SC-900 Describe the capabilities of Microsoft Entra Practice Question
A company uses Microsoft Entra ID. The security team wants to configure a policy so that when a user signs in from an unfamiliar location (not on the company's trusted IP ranges) or from an unfamiliar device, they are prompted for additional verification (e.g., MFA). However, if the sign-in is from a trusted location (e.g., office IP range) and a known device, no additional verification is required. Which Microsoft Entra ID feature should they configure?
⚠ Common exam trap
Many candidates confuse Microsoft Entra ID Protection with Conditional Access, but ID Protection provides risk signals (e.g., unfamiliar sign-in properties) that can be used by Conditional Access policies, not the policy engine itself that enforces location- and device-based MFA prompts.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Microsoft Entra Conditional Access
Microsoft Entra Conditional Access is the correct feature because it allows administrators to define policies that evaluate sign-in context—such as user location (via named locations with trusted IP ranges) and device state (compliant or hybrid Azure AD joined)—and then enforce actions like requiring MFA only when conditions are not met. This directly matches the requirement to prompt for additional verification from unfamiliar locations or devices while skipping it for trusted ones.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Microsoft Entra ID Protection
Why it's wrong here
Identity Protection detects risks like unfamiliar sign-in properties, but it uses risk levels rather than directly checking trusted locations and known devices. It can require MFA based on risk, but the scenario explicitly wants to allow trusted locations and known devices to skip MFA, which is more granularly configured in Conditional Access.
When this WOULD be correct
A question asking which feature detects and reports risky sign-ins (e.g., from anonymous IP addresses or leaked credentials) without requiring policy enforcement would make ID Protection correct.
- ✓
Microsoft Entra Conditional Access
Why this is correct
Microsoft Entra Conditional Access is the correct solution as it enables granular policy enforcement based on real-time sign-in signals. It allows administrators to define conditions such as user/group, location (via named locations), and device state (e.g., compliant, hybrid Azure AD joined) to determine access. This capability directly supports requiring multi-factor authentication (MFA) for untrusted contexts while explicitly allowing trusted locations and known devices to bypass MFA, aligning perfectly with the scenario's need for conditional authentication.
- ✗
Microsoft Entra Privileged Identity Management (PIM)
Why it's wrong here
Microsoft Entra Privileged Identity Management (PIM) is designed to manage, control, and monitor access to important resources by providing just-in-time (JIT) access and approval workflows for privileged roles. Its primary function is to minimize the standing access of administrators and other high-privilege users. PIM does not, however, provide the functionality to enforce conditional authentication policies like MFA requirements based on sign-in location or device trust for regular user access.
When this WOULD be correct
A question asks: 'The security team needs to require approval for activating the Global Administrator role and limit its usage to a specific time window.' In that scenario, PIM is the correct feature to configure role activation policies.
- ✗
Microsoft Entra Access Reviews
Why it's wrong here
Microsoft Entra Access Reviews are a governance feature used to periodically evaluate and certify who has access to specific resources, such as group memberships, application assignments, or privileged roles. Their purpose is to ensure that only authorized individuals maintain access over time by reviewing existing permissions. This feature does not dynamically control sign-in authentication requirements, such as enforcing or bypassing multi-factor authentication based on real-time conditions like location or device state.
When this WOULD be correct
An exam question might ask: 'The compliance team needs to verify that all users with access to a sensitive application still require that access. Which feature should they use?' In that case, Access Reviews would be correct.
Option-by-option analysis
Why each answer is right or wrong
Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The SC-900 exam frequently reuses these exact scenarios with slightly different constraints.
✓Microsoft Entra Conditional AccessCorrect answer▾
Why this is correct
Microsoft Entra Conditional Access is the correct solution as it enables granular policy enforcement based on real-time sign-in signals. It allows administrators to define conditions such as user/group, location (via named locations), and device state (e.g., compliant, hybrid Azure AD joined) to determine access. This capability directly supports requiring multi-factor authentication (MFA) for untrusted contexts while explicitly allowing trusted locations and known devices to bypass MFA, aligning perfectly with the scenario's need for conditional authentication.
✗Microsoft Entra ID ProtectionWrong answer — click to see why▾
Why this is wrong here
Microsoft Entra ID Protection identifies risks like unfamiliar sign-in properties but does not enforce access policies; it only provides risk signals. Conditional Access is needed to actually require MFA based on those signals.
★ When this WOULD be the correct answer
A question asking which feature detects and reports risky sign-ins (e.g., from anonymous IP addresses or leaked credentials) without requiring policy enforcement would make ID Protection correct.
Why candidates choose this
Candidates confuse risk detection (ID Protection) with risk-based policy enforcement (Conditional Access), assuming the feature that identifies risks also automatically applies controls.
✗Microsoft Entra Privileged Identity Management (PIM)Wrong answer — click to see why▾
Why this is wrong here
Privileged Identity Management (PIM) manages just-in-time privileged role activation and oversight, not sign-in risk policies based on location or device trust. The described policy requires Conditional Access to evaluate conditions like location and device state before prompting for MFA.
★ When this WOULD be the correct answer
A question asks: 'The security team needs to require approval for activating the Global Administrator role and limit its usage to a specific time window.' In that scenario, PIM is the correct feature to configure role activation policies.
Why candidates choose this
Candidates may confuse PIM's role-based access controls with general access policies, or assume 'identity protection' features like risk-based policies are part of PIM, leading them to select it for any security policy involving identities.
✗Microsoft Entra Access ReviewsWrong answer — click to see why▾
Why this is wrong here
Access Reviews are used to review and certify user access rights periodically, not to enforce real-time sign-in policies based on location or device trust.
★ When this WOULD be the correct answer
An exam question might ask: 'The compliance team needs to verify that all users with access to a sensitive application still require that access. Which feature should they use?' In that case, Access Reviews would be correct.
Why candidates choose this
Candidates may confuse Access Reviews with security policies because both involve access control, but Access Reviews focus on attestation and certification, not on conditional enforcement during sign-in.
Analysis generated from the official SC-900blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”
Go deeper
Related to this question
Learn chapter
Core Security Concepts
Key term
Policy
A policy is a set of rules or guidelines that defines how an organization manages, secures, and operates its IT systems and services.
Key term
MFA
Multi-Factor Authentication (MFA) is a security method that requires a user to verify their identity using two or more different types of evidence, such as a password plus a code from a phone, before they can access an account or system.
About these practice questions
This SC-900 question is part of Courseiva's 1,250-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.