SC-100 · Question #183
You have a Microsoft 365 tenant. Your company uses a third-party software as a service (SaaS) app named App1 that is integrated with an Azure AD tenant. You need to design a security strategy to meet
The correct answer is A. Microsoft Entra Identity Governance. Microsoft Entra Identity Governance (formerly Azure AD Identity Governance) is the correct answer because it addresses all three requirements. For self-service access requests: Entitlement Management allows users to request access to App1 through access packages without admin int
Question
You have a Microsoft 365 tenant. Your company uses a third-party software as a service (SaaS) app named App1 that is integrated with an Azure AD tenant. You need to design a security strategy to meet the following requirements:
- Users must be able to request access to App1 by using a self-service
request.
- When users request access to App1, they must be prompted to provide
additional information about their request.
- Every three months, managers must verify that the users still require
access to App1. What should you include in the design?
Options
- AMicrosoft Entra Identity Governance
- Bconnected apps in Microsoft Defender for Cloud Apps
- Caccess policies in Microsoft Defender for Cloud Apps
- DAzure AD Application Proxy
How the community answered
(65 responses)- A75% (49)
- B6% (4)
- C3% (2)
- D15% (10)
Explanation
Microsoft Entra Identity Governance (formerly Azure AD Identity Governance) is the correct answer because it addresses all three requirements. For self-service access requests: Entitlement Management allows users to request access to App1 through access packages without admin intervention. For prompting additional information: access package policies can require requestors to fill out custom questions or justification fields when submitting a request. For quarterly access reviews by managers: Access Reviews can be scheduled on a recurring basis (every 3 months) and assigned to managers, who must verify whether each user still needs access. Defender for Cloud Apps (B, C) focuses on cloud app discovery, CASB controls, and conditional access app control - not self-service access lifecycle. Azure AD Application Proxy (D) is for on-premises app publishing, not access governance.
Topics
Community Discussion
No community discussion yet for this question.