SC-900 Describe the capabilities of Microsoft Entra Practice Question
An organization has Microsoft Sentinel and Microsoft Defender XDR. They want to automatically block a user's sign-in if a high-risk alert is triggered. Which Microsoft Entra feature integrates with these products to enforce access controls?
⚠ Common exam trap
Many candidates confuse Microsoft Entra Identity Protection (which only detects and reports risk) with Conditional Access (which enforces the actual block), leading them to select Identity Protection alone instead of the integrated Conditional Access solution.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Conditional Access with Identity Protection integration
Conditional Access with Identity Protection integration allows organizations to create policies that automatically block sign-ins when Microsoft Sentinel or Microsoft Defender XDR triggers a high-risk alert. This integration leverages risk signals from Identity Protection to enforce real-time access controls, such as blocking authentication, without manual intervention.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Conditional Access with Identity Protection integration
Why this is correct
Conditional Access policies, when integrated with Microsoft Entra Identity Protection, can evaluate real-time sign-in risk levels detected by Identity Protection. These policies can then enforce automated actions, such as blocking access, requiring multifactor authentication, or forcing a password change, based on the configured risk thresholds. This provides a robust, automated mechanism to prevent unauthorized access attempts from risky sign-ins.
- ✗
Microsoft Entra Access Reviews
Why it's wrong here
Microsoft Entra Access Reviews are designed for periodic verification of user access rights to resources or roles, ensuring that only necessary permissions are maintained over time. While crucial for compliance and least privilege principles, Access Reviews operate on a scheduled or manual basis and do not provide real-time enforcement to block suspicious sign-in attempts as they occur. Their purpose is auditing and remediation of standing access, not dynamic threat response.
- ✗
Microsoft Entra Identity Protection
Why it's wrong here
Microsoft Entra Identity Protection is a powerful tool that detects potential vulnerabilities affecting user identities and identifies suspicious actions related to those identities, such as impossible travel or leaked credentials. It generates risk detections and calculates a user or sign-in risk level. However, Identity Protection itself primarily focuses on detection and reporting; it requires integration with Microsoft Entra Conditional Access policies to automatically enforce real-time actions like blocking sign-ins based on the detected risk.
- ✗
Microsoft Entra Privileged Identity Management
Why it's wrong here
Microsoft Entra Privileged Identity Management (PIM) is a service within Microsoft Entra ID that manages, controls, and monitors access to important resources by providing just-in-time and just-enough access to privileged roles. PIM focuses on reducing the exposure time of privileges by requiring activation for administrative roles. It does not, however, provide functionality to detect or block risky sign-in attempts in real-time based on identity risk signals.
Go deeper
Related to this question
Learn chapter
Identity Concepts
Key term
Organization
An Organization is a top-level container in Google Cloud that represents your company or entities and serves as the root node for all your cloud resources, policies, and access control.
Key term
Identity protection
Identity protection is the set of policies, technologies, and practices used to secure digital identities and prevent unauthorized access to systems and data.
About these practice questions
Courseiva writes every SC-900 question from scratch — 1,250 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.