How to Remove Unused Managed Identity Permissions in Entra Permissions Management

Plan and implement privileged access Monitor identity activity by using logs, workbooks, and reports
Answer Correct answer: A — Configure an Autopilot rule in Entra Permissions Management so unused managed identity permissions are automatically revoked after 90 days.

You have a Microsoft 365 subscription that is onboarded to Microsoft Entra Permissions Management. You need to identify managed identities that are assigned permissions and remove any permissions that have been unused for 90 days. The solution must minimize administrative effort. What should you do in the Entra Permissions Management portal?

  1. Configure an Autopilot rule. Correct Answer
  2. Schedule a Permissions analytics report.
  3. From Microsoft Entra Insights, review Service principals with privileged role assignments.
  4. Run an audit query.

Community Votes

A
67%
B
33%

67% of anonymous learners picked answer A. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

The question tests whether you know the difference between identifying unused permissions (reporting/querying) and removing them (Autopilot remediation) in Entra Permissions Management.

Microsoft Entra Permissions Management can automatically detect and revoke permissions that managed identities have not used for 90 days. This page confirms that an Autopilot rule is the correct, low-effort mechanism, while reports and audit queries only surface the data.

Choosing the Permissions analytics report (B) because it lists permissions unused for 90 days — but a report only surfaces data and leaves the actual revocation as manual administrative work.

Community Discussion (3 comments)

aleksandur_nasev 👍 1 Selected: B
Option B To achieve your goal of identifying and removing unused permissions for managed identities with minimal administrative effort, you should schedule a Permissions analytics report. This report will help you identify permissions that have been unused for 90 days, allowing you to take appropriate action to remove them
rvln7 👍 1 Selected: A
A. Configure an Autopilot rule → ✅ Correct Answer - Autopilot rules in Microsoft Entra Permissions Management allow you to automatically revoke unused permissions based on a predefined policy. - You can set a condition to remove permissions that have been unused for 90 days, minimizing manual work. B. Schedule a Permissions analytics report → ❌ Incorrect - This only identifies unused permissions but does not remove them. - It still requires manual intervention to review and revoke permissions, which is not the most efficient option.
armid 👍 1 Selected: A
"remove" not sure how scheduling the report will help you other than going in and manually remove the permissions which sounds like administrative effort

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

Autopilot rules in Microsoft Entra Permissions Management are the built-in automation engine for permissions hygiene: you define a condition (for example, permissions unused for 90 days, scoped to managed identities or service principals) and the rule performs the action automatically, such as revoking the unused permissions or triggering an alert. Because the requirement spans both identification and removal, and explicitly says to minimize administrative effort, an Autopilot rule is the only option that closes the loop by itself. As rvln7 put it, Autopilot rules "allow you to automatically revoke unused permissions based on a predefined policy." The 90-day unused condition is exactly the kind of threshold Autopilot supports for permissions on managed identities in onboarded Azure, AWS, and GCP environments.

Why the Other Options Are Wrong

Scheduling a Permissions analytics report (B) does give visibility into permissions and their last-used date, but it is an output-only artifact: someone still has to open it, evaluate the findings, and remove each permission, which directly contradicts the minimal-effort requirement. That is the point armid makes with "remove" not sure how scheduling the report will help you. Reviewing service principals with privileged role assignments in Microsoft Entra Insights (C) focuses on directory role assignments rather than unused cloud resource permissions and offers no removal workflow. Running an audit query (D) is a forensic/investigation activity for tracing activity in the audit logs, not a governance control that revokes entitlements. Only Autopilot rules perform the action, not merely the discovery.

Community Comment Notes

Most learners landed on A (67 votes) with reasoning that matches the official product behavior, and rvln7 explicitly flagged the report option as incorrect because it only identifies unused permissions. aleksandur_nasev argued for B on the grounds that the report identifies permissions unused for 90 days, which is true but stops short of the stated goal of removing them. armid's comment captures the deciding word in the stem — the solution must remove permissions, and manual removal is administrative effort. The dissenting vote therefore reflects a common reading error rather than a different product feature.

Official Reference

Exam Strategy

Read the verb in the requirement carefully: 'identify' maps to reports, queries, and dashboards, while 'remove' or 'remediate' with minimal effort maps to Autopilot rules. In SC-300 scenarios, when the stem asks for both detection and action, pick the automation feature rather than the reporting feature.

Frequently Asked Questions

Why is a Permissions analytics report wrong if it shows permissions unused for 90 days?

The report only surfaces the unused permissions; a human must still review it and remove each permission, which does not meet the requirement to minimize administrative effort.

Can an Autopilot rule target managed identities specifically?

Yes. Autopilot rules scope by conditions such as identity type and last-used age, so managed identities holding unused permissions can be remediated automatically.

Related Analysis

Practice All SC-300 Questions

Access 80 questions with complete answers and detailed explanations.

View Full SC-300 Practice Test →

← Back to SC-300 Study Guide