Integrating Active Directory with Azure AD: Ensuring Group Owner Notifications for Membership Management

Group Membership Management Notifications

Question

Your network contains an on-premises Active Directory forest.

You discover that when users change jobs within your company, the membership of the user groups are not being updated. As a result, the users can access resources that are no longer relevant to their job.

You plan to integrate Active Directory and Azure Active Directory (Azure AD) by using Azure AD Connect.

You need to recommend a solution to ensure that group owners are emailed monthly about the group memberships they manage.

What should you include in the recommendation?

Answers

Explanations

Click on the arrows to vote for the correct answer

A. B. C. D.

A

https://docs.microsoft.com/en-us/azure/active-directory/governance/access-reviews-overview

The solution to ensure that group owners are emailed monthly about the group memberships they manage, after integrating on-premises Active Directory with Azure Active Directory (Azure AD) using Azure AD Connect, is Azure AD access reviews (option A).

Azure AD access reviews allow administrators to review and manage group memberships periodically. Group owners can be notified by email to review group memberships and remove any unnecessary access. This feature helps ensure that users only have access to the resources they need to do their jobs, and access is removed when it is no longer required.

Option B (Tenant Restrictions) is not relevant to this scenario, as it is used to restrict access to Azure AD tenant for specific IP addresses or locations.

Option C (Azure AD Identity Protection) is a feature that helps secure access to applications and data by providing risk-based conditional access policies. However, it is not relevant to the scenario described in the question.

Option D (Conditional access policies) is another feature that helps secure access to applications and data by setting policies based on user, device, location, and other factors. However, it is not directly relevant to the scenario described in the question as it does not provide a mechanism for group owners to review and manage group memberships.

Therefore, the correct recommendation in this scenario is option A (Azure AD access reviews).