Using Microsoft Entra Permissions Management to find unused RBAC assignments
You have 10 Azure subscriptions that contain 100 role-based access control (RBAC) role assignments. You plan to consolidate the role assignments. You need to recommend a solution to identify which role assignments were NOT used during the last 90 days. The solution must minimize administrative effort. What should you include in the recommendation?
Community Votes
57% of anonymous learners picked answer D. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
Permissions Management (CIEM) reports unused permissions over time across many subscriptions; access reviews (B) assess whether a user should keep membership, not whether a role was used, and PIM (C) governs eligibility rather than usage.
To identify which RBAC role assignments across 10 subscriptions were not used in the last 90 days with minimal effort, use Microsoft Entra Permissions Management, whose analytics reveal unused permissions and identities that have not exercised a permission over a period, across multicloud subscriptions.
Choosing Entra access reviews (B) — they review whether users still need group/role membership, not whether a role assignment was actually used in the last 90 days.
Community Discussion (13 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
Microsoft Entra Permissions Management (a CIEM solution) provides usage analytics that show which identities have not used a permission (including RBAC role assignments) over a defined period such as 90 days, across many subscriptions, with minimal administrative effort. This directly answers the requirement to find unused role assignments.Why the Other Options Are Wrong
Microsoft Entra access reviews (B) ask reviewers whether a user should retain membership/assignment, but they do not measure whether the assignment was actually used. PIM (C) manages eligible/just-in-time assignment, not usage history. Defender for Cloud (A) focuses on security posture, not permission usage.Community Comment Notes
The community favored D (53 votes). Comments cite the Permissions Management overview and the three-step permissions-management operations guide showing it can report identities that have not used a permission in the last 90 days; a minority (B, 40 votes) confused access reviews with usage detection.Official Reference
Related Analysis
Practice All SC-100 Questions
Access 110 questions with complete answers and detailed explanations.
View Full SC-100 Practice Test →