Using Entra Permissions Management to discover permissions across Azure, AWS, and GCP

Design solutions for securing privileged access
Answer Correct answer: D — Entra Permissions Management discovers and reviews permissions across Azure, AWS, and GCP in a single multicloud view.

You have a multicloud environment that contains Azure, Amazon Web Services (AWS), and Google Cloud Platform (GCP) subscriptions. You need to discover and review role assignments across the subscriptions. What should you use?

  1. Azure Lighthouse
  2. Microsoft Defender for Identity
  3. Microsoft Entra ID Governance
  4. Microsoft Entra Permissions Management Correct Answer

Community Votes

D
80%
C
20%

80% of anonymous learners picked answer D. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

Permissions Management (CIEM) is purpose-built for multicloud permission discovery and review across Azure, AWS, and GCP; Entra ID Governance and Defender for Identity are single-cloud/AD-focused, and Lighthouse is for Azure cross-tenant delegation.

To discover and review role assignments across Azure, AWS, and GCP subscriptions in a multicloud environment, use Microsoft Entra Permissions Management, a CIEM solution that provides cross-cloud visibility and management of permissions.

Choosing Entra ID Governance (C) — it governs identities within Entra ID but does not provide cross-cloud (AWS/GCP) permission discovery like Permissions Management.

Community Discussion (3 comments)

Ali96 👍 2 Selected: D
Microsoft Entra Permissions Management is designed to provide visibility and management of permissions across multiple cloud platforms, including Azure, AWS, and GCP.
tuyi2 👍 2 Selected: D
https://learn.microsoft.com/en-us/entra/permissions-management/overview
676ae1a 👍 1 Selected: C
La opción correcta es Gobernanza de identidades de Microsoft Entra La Gobernanza de identidades de Microsoft Entra te permite descubrir y revisar las asignaciones de roles en todas las suscripciones de Azure, AWS y GCP de manera centralizada y eficiente.

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

Microsoft Entra Permissions Management (CIEM) is designed to discover and manage permissions across multiple cloud platforms, including Azure, AWS, and GCP, giving a centralized view of role assignments across the subscriptions.

Why the Other Options Are Wrong

Azure Lighthouse (A) is for delegating management of Azure resources to a partner/managing tenant, not for discovering AWS/GCP permissions. Defender for Identity (B) monitors on-premises AD DS only. Entra ID Governance (C) manages identity lifecycle within Entra ID but does not span AWS/GCP.

Community Comment Notes

The community favored D (80 votes). Comments cite the Permissions Management overview confirming cross-cloud (Azure, AWS, GCP) visibility; a minority (C, 20 votes) mistakenly suggested Entra ID Governance.

Official Reference

Related Analysis

Practice All SC-100 Questions

Access 110 questions with complete answers and detailed explanations.

View Full SC-100 Practice Test →

← Back to SC-100 Study Guide