SC-300 · Question #89
Hotspot Question Your company has an Azure Active Directory (Azure AD) tenant named contoso.com. The company has a business partner named Fabrikam, Inc. Fabrikam uses Azure AD and has two verified…
The correct answer is To allow access for users who have fabrikam.com email addresses, configure:: An access package policy in Identity Governance; To block access for users who have litwareinc.com email addresses, configure:: The External collaboration settings in Azure AD. This question tests your knowledge of Azure AD Entitlement Management connected organizations and how to restrict access packages to specific domains within a partner organization that has multiple verified domains.
Question
Answer Area
- To allow access for users who have fabrikam.com email addresses, configure:An access package policy in Identity GovernanceAn access package assignment in Identity GovernanceAn access package policy in Identity GovernanceA conditional access policy in Azure ADThe External collaboration settings in Azure AD
- To block access for users who have litwareinc.com email addresses, configure:The External collaboration settings in Azure ADAn access package assignment in Identity GovernanceAn access package policy in Identity GovernanceA conditional access policy in Azure ADThe External collaboration settings in Azure AD
How the community answered
(1 responses)- An access package assignment in Identity Governance|An access package policy in Identity Governance100% (1)
Explanation
This question tests your knowledge of Azure AD Entitlement Management connected organizations and how to restrict access packages to specific domains within a partner organization that has multiple verified domains.
Approach. When you create a connected organization for Fabrikam, it initially includes all verified domains (fabrikam.com and litwareinc.com). To restrict package1 to only fabrikam.com email addresses, you need to edit the connected organization and remove the litwareinc.com domain from it, leaving only fabrikam.com. Then, in the access package policy, set the requestor scope to 'All members (users) of connected organizations' or specifically target the Fabrikam connected organization. By removing litwareinc.com from the connected organization's domain list, only users with fabrikam.com email addresses will be recognized as members of that connected organization and thus eligible to request package1.
Concept tested. Azure AD Entitlement Management - Connected Organizations and domain-based access restriction for access packages. Specifically, how to manage which domains are associated with a connected organization to control which external users can request an access package.
Topics
Community Discussion
No community discussion yet for this question.