Home › Forums › Azure › SC-300 Microsoft Identity and Access Administrator › Incorrect access review question
-
You manage a Microsoft 365 tenant that uses Microsoft Entra ID for identity and access management. The Sign-in activity report recently revealed that a guest contractor had signed up for the Exchange admin center.
To strengthen security, your manager suggests implementing Conditional Access policies to control guest sign-ins. However, your compliance team requires a recurring monthly review of guest access to the Exchange admin center, and mandates that any guest user who fails the review must be blocked from signing in.
Which solution should you implement to meet the compliance requirement?
<ul data-question_id=”15688″ data-type=”single”>
- A tenant-wide access review targeting all guest users with “Block sign-in, then remove” auto-apply.
- An access review of groups where guest accounts are members.
- An access review of apps where guest users are assigned.
- A Lifecycle Workflows automation to disable and remove guest accounts at offboarding.
Tutorials Dojo confirmed correct answer is An access review of groups where guest accounts are members as the access is granted through security groups. But there is no indication of security groups in the question. It only mentioned the application so the appopirate answer would be An access review of apps where guest users are assigned right.
Please validate and confirm.
Log in to reply.