SC-300 - Plan and Automate Identity Governance (25% of the exam) - Section 4.3

Plan, implement, and manage access reviews in Microsoft Entra.

Create access reviews in Microsoft Entra with appropriate scope, recurrence, and reviewer assignments for group memberships, application access, and privileged roles. Enable automatic apply results so that access is removed when reviewers do not respond, and monitor completion rates and outcomes.

access review scopereviewers and recurrenceaccess review monitoringautomatic apply resultsresponding to reviews

Practice question for this objective

Free samplePlan and Automate Identity Governancemedium

A governance architect must design an access review that covers users with eligible and active assignments to the Global Administrator role and ensures the review repeats every three months. The review must target the privileged role assignments specifically rather than a group or application. Which review resource type should the architect select?

  • ACreate the access review on a security group that contains the role members, then set the recurrence to quarterly so the role assignments are reviewed indirectly through the group.
  • BCreate an access review for the Microsoft Entra role in Privileged Identity Management, scoped to Global Administrator with a quarterly recurrence covering eligible and active assignments. Correct
  • CCreate the access review on the enterprise application that represents the directory, then schedule it quarterly to capture everyone who holds the Global Administrator role.
  • DCreate an access package in entitlement management for the Global Administrator role, then attach a quarterly access review to that package to cover the role holders.
Access reviews that target Microsoft Entra privileged role assignments, including eligible and active, are created through Privileged Identity Management. Reviewing who holds a directory role requires an access review created in Privileged Identity Management for that Microsoft Entra role, which directly enumerates eligible and active assignments and supports recurrence. Group, application, and access-package reviews target different objects and cannot review the role assignments themselves.

Why A is wrong: Reviewing a security group reviews group membership, not the role assignments themselves, and the membership may not match who actually holds the role, so it does not directly target the privileged role.

Why B is correct: Access reviews for Microsoft Entra roles are created in Privileged Identity Management, target the role directly, include eligible and active assignments, and support a quarterly recurrence, matching every requirement.

Why C is wrong: An enterprise application review covers that application's assignments, not Microsoft Entra directory role membership, so it would not enumerate eligible and active Global Administrator holders as required.

Why D is wrong: Entitlement management governs access packages for resources rather than directory role assignments, so an access package cannot enumerate eligible and active Global Administrator assignments for review.

See more SC-300 practice questions, answers explained.

Exam traps in Plan and Automate Identity Governance

Answers that look right on this material and are not. Each one is a distractor from a different question in the SC-300 bank for this domain.

  • Create a lifecycle workflow with a leaver task that runs quarterly, detects guest accounts that have become inactive, and deletes any guest whose sponsor has left the organisation.

    Why it is wrong: Lifecycle workflows automate employee joiner, mover, and leaver tasks driven by attributes such as employeeHireDate, and they do not put a sponsor in the loop to approve continued guest access, so they cannot perform sponsor-reviewed removal.

  • Set the 'If reviewers don't respond' option to Remove access so undecided members lose their membership

    Why it is wrong: This is the right setting but the wrong value; choosing Remove access would strip undecided members, the opposite of the team's requirement to retain access.

  • Set the reviewers to the group owners instead of selected users, because owner-made decisions are the only decisions Microsoft Entra ID will enforce on a group's membership.

    Why it is wrong: The reviewer type changes who decides, not whether decisions are enforced, and decisions from any reviewer can be applied, so changing reviewers does not cause denied members to be removed.

Examworthy is not affiliated with or endorsed by Microsoft. Original, blueprint-aligned practice material only.