SC-300 - Plan and Automate Identity Governance - Section 4.1

Plan and implement entitlement management with catalogs and access packages in Microsoft Entra.

Design entitlement management catalogs and access packages that bundle resources, define approval and assignment policies, and allow users to self-request access. Configure expiry, review, and automatic removal so access rights align with the principle of least privilege over time.

entitlement managementcatalogsaccess packagesaccess requestsapproval and assignment policies

Practice question for this objective

Free samplePlan and Automate Identity Governancemedium

An identity governance team publishes access packages that partner staff should be able to request for themselves. The partners sign in with their own Microsoft Entra tenant, and the team wants those external users to discover and request the packages directly while keeping the requests scoped to that one partner. Which Microsoft Entra entitlement management object must the administrator define so that users from the partner tenant are recognised as an eligible external requestor population?

  • AA B2B direct connect trust that maps the partner tenant into shared channels for requestors
  • BA dynamic membership group that captures partner guest accounts once they have been invited
  • CA cross-tenant access setting that enables inbound B2B collaboration for the partner tenant
  • DA connected organization that references the partner tenant as an allowed external requestor source Correct
A connected organization registers an external directory so its users form a known population that entitlement management access package policies can offer self-service requests to. Entitlement management uses connected organizations to model external partners. Registering the partner tenant as a connected organization lets an access package assignment policy scope self-service requests to users from that specific directory, which is why the other constructs, while related to external access, do not establish the requestor population.

Why A is wrong: B2B direct connect enables shared channel access without guest objects but is not how entitlement management identifies an external requestor population for access packages.

Why B is wrong: A dynamic group can collect existing guests but cannot make a partner directory a recognised external requestor source before any user is onboarded.

Why C is wrong: Cross-tenant access settings govern whether collaboration is permitted at all, but they do not define the external requestor population entitlement management offers packages to.

Why D is correct: A connected organization registers the partner directory so its users are treated as a known external population that access package assignment policies can target for self-service requests.

See more SC-300 practice questions, answers explained.

More in this domain

Back to all Plan and Automate Identity Governance objectives, or the SC-300 cert hub.

Examworthy is not affiliated with or endorsed by Microsoft. Original, blueprint-aligned practice material only.