An auditor requires that nobody who can raise a supplier payment can also approve one. Both capabilities are granted through access packages, and the block must take effect when the second package is requested rather than being found afterwards. What should you recommend?
- A.
Create a quarterly access review of both access packages and ask the reviewers to remove anyone holding both
- B.
Require two-stage approval on both access packages so that a second approver notices the conflict before granting access
- C.
Add a Conditional Access policy that blocks sign-in to the payments application when the user is a member of both groups
- D.
Configure the two access packages as incompatible with each other in entitlement management, so a request is blocked while the user holds the other
Show answer
Answer: D
Entitlement management can mark access packages as incompatible, which prevents the request at the point of request rather than detecting the conflict later.
- A. A quarterly review detects the conflict after the fact and relies on reviewers correlating two packages themselves.
- B. Two-stage approval adds another human judgement and still depends on the approver knowing what else the requester holds.
- C. Conditional Access blocks a sign-in rather than the entitlement, leaving the conflicting access assigned and other systems unaffected.
- D. Incompatible access packages are checked during the request, so the conflicting combination is never granted in the first place.
