SC-100 Practice Question: Design solutions that align with security best practices and priorities
Which THREE are security best practices for Microsoft Entra ID? (Select three.)
⚠ Common exam trap
Candidates often assume disabling self-service password reset (SSPR) improves security by reducing attack surface, but in reality, SSPR reduces help desk load and encourages users to reset compromised passwords quickly, while blocking legacy authentication is the actual critical control to prevent MFA bypass.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Block legacy authentication protocols
Option A is correct because blocking legacy authentication protocols (such as IMAP, POP3, SMTP AUTH, and older Office clients that cannot enforce MFA) closes a common bypass that attackers use to conduct password-spray and credential-stuffing attacks against Microsoft Entra ID. Option B is correct because enabling multifactor authentication for all administrators adds a strong second factor to privileged sign-ins, directly mitigating the risk of compromised admin credentials, and Microsoft recommends MFA for all users with privileged roles. Option E is correct because Privileged Identity Management enforces just-in-time role activation with approval, justification, and time-bound assignments, reducing standing privileged access that attackers could abuse. Option C is not a best practice because self-service password reset improves security and reduces helpdesk burden when combined with MFA and strong authentication methods. Option D is not inherently a security best practice because synchronizing all on-premises accounts can propagate stale, unnecessary, or compromised identities into Entra ID; synchronization should be scoped to required accounts with proper governance.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Block legacy authentication protocols
Why this is correct
Legacy authentication protocols such as POP3, IMAP, and SMTP Auth do not support modern authentication or conditional access, forcing password-only sign-ins. Since these protocols bypass MFA enforcement, they are a primary gateway for password spray and credential-stuffing attacks. Microsoft recommends blocking them entirely via Conditional Access or tenant-wide settings, reserving exceptions only for unavoidable service accounts.
- ✓
Enable multifactor authentication for all administrators
Why this is correct
Administrative accounts hold delegated control over tenant configuration, users, and security policies, making them the highest-value targets for attackers. Enabling multifactor authentication adds an independent verification factor, effectively neutralizing credential theft and phishing attempts. Microsoft has observed that MFA alone blocks over 99% of account compromise attempts, and for admins it should be required unconditionally, ideally with phishing-resistant methods like Windows Hello for Business or FIDO2 keys.
- ✗
Disable self-service password reset for users
Why it's wrong here
Self-service password reset (SSPR) is a security enhancement, not a convenience feature to disable. When disabled, users are forced to contact the help desk, which creates opportunities for social engineering and leaves passwords stale or reused. SSPR integrated with MFA and registration policies actually strengthens identity verification by providing a self-service channel that enforces strong password requirements and reduces the likelihood of compromised credentials being used.
- ✗
Synchronize all on-premises user accounts to Microsoft Entra ID
Why it's wrong here
Synchronizing every on-premises account to Entra ID indiscriminately expands the attack surface by giving each account a cloud identity that can be targeted. Many on-premises accounts are legacy service accounts, disabled users, or non-person accounts that rarely need cloud access yet become exploitable footholds. Best practice is to sync only active accounts that require Entra ID capabilities, apply scoped filtering, and continuously remove stale identities to minimize lateral movement and credential theft risk.
- ✓
Use Privileged Identity Management to enforce just-in-time access
Why this is correct
Privileged Identity Management (PIM) delivers just-in-time administrative access, meaning privileged roles are activated only for a specific time window and often only after approval and MFA. This eliminates permanent standing privileges, drastically shrinking the period an attacker can abuse a stolen admin credential. PIM also records activation history and can trigger alerts, providing a clear audit trail for every privileged action.
Go deeper
Related to this question
About these practice questions
One of 605 original SC-100 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.