SC-300 - Plan and Automate Identity Governance (25% of the exam) - Section 4.2

Manage the lifecycle of external users, terms of use, and connected organizations.

Manage the lifecycle of external users by configuring terms of use, connected organizations, and access package expiration so that guest access is removed when it lapses. Use lifecycle workflows to automate joiner, mover, and leaver tasks triggered by HR-driven attribute changes.

terms of useexternal user lifecycleconnected organizationsaccess package expirationlifecycle workflows

Practice question for this objective

Free samplePlan and Automate Identity Governancemedium

An organisation publishes an access package that bundles internal HR systems and must be requestable by employees, but must never be discoverable or requestable by guest or external users brought in from connected organisations. Which assignment policy configuration on the access package enforces this?

  • AConfigure the assignment policy so that only users in the directory, scoped to specific internal groups, can request the package, leaving the For users not in your directory option disabled. Correct
  • BSet the policy so that external users from connected organisations can request access, then add a manual approval step that the resource owner uses to reject every guest request.
  • CCreate a separate catalog marked as internal and move the access package into it, because catalog visibility settings stop guests from requesting any package it contains.
  • DEnable the policy for all users in your directory and rely on a Conditional Access policy that blocks guest accounts from reaching the entitlement management request portal.
The requestor scope on an access package assignment policy determines whether internal users only, specific groups, or external users may discover and request the package. Each access package assignment policy defines a requestor scope. Restricting the scope to specific internal directory users or groups and not enabling the external-requestor option means guests and connected-organisation users never see or request the package. Catalog settings govern publishing, not requestor eligibility, and Conditional Access controls access rather than request discovery.

Why A is correct: The requestor scope on an assignment policy decides who may request a package, and limiting it to internal directory users while not enabling external requestors prevents guests from discovering or requesting it.

Why B is wrong: Allowing external users to request still makes the package discoverable to them and relies on a manual rejection each time, which is error-prone and does not prevent guests from requesting in the first place.

Why C is wrong: Catalog enablement controls whether packages can be published, not who may request a published package; the per-policy requestor scope, not the catalog, determines guest eligibility.

Why D is wrong: All users in your directory still includes existing guest accounts, and Conditional Access governs sign-in access rather than per-package requestor eligibility, so guests could still request the package.

See more SC-300 practice questions, answers explained.

Exam traps in Plan and Automate Identity Governance

Answers that look right on this material and are not. Each one is a distractor from a different question in the SC-300 bank for this domain.

  • An entitlement management access package that the new worker requests on their first day

    Why it is wrong: An access package requires a request and grants resources, but it is not driven by a hire-date attribute and cannot orchestrate joiner tasks on a schedule.

  • An access review scheduled to recur daily that examines all employee accounts and removes access from any worker whose manager declines to approve their continued membership.

    Why it is wrong: Access reviews depend on a reviewer making a decision each cycle rather than firing on a date attribute, so they cannot deterministically disable an account and strip groups exactly on a worker's last day without human input.

  • On the access package's resource roles, by removing each external user from the underlying groups on a schedule managed through a recurring lifecycle workflow leaver task.

    Why it is wrong: Editing resource roles or running a leaver workflow does not reset the entitlement management assignment record, so users could retain other access and the package would not require a fresh re-approved request, missing the intended control.

Examworthy is not affiliated with or endorsed by Microsoft. Original, blueprint-aligned practice material only.