MS-900 Practice Question: Describe security, compliance, privacy, and trust in Microsoft 365
Which TWO are features of Microsoft Entra ID? (Choose two.)
⚠ Common exam trap
MS-900 often tests the confusion between identity features (Entra ID) and device/compliance features (Intune, Purview), so candidates must remember that MDM, DLP, and sensitivity labels belong to other Microsoft 365 services.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Identity and access management
Option B (Identity and access management) is correct because Microsoft Entra ID is Microsoft's cloud-based identity provider, delivering authentication, authorization, SSO, conditional access, and directory services for users, groups, and applications. Option D (Multi-Factor Authentication) is correct because Entra ID natively provides Microsoft Entra multifactor authentication, requiring a second verification factor such as the Microsoft Authenticator app, SMS, or a FIDO2 key during sign-in. Option A (Mobile device management) does not belong because MDM is delivered by Microsoft Intune, not Entra ID, even though Intune integrates with Entra ID for identity. Option C (Data Loss Prevention policies) does not belong because DLP is a Microsoft Purview compliance capability that protects sensitive data across Exchange, SharePoint, and endpoints. Option E (Sensitivity labels) does not belong because sensitivity labels are also a Microsoft Purview Information Protection feature used to classify and protect content, not an Entra ID identity feature.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Mobile device management
Why it's wrong here
Mobile device management enrols and configures devices, and is delivered by Microsoft Intune, not Microsoft Entra ID. Tempting because Entra ID registers devices and enables conditional access, it would be correct when the requirement is enforcing compliance policies, configuration profiles or remote wipe on enrolled endpoints.
- ✓
Identity and access management
Why this is correct
Identity and access management is a core Microsoft Entra ID capability, providing authentication, authorisation, and conditional access for users and applications. It satisfies the requirement by governing who can access which resources across cloud and on-premises environments.
- ✗
Data Loss Prevention policies
Why it's wrong here
Data Loss Prevention policies belong to Microsoft Purview, which inspects and protects sensitive content across Exchange, SharePoint and endpoints; Microsoft Entra ID governs identities, authentication and conditional access. It tempts because both are Microsoft 365 compliance-adjacent services, but DLP would be the answer for a question about classifying or blocking sensitive data.
- ✓
Multi-Factor Authentication
Why this is correct
Multi-Factor Authentication is a core Microsoft Entra ID feature, satisfying the stem's requirement for native identity capabilities. It enforces a second verification factor—such as a phone app, SMS code, or hardware token—during sign-in, directly reducing credential-theft risk. Entra ID bundles MFA within its identity platform, unlike standalone on-premises solutions requiring separate infrastructure.
- ✗
Sensitivity labels
Why it's wrong here
Sensitivity labels classify and protect content in Microsoft 365 workloads such as SharePoint, Exchange and Teams, and are configured through Microsoft Purview, not Microsoft Entra ID. Tempting because both govern data access, it would be correct when the requirement is applying encryption or marking documents and emails according to their confidentiality.
Go deeper
Related to this question
Learn chapter
Microsoft 365 Alert Policies
Key term
Data Loss Prevention
Data Loss Prevention (DLP) is a set of tools and processes that help organizations stop sensitive information from being shared, leaked, or stolen, whether accidentally or on purpose.
Key term
MDM
MDM stands for Mobile Device Management, a technology that allows IT administrators to securely manage, monitor, and enforce policies on mobile devices like smartphones and tablets from a central console.
About these practice questions
Courseiva writes every MS-900 question from scratch — 794 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This MS-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-900 exam.