Courseiva

SC-100 Practice Question: Design security operations, identity, and compliance capabilities

Your organization uses Microsoft Entra ID with external identities. You need to design a solution that allows partners to self-service sign up using their existing Microsoft Entra ID or Microsoft account credentials, while preventing them from accessing other resources. What should you use?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Microsoft Entra B2B collaboration

Microsoft Entra B2B collaboration is correct because it lets you invite external partners as guest users who can redeem invitations and sign in with their existing work/school account (Microsoft Entra ID) or Microsoft account, while access is scoped only to the resources you explicitly share. Guest users in B2B are represented in your tenant and governed by Conditional Access and entitlement management, so they cannot access other resources by default. Entra B2C is for customer-facing apps with local or social identities, not partner collaboration in your corporate tenant. Identity Protection provides risk-based sign-in and user risk policies, not partner onboarding. Direct federation with a partner's IdP requires configuring a SAML/WS-Fed trust per partner and does not provide the self-service invitation and redemption model of B2B.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Microsoft Entra B2C

    Why it's wrong here

    Microsoft Entra B2C is a customer identity and access management service intended for consumers or customers who sign up with local accounts or social identities in a dedicated Azure AD B2C tenant. It is not integrated with your primary tenant for enabling existing enterprise credentials of partner organizations, and it does not support self-service sign-up using an external work account. Therefore, it is not the correct choice for this scenario.

  • ✗

    Microsoft Entra Identity Protection

    Why it's wrong here

    Microsoft Entra Identity Protection is a risk-based security tool that detects potential vulnerabilities and suspicious activities such as risky sign-ins and compromised users. It does not provide an identity management or federation mechanism, nor does it enable external users to self-service sign up with their existing credentials. It can enforce conditional access policies, but it cannot create or manage external identities, making it irrelevant to the requirement.

  • ✓

    Microsoft Entra B2B collaboration

    Why this is correct

    Microsoft Entra B2B collaboration is the correct choice because it allows external users to access apps with their own existing identities, and its self-service sign-up feature lets partners initiate access by providing their details without requiring a pre-configured federation trust. B2B collaboration creates guest accounts in your tenant, supports integration with various identity providers including Microsoft Entra ID and Google, and is designed specifically for business-to-business partnerships. This satisfies both the self-service and existing-credential requirements of the scenario.

  • ✗

    Direct federation with partner's IdP

    Why it's wrong here

    Direct federation with a partner's identity provider requires manual configuration of a trust relationship between your tenant and the partner's SAML or WS-Fed IdP, including defining claims mapping and domain verification. This process is initiated and managed by administrators on both sides, not by end users, so it does not support self-service sign-up. Additionally, direct federation is a separate mechanism from B2B collaboration and does not create guest objects in your directory, making it unsuitable for a self-service scenario.

About these practice questions

This SC-100 question is part of Courseiva's 605-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.