SC-900 Describe the capabilities of Microsoft Entra Practice Question
A company uses Microsoft Entra ID (Microsoft Entra ID) and wants to configure self-service password reset (SSPR) for all users. The security team requires that users must verify their identity with at least two methods before resetting a password. Which SSPR setting should be configured?
⚠ Common exam trap
SC-900 often tests the confusion between SSPR authentication method count and MFA authentication method requirements, causing candidates to pick combined registration or re-registration options that sound security-related but do not enforce the two-method verification.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Number of methods required to reset: 2
The 'Number of methods required to reset' setting in Microsoft Entra ID SSPR controls how many authentication methods a user must successfully verify before being allowed to reset their password. Setting it to 2 enforces the security team's requirement that users verify identity with at least two methods. This is configured under Authentication methods in the Entra ID password reset blade.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Number of methods required to reset: 2
Why this is correct
This setting, configured within Microsoft Entra ID's Self-Service Password Reset (SSPR) policy, directly controls the security posture of the SSPR process. It dictates the number of distinct authentication factors a user must successfully provide to verify their identity before being allowed to reset their password. Setting this value to '2' ensures a multi-factor authentication approach for password resets, significantly enhancing security by requiring more than one proof of identity.
- ✗
Require re-registration on every authentication
Why it's wrong here
This setting, if it existed in this exact phrasing, would imply a highly disruptive and impractical security measure, forcing users to re-enroll their authentication methods (like phone numbers or authenticator apps) each time they authenticate. While some policies might enforce periodic re-registration or re-authentication, this specific action does not configure the *number* of distinct authentication methods required for a *single* self-service password reset attempt. It's about frequency of registration, not the count of methods per reset.
- ✗
Enable combined registration for SSPR and MFA
Why it's wrong here
Enabling combined registration for Self-Service Password Reset (SSPR) and Multi-Factor Authentication (MFA) streamlines the user onboarding experience by allowing users to set up their authentication methods for both services simultaneously. This feature improves usability and adoption by reducing friction during initial setup. However, it is purely an enrollment experience setting and does not dictate the *number of authentication methods* a user must successfully present when actually performing a password reset.
- ✗
Set password expiration to 0 days
Why it's wrong here
Setting password expiration to 0 days would effectively mean passwords expire immediately upon creation or change, rendering them unusable. This is an extreme and impractical password policy setting that dictates the *lifespan* of a password, not the *methods* used to verify identity during a self-service password reset. Password expiration policies are distinct from authentication method requirements for SSPR and do not influence the number of factors needed to prove identity for a reset.
Go deeper
Related to this question
Learn chapter
Security Defaults in Entra ID
Key term
Identity
Identity is the unique set of attributes that defines a user, device, or service in a computer system, determining what they can access and do.
Key term
SSPR
Self-Service Password Reset — a system that allows users to reset their own passwords without contacting IT support.
About these practice questions
This SC-900 question is part of Courseiva's 1,279-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.