Courseiva

SC-900 Practice Question: Describe the concepts of security, compliance, and identity

A company uses Microsoft Entra ID and has multiple departments with separate organizational units (OUs) in its on-premises Active Directory. The help desk team needs to be able to reset passwords for users only in the Finance department. What feature should be used to delegate this administrative scope?

⚠ Common exam trap

Watch out — candidates often confuse delegation of administrative scope (Administrative Units) with membership automation (Dynamic groups) or access control (Conditional Access), leading candidates to pick a feature that manages users rather than one that limits administrative permissions.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Administrative Units

Administrative Units (AUs) in Microsoft Entra ID allow you to delegate administrative permissions over a subset of users, groups, or devices without granting broader tenant-wide access. By creating an AU for the Finance department and assigning the Helpdesk Administrator role scoped to that AU, the help desk team can reset passwords only for Finance users, matching the on-premises OU structure.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Dynamic groups

    Why it's wrong here

    Dynamic groups in Microsoft Entra ID automate membership management by defining rules based on user or device attributes, such as department or country. While they efficiently organize users into logical sets, their primary function is membership automation, not the delegation of administrative authority. They cannot be used to grant specific administrators the ability to manage only the members of that group, nor do they define a scope for administrative roles.

    When this WOULD be correct

    A question asks: 'A company wants to automatically assign licenses to all users in the Finance department based on their department attribute. Which feature should be used?' In that scenario, Dynamic groups would be correct.

  • Administrative Units

    Why this is correct

    Administrative Units (AUs) in Microsoft Entra ID are specifically designed to enable scoped administration by defining a subset of users, groups, or devices. For a company with multiple departments, AUs allow the delegation of administrative roles, such as User Administrator or Group Administrator, to manage only the identities within a particular department's AU. This ensures that departmental administrators can perform necessary management tasks without gaining tenant-wide privileges, adhering to the principle of least privilege.

  • Conditional Access policies

    Why it's wrong here

    Conditional Access policies in Microsoft Entra ID are security tools that enforce specific access requirements based on conditions like user location, device compliance, or application being accessed. These policies determine *if* and *how* a user can access resources at the time of sign-in, for example, by requiring MFA or a compliant device. They are purely about access control and session management, not about delegating the ability to perform administrative tasks like user management or password resets to other administrators.

    When this WOULD be correct

    A company wants to require multi-factor authentication for all users accessing financial applications from outside the corporate network. Conditional Access policies would be used to enforce this access control based on the location condition.

  • Privileged Identity Management (PIM)

    Why it's wrong here

    Microsoft Entra Privileged Identity Management (PIM) focuses on managing, controlling, and monitoring access to important resources by providing just-in-time and just-enough access for eligible roles. It requires activation for roles and often incorporates multi-factor authentication and approval workflows to elevate privileges temporarily. However, PIM governs *how* and *when* a role is used, not *what* specific subset of users or devices that role can manage within a larger directory; it does not inherently scope administrative permissions to a particular department or organizational unit.

    When this WOULD be correct

    A company needs to provide just-in-time access to the Global Administrator role for help desk staff, with approval workflows and time limits, to reduce standing privileges. PIM would be the correct feature to enable this.

Option-by-option analysis

Why each answer is right or wrong

Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The SC-900 exam frequently reuses these exact scenarios with slightly different constraints.

Administrative UnitsCorrect answer

Why this is correct

Administrative Units (AUs) in Microsoft Entra ID are specifically designed to enable scoped administration by defining a subset of users, groups, or devices. For a company with multiple departments, AUs allow the delegation of administrative roles, such as User Administrator or Group Administrator, to manage only the identities within a particular department's AU. This ensures that departmental administrators can perform necessary management tasks without gaining tenant-wide privileges, adhering to the principle of least privilege.

Dynamic groupsWrong answer — click to see why

Why this is wrong here

Dynamic groups automatically manage group membership based on user attributes (e.g., department), but they do not provide delegated administrative scopes for tasks like password reset. Administrative Units are required to delegate administration over specific sets of users.

★ When this WOULD be the correct answer

A question asks: 'A company wants to automatically assign licenses to all users in the Finance department based on their department attribute. Which feature should be used?' In that scenario, Dynamic groups would be correct.

Why candidates choose this

Candidates may confuse dynamic groups with administrative units because both can group users by department, but dynamic groups are for automatic membership, not for delegating administrative permissions.

Conditional Access policiesWrong answer — click to see why

Why this is wrong here

Conditional Access policies control access to applications based on conditions like location or device state, not for delegating administrative tasks like password resets to specific user scopes.

★ When this WOULD be the correct answer

A company wants to require multi-factor authentication for all users accessing financial applications from outside the corporate network. Conditional Access policies would be used to enforce this access control based on the location condition.

Why candidates choose this

Candidates may confuse Conditional Access with administrative delegation because both involve setting conditions and scopes, but Conditional Access is for access control, not administrative role delegation.

Privileged Identity Management (PIM)Wrong answer — click to see why

Why this is wrong here

Privileged Identity Management (PIM) provides time-based and approval-based role activation to manage privileged access, but it does not delegate administrative scope over specific organizational units. PIM manages roles like Global Administrator, not scoped password reset permissions for a department.

★ When this WOULD be the correct answer

A company needs to provide just-in-time access to the Global Administrator role for help desk staff, with approval workflows and time limits, to reduce standing privileges. PIM would be the correct feature to enable this.

Why candidates choose this

Candidates may confuse PIM's role management with delegation of administrative tasks, thinking it can scope permissions to specific users or groups, when it actually controls role activation and assignment.

Analysis generated from the official SC-900blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”

About these practice questions

Courseiva writes every SC-900 question from scratch — 1,250 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.