Courseiva
Describe the capabilities of Microsoft EntrahardMultiple ChoiceObjective-mapped

SC-900 Describe the capabilities of Microsoft Entra Practice Question

A multinational organization uses Microsoft Entra ID for identity management. External contractors need temporary elevated access to Azure resources for a critical project. The access must be time-bound (expires after 8 hours), require manager approval, and enforce multifactor authentication (MFA) when contractors activate the role. Which Microsoft Entra capability should they configure?

⚠ Common exam trap

Test-takers frequently confuse Conditional Access (which enforces MFA at sign-in) with PIM's ability to enforce MFA specifically during role activation, or they mistakenly think Access Reviews can grant time-bound access, when in fact Access Reviews only validate existing access and do not provide JIT activation or approval workflows.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Privileged Identity Management (PIM)

Privileged Identity Management (PIM) is the correct choice because it provides just-in-time (JIT) privileged access to Azure resources with time-bound activation (e.g., 8-hour expiry), requires approval workflows (manager approval), and enforces multifactor authentication (MFA) during role activation. PIM is specifically designed to manage, control, and monitor access to critical resources through time-limited, approved, and MFA-protected role assignments.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Privileged Identity Management (PIM)

    Why this is correct

    Microsoft Entra Privileged Identity Management (PIM) enables organizations to manage, control, and monitor access to important resources. It provides just-in-time (JIT) access, allowing users to activate privileged roles for a limited time period. This activation often requires multi-factor authentication (MFA) and an approval workflow, ensuring that elevated permissions are granted only when necessary and with proper oversight, significantly reducing the attack surface for privileged accounts.

  • Identity Protection

    Why it's wrong here

    Microsoft Entra Identity Protection focuses on detecting and remediating identity-based risks. It analyzes sign-in and user behavior to identify potential threats such as leaked credentials, impossible travel, or suspicious IP addresses. While crucial for security, Identity Protection primarily provides risk signals and automated remediation actions like blocking or forcing password resets, rather than managing the activation of time-bound, just-in-time privileged role assignments.

  • Conditional Access

    Why it's wrong here

    Microsoft Entra Conditional Access enforces policies based on specific conditions evaluated at the time of a user's sign-in attempt. These policies can grant or block access, or require additional authentication steps like MFA, based on factors such as user group, location, device state, or application being accessed. However, Conditional Access does not facilitate the temporary activation of privileged roles with time limits or require an approval process for role elevation.

  • Access Reviews

    Why it's wrong here

    Microsoft Entra Access Reviews enable organizations to periodically review and attest to user access rights to various resources, including group memberships and application assignments. This feature helps ensure that users maintain only the necessary permissions over time, supporting compliance and least privilege principles. While vital for governance, Access Reviews are a tool for auditing existing access and facilitating recertification, not for providing just-in-time, time-bound role activation with approval workflows.

About these practice questions

Courseiva writes every SC-900 question from scratch — 1,250 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.