Implement Zero-Trust Identity Strategy in Microsoft Entra ID
Which TWO actions should you take to implement a zero-trust identity strategy in Microsoft Entra ID?
Quick Answer
The correct actions to implement a zero-trust identity strategy in Microsoft Entra ID are to configure Conditional Access policies based on user risk and device compliance. These two controls directly enforce the zero-trust principle of "never trust, always verify" by continuously evaluating real-time signals—such as sign-in risk and device health—before granting access to resources. On the Microsoft Cybersecurity Architect exam, this question tests your ability to distinguish between core zero-trust enforcement mechanisms and general identity features; a common trap is confusing passwordless authentication or single sign-on with zero-trust actions, when in fact they are convenience or modernization steps, not conditional enforcement. Remember that zero-trust identity hinges on dynamic policy decisions, not static credentials or synchronization. Memory tip: think "Risk + Compliance = Real-time Control" to recall that user risk and device compliance are the two key signals for Conditional Access in a zero-trust strategy.
⚠ Common exam trap
SC-100 often tests the difference between identity hygiene features (SSO, passwordless, directory sync) and actual zero-trust enforcement controls (MFA and risk-based Conditional Access), and candidates who pick SSO or sync as zero-trust actions fall for the distractor.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Require multi-factor authentication for all users
Option B is correct because requiring multi-factor authentication (MFA) for all users is a foundational zero-trust control in Microsoft Entra ID: it enforces verification of identity beyond a password, directly supporting the 'verify explicitly' principle and reducing the risk of credential compromise. Option E is correct because Conditional Access policies that evaluate signals such as user risk (via Entra ID Protection) and device compliance (via Intune) implement adaptive, context-aware access decisions, which is the core enforcement mechanism of a zero-trust identity strategy. Options A, C, and D are not the required actions: enabling single sign-on (A) improves user experience but does not itself verify identity or enforce least-privilege access; passwordless authentication (C) is a strong phishing-resistant method but is not mandatory for zero trust and can be a subset of MFA strategy; and synchronizing on-premises identities (D) via Entra Connect extends identity reach but does not by itself enforce zero-trust verification or policy-based access.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Enable single sign-on for all applications
Why it's wrong here
Single sign-on consolidates authentication but grants broad access once a session exists, contradicting least-privilege verification. Zero trust needs per-resource Conditional Access evaluation. SSO suits scenarios reducing credential prompts across federated apps, not enforcing continuous authorisation decisions.
- ✓
Require multi-factor authentication for all users
Why this is correct
Requiring multi-factor authentication for all users directly enforces the zero-trust principle of verify explicitly, ensuring every sign-in is validated rather than trusted by network location. It satisfies the stem's identity-strategy constraint by adding a possession factor to credentials, blocking compromised-password attacks that single-factor authentication would otherwise permit.
- ✗
Implement passwordless authentication for all users
Why it's wrong here
Passwordless authentication removes credential theft risk but does not by itself verify device compliance or session context. Zero trust demands continuous evaluation through Conditional Access. Passwordless sign-in is the right choice when the requirement is phishing-resistant MFA for all users, not the broader zero-trust model.
- ✗
Synchronize all on-premises identities to the cloud
Why it's wrong here
Cloud-only synchronisation alone does not enforce zero-trust verification; it merely centralises identities. Zero trust requires Conditional Access policies that evaluate signals per session. Directory sync is the prerequisite for hybrid identity scenarios, such as staged migration to Microsoft Entra ID, not the control itself.
- ✓
Configure Conditional Access policies based on user risk and device compliance
Why this is correct
Conditional Access evaluates signals at sign-in, so risk-based and device-compliance conditions enforce least-privilege access dynamically rather than trusting a session by default. This satisfies zero trust's verify-explicitly principle, blocking or challenging access when user risk rises or the device falls out of compliance.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SC-100 question from scratch — 605 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on SC-100
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. Which TWO actions should you take to implement a Zero Trust security strategy for identity and access? (Choose two.)
medium- ✓ A.Require Multi-Factor Authentication for all users.
- B.Use VPN for remote access to the corporate network.
- ✓ C.Implement Conditional Access policies that evaluate user, device, and location.
- D.Rely on strong passwords only.
- E.Create shared accounts for temporary workers.
Why A: Option A is correct because requiring Multi-Factor Authentication (MFA) for all users enforces the Zero Trust principle of verifying identity explicitly, ensuring that a compromised password alone cannot grant access. Option C is correct because Conditional Access policies evaluate signals such as user identity, device compliance, and location to make dynamic, context-aware access decisions, which is central to Zero Trust's 'never trust, always verify' model. Options B, D, and E do not belong: VPNs grant broad network-level access once authenticated rather than per-resource verification, strong passwords alone are a single factor vulnerable to credential theft, and shared accounts eliminate individual accountability and violate least-privilege and explicit-verification principles.
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.