nerdexam
Microsoft

SC-300 · Question #89

Hotspot Question Your company has an Azure Active Directory (Azure AD) tenant named contoso.com. The company has a business partner named Fabrikam, Inc. Fabrikam uses Azure AD and has two verified…

The correct answer is To allow access for users who have fabrikam.com email addresses, configure:: An access package policy in Identity Governance; To block access for users who have litwareinc.com email addresses, configure:: The External collaboration settings in Azure AD. This question tests your knowledge of Azure AD Entitlement Management connected organizations and how to restrict access packages to specific domains within a partner organization that has multiple verified domains.

Submitted by helene.fr· Mar 6, 2026Plan and implement identity governance

Question

Hotspot Question Your company has an Azure Active Directory (Azure AD) tenant named contoso.com. The company has a business partner named Fabrikam, Inc. Fabrikam uses Azure AD and has two verified domain names of fabrikam.com and litwareinc.com. Both domain names are used for Fabrikam email addresses. You plan to create an access package named package1 that will be accessible only to the users at Fabrikam. You create a connected organization for Fabrikam. You need to ensure that the package1 will be accessible only to users who have fabrikam.com email addresses. What should you do? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point. Answer:

Answer Area

  • To allow access for users who have fabrikam.com email addresses, configure:An access package policy in Identity Governance
    An access package assignment in Identity GovernanceAn access package policy in Identity GovernanceA conditional access policy in Azure ADThe External collaboration settings in Azure AD
  • To block access for users who have litwareinc.com email addresses, configure:The External collaboration settings in Azure AD
    An access package assignment in Identity GovernanceAn access package policy in Identity GovernanceA conditional access policy in Azure ADThe External collaboration settings in Azure AD

How the community answered

(1 responses)
  • An access package assignment in Identity Governance|An access package policy in Identity Governance
    100% (1)

Explanation

This question tests your knowledge of Azure AD Entitlement Management connected organizations and how to restrict access packages to specific domains within a partner organization that has multiple verified domains.

Approach. When you create a connected organization for Fabrikam, it initially includes all verified domains (fabrikam.com and litwareinc.com). To restrict package1 to only fabrikam.com email addresses, you need to edit the connected organization and remove the litwareinc.com domain from it, leaving only fabrikam.com. Then, in the access package policy, set the requestor scope to 'All members (users) of connected organizations' or specifically target the Fabrikam connected organization. By removing litwareinc.com from the connected organization's domain list, only users with fabrikam.com email addresses will be recognized as members of that connected organization and thus eligible to request package1.

Concept tested. Azure AD Entitlement Management - Connected Organizations and domain-based access restriction for access packages. Specifically, how to manage which domains are associated with a connected organization to control which external users can request an access package.

Reference. https://learn.microsoft.com/en-us/azure/active-directory/governance/entitlement-management-organization

Topics

#entitlement management#access packages#connected organizations#external collaboration

Community Discussion

No community discussion yet for this question.

Full SC-300 Practice