Describe the capabilities of Microsoft Entra
Identity Governance, Privilege, and Risk
CoreUse governance, access reviews, PIM, and ID Protection for lifecycle, privilege, and risk needs.
Aligned to the SC-900 skills measured as of July 28, 2026; product behavior verified September 10, 2026.
Why this matters
Access that was correct yesterday can become excessive today. Governance and protection capabilities help maintain appropriate access, reduce standing privilege, and respond to identity risk.
Must Know
- Microsoft Entra ID Governance helps ensure the right identities have the right access to the right resources at the right time through identity, access, and privileged-access lifecycle capabilities.
- Access reviews let organizations periodically recertify memberships, application access, and role assignments and remove access that is no longer justified.
- Privileged Identity Management (PIM) supports just-in-time and time-bound privileged access, approval, MFA, justification, notifications, and auditing for supported roles.
- Microsoft Entra ID Protection detects, investigates, and helps remediate identity-based risks such as risky users and risky sign-ins.
- Identity Protection risk signals can inform Conditional Access decisions; the products remain distinct.
Compare and Distinguish
- ID Governance vs ID Protection: access lifecycle and entitlement oversight versus detection and remediation of identity risk.
- Access review vs PIM: periodic confirmation of continuing access versus controlled activation and oversight of privileged roles.
- PIM eligible assignment vs active assignment: ability to activate when needed versus currently usable role privilege.
- ID Protection vs Conditional Access: risk detection and signals versus policy evaluation and enforcement.
Scenario examples
- A manager reviews whether contractors still need access to an application.
- An administrator activates an eligible privileged role for a limited period after approval.
- A risky sign-in signal causes a Conditional Access policy to require stronger verification or block access.
Exam traps
- An access review does not replace real-time sign-in risk detection.
- PIM does not eliminate the need for least privilege or access reviews.
- ID Protection detects risk; Conditional Access applies the configured access decision.
- Permanent broad privilege is not the same as just-in-time activation.
Key takeaways
- Govern access throughout its lifecycle.
- Use reviews to recertify access and PIM to control privileged activation.
- Use ID Protection for identity risk signals and remediation.
- Combine capabilities without treating them as synonyms.
Ready for the quiz?
- Which capability recertifies access?
- Which capability makes a role eligible for time-limited activation?
- How can ID Protection and Conditional Access work together?
Related objectives
- D2.4.S1 — Describe Microsoft Entra ID Governance
- D2.4.S2 — Describe access reviews
- D2.4.S3 — Describe the capabilities of Microsoft Entra Privileged Identity Management
- D2.4.S4 — Describe Microsoft Entra ID Protection