In an Azure AD tenant (contoso.com) Group1 uses assigned membership and contains 50 members (including 20 guest users). You must implement a recurring evaluation of Group1 membership that: repeats automatically every three months; allows each member to indicate whether they should remain in the group; automatically removes users who say they do not need membership; and automatically removes users who fail to respond. What should you implement?
Choose an answer
Tap an option to check your answer.
Correct answer: Create an access review..
Why this is the answer
Creating an access review directly addresses all requirements. Access reviews allow you to schedule recurring evaluations (every three months), prompt users to self-attest their need for group membership, and automatically remove users who deny access or fail to respond. Azure AD Identity Protection focuses on detecting and remediating identity-based risks, not group membership attestation. Changing the membership type to Dynamic User automates membership based on user attributes, but doesn't involve user attestation or scheduled reviews for existing members. Azure AD Privileged Identity Management (PIM) manages just-in-time access for privileged roles and resources, which is not the scenario described for Group1.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed