Using Microsoft Entra Permissions Management to find unused RBAC assignments

Design solutions for securing privileged access
Answer Correct answer: D — Microsoft Entra Permissions Management shows unused permissions and identities across subscriptions, identifying role assignments not used in 90 days.

You have 10 Azure subscriptions that contain 100 role-based access control (RBAC) role assignments. You plan to consolidate the role assignments. You need to recommend a solution to identify which role assignments were NOT used during the last 90 days. The solution must minimize administrative effort. What should you include in the recommendation?

  1. Microsoft Defender for Cloud
  2. Microsoft Entra access reviews
  3. Microsoft Entra Privileged Identity Management (PIM)
  4. Microsoft Entra Permissions Management Correct Answer

Community Votes

D
57%
B
43%

57% of anonymous learners picked answer D. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

Permissions Management (CIEM) reports unused permissions over time across many subscriptions; access reviews (B) assess whether a user should keep membership, not whether a role was used, and PIM (C) governs eligibility rather than usage.

To identify which RBAC role assignments across 10 subscriptions were not used in the last 90 days with minimal effort, use Microsoft Entra Permissions Management, whose analytics reveal unused permissions and identities that have not exercised a permission over a period, across multicloud subscriptions.

Choosing Entra access reviews (B) — they review whether users still need group/role membership, not whether a role assignment was actually used in the last 90 days.

Community Discussion (13 comments)

424ede1 👍 1 Selected: D
Microsoft Entra Permissions Management The answer is obvious in following Microsoft diagrams https://learn.microsoft.com/en-us/entra/architecture/permissions-manage-ops-guide-three
AleFerrillo 👍 1 Selected: D
EPM can tell you if an identity has not used a permission in the last 90 days
Lrrr_FromOmicronPersei8 👍 1 Selected: D
Entra Permissions Management
Sundaycorn 👍 2 Selected: B
Access reviews cover rbac roles which this question is asking. Microsoft Entrance Permissions Management covers users, groups, sites etc.
lam_15 👍 1 Selected: D
Microsoft Entra Permissions Management: https://learn.microsoft.com/en-us/entra/permissions-management/overview
RabbitB 👍 1 Selected: D
Entra Permissions Management. This explains everything. https://www.youtube.com/watch?v=-S-z3qx79YQ
oscarpopi 👍 1 Selected: D
Right answer is EPM -> 100 subscriptions and minimal effort.
Er_01 👍 1 Selected: C
The best answer is C as it can create a review every quarter to verify membership or self review access, which would give you a list. The question is incomplete as it leaves out the taking action part to remove stale access.
zpack 👍 2 Selected: D
Wrong answer, correct is D. Access review is to see if users should still belong to groups, not to see if a role wasn't used in 90 days.
Ali96 👍 1 Selected: B
Entra access reviews
reyreyg 👍 1 Selected: B
https://learn.microsoft.com/en-us/entra/id-governance/access-reviews-overview
676ae1a 👍 1 Selected: B
B.Reseñas de acceso a Microsoft Entra: Esta herramienta permite auditar y revisar el uso de roles y permisos en Azure, facilitando la identificación de asignaciones de roles que no se han utilizado. Puedes generar informes detallados y filtrar las asignaciones de roles según el período de tiempo especificado
AlbertE1nstein 👍 1 Selected: B
B. Microsoft Entra access reviews

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

Microsoft Entra Permissions Management (a CIEM solution) provides usage analytics that show which identities have not used a permission (including RBAC role assignments) over a defined period such as 90 days, across many subscriptions, with minimal administrative effort. This directly answers the requirement to find unused role assignments.

Why the Other Options Are Wrong

Microsoft Entra access reviews (B) ask reviewers whether a user should retain membership/assignment, but they do not measure whether the assignment was actually used. PIM (C) manages eligible/just-in-time assignment, not usage history. Defender for Cloud (A) focuses on security posture, not permission usage.

Community Comment Notes

The community favored D (53 votes). Comments cite the Permissions Management overview and the three-step permissions-management operations guide showing it can report identities that have not used a permission in the last 90 days; a minority (B, 40 votes) confused access reviews with usage detection.

Official Reference

Related Analysis

Practice All SC-100 Questions

Access 110 questions with complete answers and detailed explanations.

View Full SC-100 Practice Test →

← Back to SC-100 Study Guide