20+ practice questions focused on Describe the capabilities of Microsoft Entra — one of the most tested topics on the Microsoft Security, Compliance, and Identity Fundamentals SC-900 exam. Each question includes a detailed explanation so you learn why the right answer is correct.
Start Describe the capabilities of Microsoft Entra PracticeA security team is using Microsoft Entra ID Protection. They want to automatically block sign-ins from known malicious IP addresses, but if a user's account is compromised (e.g., leaked credentials), they want to force the user to change their password upon next sign-in. Which two risk policies should they configure? (Select all that apply.)
Explanation: The sign-in risk policy in Microsoft Entra ID Protection can be configured to automatically block access when a sign-in is detected as high risk, such as from a known malicious IP address. This policy evaluates real-time risk signals during authentication and enforces the specified action (e.g., 'Block access'). The user risk policy, on the other hand, evaluates the cumulative risk of a user account (e.g., leaked credentials) and can be configured to require a password change upon next sign-in for high-risk users.
A company uses Microsoft Entra ID (Azure AD). The security team wants to create a Conditional Access policy that meets the following requirements: - Require multi-factor authentication (MFA) when users access a sensitive financial application from an untrusted network. - Additionally, require that the device accessing the app is compliant with company policies (e.g., encryption enabled). Which two conditions should the team configure in the Conditional Access policy? (Choose two.)
Explanation: Both (Location) and (Device state) are correct. (Location) is correct because the policy requires MFA when users access the sensitive financial application from an untrusted network. In Microsoft Entra ID Conditional Access, the Location condition uses named locations (such as trusted IP ranges or countries) to determine whether a network is trusted or untrusted, enabling the policy to trigger MFA only when access originates from an untrusted location. (Device state) is correct because the policy requires that the device accessing the app is compliant with company policies. The Device state condition allows you to enforce requirements like 'Require device to be marked as compliant' or 'Require Hybrid Microsoft Entra ID joined device'.
A company uses Microsoft Entra ID. They want to enforce that users accessing the finance app from outside the corporate network must use multifactor authentication (MFA) and access from a device marked as compliant. Additionally, if the user's sign-in risk is medium or higher, access must be blocked. Which component of a Conditional Access policy should the administrator configure to specify the 'Block access' action for high-risk sign-ins?
Explanation: The 'Block access' action is specified within the Grant controls section of a Conditional Access policy. Grant controls allow administrators to either require specific conditions (like MFA or compliant device) to be met for access to be granted, or to explicitly block access entirely. By selecting 'Block access' in the Grant controls, the policy enforces that any user meeting the policy's conditions (such as high sign-in risk) is denied access.
A company uses Microsoft Entra ID. They want to require users to perform multifactor authentication (MFA) every 30 days on devices that are marked as compliant, but require MFA for every sign-in attempt on non-compliant devices. Which Conditional Access control should they configure to meet this requirement?
Explanation: The requirement specifies different MFA frequency based on device compliance: every 30 days for compliant devices and every sign-in for non-compliant devices. This is achieved by configuring a Session control called 'Sign-in frequency' in a Conditional Access policy, which allows administrators to set the reauthentication interval (e.g., 30 days) and can be scoped to specific conditions like device state (compliant vs. non-compliant). Grant controls like 'Require MFA' enforce MFA but do not control the frequency of re-prompting.
A company wants to allow external customers to sign in to a custom web application using their existing Google or Facebook accounts. Which Microsoft Entra ID feature should they use?
Explanation: Microsoft Entra ID B2C (Business-to-Consumer) is the correct feature because it is specifically designed for customer-facing applications that need to support external identity providers like Google and Facebook. It allows users to sign in with their existing social accounts via OAuth 2.0 and OpenID Connect protocols, while providing customizable user journeys and branding. This is distinct from B2B collaboration, which is intended for business partner access to enterprise resources.
+15 more Describe the capabilities of Microsoft Entra questions available
Practice all Describe the capabilities of Microsoft Entra questions1. Baseline your knowledge
Start with 10 questions to gauge your current understanding of Describe the capabilities of Microsoft Entra. This tells you whether you need a concept refresher or just practice.
2. Review every explanation
For each question — right or wrong — read the full explanation. Understanding why an answer is correct is more valuable than knowing the answer itself.
3. Focus on exam traps
Describe the capabilities of Microsoft Entra questions on the SC-900 frequently use trap wording. Look for subtle differences in answers that test your precision, not just general knowledge.
4. Reach 80% consistently
Do repeated sessions until you score 80%+ three times in a row. Then move to mixed-mode practice to test cross-topic recall under realistic conditions.
The exact number varies per candidate. Describe the capabilities of Microsoft Entra is tested as part of the Microsoft Security, Compliance, and Identity Fundamentals SC-900 blueprint. Practicing with targeted Describe the capabilities of Microsoft Entra questions ensures you can handle any format or difficulty that appears.
Yes. Courseiva provides free SC-900 practice questions across all exam topics and domains. The platform includes topic-based practice, mock exams, missed-question review, bookmarked questions, and readiness tracking — no account required.
Difficulty is subjective, but Describe the capabilities of Microsoft Entra is a high-priority exam concept tested in multiple ways — direct recall, scenario analysis, and command-output interpretation. Consistent practice is the best way to build confidence.
Launch a full Describe the capabilities of Microsoft Entra practice session with instant scoring and detailed explanations.
Start Describe the capabilities of Microsoft Entra Practice →