An organization uses Microsoft Entra ID Governance Access Packages to manage external partner access. A security engineer needs to ensure that external users automatically lose access when their access package assignment expires, without requiring manual intervention. Which feature should be configured?
Select an answer to reveal the explanation.
Short Explanation and Infographic
Here's the deal — b is correct because Microsoft Entra ID Governance lifecycle workflows can be configured to trigger leaver workflows based on access package expiration attributes, automatically removing access and disabling accounts when assignments expire. A is incorrect because while access packages have expiration policies that remove the package assignment, additional lifecycle workflow automation ensures all downstream access is also removed automatically.
Full explanation below image
Full Explanation
B is correct because Microsoft Entra ID Governance lifecycle workflows can be configured to trigger leaver workflows based on access package expiration attributes, automatically removing access and disabling accounts when assignments expire. A is incorrect because while access packages have expiration policies that remove the package assignment, additional lifecycle workflow automation ensures all downstream access is also removed automatically. C is incorrect because session token lifetime policies control session duration, not access package membership or group membership removal. D is incorrect because access reviews require periodic triggers and reviewer action, not automatic removal on a specific expiration date.