AZ-900 Describe Azure management and governance Practice Question
Which Azure identity feature ensures that users must provide an additional form of verification beyond their password when signing in?
⚠ Common exam trap
Watch out — candidates often confuse Azure AD Conditional Access with the actual MFA feature, thinking that Conditional Access itself provides the extra verification, when in reality it only enforces policies that require MFA to be performed.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Azure Multi-Factor Authentication (MFA)
Azure Multi-Factor Authentication (MFA) is the correct answer because it explicitly requires users to provide an additional verification factor—such as a phone call, text message, or app notification—beyond just their password. This implements a second layer of security, making it harder for unauthorized users to gain access even if a password is compromised. MFA is a core identity security feature in Azure AD that directly addresses the requirement for extra verification.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Azure AD Single Sign-On
Why it's wrong here
Azure AD Single Sign-On streamlines authentication by allowing a user to sign in once and then access multiple applications without re-entering credentials, based on a shared session or token. While this convenience relies on strong initial authentication, SSO does not add a second verification factor; it merely reuses the existing authentication context. An attacker with a stolen password would still be able to gain access through SSO across all connected apps unless MFA is separately enforced, which is why SSO is not the mechanism for an additional security check.
- ✓
Azure Multi-Factor Authentication (MFA)
Why this is correct
Azure Multi-Factor Authentication is the security feature that actually requires a user to prove their identity by providing at least two independent verification factors, such as a password plus a code from an authenticator app or a biometric scan. This additional factor ensures that even if a password is stolen, an attacker cannot sign in without the second credential. MFA is the direct mechanism for that extra verification step, making it the correct answer for enforcing a second verification requirement.
- ✗
Azure AD Conditional Access
Why it's wrong here
Azure AD Conditional Access acts as a policy-decision and enforcement engine that evaluates conditions like user location, device state, and sign-in risk, then determines whether to allow access, block it, or require MFA. It controls the circumstances under which MFA is invoked, such as for users outside a corporate network or on unmanaged devices, but it is not the authentication mechanism itself. The actual step-up verification is performed by MFA when Conditional Access triggers a policy requiring it, so Conditional Access is misidentified as the second-factor mechanism.
- ✗
Azure Identity Protection
Why it's wrong here
Azure Identity Protection is a risk-assessment engine that uses signals such as leaked credentials, anonymous IP addresses, and impossible travel to assign a risk score to sign-ins. It does not present a verification challenge itself; rather, it can trigger actions like requiring password changes or blocking access. MFA is the concrete authentication mechanism that performs the second-factor verification, whereas Identity Protection merely identifies risky scenarios and recommends or enforces policy responses.
Go deeper
Related to this question
Learn chapter
Azure Cost Management and Billing
Key term
Security
Security in IT is the practice of protecting systems, networks, and data from unauthorized access, damage, or theft.
Key term
Feature
A feature is a distinct unit of functionality that delivers value to the user, often managed and tracked throughout the software development lifecycle.
About these practice questions
This AZ-900 question is part of Courseiva's 981-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-900 exam.