Courseiva
Describe Azure management and governancemediumMultiple ChoiceObjective-mapped

AZ-900 Describe Azure management and governance Practice Question

Which Azure identity feature ensures that users must provide an additional form of verification beyond their password when signing in?

⚠ Common exam trap

Watch out — candidates often confuse Azure AD Conditional Access with the actual MFA feature, thinking that Conditional Access itself provides the extra verification, when in reality it only enforces policies that require MFA to be performed.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Azure Multi-Factor Authentication (MFA)

Azure Multi-Factor Authentication (MFA) is the correct answer because it explicitly requires users to provide an additional verification factor—such as a phone call, text message, or app notification—beyond just their password. This implements a second layer of security, making it harder for unauthorized users to gain access even if a password is compromised. MFA is a core identity security feature in Azure AD that directly addresses the requirement for extra verification.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Azure AD Single Sign-On

    Why it's wrong here

    Azure AD Single Sign-On streamlines authentication by allowing a user to sign in once and then access multiple applications without re-entering credentials, based on a shared session or token. While this convenience relies on strong initial authentication, SSO does not add a second verification factor; it merely reuses the existing authentication context. An attacker with a stolen password would still be able to gain access through SSO across all connected apps unless MFA is separately enforced, which is why SSO is not the mechanism for an additional security check.

  • Azure Multi-Factor Authentication (MFA)

    Why this is correct

    Azure Multi-Factor Authentication is the security feature that actually requires a user to prove their identity by providing at least two independent verification factors, such as a password plus a code from an authenticator app or a biometric scan. This additional factor ensures that even if a password is stolen, an attacker cannot sign in without the second credential. MFA is the direct mechanism for that extra verification step, making it the correct answer for enforcing a second verification requirement.

  • Azure AD Conditional Access

    Why it's wrong here

    Azure AD Conditional Access acts as a policy-decision and enforcement engine that evaluates conditions like user location, device state, and sign-in risk, then determines whether to allow access, block it, or require MFA. It controls the circumstances under which MFA is invoked, such as for users outside a corporate network or on unmanaged devices, but it is not the authentication mechanism itself. The actual step-up verification is performed by MFA when Conditional Access triggers a policy requiring it, so Conditional Access is misidentified as the second-factor mechanism.

  • Azure Identity Protection

    Why it's wrong here

    Azure Identity Protection is a risk-assessment engine that uses signals such as leaked credentials, anonymous IP addresses, and impossible travel to assign a risk score to sign-ins. It does not present a verification challenge itself; rather, it can trigger actions like requiring password changes or blocking access. MFA is the concrete authentication mechanism that performs the second-factor verification, whereas Identity Protection merely identifies risky scenarios and recommends or enforces policy responses.

About these practice questions

This AZ-900 question is part of Courseiva's 981-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AZ-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-900 exam.