MS-900 Describe Microsoft 365 apps and services Practice Question
A multinational corporation wants to provide a single sign-on experience for employees accessing third-party SaaS applications alongside Microsoft 365. Which Microsoft Entra ID feature should they use?
⚠ Common exam trap
Test-takers frequently confuse 'Seamless SSO' (Option D) with full SSO federation, but Seamless SSO only handles the initial sign-in experience on domain-joined devices and does not extend SSO to third-party SaaS applications.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Microsoft Entra ID as identity provider with SSO integration
Microsoft Entra ID as an identity provider with SSO integration (Option B) is correct because it allows the organization to act as the central identity source for both Microsoft 365 and third-party SaaS applications. By configuring federated SSO (using SAML 2.0 or OpenID Connect), users authenticate once against Entra ID and gain seamless access to all integrated apps, eliminating the need for separate credentials.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Password hash synchronization
Why it's wrong here
Password hash synchronization (PHS) replicates a cryptographic hash of a user's on-premises Active Directory password into Microsoft Entra ID, enabling the user to authenticate to Entra ID with the same password. However, it does not provide single sign-on: after PHS, the user is still prompted for credentials when launching Entra-integrated applications because no federated trust or session token is established between the workstation and the cloud identity provider.
- ✓
Microsoft Entra ID as identity provider with SSO integration
Why this is correct
Microsoft Entra ID as identity provider with SSO integration serves as the central cloud identity provider that supports industry-standard SSO protocols such as SAML 2.0, OpenID Connect, and WS-Fed. A user authenticates once to Entra ID and receives a session token that is accepted by thousands of pre-integrated SaaS applications, eliminating the need to sign in again to each application. This directly fulfills the multinational's requirement for single sign-on, making it the correct option.
- ✗
Multifactor authentication
Why it's wrong here
Multifactor authentication (MFA) is a security layer that requires additional proof of identity, such as a one-time passcode or biometric, in addition to the primary password. It strengthens the authentication event but does not create a shared session across multiple applications; each app still needs its own authentication context. MFA should be combined with SSO to secure the initial sign-on, but it never substitutes for the identity provider's token-based single sign-on functionality.
- ✗
Seamless single sign-on
Why it's wrong here
Seamless single sign-on is a Microsoft Entra Connect feature that automatically signs a user into Entra ID when they are on a Windows domain-joined device connected to the corporate network, using Kerberos tickets. It only removes the password prompt for that initial Entra ID authentication and does not itself integrate or federate SaaS applications; it also depends on the device being domain-joined and on-network. Thus it is too narrow to deliver the broad SSO for cloud apps that the multinational requires.
Go deeper
Related to this question
Learn chapter
Entra ID Access Reviews
Key term
Microsoft 365
Microsoft 365 is a subscription-based cloud service from Microsoft that combines productivity tools like Office apps with security, device management, and online storage.
Key term
Microsoft Entra ID
Microsoft Entra ID is a cloud-based identity and access management service that lets employees sign in and access resources both inside and outside of your organization.
About these practice questions
This MS-900 question is part of Courseiva's 794-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This MS-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-900 exam.