Exam objective

SC-300

Plan and implement entitlement management in Microsoft Entra

This objective sits in Plan and automate identity governance, which carries 28% of the Identity and Access Admin exam. The questions below are original, written from the official objective title above, and each explanation cites the Microsoft Azure page it rests on.

Objective title verbatim from the official objectives. Microsoft Azure exam page ↗

A worked example

Shown solved, with the whole explanation open: this is what every question here carries.

Plan and automate identity governance

An identity administrator wants a user's group memberships, app roles, and SharePoint site roles to be removed automatically on the project's fixed end date, regardless of whether any of the user's attributes ever change. What should be configured in entitlement management?

Create a dynamic group scoped to a project membership attributeDynamic groups also react to attribute changes on the user object, they don't enforce a date-based removal independent of attributes.
Configure an automatic assignment policy based on user attribute changesAutomatic assignment policies add or remove access based on changes to user attributes, not on a fixed calendar date unrelated to attribute changes.
Trigger a Logic App workflow when the access request is approvedLogic Apps triggered on request approval run custom workflow actions at request time, they don't provide scheduled date-based removal.
Configure lifecycle settings for the access package to set an expiration dateCorrect · your answerCorrect: lifecycle settings remove assignments on a specific date, matching the fixed project end date requirement.
Configure a recurring access review with automatic removal on denialRecurring access reviews depend on a reviewer's decision to remove access, not on an automatic fixed expiration date.

Correct.

Checked against learn.microsoft.com, July 2026

Concept

Entitlement management offers two distinct automation mechanisms for removing access packages: automatic assignment policies driven by attribute changes, and lifecycle settings driven by fixed dates or expiration rules.

Why D

Because removal must happen on a specific calendar date independent of attribute changes, lifecycle settings for the access package (expiration date) are the correct mechanism, not attribute-driven automatic assignment.

Source

Adding and removing a user's group memberships, application roles, and SharePoint site roles, on a specific date Configure lifecycle settings for an access package in entitlement management…

Identity governance overview, checked July 2026
#entitlement management#lifecycle settings#automatic assignment policy#access packages

Now you: practice questions

No account needed. The explanation opens when you answer.

Sample question 1 of 3

Plan and automate identity governance

A company wants identities from a partner organization to request access to its resources. Approved requesters must be added as guests automatically, and removed automatically when their access rights expire. Which capability should the company configure?

Sample question 2 of 3

Plan and automate identity governance

Which lifecycle activities does entitlement management automate?

Sample question 3 of 3

Plan and automate identity governance

Which resource types can entitlement management govern access to?

Full Identity and Access Admin question bank coming

We’re writing the complete bank from the official objectives right now. Leave your email and we’ll tell you when it ships, nothing else, ever.

Read the sources

These are the official pages the questions above cite. Reading them is studying the objective from the primary source, which is what the explanations point you toward anyway.

More objectives in Plan and automate identity governance