Courseiva
Describe the capabilities of Microsoft EntramediumMultiple ChoiceObjective-mapped

SC-900 Describe the capabilities of Microsoft Entra Practice Question

An organization decides to eliminate passwords for their employees. They deploy Windows Hello for Business on company-issued laptops, allowing users to sign in with a PIN or a biometric gesture (e.g., fingerprint). The IT team also enables Microsoft Authenticator and FIDO2 security keys as alternative sign-in methods. Which Microsoft Entra ID capability are they leveraging?

⚠ Common exam trap

A common mix-up: candidates confuse the authentication method (passwordless) with the security policies that protect it (Conditional Access) or the risk detection that monitors it (Identity Protection), leading them to select a wrong answer that sounds related but is not the core capability being demonstrated.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Passwordless authentication

The organization is implementing passwordless authentication by removing passwords and using Windows Hello for Business (PIN/biometrics), Microsoft Authenticator, and FIDO2 security keys. These methods replace the password with a cryptographic key pair bound to the device or user, satisfying the definition of passwordless authentication in Microsoft Entra ID.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Microsoft Entra ID Protection

    Why it's wrong here

    Microsoft Entra ID Protection is a security service focused on detecting, investigating, and remediating identity-based risks within an organization. It identifies vulnerabilities like leaked credentials, anomalous sign-in patterns, and infected devices. While crucial for enhancing overall identity security, its role is to monitor and protect existing authentication processes and user identities, not to provide alternative passwordless sign-in mechanisms or eliminate the use of passwords.

    When this WOULD be correct

    A question describing an organization that wants to automatically block sign-ins from risky IP addresses or detect compromised credentials would make Entra ID Protection the correct answer. For example: 'An organization uses risk-based policies to require MFA when a sign-in is from an anonymous IP address.'

  • Conditional Access

    Why it's wrong here

    Conditional Access is a powerful policy engine within Microsoft Entra ID that enforces access decisions based on various signals, such as user location, device compliance, or application sensitivity. It determines when and how users can access resources, potentially requiring multi-factor authentication or restricting access. However, Conditional Access itself does not offer authentication methods; it merely evaluates the authentication outcome and applies controls, meaning it cannot eliminate the initial password requirement.

    When this WOULD be correct

    An organization wants to require multi-factor authentication (MFA) for all users accessing sensitive apps, but only when they sign in from untrusted networks. They configure a policy that triggers MFA based on location and risk level. This scenario uses Conditional Access to enforce access controls.

  • Passwordless authentication

    Why this is correct

    Passwordless authentication directly addresses the goal of eliminating passwords by replacing them with stronger, more convenient alternatives. In Microsoft Entra ID, this includes methods like Windows Hello for Business, Microsoft Authenticator app, and FIDO2 security keys. These methods leverage biometrics, device-bound credentials, or cryptographic keys to verify user identity, significantly enhancing security and streamlining the sign-in experience without ever requiring a traditional password.

  • Self-Service Password Reset (SSPR)

    Why it's wrong here

    Self-Service Password Reset (SSPR) is a feature that empowers users to reset their own forgotten or expired passwords without administrator intervention. While it improves user productivity and reduces help desk calls, SSPR inherently relies on the continued existence of passwords. It facilitates the management of passwords, but it does not eliminate the need for users to create, remember, or use a password for authentication.

    When this WOULD be correct

    A question where users are allowed to reset their own passwords without IT help, using methods like security questions, email, or phone verification, and the organization wants to reduce helpdesk calls for password resets.

Option-by-option analysis

Why each answer is right or wrong

Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The SC-900 exam frequently reuses these exact scenarios with slightly different constraints.

Passwordless authenticationCorrect answer

Why this is correct

Passwordless authentication directly addresses the goal of eliminating passwords by replacing them with stronger, more convenient alternatives. In Microsoft Entra ID, this includes methods like Windows Hello for Business, Microsoft Authenticator app, and FIDO2 security keys. These methods leverage biometrics, device-bound credentials, or cryptographic keys to verify user identity, significantly enhancing security and streamlining the sign-in experience without ever requiring a traditional password.

Microsoft Entra ID ProtectionWrong answer — click to see why

Why this is wrong here

Microsoft Entra ID Protection is a security tool that detects and remediates identity-based risks (e.g., leaked credentials, anomalous sign-ins), not a method for eliminating passwords. The question focuses on deploying passwordless sign-in methods (PIN, biometrics, Authenticator, FIDO2), which is a passwordless authentication capability.

★ When this WOULD be the correct answer

A question describing an organization that wants to automatically block sign-ins from risky IP addresses or detect compromised credentials would make Entra ID Protection the correct answer. For example: 'An organization uses risk-based policies to require MFA when a sign-in is from an anonymous IP address.'

Why candidates choose this

Candidates may confuse 'passwordless authentication' with 'identity protection' because both are security features in Entra ID, and the scenario involves eliminating passwords, which could be seen as a protective measure against password attacks.

Conditional AccessWrong answer — click to see why

Why this is wrong here

Conditional Access is a policy engine that enforces access controls based on signals like user, device, or location, but it is not the capability that enables passwordless sign-in methods like Windows Hello for Business, Microsoft Authenticator, or FIDO2 keys.

★ When this WOULD be the correct answer

An organization wants to require multi-factor authentication (MFA) for all users accessing sensitive apps, but only when they sign in from untrusted networks. They configure a policy that triggers MFA based on location and risk level. This scenario uses Conditional Access to enforce access controls.

Why candidates choose this

Candidates may confuse the policy enforcement layer (Conditional Access) with the authentication method itself (passwordless), especially when passwordless methods are often combined with Conditional Access policies for security.

Self-Service Password Reset (SSPR)Wrong answer — click to see why

Why this is wrong here

The scenario describes eliminating passwords and using PIN, biometrics, Authenticator, and FIDO2 keys for sign-in, which is passwordless authentication. SSPR is a feature that allows users to reset their own passwords when forgotten, not to eliminate passwords entirely.

★ When this WOULD be the correct answer

A question where users are allowed to reset their own passwords without IT help, using methods like security questions, email, or phone verification, and the organization wants to reduce helpdesk calls for password resets.

Why candidates choose this

Candidates may confuse passwordless authentication with password reset capabilities, thinking that eliminating passwords involves resetting them, or they may not clearly distinguish between authentication methods and self-service recovery options.

Analysis generated from the official SC-900blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”

About these practice questions

Courseiva writes every SC-900 question from scratch — 1,250 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.