certslothcertsloth
SC-300/Topic 06

Microsoft / Associate

Entitlements, Access Reviews and Privileged Elevation

2 min read5 recall promptsReviewed 2026-10-10

Memory hook: Grant for a reason, expire on purpose, review with evidence.

Must remember

Entitlement management groups resources into access packages within catalogs. Policies define who can request, who approves, duration and lifecycle behavior. Connected organizations and terms of use support governed external collaboration. An approval workflow without expiry or owner review can leave access indefinitely.

Access reviews periodically ask accountable reviewers to confirm continuing need. Configure population, recurrence, recommendations and what happens to unreviewed/denied access. Review completion is not enough if removal decisions are never applied. Guests who leave a partner organization may still have local resource assignments unless lifecycle processes handle them.

Privileged Identity Management distinguishes eligible assignments from active access. Activation can require justification, MFA, approval and limited duration according to configuration. PIM manages supported Entra roles, Azure resource roles and group membership/ownership scenarios. Eligibility is not identical to an always-active role.

Monitor request/approval history and privileged actions. Protect emergency accounts outside common lockout paths, with strong credentials, tightly controlled use and alerting. Do not leave permanent broad privilege merely to make support convenient; also do not make recovery impossible by putting every administrator behind one fragile dependency.

Choose under exam pressure

Requirement Choice and reason
Partner needs temporary access to several resources Access package with approval and expiry.
Administrator occasionally needs a powerful role Eligible PIM assignment with controlled activation.
Confirm existing access still justified Access review with applied decisions.

Traps

  • An approved request does not justify access forever.
  • PIM eligibility does not automatically mean the role is active now.

Active recall

1. Catalog versus access package?

Container for governed resources versus a requestable bundle and its access policies.

2. What should follow a denied review?

Apply the configured access-removal decision and verify it.

3. Eligible versus active?

Can request/perform activation versus currently has the role’s privileges.

4. Why audit approvals?

To detect unjustified elevation, collusion or misuse.

5. Why design guest lifecycle?

External relationships change while local entitlements can persist.

Sources

CLOSE THE NOTES. EXPLAIN THE CHOICE.

How well could you recall it?

Your next review is based on this answer. Progress stays in this browser.

Search across every published topic.