SC-900 Describe the capabilities of Microsoft Entra Practice Question
A company uses Microsoft Entra ID. The IT department has three teams: Helpdesk, Global Administrators, and Security Administrators. The company wants to allow the Helpdesk team to manage password resets and group memberships, but only for users who belong to the 'Sales' organizational unit. Which Microsoft Entra feature should the administrator use to define this delegated administrative scope?
⚠ Common exam trap
Watch out — candidates often confuse Privileged Identity Management (PIM) with scope delegation, but PIM controls *when* a role is used (time-bound activation), not *where* it can be applied (scope), which is the core requirement of this question.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Administrative Units
Administrative Units (AUs) in Microsoft Entra ID allow you to delegate administrative permissions scoped to specific organizational units, such as the 'Sales' OU. By placing Sales users into an AU and assigning the Helpdesk team roles like 'Helpdesk Administrator' or 'User Administrator' scoped to that AU, you precisely control which users they can manage for password resets and group memberships. This directly meets the requirement for delegated administrative scope without granting broader tenant-wide permissions.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Administrative Units
Why this is correct
Administrative Units (AUs) in Microsoft Entra ID enable the delegation of administrative permissions over a specific subset of users, groups, or devices. By creating an AU and assigning administrators to it, their management scope is restricted solely to the objects contained within that unit, such as users belonging to a particular department or location. This capability directly addresses the need to decentralize IT administration without granting broad, tenant-wide privileges.
- ✗
Privileged Identity Management (PIM)
Why it's wrong here
Microsoft Entra Privileged Identity Management (PIM) focuses on managing, controlling, and monitoring access to important resources by providing just-in-time and just-enough access for privileged roles. It allows administrators to activate eligible roles for a limited time, reducing the exposure time of standing privileges. While PIM enhances security for privileged roles, it does not provide a mechanism to restrict the *scope* of an administrator's permissions to only a specific subset of users or devices within the directory.
- ✗
Conditional Access policies
Why it's wrong here
Conditional Access policies evaluate conditions such as user, device, location, and application at the time of sign-in to enforce access decisions, like requiring multi-factor authentication or blocking access. They are designed to protect resource access by end-users based on defined policies, not to delegate or restrict the scope of administrative roles within Microsoft Entra ID. Therefore, they cannot be used to assign specific administrative rights over a subset of directory objects.
- ✗
Identity Governance (Access Reviews)
Why it's wrong here
Microsoft Entra Identity Governance, which includes features like Access Reviews and Entitlement Management, is designed to manage and govern the identity and access lifecycle. Access Reviews specifically help organizations efficiently manage group memberships, access to enterprise applications, and role assignments by regularly reviewing who has access to what. However, Identity Governance capabilities do not provide a mechanism to delegate administrative roles with a restricted scope over a subset of directory objects.
Go deeper
Related to this question
Learn chapter
Core Security Concepts
Key term
Security
Security in IT is the practice of protecting systems, networks, and data from unauthorized access, damage, or theft.
Key term
User
A user is any person, system, or device that interacts with an IT service, resource, or identity system, typically authenticated through credentials and authorized to perform specific actions.
About these practice questions
This SC-900 question is part of Courseiva's 1,250-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.