SC-900 Describe the capabilities of Microsoft Entra Practice Question
A company's security team discovers that most recent account compromises resulted from attackers exploiting legacy authentication protocols (POP3, IMAP, SMTP Auth) that do not support multi-factor authentication. The team wants to immediately block all sign-in attempts using these legacy protocols while still allowing modern authentication methods (e.g., OAuth 2.0). Which Microsoft Entra ID feature should they configure?
⚠ Common exam trap
Watch out — candidates often confuse the 'block legacy authentication' capability with MFA or Identity Protection, assuming that enabling MFA alone will stop legacy protocol abuse, when in fact legacy protocols bypass MFA entirely and require a Conditional Access policy to be explicitly blocked.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Conditional Access
Conditional Access policies in Microsoft Entra ID can be configured to block authentication attempts from legacy protocols (POP3, IMAP, SMTP Auth) by targeting client apps that do not support modern authentication. This allows the security team to immediately enforce a block on all sign-ins using these protocols while still permitting modern OAuth 2.0-based methods, directly addressing the requirement without disabling MFA for users who can use modern clients.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Conditional Access
Why this is correct
Conditional Access policies can include a 'Block legacy authentication' condition. This allows administrators to create a policy that blocks all sign-ins from clients that do not support MFA, effectively stopping attacks that rely on legacy protocols while preserving modern authentication.
- ✗
Identity Protection
Why it's wrong here
Identity Protection detects risky sign-ins and users but does not directly block specific protocols. It can trigger risk-based conditional access, but the scenario requires a direct block on legacy authentication protocols, which is a Conditional Access condition.
When this WOULD be correct
A company wants to automatically block sign-ins from compromised accounts or from anonymous IP addresses. Identity Protection should be configured to enforce risk-based policies, such as requiring MFA for high-risk sign-ins or blocking sign-ins from risky sessions.
- ✗
Privileged Identity Management
Why it's wrong here
Privileged Identity Management (PIM) is a service within Azure AD that enables organizations to manage, control, and monitor access to important resources. Its primary function is to provide just-in-time (JIT) and just-enough-access (JEA) to privileged roles, reducing the exposure time of elevated permissions. PIM focuses on who can access what and when, but it does not govern the underlying authentication protocols (like legacy authentication) used by clients to initiate a sign-in attempt. Therefore, PIM cannot be used to block specific authentication protocols.
When this WOULD be correct
A company wants to implement just-in-time privileged access for administrators, requiring approval and time-bound role activation for elevated permissions. In that scenario, configuring Privileged Identity Management would be the correct answer.
- ✗
Multi-factor Authentication
Why it's wrong here
Multi-factor Authentication (MFA) is a security measure that requires users to provide two or more verification factors to gain access to a resource. While essential for enhancing identity security, MFA itself is an authentication method that verifies user identity, not a mechanism to block specific authentication protocols. Legacy authentication protocols, by their nature, often lack the capability to prompt for or process additional authentication factors, meaning MFA cannot be directly enforced on them. Therefore, requiring MFA doesn't inherently block legacy protocols; a separate policy is needed.
When this WOULD be correct
A company wants to require all users to verify their identity with a second factor (e.g., phone call or app notification) during sign-in. The correct answer would be Multi-factor Authentication, as it is the feature that provides the additional verification step.
Option-by-option analysis
Why each answer is right or wrong
Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The SC-900 exam frequently reuses these exact scenarios with slightly different constraints.
✓Conditional AccessCorrect answer▾
Why this is correct
Conditional Access policies can include a 'Block legacy authentication' condition. This allows administrators to create a policy that blocks all sign-ins from clients that do not support MFA, effectively stopping attacks that rely on legacy protocols while preserving modern authentication.
✗Identity ProtectionWrong answer — click to see why▾
Why this is wrong here
Identity Protection is designed to detect and respond to identity-based risks, such as suspicious sign-ins or leaked credentials, but it does not provide the capability to block specific authentication protocols like POP3, IMAP, or SMTP Auth.
★ When this WOULD be the correct answer
A company wants to automatically block sign-ins from compromised accounts or from anonymous IP addresses. Identity Protection should be configured to enforce risk-based policies, such as requiring MFA for high-risk sign-ins or blocking sign-ins from risky sessions.
Why candidates choose this
Candidates may confuse Identity Protection's risk detection with the ability to enforce access controls, not realizing that blocking legacy protocols is a Conditional Access policy action, not a risk-based detection feature.
✗Privileged Identity ManagementWrong answer — click to see why▾
Why this is wrong here
Privileged Identity Management (PIM) manages, controls, and monitors access to privileged roles, but it does not block legacy authentication protocols. The question requires blocking sign-in attempts based on authentication protocol, which is a Conditional Access policy capability.
★ When this WOULD be the correct answer
A company wants to implement just-in-time privileged access for administrators, requiring approval and time-bound role activation for elevated permissions. In that scenario, configuring Privileged Identity Management would be the correct answer.
Why candidates choose this
Candidates may confuse PIM's role in controlling access with the ability to enforce authentication policies, or they might think that blocking legacy protocols is a privilege management task rather than an access control policy.
✗Multi-factor AuthenticationWrong answer — click to see why▾
Why this is wrong here
Multi-factor Authentication (MFA) is an authentication method, not a policy to block legacy protocols. The question asks for a feature to block sign-in attempts using legacy protocols, which requires a conditional access policy to enforce MFA or block specific authentication methods.
★ When this WOULD be the correct answer
A company wants to require all users to verify their identity with a second factor (e.g., phone call or app notification) during sign-in. The correct answer would be Multi-factor Authentication, as it is the feature that provides the additional verification step.
Why candidates choose this
Candidates may confuse the goal of blocking legacy protocols with requiring MFA, thinking that enabling MFA will automatically prevent legacy protocol attacks, but MFA alone does not block legacy protocols unless enforced via Conditional Access.
Analysis generated from the official SC-900blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”
Go deeper
Related to this question
Learn chapter
Core Security Concepts
Key term
Security
Security in IT is the practice of protecting systems, networks, and data from unauthorized access, damage, or theft.
Key term
SMTP
SMTP (Simple Mail Transfer Protocol) is the standard internet protocol used to send emails from a client to a server or between email servers.
About these practice questions
Courseiva writes every SC-900 question from scratch — 1,250 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.