Courseiva
Describe the capabilities of Microsoft EntramediumMultiple ChoiceObjective-mapped

SC-900 Describe the capabilities of Microsoft Entra Practice Question

A company uses Microsoft Entra ID and wants to allow users to reset their own passwords without help desk intervention. However, they want to ensure that only users who have already registered for multifactor authentication (MFA) can use self-service password reset (SSPR). Which Microsoft Entra feature should the administrator configure to enforce this requirement?

⚠ Common exam trap

Test-takers frequently confuse Conditional Access (which enforces MFA during sign-in) with the SSPR registration requirement, but Conditional Access does not control the SSPR registration prerequisite—only the SSPR settings can enforce that users must be MFA-registered before using password reset.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Self-Service Password Reset (SSPR) settings

Self-Service Password Reset (SSPR) settings in Microsoft Entra ID include a configuration option to require users to register for multifactor authentication (MFA) before they can use SSPR. By enabling the 'Require users to register when they sign in' setting under SSPR, the administrator ensures that only MFA-registered users can reset their own passwords, meeting the requirement without additional policies.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Conditional Access

    Why it's wrong here

    Conditional Access policies evaluate conditions at the time of a sign-in or access attempt and then enforce controls such as requiring MFA, blocking access, or mandating a compliant device. While it can require MFA for specific applications or user actions, it does not directly manage the registration process for authentication methods used by Self-Service Password Reset (SSPR). The prerequisite for users to register for MFA before using SSPR is configured within SSPR policy settings, not through Conditional Access.

  • Self-Service Password Reset (SSPR) settings

    Why this is correct

    Self-Service Password Reset (SSPR) settings in Microsoft Entra ID directly control the user experience for password resets, including the authentication methods users must register and use. Administrators can configure the "Number of methods required to reset" and specify which "Methods available to users." Crucially, SSPR also offers an "Enforce registration" option, which can prompt users to register for SSPR (and thus their chosen authentication methods, including MFA options) at their next sign-in, ensuring they are prepared before a reset is needed.

  • Identity Protection

    Why it's wrong here

    Microsoft Entra ID Protection focuses on detecting vulnerabilities (e.g., weak credentials) and risk events (e.g., impossible travel, anomalous sign-in activity) related to user identities. It can then trigger automated responses, such as requiring a password change or MFA, or blocking access based on detected risks. However, its primary role is risk detection and response, not the proactive configuration of user authentication method registration requirements for services like SSPR, nor does it manage the enrollment process itself.

  • Privileged Identity Management

    Why it's wrong here

    Microsoft Entra Privileged Identity Management (PIM) is designed to manage, control, and monitor access to important resources within Microsoft Entra ID, Azure, and other Microsoft Online Services. Its core functions include providing just-in-time access, approval workflows, and access reviews for privileged roles. PIM's scope is specifically around managing privileged access and its associated lifecycle, not the general user authentication method registration policies for services like SSPR that apply to all users.

About these practice questions

One of 1,250 original SC-900 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.