SC-900 Describe the capabilities of Microsoft Entra Practice Question
A company uses Microsoft Entra ID and wants to enforce multi-factor authentication (MFA) only for external guest users, while allowing internal employees to sign in without MFA. Which Conditional Access setting should be configured?
⚠ Common exam trap
Candidates often confuse exclusion-based approaches (like excluding internal users by group) with direct targeting of guest identity types, leading them to choose Option B instead of the more precise and scalable Option C.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Target the 'Guest or external users' identity type
Conditional Access allows targeting the 'Guest or external users' identity type, which enables MFA enforcement exclusively for external guest users without affecting internal employees. This setting leverages the user type attribute in Microsoft Entra ID to differentiate between internal and external identities, providing granular control over authentication requirements.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Require MFA for all users
Why it's wrong here
Implementing a Conditional Access policy that requires multi-factor authentication (MFA) for 'All users' would indiscriminately apply this security control to every identity within the Microsoft Entra tenant. While this approach would certainly cover external users, it would also impose the MFA requirement on all internal employees. This directly contradicts the specific objective of enforcing MFA *only* for external users, as it lacks the necessary specificity to differentiate user types.
When this WOULD be correct
In a scenario where the company requires MFA for all users regardless of identity type, such as a security policy mandating MFA for every sign-in to protect against credential theft.
- ✗
Exclude internal users by group
Why it's wrong here
Excluding internal users by group fails because it is a refinement of an *included* scope, not the primary mechanism for defining the target users. To enforce MFA *only* for external guests, the Conditional Access policy must explicitly *include* "Guest or external users" as its target. While excluding internal users would prevent them from being prompted, it doesn't directly configure the policy to apply *only* to guests. This option is tempting as it addresses the internal user exemption, and it would be the correct choice if a policy were configured for "All users" and a specific internal group needed to be exempted from its conditions.
When this WOULD be correct
If the requirement were to enforce MFA for all users except a specific group of internal employees (e.g., IT admins), then excluding that group by group membership would be correct.
- ✓
Target the 'Guest or external users' identity type
Why this is correct
Conditional Access policies in Microsoft Entra ID provide the precise control needed to enforce requirements based on identity types. By configuring a policy to include the 'Guest or external users' identity type, administrators can specifically mandate multi-factor authentication (MFA) solely for B2B collaboration guests and other external identities. This direct targeting ensures that internal users are not affected, thereby accurately meeting the requirement to enforce MFA exclusively for external users.
- ✗
Use Identity Protection's user risk policy
Why it's wrong here
Microsoft Entra ID Protection's user risk policy is designed to detect and respond to potential compromises of user accounts based on observed risky behaviors and signals. While these policies can enforce controls like MFA when a user's risk level is high, they are triggered by a dynamic risk assessment, not by the user's inherent identity type (internal vs. external). Therefore, a user risk policy cannot be configured to *only* target external users for MFA, as it would apply to any user, internal or external, exhibiting risky behavior.
When this WOULD be correct
A question asks: 'A company wants to block sign-ins for users with compromised credentials detected by Microsoft. Which policy should be configured?' Then Identity Protection's user risk policy would be correct.
Option-by-option analysis
Why each answer is right or wrong
Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The SC-900 exam frequently reuses these exact scenarios with slightly different constraints.
✓Target the 'Guest or external users' identity typeCorrect answer▾
Why this is correct
Conditional Access policies in Microsoft Entra ID provide the precise control needed to enforce requirements based on identity types. By configuring a policy to include the 'Guest or external users' identity type, administrators can specifically mandate multi-factor authentication (MFA) solely for B2B collaboration guests and other external identities. This direct targeting ensures that internal users are not affected, thereby accurately meeting the requirement to enforce MFA exclusively for external users.
✗Require MFA for all usersWrong answer — click to see why▾
Why this is wrong here
This option applies MFA to all users, including internal employees, which contradicts the requirement to enforce MFA only for external guest users.
★ When this WOULD be the correct answer
In a scenario where the company requires MFA for all users regardless of identity type, such as a security policy mandating MFA for every sign-in to protect against credential theft.
Why candidates choose this
Candidates may think requiring MFA for all users is simpler and still covers external users, overlooking the need to exclude internal employees as specified.
✗Exclude internal users by groupWrong answer — click to see why▾
Why this is wrong here
Excluding internal users by group does not specifically target external guest users; it would still require MFA for all other users, including guests, but the question asks for MFA only for external guests, not all users.
★ When this WOULD be the correct answer
If the requirement were to enforce MFA for all users except a specific group of internal employees (e.g., IT admins), then excluding that group by group membership would be correct.
Why candidates choose this
Candidates may think that excluding internal users by group is a straightforward way to exempt them, but they overlook that the policy would still apply to all other users, including guests, which is not the desired outcome.
✗Use Identity Protection's user risk policyWrong answer — click to see why▾
Why this is wrong here
Identity Protection's user risk policy requires Azure AD Premium P2 and evaluates sign-in risk, not user type. It cannot target only external guest users for MFA enforcement.
★ When this WOULD be the correct answer
A question asks: 'A company wants to block sign-ins for users with compromised credentials detected by Microsoft. Which policy should be configured?' Then Identity Protection's user risk policy would be correct.
Why candidates choose this
Candidates may confuse risk-based policies with identity-based targeting, assuming user risk policy can be scoped to guest users only.
Analysis generated from the official SC-900blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”
Go deeper
Related to this question
Learn chapter
Identity Concepts
Key term
Conditional access
Conditional access is a security framework that evaluates signals like user location, device health, and risk level to grant or block access to resources in real time.
Key term
MFA
Multi-Factor Authentication (MFA) is a security method that requires a user to verify their identity using two or more different types of evidence, such as a password plus a code from a phone, before they can access an account or system.
About these practice questions
This SC-900 question is part of Courseiva's 1,250-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.