SC-900 Describe the capabilities of Microsoft Entra Practice Question
An organization decides to eliminate passwords for their employees. They deploy Windows Hello for Business on company-issued laptops, allowing users to sign in with a PIN or a biometric gesture (e.g., fingerprint). The IT team also enables Microsoft Authenticator and FIDO2 security keys as alternative sign-in methods. Which Microsoft Entra ID capability are they leveraging?
⚠ Common exam trap
A common mix-up: candidates confuse the authentication method (passwordless) with the security policies that protect it (Conditional Access) or the risk detection that monitors it (Identity Protection), leading them to select a wrong answer that sounds related but is not the core capability being demonstrated.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Passwordless authentication
The organization is implementing passwordless authentication by removing passwords and using Windows Hello for Business (PIN/biometrics), Microsoft Authenticator, and FIDO2 security keys. These methods replace the password with a cryptographic key pair bound to the device or user, satisfying the definition of passwordless authentication in Microsoft Entra ID.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Microsoft Entra ID Protection
Why it's wrong here
Microsoft Entra ID Protection is a security service focused on detecting, investigating, and remediating identity-based risks within an organization. It identifies vulnerabilities like leaked credentials, anomalous sign-in patterns, and infected devices. While crucial for enhancing overall identity security, its role is to monitor and protect existing authentication processes and user identities, not to provide alternative passwordless sign-in mechanisms or eliminate the use of passwords.
When this WOULD be correct
A question describing an organization that wants to automatically block sign-ins from risky IP addresses or detect compromised credentials would make Entra ID Protection the correct answer. For example: 'An organization uses risk-based policies to require MFA when a sign-in is from an anonymous IP address.'
- ✗
Conditional Access
Why it's wrong here
Conditional Access is a powerful policy engine within Microsoft Entra ID that enforces access decisions based on various signals, such as user location, device compliance, or application sensitivity. It determines when and how users can access resources, potentially requiring multi-factor authentication or restricting access. However, Conditional Access itself does not offer authentication methods; it merely evaluates the authentication outcome and applies controls, meaning it cannot eliminate the initial password requirement.
When this WOULD be correct
An organization wants to require multi-factor authentication (MFA) for all users accessing sensitive apps, but only when they sign in from untrusted networks. They configure a policy that triggers MFA based on location and risk level. This scenario uses Conditional Access to enforce access controls.
- ✓
Passwordless authentication
Why this is correct
Passwordless authentication directly addresses the goal of eliminating passwords by replacing them with stronger, more convenient alternatives. In Microsoft Entra ID, this includes methods like Windows Hello for Business, Microsoft Authenticator app, and FIDO2 security keys. These methods leverage biometrics, device-bound credentials, or cryptographic keys to verify user identity, significantly enhancing security and streamlining the sign-in experience without ever requiring a traditional password.
- ✗
Self-Service Password Reset (SSPR)
Why it's wrong here
Self-Service Password Reset (SSPR) is a feature that empowers users to reset their own forgotten or expired passwords without administrator intervention. While it improves user productivity and reduces help desk calls, SSPR inherently relies on the continued existence of passwords. It facilitates the management of passwords, but it does not eliminate the need for users to create, remember, or use a password for authentication.
When this WOULD be correct
A question where users are allowed to reset their own passwords without IT help, using methods like security questions, email, or phone verification, and the organization wants to reduce helpdesk calls for password resets.
Option-by-option analysis
Why each answer is right or wrong
Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The SC-900 exam frequently reuses these exact scenarios with slightly different constraints.
✓Passwordless authenticationCorrect answer▾
Why this is correct
Passwordless authentication directly addresses the goal of eliminating passwords by replacing them with stronger, more convenient alternatives. In Microsoft Entra ID, this includes methods like Windows Hello for Business, Microsoft Authenticator app, and FIDO2 security keys. These methods leverage biometrics, device-bound credentials, or cryptographic keys to verify user identity, significantly enhancing security and streamlining the sign-in experience without ever requiring a traditional password.
✗Microsoft Entra ID ProtectionWrong answer — click to see why▾
Why this is wrong here
Microsoft Entra ID Protection is a security tool that detects and remediates identity-based risks (e.g., leaked credentials, anomalous sign-ins), not a method for eliminating passwords. The question focuses on deploying passwordless sign-in methods (PIN, biometrics, Authenticator, FIDO2), which is a passwordless authentication capability.
★ When this WOULD be the correct answer
A question describing an organization that wants to automatically block sign-ins from risky IP addresses or detect compromised credentials would make Entra ID Protection the correct answer. For example: 'An organization uses risk-based policies to require MFA when a sign-in is from an anonymous IP address.'
Why candidates choose this
Candidates may confuse 'passwordless authentication' with 'identity protection' because both are security features in Entra ID, and the scenario involves eliminating passwords, which could be seen as a protective measure against password attacks.
✗Conditional AccessWrong answer — click to see why▾
Why this is wrong here
Conditional Access is a policy engine that enforces access controls based on signals like user, device, or location, but it is not the capability that enables passwordless sign-in methods like Windows Hello for Business, Microsoft Authenticator, or FIDO2 keys.
★ When this WOULD be the correct answer
An organization wants to require multi-factor authentication (MFA) for all users accessing sensitive apps, but only when they sign in from untrusted networks. They configure a policy that triggers MFA based on location and risk level. This scenario uses Conditional Access to enforce access controls.
Why candidates choose this
Candidates may confuse the policy enforcement layer (Conditional Access) with the authentication method itself (passwordless), especially when passwordless methods are often combined with Conditional Access policies for security.
✗Self-Service Password Reset (SSPR)Wrong answer — click to see why▾
Why this is wrong here
The scenario describes eliminating passwords and using PIN, biometrics, Authenticator, and FIDO2 keys for sign-in, which is passwordless authentication. SSPR is a feature that allows users to reset their own passwords when forgotten, not to eliminate passwords entirely.
★ When this WOULD be the correct answer
A question where users are allowed to reset their own passwords without IT help, using methods like security questions, email, or phone verification, and the organization wants to reduce helpdesk calls for password resets.
Why candidates choose this
Candidates may confuse passwordless authentication with password reset capabilities, thinking that eliminating passwords involves resetting them, or they may not clearly distinguish between authentication methods and self-service recovery options.
Analysis generated from the official SC-900blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”
Go deeper
Related to this question
Learn chapter
Core Security Concepts
Key term
Biometrics
Biometrics is the technology that uses unique physical or behavioral traits, like fingerprints or voice patterns, to verify a person's identity.
Key term
Key pair
A key pair is a set of two cryptographic keys—a public key and a private key—used together to encrypt and decrypt data or to create and verify digital signatures.
About these practice questions
Courseiva writes every SC-900 question from scratch — 1,250 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.