SC-900 Describe the capabilities of Microsoft Entra Practice Question
A company wants to provide external consultants with access to a specific application using their LinkedIn or Google accounts. Which Microsoft Entra feature allows this?
⚠ Common exam trap
Watch out — candidates often confuse Conditional Access (which controls access after authentication) with the ability to authenticate external users, or they mistakenly think PIM or Identity Protection can directly enable social identity provider sign-in.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Microsoft Entra External ID
Microsoft Entra External ID (formerly Azure AD External Identities) is the correct feature because it enables external users—such as consultants—to sign in using their own identity providers (IdPs) like LinkedIn or Google via federation. This allows the company to grant access to a specific application without creating separate Microsoft Entra accounts for each consultant, leveraging social identity providers through OpenID Connect or OAuth 2.0 protocols.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Microsoft Entra Conditional Access
Why it's wrong here
Microsoft Entra Conditional Access is a policy engine that evaluates conditions like user, device, location, and application *after* a user has attempted to authenticate. It then enforces access controls such as multi-factor authentication or blocking access based on these conditions. While crucial for securing access, it does not provide the foundational mechanism for external identities to be onboarded or federated into the organization's directory in the first place.
- ✓
Microsoft Entra External ID
Why this is correct
Microsoft Entra External ID is the comprehensive solution for managing and securing identities for external users, including partners, customers, and consultants. It enables organizations to collaborate securely by allowing these external users to sign in with their own identities, such as those from other Microsoft Entra tenants, social identity providers like Google or Facebook, or even via email one-time passcodes. This service specifically facilitates the onboarding and management of external users for resource access without creating full internal accounts.
- ✗
Microsoft Entra Privileged Identity Management
Why it's wrong here
Microsoft Entra Privileged Identity Management (PIM) is designed to manage, control, and monitor access to important resources within an organization by providing just-in-time and just-enough access for privileged roles. It focuses on reducing the risk associated with excessive, unnecessary, or misused access permissions for *existing* identities, whether internal or external. PIM does not, however, provide the core functionality for initially establishing or federating external user identities into the directory for collaboration.
- ✗
Microsoft Entra Identity Protection
Why it's wrong here
Microsoft Entra Identity Protection is a security feature focused on detecting, investigating, and remediating identity-based risks within an organization. It analyzes sign-in and user behavior to identify potential threats like compromised credentials, anomalous sign-ins, or risky user activities. While vital for securing *any* identity, including external ones, it does not serve as the primary service for provisioning or managing external user accounts to grant them initial access to company resources.
Go deeper
Related to this question
Learn chapter
Identity Concepts
Key term
OAuth
OAuth is an open standard for access delegation that allows users to grant third-party applications limited access to their resources without sharing their credentials.
Key term
OpenID Connect
OpenID Connect is an identity layer on top of OAuth 2.0 that allows applications to verify a user's identity and obtain basic profile information in a standardized way.
About these practice questions
Courseiva writes every SC-900 question from scratch — 1,250 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.