SC-900 Describe the capabilities of Microsoft Entra Practice Question
A company wants to provide employees with single sign-on access to both Microsoft 365 and a third-party SaaS application. Which feature of Microsoft Entra ID should they use?
⚠ Common exam trap
Many candidates confuse Conditional Access (a policy engine) with the underlying federation trust required for SSO, mistakenly thinking that policy enforcement alone enables single sign-on.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Federation
Federation (Option C) is correct because it establishes a trust relationship between Microsoft Entra ID and the third-party SaaS application's identity provider using standards like SAML 2.0 or WS-Federation. This allows users to authenticate once with their corporate credentials and gain access to both Microsoft 365 and the third-party app without separate logins, enabling true single sign-on (SSO).
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Identity Protection
Why it's wrong here
Azure AD Identity Protection is a security feature designed to detect, investigate, and remediate identity-based risks. It analyzes sign-in attempts and user behavior to identify anomalies like leaked credentials or suspicious locations, then enforces automated responses such as blocking access or requiring multi-factor authentication. Its purpose is risk mitigation and security posture improvement, not to establish the underlying mechanism for single sign-on.
- ✗
Conditional Access
Why it's wrong here
Conditional Access policies in Azure AD define 'if-then' rules to control access to resources based on specific conditions like user location, device state, or sign-in risk. While it can enforce strong authentication or restrict access, it acts as an enforcement layer *after* an identity has been established or is attempting to be established. It does not provide the foundational framework for a user to authenticate once and gain seamless access to multiple, distinct applications without re-entering credentials.
- ✓
Federation
Why this is correct
Federation establishes a trust relationship between an identity provider (IdP) and one or more service providers (SPs), enabling users to authenticate once with the IdP and gain access to multiple SPs without re-entering credentials. This mechanism, often leveraging protocols like SAML or OpenID Connect, allows the IdP to assert a user's identity to various applications. It is the core technology that facilitates single sign-on (SSO) across different applications and organizational boundaries.
- ✗
Privileged Identity Management
Why it's wrong here
Azure AD Privileged Identity Management (PIM) is a service focused on managing, controlling, and monitoring access to highly privileged roles and resources within Azure AD and Azure. It provides just-in-time (JIT) access, requiring users to activate roles for a limited time and often with multi-factor authentication, to minimize the attack surface of standing administrative permissions. PIM's primary function is securing and auditing elevated access, not providing a general single sign-on experience for all users across standard business applications.
Go deeper
Related to this question
Learn chapter
Identity Concepts
Key term
SAML
Security Assertion Markup Language (SAML) is an open standard that allows one system to securely tell another system that a user is who they say they are, without sharing the user's password.
Key term
Identity provider
An identity provider (IdP) is a system that creates, stores, and manages digital identities and authenticates users for other applications and services.
About these practice questions
One of 1,250 original SC-900 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.