Courseiva

SC-100 Practice Question: Design security operations, identity, and compliance capabilities

Which THREE are valid methods to secure privileged access in Microsoft Entra ID? (Choose three.)

⚠ Common exam trap

It's easy for candidates to confuse general security best practices (like device enrollment or self-service password reset) with specific methods for securing privileged access, which require granular controls like PIM, conditional access, and privileged groups.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Use privileged access groups to manage elevated access to resources.

Option A is correct because privileged access groups in Microsoft Entra ID (specifically Privileged Access Management for groups) let you assign users as eligible or active members of a role-assignable group, so elevated access to resources is governed and time-bound rather than permanently granted. Option C is correct because Privileged Identity Management (PIM) provides just-in-time role activation with approval workflows, MFA on activation, justification, and time-limited assignments, which directly reduces standing privileged access. Option D is correct because a Conditional Access policy that requires multifactor authentication for directory roles (admin roles) enforces strong authentication at sign-in for privileged accounts, a core control for securing privileged access. Option B is not one of the three because Intune device enrollment/compliance is a device-management control that can be referenced in Conditional Access but is not itself a privileged-access security method. Option E is not correct because self-service password reset is an end-user credential-recovery feature and does not govern or restrict privileged access.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Use privileged access groups to manage elevated access to resources.

    Why this is correct

    Privileged access groups, such as role-assignable groups in Microsoft Entra ID, allow administrators to assign highly privileged Microsoft Entra ID roles to a group rather than to individual users. This enables scalable and consistent membership management, and when integrated with Privileged Identity Management (PIM), group membership can be time-limited so users hold elevated access only during an approved activation window. Because the group itself carries the role, adding or removing members centrally controls privileged access across multiple resources.

  • ✗

    Require device enrollment via Microsoft Intune.

    Why it's wrong here

    Requiring device enrollment in Microsoft Intune is a device management control that establishes compliance and configuration state for endpoints. A compliant device can serve as a signal in a conditional access policy, but enrollment alone does not grant, restrict, or time-limit privileged roles. It addresses which devices are trusted for sign-in, not what elevated rights a user holds in Entra ID or Azure resources, so it is not a method for securing privileged access.

  • ✓

    Use Privileged Identity Management (PIM) for just-in-time access.

    Why this is correct

    Privileged Identity Management (PIM) in Microsoft Entra ID enforces just-in-time activation by letting eligible users elevate to high-privilege roles only for a predefined, time-limited window. Activation can require approval, business justification, or multi-factor authentication, and the role automatically expires once the window elapses. This substantially reduces standing administrative privileges and limits the window of attack, making it a core privileged access control.

  • ✓

    Configure conditional access policies to require MFA for admins.

    Why this is correct

    Conditional access policies in Microsoft Entra ID can target users and groups that hold privileged administrative roles and require multi-factor authentication as a condition for sign-in. Because these accounts have elevated permissions, enforcing MFA at authentication time significantly reduces the risk of credential compromise being used to gain privileged access. This is a direct identity-layer security control that complements just-in-time elevation and group-based access management.

  • ✗

    Enable self-service password reset for all users.

    Why it's wrong here

    Self-service password reset (SSPR) is a convenience feature that lets end users unlock accounts or reset passwords using pre-registered verification methods. While it reduces helpdesk load, it does not govern privileged identity access, enforce MFA for administrators, or introduce time-limited elevated roles. Enabling SSPR for all users leaves standing privileges unchanged and offers no mechanism to constrain or monitor privileged actions.

About these practice questions

This SC-100 question is part of Courseiva's 605-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.