SC-900 Describe the capabilities of Microsoft Entra Practice Question
A multinational organization uses Microsoft Entra ID and wants to allow employees to sign in to a custom customer-facing application using their existing social identities (e.g., LinkedIn, Google). They also need to enforce a specific terms of use agreement and be able to revoke a user's access if their social account is compromised. Which Microsoft Entra capability should they configure?
⚠ Common exam trap
It's easy for candidates to confuse Microsoft Entra B2B collaboration (designed for external business partners accessing internal apps) with Microsoft Entra External ID (B2C) (designed for customer-facing apps with social identity providers), because both involve external users, but their use cases and capabilities are fundamentally different.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Microsoft Entra External ID (B2C)
Microsoft Entra External ID (B2C) is the correct choice because it is specifically designed for customer-facing applications that need to support social identity providers (like LinkedIn and Google) via OAuth 2.0 and OpenID Connect. It allows you to enforce a custom terms of use agreement during sign-up and provides the ability to revoke a user's access by disabling their account in the B2C directory or removing the social identity mapping, which directly addresses the requirement to respond to a compromised social account.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Microsoft Entra External ID (B2C)
Why this is correct
Microsoft Entra External ID (B2C) is specifically engineered for Customer Identity and Access Management (CIAM) scenarios, enabling organizations to manage millions of customer identities for their public-facing applications. It natively supports sign-up and sign-in with a wide array of social identity providers like Google, Facebook, and LinkedIn, alongside local accounts. This service allows for extensive customization of user journeys, branding, and the integration of terms of use, making it ideal for consumer applications requiring flexible authentication and authorization for external users.
- ✗
Microsoft Entra B2B collaboration
Why it's wrong here
Microsoft Entra B2B collaboration is designed for inviting external business partners and guests to access an organization's internal applications and resources securely. While it supports federation with other Microsoft Entra tenants or SAML/WS-Fed identity providers, its primary focus is on inter-organizational collaboration, not consumer-facing applications. It does not natively provide a self-service sign-up experience for general customers using social identity providers like Google or Facebook for direct access to public services.
- ✗
Microsoft Entra Identity Protection
Why it's wrong here
Microsoft Entra Identity Protection is a security feature focused on detecting, investigating, and remediating identity-based risks within an organization's Microsoft Entra ID tenant. It monitors for suspicious activities like leaked credentials, unfamiliar sign-in locations, or impossible travel, and can enforce automated remediation actions such as multi-factor authentication prompts or password resets. However, Identity Protection is not an identity provider or a CIAM solution; it does not manage the lifecycle of external customer identities or facilitate authentication through social identity providers.
- ✗
Microsoft Entra Conditional Access
Why it's wrong here
Microsoft Entra Conditional Access allows organizations to implement fine-grained access control policies based on various signals, such as user location, device compliance, or application sensitivity, for already authenticated users. Its purpose is to enforce specific requirements, like requiring MFA or blocking access, after an identity has been established. Conditional Access is not an identity provider itself, nor does it manage the creation or authentication of external customer identities via social identity providers; it acts as a policy enforcement engine atop existing identity solutions.
Go deeper
Related to this question
Learn chapter
Identity Concepts
Key term
User
A user is any person, system, or device that interacts with an IT service, resource, or identity system, typically authenticated through credentials and authorized to perform specific actions.
Key term
OAuth
OAuth is an open standard for access delegation that allows users to grant third-party applications limited access to their resources without sharing their credentials.
About these practice questions
One of 1,250 original SC-900 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.