SC-900 Describe the capabilities of Microsoft Entra Practice Question
A company uses Microsoft Entra ID (Microsoft Entra ID) and wants to configure self-service password reset (SSPR) for all users. The security team requires that users must verify their identity with at least two methods before resetting a password. Which SSPR setting should be configured?
⚠ Common exam trap
Candidates might confuse combined registration (Option C) with the number of methods required for reset, overlooking the direct control for identity verification.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Number of methods required to reset: 2
Self-Service Password Reset (SSPR) in Microsoft Entra ID allows administrators to set the number of authentication methods required to reset a password. By setting 'Number of methods required to reset' to 2, users must provide two verification methods (e.g., email and phone) to confirm their identity.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Number of methods required to reset: 2
Why this is correct
This setting, configured within Microsoft Entra ID's Self-Service Password Reset (SSPR) policy, directly controls the security posture of the SSPR process. It dictates the number of distinct authentication factors a user must successfully provide to verify their identity before being allowed to reset their password. Setting this value to '2' ensures a multi-factor authentication approach for password resets, significantly enhancing security by requiring more than one proof of identity.
- ✗
Require re-registration on every authentication
Why it's wrong here
This setting, if it existed in this exact phrasing, would imply a highly disruptive and impractical security measure, forcing users to re-enroll their authentication methods (like phone numbers or authenticator apps) each time they authenticate. While some policies might enforce periodic re-registration or re-authentication, this specific action does not configure the *number* of distinct authentication methods required for a *single* self-service password reset attempt. It's about frequency of registration, not the count of methods per reset.
- ✗
Enable combined registration for SSPR and MFA
Why it's wrong here
Enabling combined registration for Self-Service Password Reset (SSPR) and Multi-Factor Authentication (MFA) streamlines the user onboarding experience by allowing users to set up their authentication methods for both services simultaneously. This feature improves usability and adoption by reducing friction during initial setup. However, it is purely an enrollment experience setting and does not dictate the *number of authentication methods* a user must successfully present when actually performing a password reset.
- ✗
Set password expiration to 0 days
Why it's wrong here
Setting password expiration to 0 days would effectively mean passwords expire immediately upon creation or change, rendering them unusable. This is an extreme and impractical password policy setting that dictates the *lifespan* of a password, not the *methods* used to verify identity during a self-service password reset. Password expiration policies are distinct from authentication method requirements for SSPR and do not influence the number of factors needed to prove identity for a reset.
Go deeper
Related to this question
Learn chapter
Core Security Concepts
Key term
SSPR
Self-Service Password Reset — a system that allows users to reset their own passwords without contacting IT support.
Key term
Self-service password reset
Self-service password reset (SSPR) is a Microsoft identity feature that allows users to reset their own passwords without needing help from an IT helpdesk.
About these practice questions
This SC-900 question is part of Courseiva's 1,250-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.