SC-900 Microsoft Entra ID Password Protection Practice Question
A company uses Microsoft Entra ID. The security team wants to enforce a policy that prevents users from choosing commonly used weak passwords like 'Winter2024!' or 'Password@123', and also blocks customized variants based on organizational context (e.g., company name). Users must create passwords that meet standard complexity requirements. Which Microsoft Entra ID feature should they enable?
⚠ Common exam trap
A common mix-up: candidates confuse Self-Service Password Reset (SSPR) with password policy enforcement, but SSPR only facilitates password changes and does not block weak passwords; the actual blocking is done by Password Protection, which is a separate feature.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Microsoft Entra ID Password Protection
Microsoft Entra ID Password Protection (B) is the correct feature because it specifically enforces custom banned password lists that block weak passwords like 'Winter2024!' and organizational variants such as the company name. It works alongside standard password complexity requirements to prevent users from choosing passwords that appear on a global banned list or a tenant-specific custom list. This directly addresses the security team's need to block commonly used weak passwords and context-based variants.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Password hash synchronization
Why it's wrong here
Password hash synchronization is a feature of Microsoft Entra Connect that synchronizes password hashes from on-premises AD to Microsoft Entra ID for hybrid identity. It does not enforce password policies.
When this WOULD be correct
In a hybrid identity scenario where the organization wants to enable cloud authentication for users synced from on-premises AD, enabling password hash synchronization would be the correct answer.
- ✓
Microsoft Entra ID Password Protection
Why this is correct
Correct. Microsoft Entra ID Password Protection blocks weak passwords and their common variants, including custom banned lists. It is the appropriate feature for enforcing strong password choices beyond default complexity.
- ✗
Self-Service Password Reset
Why it's wrong here
Self-Service Password Reset (SSPR) allows users to reset their own passwords when forgotten, but it does not prevent users from choosing weak passwords during the reset or initial set.
When this WOULD be correct
A company wants to enable users to reset their forgotten passwords without IT helpdesk intervention, while still requiring multi-factor authentication for the reset process. The correct answer would be Self-Service Password Reset (SSPR) with appropriate authentication methods.
- ✗
Conditional Access
Why it's wrong here
Conditional Access policies enforce access controls based on signals like user, location, and device state. They do not verify password strength or block weak passwords.
When this WOULD be correct
A company wants to require multi-factor authentication when users sign in from untrusted locations or devices. Which Microsoft Entra ID feature should they use?
Option-by-option analysis
Why each answer is right or wrong
Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The SC-900 exam frequently reuses these exact scenarios with slightly different constraints.
✓Microsoft Entra ID Password ProtectionCorrect answer▾
Why this is correct
Correct. Microsoft Entra ID Password Protection blocks weak passwords and their common variants, including custom banned lists. It is the appropriate feature for enforcing strong password choices beyond default complexity.
✗Password hash synchronizationWrong answer — click to see why▾
Why this is wrong here
Password hash synchronization is a feature for syncing password hashes from on-premises AD to Entra ID for authentication, not for enforcing password policies like blocking weak or context-specific passwords.
★ When this WOULD be the correct answer
In a hybrid identity scenario where the organization wants to enable cloud authentication for users synced from on-premises AD, enabling password hash synchronization would be the correct answer.
Why candidates choose this
Candidates may confuse password policy enforcement with password synchronization, thinking that syncing hashes also applies policy checks, or they may misremember the name of the password protection feature.
✗Self-Service Password ResetWrong answer — click to see why▾
Why this is wrong here
Self-Service Password Reset (SSPR) allows users to reset their own passwords but does not enforce password policies that block weak or context-specific passwords. The question asks for a feature to prevent weak passwords, which is handled by Password Protection, not SSPR.
★ When this WOULD be the correct answer
A company wants to enable users to reset their forgotten passwords without IT helpdesk intervention, while still requiring multi-factor authentication for the reset process. The correct answer would be Self-Service Password Reset (SSPR) with appropriate authentication methods.
Why candidates choose this
Candidates may confuse SSPR with password policy enforcement because both relate to password management, or they might think SSPR includes policy checks when it only facilitates password changes.
✗Conditional AccessWrong answer — click to see why▾
Why this is wrong here
Conditional Access is used to enforce access controls based on signals like user location or device state, not to enforce password complexity or block weak passwords.
★ When this WOULD be the correct answer
A company wants to require multi-factor authentication when users sign in from untrusted locations or devices. Which Microsoft Entra ID feature should they use?
Why candidates choose this
Candidates may confuse policy enforcement for password strength with broader access control policies, assuming Conditional Access can handle password rules.
Analysis generated from the official SC-900blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”
Go deeper
Related to this question
Learn chapter
Core Security Concepts
Key term
Policy
A policy is a set of rules or guidelines that defines how an organization manages, secures, and operates its IT systems and services.
Key term
Microsoft Entra ID
Microsoft Entra ID is a cloud-based identity and access management service that lets employees sign in and access resources both inside and outside of your organization.
About these practice questions
One of 1,250 original SC-900 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.