Courseiva
Describe the capabilities of Microsoft EntramediumMultiple ChoiceObjective-mapped

SC-900 Describe the capabilities of Microsoft Entra Practice Question

A company uses Microsoft Entra ID and wants to enforce multi-factor authentication (MFA) only for external guest users, while allowing internal employees to sign in without MFA. Which Conditional Access setting should be configured?

⚠ Common exam trap

Candidates often confuse exclusion-based approaches (like excluding internal users by group) with direct targeting of guest identity types, leading them to choose Option B instead of the more precise and scalable Option C.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Target the 'Guest or external users' identity type

Conditional Access allows targeting the 'Guest or external users' identity type, which enables MFA enforcement exclusively for external guest users without affecting internal employees. This setting leverages the user type attribute in Microsoft Entra ID to differentiate between internal and external identities, providing granular control over authentication requirements.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Require MFA for all users

    Why it's wrong here

    Implementing a Conditional Access policy that requires multi-factor authentication (MFA) for 'All users' would indiscriminately apply this security control to every identity within the Microsoft Entra tenant. While this approach would certainly cover external users, it would also impose the MFA requirement on all internal employees. This directly contradicts the specific objective of enforcing MFA *only* for external users, as it lacks the necessary specificity to differentiate user types.

    When this WOULD be correct

    In a scenario where the company requires MFA for all users regardless of identity type, such as a security policy mandating MFA for every sign-in to protect against credential theft.

  • Exclude internal users by group

    Why it's wrong here

    Excluding internal users by group fails because it is a refinement of an *included* scope, not the primary mechanism for defining the target users. To enforce MFA *only* for external guests, the Conditional Access policy must explicitly *include* "Guest or external users" as its target. While excluding internal users would prevent them from being prompted, it doesn't directly configure the policy to apply *only* to guests. This option is tempting as it addresses the internal user exemption, and it would be the correct choice if a policy were configured for "All users" and a specific internal group needed to be exempted from its conditions.

    When this WOULD be correct

    If the requirement were to enforce MFA for all users except a specific group of internal employees (e.g., IT admins), then excluding that group by group membership would be correct.

  • Target the 'Guest or external users' identity type

    Why this is correct

    Conditional Access policies in Microsoft Entra ID provide the precise control needed to enforce requirements based on identity types. By configuring a policy to include the 'Guest or external users' identity type, administrators can specifically mandate multi-factor authentication (MFA) solely for B2B collaboration guests and other external identities. This direct targeting ensures that internal users are not affected, thereby accurately meeting the requirement to enforce MFA exclusively for external users.

  • Use Identity Protection's user risk policy

    Why it's wrong here

    Microsoft Entra ID Protection's user risk policy is designed to detect and respond to potential compromises of user accounts based on observed risky behaviors and signals. While these policies can enforce controls like MFA when a user's risk level is high, they are triggered by a dynamic risk assessment, not by the user's inherent identity type (internal vs. external). Therefore, a user risk policy cannot be configured to *only* target external users for MFA, as it would apply to any user, internal or external, exhibiting risky behavior.

    When this WOULD be correct

    A question asks: 'A company wants to block sign-ins for users with compromised credentials detected by Microsoft. Which policy should be configured?' Then Identity Protection's user risk policy would be correct.

Option-by-option analysis

Why each answer is right or wrong

Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The SC-900 exam frequently reuses these exact scenarios with slightly different constraints.

Target the 'Guest or external users' identity typeCorrect answer

Why this is correct

Conditional Access policies in Microsoft Entra ID provide the precise control needed to enforce requirements based on identity types. By configuring a policy to include the 'Guest or external users' identity type, administrators can specifically mandate multi-factor authentication (MFA) solely for B2B collaboration guests and other external identities. This direct targeting ensures that internal users are not affected, thereby accurately meeting the requirement to enforce MFA exclusively for external users.

Require MFA for all usersWrong answer — click to see why

Why this is wrong here

This option applies MFA to all users, including internal employees, which contradicts the requirement to enforce MFA only for external guest users.

★ When this WOULD be the correct answer

In a scenario where the company requires MFA for all users regardless of identity type, such as a security policy mandating MFA for every sign-in to protect against credential theft.

Why candidates choose this

Candidates may think requiring MFA for all users is simpler and still covers external users, overlooking the need to exclude internal employees as specified.

Exclude internal users by groupWrong answer — click to see why

Why this is wrong here

Excluding internal users by group does not specifically target external guest users; it would still require MFA for all other users, including guests, but the question asks for MFA only for external guests, not all users.

★ When this WOULD be the correct answer

If the requirement were to enforce MFA for all users except a specific group of internal employees (e.g., IT admins), then excluding that group by group membership would be correct.

Why candidates choose this

Candidates may think that excluding internal users by group is a straightforward way to exempt them, but they overlook that the policy would still apply to all other users, including guests, which is not the desired outcome.

Use Identity Protection's user risk policyWrong answer — click to see why

Why this is wrong here

Identity Protection's user risk policy requires Azure AD Premium P2 and evaluates sign-in risk, not user type. It cannot target only external guest users for MFA enforcement.

★ When this WOULD be the correct answer

A question asks: 'A company wants to block sign-ins for users with compromised credentials detected by Microsoft. Which policy should be configured?' Then Identity Protection's user risk policy would be correct.

Why candidates choose this

Candidates may confuse risk-based policies with identity-based targeting, assuming user risk policy can be scoped to guest users only.

Analysis generated from the official SC-900blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”

Go deeper

Related to this question

About these practice questions

This SC-900 question is part of Courseiva's 1,250-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.