policies, Litwareinc users fall outside the request scope, while Fabrikam users will lose Group1 access when their assignment expires at 365 days and will be removed from the tenant 30 days later.
Question
Exhibits
Answer Area
- Require approvalNo
- EnabledYes
- Require access reviewsNo
Explanation
Based on the configured Entitlement Management policies, Litwareinc users fall outside the request scope, while Fabrikam users will lose Group1 access when their assignment expires at 365 days and will be removed from the tenant 30 days later.
Approach. Evaluate each statement based on the configured policies:
-
Litwareinc.com users can be assigned to package1: NO. The access package is scoped only to 'All configured connected organizations'. Because Fabrikam is the only connected organization, Litwareinc users cannot request access under this policy.
-
After 365 days, fabrikam.com users will be removed from Group1: YES. The access package specifically states 'Access package assignments expire: After 365 days'. When an assignment expires, Entitlement Management automatically revokes the user's access to the resources tied to that package, which removes them from Group1.
-
After 395 days, fabrikam.com users will be removed from the contoso.com tenant: YES. The assignment expires at 365 days. Once the user loses this assignment, the external lifecycle policy takes over, waiting 30 days before removing the external user from the directory entirely (365 + 30 = 395 days).
Common mistakes.
- common_mistake. A frequent error found in exam dumps (and partially reflected in the provided solution image) marks the second statement as 'No'. This is incorrect; Entitlement Management is designed to automatically remove resource memberships (like Group1) the moment an access package assignment expires, assuming no manual extension was requested.
Concept tested. Azure AD Entitlement Management, Access Package Expiration Policies, Connected Organizations, and External User Lifecycle Management.
Reference. https://learn.microsoft.com/en-us/entra/id-governance/entitlement-management-external-users
Topics
Community Discussion
No community discussion yet for this question.





