SC-900 Describe the capabilities of Microsoft Entra Practice Question
A multinational company needs to enforce multi-factor authentication for all users but exclude a break-glass emergency account. Which approach should they take in Microsoft Entra ID?
⚠ Common exam trap
It's easy for candidates to confuse security defaults with Conditional Access, assuming security defaults can be customized with exclusions, when in fact security defaults are a fixed baseline that cannot be modified to exclude specific accounts.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create a Conditional Access policy requiring MFA for all users, excluding the break-glass account
Conditional Access policies in Microsoft Entra ID allow granular control over authentication requirements, including the ability to exclude specific users or groups. By creating a policy that requires multi-factor authentication (MFA) for all users but explicitly excludes the break-glass account, the company ensures security while maintaining emergency access. This approach is more flexible and scalable than per-user MFA or security defaults, which lack the ability to selectively bypass MFA for critical accounts.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Use identity protection to require MFA only for high-risk users
Why it's wrong here
Using Identity Protection to require MFA only for high-risk users would not fulfill the requirement to enforce multi-factor authentication for *all* users. Identity Protection policies are designed to detect and respond to specific identity-based risks, applying MFA or other controls *conditionally* when a user or sign-in is deemed risky, rather than universally across the entire user base regardless of risk level.
- ✗
Enable security defaults and add the break-glass account to a group that bypasses MFA
Why it's wrong here
Enabling security defaults enforces a baseline set of strong security policies, including MFA for administrative roles and risky sign-ins, but it applies these settings broadly to *all* users and does not support granular exclusions. Security defaults are an 'all or nothing' configuration, meaning there is no built-in mechanism to add a break-glass account to a group that bypasses its mandatory MFA requirements.
- ✗
Enable per-user MFA for all users and turn off for the break-glass account
Why it's wrong here
Enabling per-user MFA for all users and then individually disabling it for a break-glass account is a legacy and less scalable method for managing multi-factor authentication. This approach lacks the dynamic policy enforcement, group-based assignments, and granular control offered by Conditional Access, making it cumbersome for enterprise-wide deployment and prone to administrative overhead when managing exceptions.
- ✓
Create a Conditional Access policy requiring MFA for all users, excluding the break-glass account
Why this is correct
Creating a Conditional Access policy is the recommended and most flexible method to enforce multi-factor authentication for all users while strategically excluding a break-glass account. Conditional Access allows administrators to define precise conditions, such as requiring MFA for 'All users,' and then apply specific 'Exclusions' for designated emergency access accounts, ensuring both comprehensive security and operational continuity.
Go deeper
Related to this question
Learn chapter
Core Security Concepts
Key term
User
A user is any person, system, or device that interacts with an IT service, resource, or identity system, typically authenticated through credentials and authorized to perform specific actions.
Key term
Security
Security in IT is the practice of protecting systems, networks, and data from unauthorized access, damage, or theft.
About these practice questions
One of 1,250 original SC-900 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.