Your Azure AD tenant (contoso.com) has a security group (Group1) with assigned membership containing 50 members, including 20 guest users. You must implement an automated membership review that runs every three months, lets each member indicate whether they still require membership, and automatically removes members who either indicate they do not need membership or fail to respond. What should you include in the recommendation?
Choose an answer
Tap an option to check your answer.
Correct answer: Create an access review..
Why this is the answer
Creating an access review directly addresses the requirement for automated membership review, allowing members to self-attest their continued need for access and automatically removing those who decline or don't respond. Azure AD Identity Protection focuses on detecting and remediating identity-based risks, not periodic access reviews. Changing the membership type to Dynamic User would automate membership based on user attributes, but it doesn't provide a mechanism for members to confirm their need for access or for automatic removal based on non-response. Azure AD Privileged Identity Management (PIM) manages just-in-time access for privileged roles and resources, which is a different use case than regular group membership review.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed