BrainyBeeBrainyBee
ExploreBlogStart Studying
HomeDesigning Microsoft Azure Infrastructure Solutions (AZ-305)Quick Note — Recommend a Solution for Identity Governance
LO Quick Note817 words

Quick Note — Recommend a Solution for Identity Governance

AZ-305 › Unit 1 › Design governance › Recommend a solution for identity governance

Quick Note — Recommend a Solution for Identity Governance

This lesson is about Microsoft Entra ID Governance — the control plane that decides who gets what access, for how long, and under what conditions. We cover Privileged Identity Management (PIM), access reviews, Entitlement Management (access packages), Terms of Use, and the Entra P1 versus P2 licensing line. Identity governance is distinct from authentication (covered in LO4) and Azure RBAC role design (covered in LO6): governance is the lifecycle and oversight layer that sits on top of whatever identities and roles you already have.

Retrieval target

Objective
Recommend a Solution for Identity Governance
Mode
Closed-book recall
Target time
5 minutes
Escalation
Open the full lesson after a miss

Decision anchors

PromptCompact answer
Privileged Identity Management (PIM)An Entra ID P2 service for controlling standing admin privilege. Manages Entra directory roles, Azure RBAC roles, and PIM-for-groups memberships. Lets you mark assignments as eligible (activate on demand) instead of always-on, with optional MFA, justification, approval, and time limits. Every activation is logged for audit.
Access reviewA recurring (or one-off) attestation campaign where designated reviewers — managers, group owners, the users themselves, or selected users — confirm whether a user still needs a group membership, app access, or role assignment. Configurable outcome: keep, remove, or auto-remove if not reviewed. Available for groups, apps, Entra roles, Azure roles, and access packages. Requires Entra ID P2.
Entitlement ManagementAn Entra ID P2 module that packages groups + apps + sites + role assignments into self-serve access packages, gated by approval workflows and time-bound. Lets a business owner publish 'request access to the Sales tools bundle' instead of IT manually granting each resource. Includes built-in B2B guest onboarding if the request comes from outside the tenant.
Access packageThe unit of self-serve access in Entitlement Management — a bundle of resource roles (group memberships, enterprise-app assignments, SharePoint site roles) plus policies that say who can request it, who must approve, what justification is required, and how long the assignment lasts. Lives inside a catalog.

Read the answers once, then cover the right-hand column and reconstruct each one from the prompt. A useful answer names the requirement, the recommended control or service boundary, and the nearest alternative it rejects. If you can only recognize the answer after seeing it, retrieval is not yet secure.

Turn recall into an architecture answer

For recommend a solution for identity governance, state: choose X because constraints A and B apply; reject Y because it fails C; validate with evidence D.

Ninety-second explanation

Without notes, explain:

  1. What requirement signals this learning objective rather than a neighbouring one?
  2. Which two solution families are most likely to be compared?
  3. Which hard constraint eliminates the strongest distractor?
  4. What identity, network, data, or failure boundary must appear in the design?
  5. Which operational test would prove the recommendation works?

Then compare your explanation with the full lesson. Record the missing decision rule—not merely the missed product name—in your error log.

Loading flashcards…

When to open the full lesson

Open the curriculum-linked lesson when you cannot explain a comparison, when a scenario depends on a numeric limit or SKU feature, or when the service is on a retirement path. Use current Microsoft Learn documentation for availability, limits, pricing, naming, and migration milestones; the quick note is intentionally compact.

Source and freshness

Derived from the linked AZ-305 lesson and retrieval deck, grounded in both attached course sources. Reviewed 2026-08-02. Current Microsoft documentation controls changing product contracts.

All Designing Microsoft Azure Infrastructure Solutions (AZ-305) Study Resources

Related Notes

  • Recommend a Solution for Identity Governance — Lesson5,997 words
  • AZ-305 Exam Map and Design Decision Playbook652 words
  • Unit 1 Capstone — Design identity, governance, and monitoring solutions668 words
  • Unit 1 Roadmap — Design identity, governance, and monitoring solutions639 words
  • Cram Sheet — Design authentication and authorization solutions632 words
  • Design Authentication and Authorization Solutions — Lesson4,263 words
  • Design Studio — Design authentication and authorization solutions734 words
  • Quick Note — Recommend an Authentication Solution758 words
  • Recommend an Authentication Solution — Lesson4,868 words
  • Quick Note — Recommend an Identity Management Solution796 words
  • Recommend an Identity Management Solution — Lesson5,982 words
  • Quick Note — Recommend a Solution for Authorizing Access to Azure Resources745 words

Ready to study Designing Microsoft Azure Infrastructure Solutions (AZ-305)?

