nerdexam
Microsoft

AZ-305 · Question #364

Hotspot Question You have a Microsoft Entra tenant named contoso.com that contains multiple enterprise apps. Your company has a business partner that has a Microsoft Entra tenant named fabrikam.com…

This hotspot question tests your knowledge of Microsoft Entra ID Governance features, specifically how to configure cross-tenant access and entitlement management to allow external partner (fabrikam.com) users to access enterprise apps in contoso.com.

Submitted by jakub_pl· Mar 6, 2026Design identity, governance, and monitoring solutions

Question

Hotspot Question You have a Microsoft Entra tenant named contoso.com that contains multiple enterprise apps. Your company has a business partner that has a Microsoft Entra tenant named fabrikam.com. You need to recommend an identity governance solution that will provide users in fabrikam.com with access to the enterprise apps in contoso.com. The solution must meet the following requirements: - Ensure that administrators in fabrikam.com can provide the fabrikam.com users with access to the contoso.com enterprise apps. - Automatically provision identities for the fabrikam.com users to enable access to the contoso.com enterprise apps. - Provide policy-based management of access assignments, approvals, and expirations. - Minimize administrative effort. What should you include in the recommendation? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point. Answer:

Exhibits

AZ-305 question #364 exhibit 1
AZ-305 question #364 exhibit 2

Answer Area

  • For identity provisioning:
    B2B collaborationB2B direct connectCross-tenant synchronization
  • For access management:
    Entitlement managementPermissions ManagementPrivileged Identity Management (PIM)

Explanation

This hotspot question tests your knowledge of Microsoft Entra ID Governance features, specifically how to configure cross-tenant access and entitlement management to allow external partner (fabrikam.com) users to access enterprise apps in contoso.com.

Approach. The correct recommendation involves two key components: (1) Configure a Connected Organization in Microsoft Entra Entitlement Management - this allows contoso.com to recognize fabrikam.com as a trusted partner organization, enabling fabrikam.com administrators to sponsor access requests for their users. (2) Use Access Packages in Microsoft Entra Entitlement Management - Access Packages provide policy-based management of access assignments, approvals, and expirations, and they automatically provision identities (via B2B collaboration guest accounts) for external users when access is granted, satisfying the auto-provisioning requirement. This combination minimizes administrative effort because fabrikam.com admins can manage which of their users request access, and the lifecycle (approval, expiration, removal) is automated through entitlement management policies. Cross-tenant access settings (Inbound/Outbound) may also be referenced to ensure B2B collaboration is permitted between the tenants.

Concept tested. Microsoft Entra Entitlement Management - specifically the use of Connected Organizations (to onboard fabrikam.com as a partner tenant) and Access Packages (to provide policy-driven, auto-provisioned, lifecycle-managed access to enterprise apps for external users), combined with B2B collaboration for cross-tenant identity provisioning.

Reference. https://learn.microsoft.com/en-us/entra/id-governance/entitlement-management-organization

Topics

#Microsoft Entra ID#B2B collaboration#Cross-tenant synchronization#Entitlement Management

Community Discussion

No community discussion yet for this question.

Full AZ-305 Practice