Courseiva

MS-900 Describe Microsoft 365 apps and services Practice Question

A multinational corporation wants to provide a single sign-on experience for employees accessing third-party SaaS applications alongside Microsoft 365. Which Microsoft Entra ID feature should they use?

⚠ Common exam trap

Test-takers frequently confuse 'Seamless SSO' (Option D) with full SSO federation, but Seamless SSO only handles the initial sign-in experience on domain-joined devices and does not extend SSO to third-party SaaS applications.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Microsoft Entra ID as identity provider with SSO integration

Microsoft Entra ID as an identity provider with SSO integration (Option B) is correct because it allows the organization to act as the central identity source for both Microsoft 365 and third-party SaaS applications. By configuring federated SSO (using SAML 2.0 or OpenID Connect), users authenticate once against Entra ID and gain seamless access to all integrated apps, eliminating the need for separate credentials.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Password hash synchronization

    Why it's wrong here

    Password hash synchronization (PHS) replicates a cryptographic hash of a user's on-premises Active Directory password into Microsoft Entra ID, enabling the user to authenticate to Entra ID with the same password. However, it does not provide single sign-on: after PHS, the user is still prompted for credentials when launching Entra-integrated applications because no federated trust or session token is established between the workstation and the cloud identity provider.

  • ✓

    Microsoft Entra ID as identity provider with SSO integration

    Why this is correct

    Microsoft Entra ID as identity provider with SSO integration serves as the central cloud identity provider that supports industry-standard SSO protocols such as SAML 2.0, OpenID Connect, and WS-Fed. A user authenticates once to Entra ID and receives a session token that is accepted by thousands of pre-integrated SaaS applications, eliminating the need to sign in again to each application. This directly fulfills the multinational's requirement for single sign-on, making it the correct option.

  • ✗

    Multifactor authentication

    Why it's wrong here

    Multifactor authentication (MFA) is a security layer that requires additional proof of identity, such as a one-time passcode or biometric, in addition to the primary password. It strengthens the authentication event but does not create a shared session across multiple applications; each app still needs its own authentication context. MFA should be combined with SSO to secure the initial sign-on, but it never substitutes for the identity provider's token-based single sign-on functionality.

  • ✗

    Seamless single sign-on

    Why it's wrong here

    Seamless single sign-on is a Microsoft Entra Connect feature that automatically signs a user into Entra ID when they are on a Windows domain-joined device connected to the corporate network, using Kerberos tickets. It only removes the password prompt for that initial Entra ID authentication and does not itself integrate or federate SaaS applications; it also depends on the device being domain-joined and on-network. Thus it is too narrow to deliver the broad SSO for cloud apps that the multinational requires.

About these practice questions

This MS-900 question is part of Courseiva's 794-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This MS-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-900 exam.