SC-900 Describe the capabilities of Microsoft Entra Practice Question
A company uses Microsoft Entra ID. They frequently collaborate with an external partner organization. The IT team wants to allow the partner's users to access the company's internal SharePoint site using their existing corporate credentials from their own Microsoft Entra tenant. The partner users should not have to create separate guest accounts or remember another password. Which Microsoft Entra feature should the IT team configure?
⚠ Common exam trap
Candidates often confuse B2B collaboration with B2C, thinking both are for external users, but B2C is for consumers with self-service sign-up, while B2B is for business partners using their existing corporate identities.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Microsoft Entra B2B collaboration
Microsoft Entra B2B collaboration is the correct feature because it enables external users from a partner organization to access the company's internal SharePoint site using their own corporate credentials from their Microsoft Entra tenant. B2B collaboration creates a guest user object in the resource tenant without requiring separate guest accounts or additional passwords, leveraging cross-tenant trust and SAML/WS-Federation for authentication.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Microsoft Entra B2C
Why it's wrong here
Microsoft Entra B2C (Business-to-Consumer) is a separate identity service specifically designed for customer identity and access management (CIAM), enabling organizations to manage how consumers sign up, sign in, and manage their profiles when using consumer-facing applications. It supports a vast number of consumer identities and various social identity providers, but it is not intended for secure collaboration with employees or partners from other businesses or Microsoft Entra tenants. Its purpose is distinct from inter-organizational B2B collaboration.
When this WOULD be correct
A company wants to allow external customers to sign up and log in to a consumer-facing web application using their own social accounts (e.g., Google, Facebook) or email/password, without requiring an existing corporate identity. The IT team would configure Microsoft Entra B2C to manage customer identities and authentication.
- ✓
Microsoft Entra B2B collaboration
Why this is correct
Microsoft Entra B2B collaboration is the correct solution for enabling secure and seamless collaboration with external partners. It allows organizations to invite guest users from other Microsoft Entra tenants, social identity providers, or email-verified accounts to access applications and resources within their own Microsoft Entra ID. This feature facilitates cross-organizational projects by letting external users utilize their existing credentials without creating new accounts in the host directory, ensuring efficient and governed access.
- ✗
Microsoft Entra Domain Services
Why it's wrong here
Microsoft Entra Domain Services provides managed domain services, such as domain join, LDAP, Kerberos/NTLM authentication, and Group Policy, primarily for cloud-based virtual machines and applications that require traditional Active Directory functionality. It is designed to extend classic domain controller capabilities to Azure IaaS environments, not to facilitate secure identity collaboration with external organizations or guest users from other Microsoft Entra tenants. Therefore, it does not address the requirement for external partner access.
When this WOULD be correct
A company needs to lift-and-shift on-premises applications that require LDAP, Kerberos, or NTLM authentication to Azure without managing domain controllers. Entra Domain Services would be the correct feature to provide managed domain services for those legacy apps.
- ✗
Microsoft Entra Application Proxy
Why it's wrong here
Microsoft Entra Application Proxy enables secure remote access to on-premises web applications for internal users, effectively publishing these applications to the internet without requiring a VPN. While it uses Microsoft Entra ID for authentication, its core function is to bridge on-premises applications to cloud users, not to manage or provision external identities from other organizations for collaborative purposes. It does not facilitate the invitation and management of guest users from partner tenants.
When this WOULD be correct
A company needs to provide remote access to an internal web application hosted on-premises for external users without requiring a VPN. The IT team wants to secure access with pre-authentication and conditional access policies.
Option-by-option analysis
Why each answer is right or wrong
Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The SC-900 exam frequently reuses these exact scenarios with slightly different constraints.
✓Microsoft Entra B2B collaborationCorrect answer▾
Why this is correct
Microsoft Entra B2B collaboration is the correct solution for enabling secure and seamless collaboration with external partners. It allows organizations to invite guest users from other Microsoft Entra tenants, social identity providers, or email-verified accounts to access applications and resources within their own Microsoft Entra ID. This feature facilitates cross-organizational projects by letting external users utilize their existing credentials without creating new accounts in the host directory, ensuring efficient and governed access.
✗Microsoft Entra B2CWrong answer — click to see why▾
Why this is wrong here
Microsoft Entra B2C is designed for customer-facing applications where external users sign up and manage their own identities, not for enabling existing corporate credentials from another Entra tenant to access internal resources like SharePoint.
★ When this WOULD be the correct answer
A company wants to allow external customers to sign up and log in to a consumer-facing web application using their own social accounts (e.g., Google, Facebook) or email/password, without requiring an existing corporate identity. The IT team would configure Microsoft Entra B2C to manage customer identities and authentication.
Why candidates choose this
The 'B2C' label suggests business-to-consumer, which might be confused with business-to-business (B2B). Candidates may think any external user scenario falls under B2C, overlooking that B2C is for consumer identity management, not for partner collaboration with existing corporate credentials.
✗Microsoft Entra Domain ServicesWrong answer — click to see why▾
Why this is wrong here
Microsoft Entra Domain Services provides managed domain services like domain join and group policy, not external user access to SharePoint. It does not enable cross-tenant collaboration or federated authentication for partner users.
★ When this WOULD be the correct answer
A company needs to lift-and-shift on-premises applications that require LDAP, Kerberos, or NTLM authentication to Azure without managing domain controllers. Entra Domain Services would be the correct feature to provide managed domain services for those legacy apps.
Why candidates choose this
Candidates may confuse 'Domain Services' with identity management for external access, or think it provides a broader identity solution that includes collaboration features, not realizing its focus is on legacy authentication and domain join scenarios.
✗Microsoft Entra Application ProxyWrong answer — click to see why▾
Why this is wrong here
Microsoft Entra Application Proxy is used to publish on-premises web applications externally, not to enable cross-tenant collaboration with external partners using their existing credentials.
★ When this WOULD be the correct answer
A company needs to provide remote access to an internal web application hosted on-premises for external users without requiring a VPN. The IT team wants to secure access with pre-authentication and conditional access policies.
Why candidates choose this
Candidates may confuse Application Proxy with a solution for external access, thinking it can handle partner authentication, but it is designed for publishing on-prem apps, not for B2B collaboration scenarios.
Analysis generated from the official SC-900blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”
Go deeper
Related to this question
Learn chapter
Microsoft Entra ID
Key term
Guest user
A guest user is a temporary or limited-access account that allows someone to use a system, network, or application without full user privileges and often without a permanent identity.
Key term
Collaboration
Collaboration in Microsoft 365 refers to the integrated tools and services that enable people to work together in real time, share information, and coordinate tasks from anywhere.
About these practice questions
Courseiva writes every SC-900 question from scratch — 1,250 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.