Courseiva

Implement Zero-Trust Identity Strategy in Microsoft Entra ID

Which TWO actions should you take to implement a zero-trust identity strategy in Microsoft Entra ID?

Quick Answer

The correct actions to implement a zero-trust identity strategy in Microsoft Entra ID are to configure Conditional Access policies based on user risk and device compliance. These two controls directly enforce the zero-trust principle of "never trust, always verify" by continuously evaluating real-time signals—such as sign-in risk and device health—before granting access to resources. On the Microsoft Cybersecurity Architect exam, this question tests your ability to distinguish between core zero-trust enforcement mechanisms and general identity features; a common trap is confusing passwordless authentication or single sign-on with zero-trust actions, when in fact they are convenience or modernization steps, not conditional enforcement. Remember that zero-trust identity hinges on dynamic policy decisions, not static credentials or synchronization. Memory tip: think "Risk + Compliance = Real-time Control" to recall that user risk and device compliance are the two key signals for Conditional Access in a zero-trust strategy.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Require multi-factor authentication for all users

For a zero-trust identity strategy in Microsoft Entra ID, requiring multi-factor authentication (MFA) for all users (option B) is a fundamental control to verify identity. Configuring Conditional Access policies based on user risk and device compliance (option E) enforces adaptive, context-aware access. Option A (single sign-on) improves user experience but does not directly enforce zero-trust. Option C (passwordless authentication) enhances security but is not a specific zero-trust action; MFA is more critical. Option D (synchronizing identities) supports hybrid scenarios but does not advance zero-trust principles.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Enable single sign-on for all applications

    Why it's wrong here

    SSO is about convenience, not zero-trust.

  • Require multi-factor authentication for all users

    Why this is correct

    MFA is a key zero-trust principle.

  • Implement passwordless authentication for all users

    Why it's wrong here

    Passwordless is good but not a required zero-trust action.

  • Synchronize all on-premises identities to the cloud

    Why it's wrong here

    Synchronization is unrelated to zero-trust.

  • Configure Conditional Access policies based on user risk and device compliance

    Why this is correct

    Conditional Access enforces zero-trust policies.

About these practice questions

Courseiva writes every SC-100 question from scratch — 208 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

1 more way this is tested on SC-100

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. Which TWO actions should you take to implement a Zero Trust security strategy for identity and access? (Choose two.)

medium
  • A.Require Multi-Factor Authentication for all users.
  • B.Use VPN for remote access to the corporate network.
  • C.Implement Conditional Access policies that evaluate user, device, and location.
  • D.Rely on strong passwords only.
  • E.Create shared accounts for temporary workers.

Why A: Requiring Multi-Factor Authentication (MFA) for all users is a foundational Zero Trust principle that verifies identity beyond just a password, ensuring that even if credentials are compromised, an additional factor (e.g., a one-time passcode or biometric) is needed to authenticate. This directly addresses the 'verify explicitly' pillar of Zero Trust, reducing the risk of lateral movement and unauthorized access.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.