SC-900 Describe the capabilities of Microsoft Entra Practice Question
A company uses Microsoft Entra ID. They want to require users to perform multifactor authentication (MFA) every 90 days on trusted devices, but force MFA for every sign-in on untrusted devices. Which Conditional Access session control must they configure to meet this requirement?
⚠ Common exam trap
Test-takers frequently confuse 'Persistent browser session' (which controls session persistence across browser closes) with 'Sign-in frequency' (which controls the re-authentication interval), leading them to choose the wrong option for MFA frequency requirements.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Sign-in frequency
Sign-in frequency is the Conditional Access session control that allows administrators to define the time interval after which a user must re-authenticate, even on a trusted device. By setting the sign-in frequency to 90 days for trusted devices and requiring re-authentication for every sign-in on untrusted devices (by setting the frequency to 0 or 1), the requirement is met. This control directly manages the re-prompt interval for MFA, independent of the session token lifetime.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Sign-in frequency
Why this is correct
Sign-in frequency is a session control that determines how often a user must provide authentication credentials again, such as after a set number of days or hours. It can be configured differently for trusted and untrusted devices.
- ✗
Application enforced restrictions
Why it's wrong here
Application enforced restrictions is a Conditional Access session control that delegates session management to supported cloud applications like SharePoint Online or Exchange Online. It instructs these applications to apply specific restrictions, such as preventing downloads, printing, or copy-pasting, based on policy conditions. However, this control does not dictate the frequency at which a user must re-authenticate or provide credentials; it manages actions within an active session.
- ✗
Use app enforced restrictions
Why it's wrong here
"Use app enforced restrictions" is not a valid or recognized session control option within Microsoft Entra Conditional Access policies. Conditional Access policies offer specific, predefined controls like "Application enforced restrictions" or "Sign-in frequency." Selecting a syntactically incorrect or non-existent control means the policy cannot be configured as intended, making it an invalid choice for any scenario.
- ✗
Persistent browser session
Why it's wrong here
Persistent browser session is a Conditional Access control designed to allow users to remain signed in to their browser sessions even after closing and reopening the browser. This control explicitly aims to *reduce* the frequency of sign-ins by maintaining the authenticated state for a specified duration. Therefore, it directly contradicts the requirement to periodically prompt users for re-authentication, as its purpose is to enable session persistence.
Go deeper
Related to this question
Learn chapter
Microsoft Entra ID
Key term
Session token
A session token is a unique identifier generated by a server that allows a user to remain authenticated without re-entering their credentials during a single browsing session.
Key term
User
A user is any person, system, or device that interacts with an IT service, resource, or identity system, typically authenticated through credentials and authorized to perform specific actions.
About these practice questions
Courseiva writes every SC-900 question from scratch — 1,250 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.