SC-900 Describe the capabilities of Microsoft Entra Practice Question
A company uses Microsoft Entra ID. The security manager wants to provide temporary, time-bound elevated access to the Global Administrator role only when needed, and require approval from a designated approver. Which Microsoft Entra ID capability should they use?
⚠ Common exam trap
A common mix-up: candidates confuse Conditional Access (which controls sign-in conditions) with PIM (which controls role activation), leading them to pick A because they think 'time-bound' refers to session timeout policies rather than role activation duration.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Microsoft Entra Privileged Identity Management (PIM)
Microsoft Entra Privileged Identity Management (PIM) provides just-in-time (JIT) privileged access by allowing users to activate the Global Administrator role for a limited, time-bound duration only when needed, and it enforces approval workflows from designated approvers. This directly matches the security manager's requirement for temporary, approval-based elevation.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Microsoft Entra Conditional Access
Why it's wrong here
Microsoft Entra Conditional Access enforces policies at the time of sign-in or resource access based on user, device, location, and application conditions. It determines if a user can access a resource and how, such as requiring multi-factor authentication. However, it does not manage the elevation of a user's permissions to a privileged role or provide temporary, just-in-time activation for such roles, focusing instead on access enforcement.
- ✓
Microsoft Entra Privileged Identity Management (PIM)
Why this is correct
Microsoft Entra Privileged Identity Management (PIM) is specifically designed to manage, control, and monitor access to important resources within Microsoft Entra ID, Azure, and other Microsoft services. It enables just-in-time (JIT) access, allowing users to activate privileged roles only when needed and for a limited duration. PIM enforces time-bound assignments, multi-factor authentication, and approval workflows for role activation, significantly reducing the attack surface associated with standing privileged access.
- ✗
Microsoft Entra Identity Protection
Why it's wrong here
Microsoft Entra Identity Protection focuses on detecting and remediating identity-based risks, such as compromised credentials, anomalous sign-in locations, or impossible travel scenarios. It generates risk detections and policies that can trigger actions like requiring MFA, password change, or blocking access. While crucial for security, it operates at the risk detection and remediation layer for user identities, not at the layer of managing the lifecycle, activation, or approval of privileged role assignments.
- ✗
Microsoft Entra Identity Governance (Access Reviews)
Why it's wrong here
Access Reviews within Microsoft Entra Identity Governance primarily facilitate periodic review and certification of existing access rights to ensure that users still require the access they have. They help organizations manage stale access and comply with regulatory requirements by prompting reviewers to approve or deny continued access. While important for maintaining a least-privilege posture, Access Reviews do not provide the mechanism for on-demand, just-in-time elevation of privileges or enforce approval workflows for temporary role activation.
Go deeper
Related to this question
Learn chapter
Core Security Concepts
Key term
Identity
Identity is the unique set of attributes that defines a user, device, or service in a computer system, determining what they can access and do.
Key term
PIM
Privileged Identity Management, a Microsoft Azure Active Directory tool that manages, monitors, and controls access to privileged roles on a just-in-time basis.
About these practice questions
Courseiva writes every SC-900 question from scratch — 1,250 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.