nerdexam
Microsoft

SC-100 · Question #183

You have a Microsoft 365 tenant. Your company uses a third-party software as a service (SaaS) app named App1 that is integrated with an Azure AD tenant. You need to design a security strategy to meet

The correct answer is A. Microsoft Entra Identity Governance. Microsoft Entra Identity Governance (formerly Azure AD Identity Governance) is the correct answer because it addresses all three requirements. For self-service access requests: Entitlement Management allows users to request access to App1 through access packages without admin int

Design security operations, identity, and compliance capabilities

Question

You have a Microsoft 365 tenant. Your company uses a third-party software as a service (SaaS) app named App1 that is integrated with an Azure AD tenant. You need to design a security strategy to meet the following requirements:

  • Users must be able to request access to App1 by using a self-service

request.

  • When users request access to App1, they must be prompted to provide

additional information about their request.

  • Every three months, managers must verify that the users still require

access to App1. What should you include in the design?

Options

  • AMicrosoft Entra Identity Governance
  • Bconnected apps in Microsoft Defender for Cloud Apps
  • Caccess policies in Microsoft Defender for Cloud Apps
  • DAzure AD Application Proxy

How the community answered

(65 responses)
  • A
    75% (49)
  • B
    6% (4)
  • C
    3% (2)
  • D
    15% (10)

Explanation

Microsoft Entra Identity Governance (formerly Azure AD Identity Governance) is the correct answer because it addresses all three requirements. For self-service access requests: Entitlement Management allows users to request access to App1 through access packages without admin intervention. For prompting additional information: access package policies can require requestors to fill out custom questions or justification fields when submitting a request. For quarterly access reviews by managers: Access Reviews can be scheduled on a recurring basis (every 3 months) and assigned to managers, who must verify whether each user still needs access. Defender for Cloud Apps (B, C) focuses on cloud app discovery, CASB controls, and conditional access app control - not self-service access lifecycle. Azure AD Application Proxy (D) is for on-premises app publishing, not access governance.

Topics

#Identity Governance#Access Reviews#Self-service Access#Entitlement Management

Community Discussion

No community discussion yet for this question.

Full SC-100 Practice