Temporary Access with Entra Entitlement Management
You have a Microsoft 365 subscription that contains a Microsoft SharePoint Online site named Site1 and a Microsoft 365 group named Group1. You need to ensure that the members of Group1 can access Site1 for 90 days. The solution must minimize administrative effort. What should you use?
Community Votes
100% of anonymous learners picked answer A. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
The core trap is confusing identity governance tools (access packages) with security policies (Conditional Access). Only entitlement management natively supports expiration-based access bundles with minimal admin effort.
This question tests the ability to configure temporary resource access in Microsoft Entra ID. The correct solution utilizes an access package to grant time-bound permissions while minimizing administrative overhead.
Learners often choose Conditional Access because it controls access, but they fail to realize it cannot automatically expire a user's membership or access rights after a set number of days without complex custom attributes and automation.
Community Discussion (3 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
An access package within Microsoft Entra Entitlement Management is designed specifically for this scenario. It allows administrators to bundle resources (like Site1 and Group1) and assign them to users or groups for a defined duration (90 days). Once the period expires, access is automatically revoked, satisfying the 'minimize administrative effort' requirement.Why the Other Options Are Wrong
Access reviews (B) are used to evaluate existing access, not to provision temporary access. Lifecycle workflows (C) can manage changes but require defining specific triggers and actions that are more complex than a simple expiration policy. Conditional Access (D) enforces conditions like location or device compliance but does not natively support automatic access expiration based on a timer for group membership.Community Comment Notes
Community consensus strongly favors Option A. Users note that access packages allow for automatic expiration, which directly addresses the 90-day constraint. One commenter highlighted that access packages are the standard method for granting related resources to users for a set time, effectively automating the lifecycle of the access.Exam Strategy
When you see 'temporary access', 'expiration', or 'bundle of resources', think immediately of Entitlement Management and Access Packages. Distinguish these from Conditional Access, which handles real-time security checks rather than time-based provisioning.
Frequently Asked Questions
Why not use Conditional Access for expiration?
Conditional Access evaluates requests at sign-in but cannot automatically revoke access or expire memberships after a fixed duration like 90 days.
Do access packages require user approval?
Not necessarily; you can configure them to auto-approve assignments for specific groups, minimizing administrative effort.
Related Analysis
Practice All SC-300 Questions
Access 80 questions with complete answers and detailed explanations.
View Full SC-300 Practice Test →