SC-300 - Plan and Automate Identity Governance (25% of the exam) - Section 4.1

Plan and implement entitlement management with catalogs and access packages in Microsoft Entra.

Design entitlement management catalogs and access packages that bundle resources, define approval and assignment policies, and allow users to self-request access. Configure expiry, review, and automatic removal so access rights align with the principle of least privilege over time.

entitlement managementcatalogsaccess packagesaccess requestsapproval and assignment policies

Practice question for this objective

Free samplePlan and Automate Identity Governancemedium

An identity governance team publishes access packages that partner staff should be able to request for themselves. The partners sign in with their own Microsoft Entra tenant, and the team wants those external users to discover and request the packages directly while keeping the requests scoped to that one partner. Which Microsoft Entra entitlement management object must the administrator define so that users from the partner tenant are recognised as an eligible external requestor population?

  • AA B2B direct connect trust that maps the partner tenant into shared channels for requestors
  • BA dynamic membership group that captures partner guest accounts once they have been invited
  • CA cross-tenant access setting that enables inbound B2B collaboration for the partner tenant
  • DA connected organization that references the partner tenant as an allowed external requestor source Correct
A connected organization registers an external directory so its users form a known population that entitlement management access package policies can offer self-service requests to. Entitlement management uses connected organizations to model external partners. Registering the partner tenant as a connected organization lets an access package assignment policy scope self-service requests to users from that specific directory, which is why the other constructs, while related to external access, do not establish the requestor population.

Why A is wrong: B2B direct connect enables shared channel access without guest objects but is not how entitlement management identifies an external requestor population for access packages.

Why B is wrong: A dynamic group can collect existing guests but cannot make a partner directory a recognised external requestor source before any user is onboarded.

Why C is wrong: Cross-tenant access settings govern whether collaboration is permitted at all, but they do not define the external requestor population entitlement management offers packages to.

Why D is correct: A connected organization registers the partner directory so its users are treated as a known external population that access package assignment policies can target for self-service requests.

See more SC-300 practice questions, answers explained.

Exam traps in Plan and Automate Identity Governance

Answers that look right on this material and are not. Each one is a distractor from a different question in the SC-300 bank for this domain.

  • Create an access review that targets the three resources, so partner users are reviewed every 90 days and gain access through the review approval step once they request it.

    Why it is wrong: An access review recertifies existing access on a recurring schedule; it does not bundle resources for self-service request or grant new access, so it cannot deliver the requestable bundle described.

  • An access package, into which the listed resources are added so the delegated owner can build further access packages using only the package's resources

    Why it is wrong: An access package bundles resource roles for assignment to people, but it is not the container that scopes which resources a delegated owner may draw on; the catalog provides that boundary.

  • Add the partner tenant as an allowed external identity provider in the inter-tenant access cross-tenant settings, which automatically lets that tenant's users request any access package.

    Why it is wrong: Cross-tenant access settings establish B2B trust and inbound or outbound rules, but they do not register the partner as a request scope inside entitlement management, so partner users would still not appear as eligible requestors for packages.

Examworthy is not affiliated with or endorsed by Microsoft. Original, blueprint-aligned practice material only.