How to Remove Unused Managed Identity Permissions in Entra Permissions Management
You have a Microsoft 365 subscription that is onboarded to Microsoft Entra Permissions Management. You need to identify managed identities that are assigned permissions and remove any permissions that have been unused for 90 days. The solution must minimize administrative effort. What should you do in the Entra Permissions Management portal?
Community Votes
67% of anonymous learners picked answer A. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
The question tests whether you know the difference between identifying unused permissions (reporting/querying) and removing them (Autopilot remediation) in Entra Permissions Management.
Microsoft Entra Permissions Management can automatically detect and revoke permissions that managed identities have not used for 90 days. This page confirms that an Autopilot rule is the correct, low-effort mechanism, while reports and audit queries only surface the data.
Choosing the Permissions analytics report (B) because it lists permissions unused for 90 days — but a report only surfaces data and leaves the actual revocation as manual administrative work.
Community Discussion (3 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
Autopilot rules in Microsoft Entra Permissions Management are the built-in automation engine for permissions hygiene: you define a condition (for example, permissions unused for 90 days, scoped to managed identities or service principals) and the rule performs the action automatically, such as revoking the unused permissions or triggering an alert. Because the requirement spans both identification and removal, and explicitly says to minimize administrative effort, an Autopilot rule is the only option that closes the loop by itself. As rvln7 put it, Autopilot rules "allow you to automatically revoke unused permissions based on a predefined policy." The 90-day unused condition is exactly the kind of threshold Autopilot supports for permissions on managed identities in onboarded Azure, AWS, and GCP environments.Why the Other Options Are Wrong
Scheduling a Permissions analytics report (B) does give visibility into permissions and their last-used date, but it is an output-only artifact: someone still has to open it, evaluate the findings, and remove each permission, which directly contradicts the minimal-effort requirement. That is the point armid makes with "remove" not sure how scheduling the report will help you. Reviewing service principals with privileged role assignments in Microsoft Entra Insights (C) focuses on directory role assignments rather than unused cloud resource permissions and offers no removal workflow. Running an audit query (D) is a forensic/investigation activity for tracing activity in the audit logs, not a governance control that revokes entitlements. Only Autopilot rules perform the action, not merely the discovery.Community Comment Notes
Most learners landed on A (67 votes) with reasoning that matches the official product behavior, and rvln7 explicitly flagged the report option as incorrect because it only identifies unused permissions. aleksandur_nasev argued for B on the grounds that the report identifies permissions unused for 90 days, which is true but stops short of the stated goal of removing them. armid's comment captures the deciding word in the stem — the solution must remove permissions, and manual removal is administrative effort. The dissenting vote therefore reflects a common reading error rather than a different product feature.Official Reference
Exam Strategy
Read the verb in the requirement carefully: 'identify' maps to reports, queries, and dashboards, while 'remove' or 'remediate' with minimal effort maps to Autopilot rules. In SC-300 scenarios, when the stem asks for both detection and action, pick the automation feature rather than the reporting feature.
Frequently Asked Questions
Why is a Permissions analytics report wrong if it shows permissions unused for 90 days?
The report only surfaces the unused permissions; a human must still review it and remove each permission, which does not meet the requirement to minimize administrative effort.
Can an Autopilot rule target managed identities specifically?
Yes. Autopilot rules scope by conditions such as identity type and last-used age, so managed identities holding unused permissions can be remediated automatically.
Related Analysis
Practice All SC-300 Questions
Access 80 questions with complete answers and detailed explanations.
View Full SC-300 Practice Test →