Courseiva
Describe the capabilities of Microsoft EntramediumMultiple ChoiceObjective-mapped

SC-900 Describe the capabilities of Microsoft Entra Practice Question

A company uses Microsoft Entra ID to manage identities. They want to enforce access policies based on user location, device compliance, and application sensitivity. Which Microsoft Entra ID capability should they use?

⚠ Common exam trap

It's easy for candidates to confuse Microsoft Entra ID Protection (which deals with risk detection) with Conditional Access (which enforces policies based on conditions like location and device compliance), but ID Protection does not directly enforce location- or device-based access rules.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Conditional Access

Conditional Access is the correct capability because it allows administrators to create policies that enforce access controls based on conditions such as user location, device compliance, and application sensitivity. These policies evaluate signals at sign-in time and can require multi-factor authentication, block access, or grant limited access based on the defined conditions.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Microsoft Entra ID Protection

    Why it's wrong here

    Microsoft Entra ID Protection primarily focuses on detecting vulnerabilities and identity-based risks, such as compromised credentials or suspicious sign-ins. While it can trigger automated responses like requiring MFA or blocking access based on risk levels, its core function is not to define and enforce granular access policies based on specific, arbitrary conditions like device compliance or user group membership. It acts reactively to risk, rather than proactively defining access rules based on pre-set conditions.

  • Conditional Access

    Why this is correct

    Conditional Access is the precise solution for defining and enforcing granular access policies based on a wide array of conditions. Administrators can configure policies that evaluate user attributes, device state (e.g., compliant vs. non-compliant), location, application being accessed, and sign-in risk. This allows for dynamic access control, enabling actions like requiring multi-factor authentication, blocking access, or allowing access only from managed devices, directly addressing the need for policy enforcement based on specific criteria.

  • Privileged Identity Management (PIM)

    Why it's wrong here

    Privileged Identity Management (PIM) is designed to manage, control, and monitor access to critical resources and privileged roles within Microsoft Entra ID and other Microsoft services. Its primary function is to provide just-in-time and just-enough access for administrative roles, reducing the attack surface associated with standing privileges. PIM does not, however, serve as a general-purpose policy engine for enforcing access based on broad conditions like device compliance or user location for all users and applications.

  • Microsoft Entra Connect Sync

    Why it's wrong here

    Microsoft Entra Connect Sync is a crucial tool for hybrid identity scenarios, facilitating the synchronization of user accounts, groups, and other directory objects from on-premises Active Directory to Microsoft Entra ID. Its core purpose is to ensure identity consistency across environments. This service is purely an identity synchronization mechanism and does not possess any capabilities for defining, evaluating, or enforcing access policies based on conditions like device state, location, or user risk.

About these practice questions

Courseiva writes every SC-900 question from scratch — 1,250 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.