Courseiva
Describe the capabilities of Microsoft EntraeasyMultiple ChoiceObjective-mapped

SC-900 Describe the capabilities of Microsoft Entra Practice Question

A company wants to provide employees with single sign-on access to both Microsoft 365 and a third-party SaaS application. Which feature of Microsoft Entra ID should they use?

⚠ Common exam trap

Many candidates confuse Conditional Access (a policy engine) with the underlying federation trust required for SSO, mistakenly thinking that policy enforcement alone enables single sign-on.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Federation

Federation (Option C) is correct because it establishes a trust relationship between Microsoft Entra ID and the third-party SaaS application's identity provider using standards like SAML 2.0 or WS-Federation. This allows users to authenticate once with their corporate credentials and gain access to both Microsoft 365 and the third-party app without separate logins, enabling true single sign-on (SSO).

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Identity Protection

    Why it's wrong here

    Azure AD Identity Protection is a security feature designed to detect, investigate, and remediate identity-based risks. It analyzes sign-in attempts and user behavior to identify anomalies like leaked credentials or suspicious locations, then enforces automated responses such as blocking access or requiring multi-factor authentication. Its purpose is risk mitigation and security posture improvement, not to establish the underlying mechanism for single sign-on.

  • Conditional Access

    Why it's wrong here

    Conditional Access policies in Azure AD define 'if-then' rules to control access to resources based on specific conditions like user location, device state, or sign-in risk. While it can enforce strong authentication or restrict access, it acts as an enforcement layer *after* an identity has been established or is attempting to be established. It does not provide the foundational framework for a user to authenticate once and gain seamless access to multiple, distinct applications without re-entering credentials.

  • Federation

    Why this is correct

    Federation establishes a trust relationship between an identity provider (IdP) and one or more service providers (SPs), enabling users to authenticate once with the IdP and gain access to multiple SPs without re-entering credentials. This mechanism, often leveraging protocols like SAML or OpenID Connect, allows the IdP to assert a user's identity to various applications. It is the core technology that facilitates single sign-on (SSO) across different applications and organizational boundaries.

  • Privileged Identity Management

    Why it's wrong here

    Azure AD Privileged Identity Management (PIM) is a service focused on managing, controlling, and monitoring access to highly privileged roles and resources within Azure AD and Azure. It provides just-in-time (JIT) access, requiring users to activate roles for a limited time and often with multi-factor authentication, to minimize the attack surface of standing administrative permissions. PIM's primary function is securing and auditing elevated access, not providing a general single sign-on experience for all users across standard business applications.

About these practice questions

One of 1,250 original SC-900 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.