A large enterprise uses a Microsoft Entra ID Governance access package for AI platform access. The access package includes Azure Machine Learning workspace member role, Azure OpenAI user role, and AI data store access. A business partner organization needs access to the same resources for a 6-month project. Which Entitlement Management feature allows external users to request the access package?
Select an answer to reveal the explanation.
Short Explanation and Infographic
Here's the deal — a is correct because Microsoft Entra Entitlement Management supports 'connected organizations'—you can add the partner organization's Entra ID tenant as a connected organization and configure the access package policy to allow users from that tenant to request access. Partners can then use the My Access portal to request the access package, which goes through the configured approval workflow.
Full explanation below image
Full Explanation
A is correct because Microsoft Entra Entitlement Management supports 'connected organizations'—you can add the partner organization's Entra ID tenant as a connected organization and configure the access package policy to allow users from that tenant to request access. Partners can then use the My Access portal to request the access package, which goes through the configured approval workflow. This scales to many external users without manual invitation for each person. B is wrong because manually inviting each partner user and assigning roles individually does not scale, lacks the governed lifecycle management of access packages, and bypasses the approval workflow. C is wrong because creating a separate access package for external users is an option but is not necessary if the same resources are appropriate—the question asks about allowing external users to request the existing package. D is wrong because enabling access with no approval requirement removes governance controls for external access, which violates security best practices especially for AI platform access.