Practice tests, flashcards, and all study notes — free, no sign-up.

Start Studying

Ready to study Designing Microsoft Azure Infrastructure Solutions (AZ-305)?

Practice tests, flashcards, and all study notes — free, no sign-up needed.

Start Studying — Free
Designing Microsoft Azure Infrastructure Solutions (AZ-305) ResourcesExplore All HivesBlogHome

© 2026 BrainyBee. Free AI-powered exam prep.

Recommend a Solution for Identity Governance — quick retrieval

Card 1 of 4

Front of flashcard 1 of 4

Privileged Identity Management (PIM)

easy

An Entra ID P2 service for controlling standing admin privilege. Manages Entra directory roles, Azure RBAC roles, and PIM-for-groups memberships. Lets you mark assignments as eligible (activate on demand) instead of always-on, with optional MFA, justification, approval, and time limits. Every activation is logged for audit.

pimjust-in-time

Recommend a Solution for Identity Governance — quick retrieval

Card 1

Front

Privileged Identity Management (PIM)

Back

An Entra ID P2 service for controlling standing admin privilege. Manages Entra directory roles, Azure RBAC roles, and PIM-for-groups memberships. Lets you mark assignments as eligible (activate on demand) instead of always-on, with optional MFA, justification, approval, and time limits. Every activation is logged for audit.

Card 2

Front

Access review

Back

A recurring (or one-off) attestation campaign where designated reviewers — managers, group owners, the users themselves, or selected users — confirm whether a user still needs a group membership, app access, or role assignment. Configurable outcome: keep, remove, or auto-remove if not reviewed. Available for groups, apps, Entra roles, Azure roles, and access packages. Requires Entra ID P2.

Card 3

Front

Entitlement Management

Back

An Entra ID P2 module that packages groups + apps + sites + role assignments into self-serve access packages, gated by approval workflows and time-bound. Lets a business owner publish 'request access to the Sales tools bundle' instead of IT manually granting each resource. Includes built-in B2B guest onboarding if the request comes from outside the tenant.

Card 4

Front

Access package

Back

The unit of self-serve access in Entitlement Management — a bundle of resource roles (group memberships, enterprise-app assignments, SharePoint site roles) plus policies that say who can request it, who must approve, what justification is required, and how long the assignment lasts. Lives inside a catalog.

Recommend a Solution for Identity Governance — quick retrieval

Card 1

Front

Privileged Identity Management (PIM)

Back

An Entra ID P2 service for controlling standing admin privilege. Manages Entra directory roles, Azure RBAC roles, and PIM-for-groups memberships. Lets you mark assignments as eligible (activate on demand) instead of always-on, with optional MFA, justification, approval, and time limits. Every activation is logged for audit.

Card 2

Front

Access review

Back

A recurring (or one-off) attestation campaign where designated reviewers — managers, group owners, the users themselves, or selected users — confirm whether a user still needs a group membership, app access, or role assignment. Configurable outcome: keep, remove, or auto-remove if not reviewed. Available for groups, apps, Entra roles, Azure roles, and access packages. Requires Entra ID P2.

Card 3

Front

Entitlement Management

Back

An Entra ID P2 module that packages groups + apps + sites + role assignments into self-serve access packages, gated by approval workflows and time-bound. Lets a business owner publish 'request access to the Sales tools bundle' instead of IT manually granting each resource. Includes built-in B2B guest onboarding if the request comes from outside the tenant.

Card 4

Front

Access package

Back

The unit of self-serve access in Entitlement Management — a bundle of resource roles (group memberships, enterprise-app assignments, SharePoint site roles) plus policies that say who can request it, who must approve, what justification is required, and how long the assignment lasts. Lives inside a catalog.