SC-900 Describe the capabilities of Microsoft Entra Practice Question
A company requires that all users accessing a financial application from outside the corporate network must complete multi-factor authentication (MFA). The IT team is configuring a Microsoft Entra ID Conditional Access policy to enforce this requirement. Which component of the policy should be configured to apply the MFA requirement?
⚠ Common exam trap
A common mix-up: candidates confuse Grant controls (which enforce the MFA requirement) with Conditions (which define the 'when' of the policy), leading candidates to incorrectly select Conditions because they think it controls the MFA trigger rather than the enforcement action.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Grant controls
Grant controls are the component of a Conditional Access policy that enforce the actual access requirements, such as requiring multi-factor authentication (MFA). By configuring the 'Require multi-factor authentication' checkbox under Grant controls, the policy ensures that users must complete MFA before accessing the financial application. This is the correct setting to apply the MFA requirement.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Conditions
Why it's wrong here
Conditions within a Conditional Access policy are used to evaluate various signals from the access attempt, such as user risk, sign-in risk, device platform, location, or client applications. These conditions determine *when* a policy should be applied, acting as triggers for the policy's enforcement. However, conditions themselves do not specify *what action* to take once triggered; they merely identify the context under which the policy's grant or session controls will be evaluated. Therefore, they cannot enforce MFA directly.
When this WOULD be correct
A question asks: 'Which component of a Conditional Access policy specifies that access is only allowed from trusted locations?' In that case, Conditions would be correct because it includes location conditions like IP ranges or countries.
- ✗
Assignments
Why it's wrong here
Assignments are fundamental for defining the scope of a Conditional Access policy, specifying the particular users, groups, and cloud applications that the policy will evaluate. While crucial for determining 'who' and 'what' is subject to the policy, they do not dictate the specific actions or requirements that must be met. Therefore, assignments alone cannot enforce a security control like multi-factor authentication; they only set the stage for other policy components to act.
When this WOULD be correct
In a scenario where the question asks which component specifies which users or groups are targeted by a Conditional Access policy (e.g., 'Configure a policy to require MFA for all users in the Finance group'), Assignments would be the correct answer.
- ✗
Session controls
Why it's wrong here
Session controls are designed to monitor and manage user sessions *after* initial access has been granted, often integrating with Microsoft Defender for Cloud Apps to enforce ongoing restrictions. These controls focus on managing activities during an active session, such as blocking downloads, enforcing read-only access, or requiring reauthentication during a prolonged session. However, they do not govern the initial authentication process or enforce pre-access requirements like multi-factor authentication.
When this WOULD be correct
A question asks: 'Which policy component should be configured to require users to re-authenticate every hour when accessing a sensitive app?' In that scenario, Session controls (specifically sign-in frequency) would be the correct answer.
- ✓
Grant controls
Why this is correct
Grant controls are the specific mechanisms within a Conditional Access policy that determine how access is granted or denied, and what requirements must be satisfied before access is permitted. By configuring 'Require multi-factor authentication' under Grant controls, the policy explicitly mandates that users must successfully complete an MFA challenge before they can gain access to the protected resource. This directly enforces the MFA requirement, making it the correct choice for this scenario.
Option-by-option analysis
Why each answer is right or wrong
Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The SC-900 exam frequently reuses these exact scenarios with slightly different constraints.
✓Grant controlsCorrect answer▾
Why this is correct
Grant controls are the specific mechanisms within a Conditional Access policy that determine how access is granted or denied, and what requirements must be satisfied before access is permitted. By configuring 'Require multi-factor authentication' under Grant controls, the policy explicitly mandates that users must successfully complete an MFA challenge before they can gain access to the protected resource. This directly enforces the MFA requirement, making it the correct choice for this scenario.
✗ConditionsWrong answer — click to see why▾
Why this is wrong here
Conditions define when the policy applies (e.g., location, device state), not what happens when conditions are met. The MFA requirement is enforced via Grant controls, which specify the access requirements.
★ When this WOULD be the correct answer
A question asks: 'Which component of a Conditional Access policy specifies that access is only allowed from trusted locations?' In that case, Conditions would be correct because it includes location conditions like IP ranges or countries.
Why candidates choose this
Candidates may confuse 'Conditions' with the overall policy logic, thinking that specifying MFA is a condition rather than a control action. The term 'conditions' sounds like it could include requirements, but in Conditional Access, conditions are the triggers, not the enforcement.
✗AssignmentsWrong answer — click to see why▾
Why this is wrong here
Assignments define which users, groups, or applications the policy applies to, not what happens after access is granted. The MFA requirement is enforced via Grant controls, which specify the conditions that must be met for access.
★ When this WOULD be the correct answer
In a scenario where the question asks which component specifies which users or groups are targeted by a Conditional Access policy (e.g., 'Configure a policy to require MFA for all users in the Finance group'), Assignments would be the correct answer.
Why candidates choose this
Candidates may confuse 'assignments' with the action of assigning MFA requirements, not realizing that in Conditional Access, Assignments only define scope, while Grant controls enforce the actual access conditions.
✗Session controlsWrong answer — click to see why▾
Why this is wrong here
Session controls manage user experience during a session (e.g., sign-in frequency, app restrictions), not enforce MFA. MFA enforcement is done via Grant controls, which require specific conditions to be met before access is granted.
★ When this WOULD be the correct answer
A question asks: 'Which policy component should be configured to require users to re-authenticate every hour when accessing a sensitive app?' In that scenario, Session controls (specifically sign-in frequency) would be the correct answer.
Why candidates choose this
Candidates may confuse session controls with access controls, thinking that settings like 'Require MFA reauthentication' are session controls, but in Conditional Access, MFA is a grant control, not a session control.
Analysis generated from the official SC-900blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”
Go deeper
Related to this question
Learn chapter
Microsoft Entra ID
Key term
Conditional Access policy
A Conditional Access policy is a set of rules in Microsoft Entra ID that automatically grants or blocks access to cloud apps based on signals like user identity, location, device health, and risk level.
Key term
Time-based One-time Password
A temporary, automatically generated code that changes every few seconds and is used as an extra layer of security when logging into an account.
About these practice questions
One of 1,250 original SC-900 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.