Courseiva
Describe the capabilities of Microsoft EntrahardMultiple ChoiceObjective-mapped

SC-900 Describe the capabilities of Microsoft Entra Practice Question

A multinational company needs to enforce multi-factor authentication for all users but exclude a break-glass emergency account. Which approach should they take in Microsoft Entra ID?

⚠ Common exam trap

It's easy for candidates to confuse security defaults with Conditional Access, assuming security defaults can be customized with exclusions, when in fact security defaults are a fixed baseline that cannot be modified to exclude specific accounts.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Create a Conditional Access policy requiring MFA for all users, excluding the break-glass account

Conditional Access policies in Microsoft Entra ID allow granular control over authentication requirements, including the ability to exclude specific users or groups. By creating a policy that requires multi-factor authentication (MFA) for all users but explicitly excludes the break-glass account, the company ensures security while maintaining emergency access. This approach is more flexible and scalable than per-user MFA or security defaults, which lack the ability to selectively bypass MFA for critical accounts.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Use identity protection to require MFA only for high-risk users

    Why it's wrong here

    Using Identity Protection to require MFA only for high-risk users would not fulfill the requirement to enforce multi-factor authentication for *all* users. Identity Protection policies are designed to detect and respond to specific identity-based risks, applying MFA or other controls *conditionally* when a user or sign-in is deemed risky, rather than universally across the entire user base regardless of risk level.

  • Enable security defaults and add the break-glass account to a group that bypasses MFA

    Why it's wrong here

    Enabling security defaults enforces a baseline set of strong security policies, including MFA for administrative roles and risky sign-ins, but it applies these settings broadly to *all* users and does not support granular exclusions. Security defaults are an 'all or nothing' configuration, meaning there is no built-in mechanism to add a break-glass account to a group that bypasses its mandatory MFA requirements.

  • Enable per-user MFA for all users and turn off for the break-glass account

    Why it's wrong here

    Enabling per-user MFA for all users and then individually disabling it for a break-glass account is a legacy and less scalable method for managing multi-factor authentication. This approach lacks the dynamic policy enforcement, group-based assignments, and granular control offered by Conditional Access, making it cumbersome for enterprise-wide deployment and prone to administrative overhead when managing exceptions.

  • Create a Conditional Access policy requiring MFA for all users, excluding the break-glass account

    Why this is correct

    Creating a Conditional Access policy is the recommended and most flexible method to enforce multi-factor authentication for all users while strategically excluding a break-glass account. Conditional Access allows administrators to define precise conditions, such as requiring MFA for 'All users,' and then apply specific 'Exclusions' for designated emergency access accounts, ensuring both comprehensive security and operational continuity.

About these practice questions

One of 1,250 original SC-900 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.