Objective external.users-tenantsSC-300

Implement and manage identities for external users and tenants

Objective external.users-tenants sits in Implement and manage user identities, which carries 22% of the Identity and Access Admin exam. The questions below are original, written from the official objective title above, and each explanation cites the Microsoft Azure page it rests on.

Objective title verbatim from the official objectives. Microsoft Azure exam page

A worked example

Shown solved, with the whole explanation open: this is what every question here carries.

Implement and manage user identitiesHard

A security team discovers many B2B guest accounts already in the directory that were never added through an access package request. The team wants a recurring process to confirm each guest still needs access and remove those who do not. Which feature fits?

Correct.

The concept

Governance features split by when they act. One decides whether access should be granted at all, creating the account as a side effect. Another runs on employment or contract events. A third asks on a repeating schedule whether an entitlement that already exists is still justified, and it is the only one that can clean up objects nobody requested through a governed path.

Why this answer

Because these guests already exist in the directory outside the access package request flow, recurring access reviews are the mechanism that periodically validates their continued need for access and removes them when it no longer applies.

  • Correct: access reviews are described as automating recurring reviews of existing guests and removing them when access is no longer needed.
  • BEntitlement management governs new requests and approvals for resources, it is not the tool for recertifying guests who bypassed that request process.
  • CLifecycle workflows automate tasks tied to employment status changes for internal workers, not recurring recertification of unmanaged guest accounts.
  • DPIM for Groups manages eligible role or group activation for privileged access, not general recertification of standing guest accounts.
  • EInbound provisioning creates and maintains identities from HR systems, it does not review or remove existing external guest accounts.
Read the sourceIdentity governance overview - Microsoft Learn
Verified against learn.microsoft.com · 2026-07-28
external identitiesaccess reviewsb2b guestsgovernance

Now you: objective external.users-tenants questions

No account needed. The explanation opens when you answer.

Sample question 1 of 3

Implement and manage user identitiesModerate

A company configures entitlement management so approved partner organizations can request access to a marketing app. A partner user's request is approved. What happens to that user's identity in the directory?

Sample question 2 of 3

Implement and manage user identitiesHard

A governance team wants guest users who currently hold no access package assignments removed from the directory automatically, even if no recurring review was ever scheduled for them. Which capability should they configure?

Sample question 3 of 3

Implement and manage user identitiesModerate

A partner accepts a B2B collaboration invitation to a workforce tenant. How are they represented afterwards?

Full Identity and Access Admin question bank coming

We’re writing the complete bank from the official objectives right now. Leave your email and we’ll tell you when it ships, nothing else, ever.

Read the sources

These are the official pages the questions above cite. Reading them is studying the objective from the primary source, which is what the explanations point you toward anyway.

More objectives in Implement and manage user identities