Courseiva
Describe the capabilities of Microsoft EntramediumMultiple ChoiceObjective-mapped

SC-900 Describe the capabilities of Microsoft Entra Practice Question

A company manages Azure resources for multiple departments. The security team needs to grant IT administrators temporary, just-in-time access to high-privilege roles (e.g., Contributor, Owner) only when needed, with approval workflows. Which Microsoft Entra ID capability should they configure?

⚠ Common exam trap

Candidates often confuse Privileged Identity Management (PIM) with Entitlement Management, because both involve access requests and approvals, but PIM is specifically for just-in-time privileged role activation, while Entitlement Management is for ongoing access to resources like groups and apps.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Privileged Identity Management (PIM)

Privileged Identity Management (PIM) is the correct Microsoft Entra ID capability because it provides just-in-time (JIT) activation of high-privilege roles like Contributor and Owner, with time-bound approvals and approval workflows. PIM allows administrators to request temporary elevation to a role, which must be approved by designated approvers, and the access automatically expires after the specified duration. This directly addresses the requirement for temporary, approval-based access to privileged roles.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Conditional Access

    Why it's wrong here

    Azure AD Conditional Access enforces policies at the point of sign-in, evaluating various signals like user location, device compliance, and sign-in risk to determine if access should be granted, blocked, or require multi-factor authentication. While crucial for securing access to applications and resources, it does not manage the activation or deactivation of privileged roles themselves. Instead, it governs the conditions under which an *already assigned* role or access can be utilized.

    When this WOULD be correct

    A company needs to require multi-factor authentication or block access from untrusted locations when administrators sign in to the Azure portal. Conditional Access would be the correct capability to configure such policies.

  • Identity Protection

    Why it's wrong here

    Azure AD Identity Protection focuses on detecting and remediating identity-based risks, such as leaked credentials, anomalous sign-ins, or suspicious activity. It leverages machine learning to identify potential compromises and can automatically enforce policies like requiring password changes or blocking risky users. However, its primary function is risk detection and response, not the management of just-in-time elevation for privileged administrative roles.

    When this WOULD be correct

    A question asks: 'Which Microsoft Entra ID capability should be used to automatically detect and block risky sign-ins and investigate compromised accounts?' — then Identity Protection is correct.

  • Privileged Identity Management (PIM)

    Why this is correct

    Azure AD Privileged Identity Management (PIM) is specifically designed to manage, control, and monitor access to important resources within Azure AD, Azure, and other Microsoft online services. It enforces just-in-time (JIT) access, allowing users to activate privileged roles only when needed and for a limited duration. This capability significantly reduces the attack surface by eliminating standing administrative access, requiring explicit activation and often approval workflows for elevated permissions.

  • Entitlement Management (Identity Governance)

    Why it's wrong here

    Azure AD Entitlement Management, part of Identity Governance, streamlines the lifecycle of access by enabling organizations to manage access packages for internal and external users across various resources like groups, applications, and SharePoint sites. It facilitates self-service access requests and automates access reviews, ensuring users have appropriate permissions for their roles. While it manages access, it does not specifically provide the just-in-time, time-bound activation and approval workflows for *privileged* administrative roles that PIM offers.

    When this WOULD be correct

    A company needs to automate access requests and approvals for users to join groups, access applications, or obtain SharePoint Online site memberships, with time-limited access and recurring reviews. Entitlement Management would be the correct choice for managing such access packages.

Option-by-option analysis

Why each answer is right or wrong

Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The SC-900 exam frequently reuses these exact scenarios with slightly different constraints.

Privileged Identity Management (PIM)Correct answer

Why this is correct

Azure AD Privileged Identity Management (PIM) is specifically designed to manage, control, and monitor access to important resources within Azure AD, Azure, and other Microsoft online services. It enforces just-in-time (JIT) access, allowing users to activate privileged roles only when needed and for a limited duration. This capability significantly reduces the attack surface by eliminating standing administrative access, requiring explicit activation and often approval workflows for elevated permissions.

Conditional AccessWrong answer — click to see why

Why this is wrong here

Conditional Access enforces access policies based on signals like user, device, or location, but does not provide just-in-time role activation or approval workflows for privileged roles.

★ When this WOULD be the correct answer

A company needs to require multi-factor authentication or block access from untrusted locations when administrators sign in to the Azure portal. Conditional Access would be the correct capability to configure such policies.

Why candidates choose this

Candidates may confuse Conditional Access with access control for privileged roles, not realizing that PIM specifically handles time-bound role elevation and approval workflows.

Identity ProtectionWrong answer — click to see why

Why this is wrong here

Identity Protection focuses on detecting and responding to identity-based risks (e.g., compromised credentials, risky sign-ins), not on granting temporary, just-in-time privileged access with approval workflows.

★ When this WOULD be the correct answer

A question asks: 'Which Microsoft Entra ID capability should be used to automatically detect and block risky sign-ins and investigate compromised accounts?' — then Identity Protection is correct.

Why candidates choose this

Candidates may confuse 'protecting identities' with 'managing privileged access,' or think Identity Protection includes approval workflows because it deals with security and risk.

Entitlement Management (Identity Governance)Wrong answer — click to see why

Why this is wrong here

Entitlement Management focuses on managing access packages and resource access for users, not on providing just-in-time, time-bound, approval-based elevation to high-privilege Azure roles like Contributor or Owner.

★ When this WOULD be the correct answer

A company needs to automate access requests and approvals for users to join groups, access applications, or obtain SharePoint Online site memberships, with time-limited access and recurring reviews. Entitlement Management would be the correct choice for managing such access packages.

Why candidates choose this

Candidates may confuse Entitlement Management's access request and approval workflows with PIM's just-in-time role activation, as both involve approvals and time-limited access, but Entitlement Management is for resource access, not privileged role elevation.

Analysis generated from the official SC-900blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”

About these practice questions

This SC-900 question is part of Courseiva's 1,250-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.