SC-900 Describe the capabilities of Microsoft Entra Practice Question
A user reports that they cannot access a critical application, receiving an error that their session has expired. The sign-in logs show the user was prompted for multifactor authentication (MFA) multiple times during the same session. What should an administrator review to reduce these interruptions?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Microsoft Entra Conditional Access session controls
Session controls in Conditional Access policies can be configured to reduce repeated MFA prompts within the same session, such as by adjusting the sign-in frequency or persistent browser session settings. Option A is wrong because tenant-wide MFA settings enforce MFA globally but do not control session-specific behavior. Option C is wrong because Identity Protection focuses on risk-based policies, not directly on session lifetime. Option D is wrong because Privileged Identity Management manages role activation and assignment, not session controls.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Microsoft Entra tenant-wide MFA settings
Why it's wrong here
Microsoft Entra tenant-wide MFA settings enforce multi-factor authentication for all users or specific groups across the entire tenant. While crucial for security, these settings do not offer granular control over session duration, sign-in frequency, or persistent browser sessions. They dictate *if* MFA is required, not *how often* it's prompted within an active session, making them unsuitable for optimizing user experience related to MFA frequency.
- ✓
Microsoft Entra Conditional Access session controls
Why this is correct
Microsoft Entra Conditional Access session controls are specifically designed to manage user sessions after initial authentication, including the frequency of re-authentication and the persistence of browser sessions. By configuring sign-in frequency, administrators can reduce the number of MFA prompts users receive within a defined period, enhancing productivity while maintaining security. These controls provide the granular capability to balance security posture with user experience for specific applications or conditions.
- ✗
Microsoft Entra Identity Protection policies
Why it's wrong here
Microsoft Entra Identity Protection policies focus on detecting and remediating identity-based risks, such as leaked credentials or anomalous sign-ins. These policies can trigger conditional access requirements, including MFA, when a risk is detected, but they do not directly manage the standard session lifetime or sign-in frequency for non-risky sessions. Their purpose is risk mitigation, not optimizing routine authentication prompts for a critical application.
- ✗
Microsoft Entra Privileged Identity Management settings
Why it's wrong here
Microsoft Entra Privileged Identity Management (PIM) is a service that enables organizations to manage, control, and monitor access to important resources in Azure AD, Azure, and other Microsoft online services. PIM focuses on just-in-time and just-enough access for privileged roles, requiring activation and often MFA for elevated permissions. It does not govern the session persistence or sign-in frequency for standard user access to a critical application.
Go deeper
Related to this question
Learn chapter
Identity Concepts
Key term
Identity
Identity is the unique set of attributes that defines a user, device, or service in a computer system, determining what they can access and do.
Key term
Risk
Risk is the possibility that an event or action will negatively affect an organization's ability to achieve its goals, often measured in terms of likelihood and impact.
About these practice questions
Courseiva writes every SC-900 question from scratch — 1,250 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.