SC-900 Describe the capabilities of Microsoft Entra Practice Question
A company uses Microsoft Entra ID. They want to enforce multifactor authentication (MFA) for all access to a sensitive HR application. However, they only want to require MFA when the sign-in risk is assessed as medium or high, and block access if the risk is high. Which Conditional Access components must the administrator configure to meet these requirements? (Choose the best answer)
⚠ Common exam trap
Watch out — candidates often confuse Conditions (sign-in risk) with Conditions (device platforms) or Session controls, overlooking that risk-based MFA requires both the risk condition and specific grant controls to enforce different actions per risk level.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Conditions (Sign-in risk) and Grant controls (Require multifactor authentication, Block access)
The scenario requires evaluating sign-in risk as a condition, which is configured under Conditions (Sign-in risk) in Conditional Access. The Grant controls then enforce 'Require multifactor authentication' for medium/high risk and 'Block access' for high risk, directly matching the requirements.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Assignments (Users and cloud apps) and Session controls (Sign-in frequency)
Why it's wrong here
Assignments (Users and cloud apps) define the scope of a Conditional Access policy, specifying which users and applications it targets. However, they do not dictate the *conditions* under which an action is taken, nor do they specify the *action* itself, such as requiring MFA based on risk. Session controls like 'Sign-in frequency' are designed to manage how often users are prompted to reauthenticate their existing sessions, not to dynamically enforce MFA as a direct response to a detected sign-in risk.
- ✓
Conditions (Sign-in risk) and Grant controls (Require multifactor authentication, Block access)
Why this is correct
Correct. The conditions specify when a policy applies (e.g., when risk is medium or high). Grant controls enforce the required actions: require MFA for medium/high risk and block for high risk. Block access is an available grant control.
- ✗
Conditions (Device platforms) and Grant controls (Require approved client app)
Why it's wrong here
Conditions based on 'Device platforms' are used to target policies to specific operating systems, ensuring device compliance or secure access from particular types of devices. Similarly, 'Require approved client app' is a grant control that mandates access only through applications deemed secure by the organization, such as Microsoft Outlook or Teams. Neither of these controls directly assesses or responds to real-time sign-in risk; instead, they focus on the security posture of the device or the application used for access, making them unsuitable for enforcing risk-based MFA.
- ✗
Grant controls (Require multifactor authentication) and Session controls (Application enforce restrictions)
Why it's wrong here
While 'Require multifactor authentication' is the correct grant control to enforce MFA, simply applying it without a relevant condition like 'Sign-in risk' would either enforce MFA universally or based on other non-risk factors, failing to meet the specific requirement of risk-based enforcement. 'Application enforce restrictions' is a session control designed to limit specific actions within a cloud application, such as preventing downloads or printing, after a user has already authenticated. This control does not trigger or enforce MFA based on a user's sign-in risk level.
Go deeper
Related to this question
Learn chapter
Microsoft Entra ID
Key term
Microsoft Entra ID
Microsoft Entra ID is a cloud-based identity and access management service that lets employees sign in and access resources both inside and outside of your organization.
Key term
Multifactor Authentication
Multifactor Authentication (MFA) is a security method that requires you to provide two or more pieces of evidence to prove your identity before accessing an account or system.
About these practice questions
Courseiva writes every SC-900 question from scratch — 1,250 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.