AZ-305 Practice Question: Design identity, governance, and monitoring solutions
A company uses Microsoft Entra ID (Microsoft Entra ID). They want to allow users to sign in to multiple SaaS applications using their Microsoft Entra ID credentials without being prompted again for each application. Which Microsoft Entra ID feature should they enable?
⚠ Common exam trap
It's easy for candidates to confuse MFA or Conditional Access with SSO, thinking that additional security features inherently reduce sign-in prompts, but in reality, SSO is the specific feature designed to eliminate repeated prompts, while MFA and Conditional Access are complementary security controls that do not provide that functionality.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Single Sign-On (SSO)
Single Sign-On (SSO) enables users to authenticate once with Microsoft Entra ID and then access multiple SaaS applications without being prompted again. This works by using standards like SAML 2.0 or OpenID Connect to issue a session token or cookie that is reused across applications, eliminating repeated credential prompts.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Single Sign-On (SSO)
Why this is correct
SSO in Microsoft Entra ID uses the primary authentication token (e.g., SAML, OAuth2/OIDC) to establish a federated session, so subsequent application requests are silently authenticated without re-prompting. This works because Entra ID acts as the trusted broker that issues session cookies or refresh tokens, eliminating per-app credential entry. For this scenario, deploying SSO directly satisfies the requirement for one authentication followed by seamless access across all integrated applications.
- ✗
Multi-Factor Authentication (MFA)
Why it's wrong here
MFA requires a second verification factor (like a TOTP code or FIDO2 key) at initial sign-in, but it does not create or propagate a shared session across multiple applications. Even after MFA succeeds, each app that doesn't participate in the same Entra ID session will still prompt for credentials or its own MFA challenge. Thus, MFA strengthens security but fails to remove the repeated authentication prompts the user wants to eliminate.
- ✗
Conditional Access
Why it's wrong here
Conditional Access evaluates signals (user, device, location, risk) to enforce access policies such as blocking or requiring MFA, but it operates at the policy layer rather than the authentication session layer. It can manage when a session is allowed or challenged, yet it does not generate a single-sign-on token stream that carries identity across apps. Therefore, it can refine SSO but cannot itself replace the need for a shared authentication session.
- ✗
Identity Protection
Why it's wrong here
Identity Protection uses machine learning to detect compromised identities and risky sign-ins, triggering automated responses like forced password resets or conditional access policies. It is a risk-assessment and remediation engine, not an authentication protocol or session manager, so it does nothing to suppress the repeated authentication prompts between applications. Its role is to mitigate threats, not to federate identity for seamless access.
Go deeper
Related to this question
About these practice questions
Courseiva writes every AZ-305 question from scratch — 795 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-305 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-305 exam.