SC-900 Describe the capabilities of Microsoft Entra Practice Question
A company uses Microsoft Entra ID. They want to ensure that only users with a specific role can reset passwords for other users in their organization. Which feature should they use?
⚠ Common exam trap
Many candidates confuse Privileged Identity Management (PIM) with role-based delegation, but PIM controls when a role is active, not who can perform a specific action on a specific set of users.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Administrative Units
Administrative Units allow you to delegate administrative tasks, such as password resets, to users who have a specific role scoped to a subset of users. By assigning the Helpdesk Administrator role to an Administrative Unit, you ensure that only those users can reset passwords for members of that unit, meeting the requirement precisely.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Privileged Identity Management
Why it's wrong here
Microsoft Entra Privileged Identity Management (PIM) is designed to manage, control, and monitor access to important resources within an organization. It provides just-in-time access to roles, requiring activation and often approval for time-bound assignments, thereby reducing the attack surface of standing administrative privileges. However, PIM does not inherently restrict the scope of objects (e.g., specific users or groups) that an activated administrative role can manage; it only governs the activation and duration of the role itself.
- ✗
Conditional Access
Why it's wrong here
Microsoft Entra Conditional Access policies are security tools that enforce specific conditions for users attempting to access cloud applications and resources. These policies evaluate various signals, such as user location, device compliance, and sign-in risk, to determine whether to grant access, block access, or require additional authentication steps. Conditional Access is fundamentally about controlling user access to resources, not about delegating or scoping administrative permissions to manage a subset of directory objects.
- ✓
Administrative Units
Why this is correct
Microsoft Entra Administrative Units (AUs) provide a mechanism to delegate administrative permissions over a specific subset of Microsoft Entra objects, such as users, groups, or devices. By creating an AU and adding relevant objects, an organization can assign administrative roles (e.g., User Administrator, Password Administrator) that are scoped only to the members within that unit. This ensures that administrators can manage only the users or groups they are authorized for, preventing them from affecting the entire directory.
- ✗
Identity Protection
Why it's wrong here
Microsoft Entra Identity Protection is a security feature focused on detecting, investigating, and remediating identity-based risks within an organization. It identifies potential vulnerabilities affecting identities, such as leaked credentials, and detects suspicious sign-in behaviors like impossible travel or sign-ins from infected devices. While crucial for security, Identity Protection does not offer any capabilities for delegating administrative roles or limiting the scope of management for administrators.
Go deeper
Related to this question
Learn chapter
Microsoft Entra ID
Key term
Microsoft Entra ID
Microsoft Entra ID is a cloud-based identity and access management service that lets employees sign in and access resources both inside and outside of your organization.
Key term
Administrative unit
An Administrative unit is a container in Microsoft Entra ID that allows you to delegate administrative permissions over a subset of users, groups, or devices, rather than the entire directory.
About these practice questions
One of 1,250 original SC-900 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.