Courseiva

SC-100 Practice Question: Design solutions that align with security best practices and priorities

A company is designing a Zero Trust architecture for their hybrid identity environment. They plan to require multifactor authentication (MFA) for all users accessing sensitive applications. Which Microsoft Entra ID capability should they use to enforce MFA based on risk level?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Conditional Access

Conditional Access is the correct choice because it is the Microsoft Entra ID policy engine that evaluates signals such as user, device, location, and sign-in risk, and can then require MFA for access to sensitive applications. In a Zero Trust hybrid identity design, Conditional Access policies are where you enforce MFA based on risk level, including integration with risk detections from Microsoft Entra ID Protection. Self-service password reset only lets users reset or unlock their own accounts and does not enforce MFA for application access. Privileged Identity Management governs just-in-time role activation and approvals for privileged roles, not general MFA enforcement for sensitive apps. Microsoft Entra ID Protection detects and reports risk but does not itself enforce the MFA requirement; that enforcement is done through Conditional Access.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Self-service password reset

    Why it's wrong here

    Self-service password reset (SSPR) allows users to unlock accounts or reset passwords using verified authentication data, but its purpose is account recovery, not enforcing MFA during typical sign-in sessions. Enforcing MFA requires a policy that demands a second factor at authentication time across all access requests. Because SSPR only intervenes on a forgotten/password failure scenario, it does not satisfy the requirement to force MFA on every interactive login, making it an incorrect choice.

  • ✗

    Microsoft Entra Privileged Identity Management

    Why it's wrong here

    Privileged Identity Management (PIM) provides time-boxed, just-in-time elevation privileges for Microsoft Entra roles and Azure resources, with approval workflows and MFA specifically for activating those high-privilege roles. However, PIM is scoped to privileged role activation, not to enforcing MFA for the entire user population or for all application access. The requirement is universal MFA enforcement, not just securing privileged administration, so PIM cannot serve as the enforcement mechanism for a zero trust MFA policy.

  • ✓

    Conditional Access

    Why this is correct

    Conditional Access is the correct enforcement point because it lets you build policies that require MFA based on any combination of signals—user, group, device compliance, location, application, or session risk—from the Entra Identity Protection feed and other sources. A policy such as 'Require MFA for all users' directly enforces a second factor on every authentication attempt, and can also apply step-up auth or session controls conditionally. This policy-driven control is the core of a zero trust architecture, ensuring authentication is continuously verified per access request.

  • ✗

    Microsoft Entra ID Protection

    Why it's wrong here

    Microsoft Entra ID Protection is a detection service that calculates risk scores for users and sign-ins by analyzing signals like leaked credentials, impossible travel, or anonymous IP addresses. It can trigger risk remediation like requiring a password change, but it does not natively enforce MFA or block access at the token issuance point. To turn its risk signals into an actual MFA enforcement decision, you must integrate ID Protection with Conditional Access, which uses the risk scores as conditions for requiring MFA. Therefore, ID Protection is only a data source, not the enforcement mechanism.

Go deeper

Related to this question

About these practice questions

This SC-100 question is part of Courseiva's 605-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.