An organization wants to implement periodic reviews of which users have access to an AI model access group in Microsoft Entra ID. If a reviewer does not respond, access should be automatically removed. Which feature implements this?
Select an answer to reveal the explanation.
Short Explanation and Infographic
Here's the deal — b is correct because Microsoft Entra ID Governance Access Reviews allow administrators to schedule periodic reviews where resource owners or managers certify user access. When configured with the 'Apply results to resource' setting and 'Remove access' for non-respondents, users whose access is not explicitly approved are automatically removed after the review period.
Full explanation below image
Full Explanation
B is correct because Microsoft Entra ID Governance Access Reviews allow administrators to schedule periodic reviews where resource owners or managers certify user access. When configured with the 'Apply results to resource' setting and 'Remove access' for non-respondents, users whose access is not explicitly approved are automatically removed after the review period. A is wrong because user risk policies block sign-ins based on risk signals, not scheduled access certification. C is wrong because PIM expiration applies to eligible or active role assignments, not general group memberships. D is wrong because authentication context steps up authentication requirements for specific scenarios; it does not certify group membership.