20+ practice questions focused on Describe the capabilities of Microsoft Entra — one of the most tested topics on the Microsoft Security, Compliance, and Identity Fundamentals SC-900 exam. Each question includes a detailed explanation so you learn why the right answer is correct.
Start Describe the capabilities of Microsoft Entra PracticeA security team is using Microsoft Entra ID Protection. They want to automatically block sign-ins from known malicious IP addresses, but if a user's account is compromised (e.g., leaked credentials), they want to force the user to change their password upon next sign-in. Which two risk policies should they configure? (Select all that apply.)
Explanation: The sign-in risk policy in Microsoft Entra ID Protection can be configured to automatically block access when a sign-in is detected as high risk, such as from a known malicious IP address. This policy evaluates real-time risk signals during authentication and enforces the specified action (e.g., 'Block access'). The user risk policy, on the other hand, evaluates the cumulative risk of a user account (e.g., leaked credentials) and can be configured to require a password change upon next sign-in for high-risk users.
A company uses Microsoft Entra ID (Azure AD). The security team wants to create a Conditional Access policy that meets the following requirements: - Require multi-factor authentication (MFA) when users access a sensitive financial application from an untrusted network. - Additionally, require that the device accessing the app is compliant with company policies (e.g., encryption enabled). Which two conditions should the team configure in the Conditional Access policy? (Choose two.)
Explanation: Both (Location) and (Device state) are correct. (Location) is correct because the policy requires MFA when users access the sensitive financial application from an untrusted network. In Microsoft Entra ID Conditional Access, the Location condition uses named locations (such as trusted IP ranges or countries) to determine whether a network is trusted or untrusted, enabling the policy to trigger MFA only when access originates from an untrusted location. (Device state) is correct because the policy requires that the device accessing the app is compliant with company policies. The Device state condition allows you to enforce requirements like 'Require device to be marked as compliant' or 'Require Hybrid Azure AD joined device'.
A company wants to allow external customers to sign in to a custom web application using their existing Google or Facebook accounts. Which Microsoft Entra ID feature should they use?
Explanation: Microsoft Entra ID B2C (Business-to-Consumer) is the correct feature because it is specifically designed for customer-facing applications that need to support external identity providers like Google and Facebook. It allows users to sign in with their existing social accounts via OAuth 2.0 and OpenID Connect protocols, while providing customizable user journeys and branding. This is distinct from B2B collaboration, which is intended for business partner access to enterprise resources.
A company uses Microsoft Entra ID. They want to implement two security baseline requirements: (1) Users must register for multifactor authentication (MFA) before they can use self-service password reset (SSPR). (2) Administrators must have just-in-time (JIT) access to Azure resources with approval required. Which two Microsoft Entra features should they use? (Choose two.)
Explanation: Privileged Identity Management (PIM) is the correct feature for requirement (2) because it provides just-in-time (JIT) access to Azure resources, requiring approval for role activation. PIM allows administrators to request time-bound, approved elevation of privileges, meeting the JIT and approval requirement exactly. Combined registration for SSPR and MFA is the correct feature for requirement (1) as it unifies the registration experience for both, ensuring that users register for MFA when they register for SSPR, thereby meeting the prerequisite that MFA registration occurs before SSPR can be fully utilized.
You are a consultant helping a client migrate from on-premises Active Directory to Microsoft Entra ID. The client has a large number of user accounts and wants to synchronize identities while allowing users to use their existing on-premises passwords. Which tool should you recommend?
Explanation: Microsoft Entra Connect with password hash synchronization (PHS) is the correct tool because it synchronizes user identities from on-premises Active Directory to Microsoft Entra ID and allows users to keep their existing on-premises passwords by hashing and syncing password hashes to the cloud. This meets the client's requirement for identity synchronization without requiring password changes or additional infrastructure.
+15 more Describe the capabilities of Microsoft Entra questions available
Practice all Describe the capabilities of Microsoft Entra questions1. Baseline your knowledge
Start with 10 questions to gauge your current understanding of Describe the capabilities of Microsoft Entra. This tells you whether you need a concept refresher or just practice.
2. Review every explanation
For each question — right or wrong — read the full explanation. Understanding why an answer is correct is more valuable than knowing the answer itself.
3. Focus on exam traps
Describe the capabilities of Microsoft Entra questions on the SC-900 frequently use trap wording. Look for subtle differences in answers that test your precision, not just general knowledge.
4. Reach 80% consistently
Do repeated sessions until you score 80%+ three times in a row. Then move to mixed-mode practice to test cross-topic recall under realistic conditions.
The exact number varies per candidate. Describe the capabilities of Microsoft Entra is tested as part of the Microsoft Security, Compliance, and Identity Fundamentals SC-900 blueprint. Practicing with targeted Describe the capabilities of Microsoft Entra questions ensures you can handle any format or difficulty that appears.
Yes. Courseiva provides free SC-900 practice questions across all exam topics and domains. The platform includes topic-based practice, mock exams, missed-question review, bookmarked questions, and readiness tracking — no account required.
Difficulty is subjective, but Describe the capabilities of Microsoft Entra is a high-priority exam concept tested in multiple ways — direct recall, scenario analysis, and command-output interpretation. Consistent practice is the best way to build confidence.
Launch a full Describe the capabilities of Microsoft Entra practice session with instant scoring and detailed explanations.
Start Describe the capabilities of Microsoft Entra Practice →