SC-900 Describe the capabilities of Microsoft Entra Practice Question
A company wants to ensure that only users with specific IP addresses can access its critical applications. Which Microsoft Entra feature should they configure?
⚠ Common exam trap
Watch out — candidates often confuse Identity Protection's risk-based conditional access (which uses IP reputation) with the explicit IP address location control provided by Conditional Access policies, leading them to select Identity Protection instead.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Conditional Access
Conditional Access is the correct feature because it allows administrators to create policies that enforce access controls based on conditions such as IP address location. By configuring a Conditional Access policy with a 'Locations' condition that includes only trusted IP address ranges, the company can block or grant access to critical applications based on the user's network location. This directly meets the requirement to restrict access to specific IP addresses.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Identity Protection
Why it's wrong here
Azure AD Identity Protection is a security module focused on detecting and remediating identity-based risks, such as impossible travel, leaked credentials, or sign-ins from unfamiliar locations. While it can feed risk signals into Conditional Access policies to trigger specific actions, it does not directly define or enforce network location-based access restrictions itself. Its primary function is risk detection, analysis, and reporting, not policy enforcement based on static IP addresses.
- ✗
Privileged Identity Management
Why it's wrong here
Azure AD Privileged Identity Management (PIM) is designed to manage, control, and monitor access to important organizational resources by providing just-in-time (JIT) and just-enough-access (JEA) to privileged roles. PIM focuses on time-bound access, approval workflows, and auditing for elevated permissions, ensuring that users only have necessary privileges for a limited duration. It does not offer functionality to restrict access based on the source IP address of a user's connection, as its scope is privilege lifecycle management, not network location enforcement.
- ✓
Conditional Access
Why this is correct
Azure AD Conditional Access serves as the policy engine for enforcing access controls based on specific conditions, making it the correct solution for IP-based restrictions. Administrators can define 'named locations' using public IP address ranges or country/region lists, then create policies that grant or block access if users are signing in from these specified locations. This allows precise control over who can access resources from particular network segments, directly addressing the company's requirement for IP-specific access.
- ✗
Self-Service Password Reset
Why it's wrong here
Self-Service Password Reset (SSPR) empowers users to securely reset their own forgotten or locked passwords without requiring administrator assistance. This feature is solely focused on account recovery and password management, streamlining the process for end-users and reducing helpdesk calls. SSPR provides no mechanisms or capabilities for defining, evaluating, or enforcing access restrictions based on the source IP address of a user's sign-in attempt to applications or resources.
Go deeper
Related to this question
Learn chapter
Microsoft Entra ID
Key term
Conditional access
Conditional access is a security framework that evaluates signals like user location, device health, and risk level to grant or block access to resources in real time.
Key term
Conditional Access policy
A Conditional Access policy is a set of rules in Microsoft Entra ID that automatically grants or blocks access to cloud apps based on signals like user identity, location, device health, and risk level.
About these practice questions
This SC-900 question is part of Courseiva's 1,250-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.