SC-900 Describe the capabilities of Microsoft Entra Practice Question
An organization uses Microsoft Entra ID for identity management and wants to allow external partners to access their resources using their own corporate credentials. Which feature should they enable?
⚠ Common exam trap
Test-takers frequently confuse Conditional Access (a policy engine) with the ability to invite external identities, mistakenly thinking policies alone can grant external access without a federation mechanism.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Entra External ID
Entra External ID (formerly Azure AD B2B) enables organizations to invite external partners to access resources using their own corporate credentials. This feature leverages federation protocols such as SAML, WS-Fed, or OpenID Connect to authenticate the partner's identity in their home tenant, eliminating the need for separate local accounts.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Entra External ID
Why this is correct
Microsoft Entra External ID is the comprehensive solution designed for managing all external identities, including partners, customers, and other collaborators. It facilitates secure business-to-business (B2B) collaboration by allowing organizations to invite guest users from other Microsoft Entra tenants, social identity providers, or via email one-time passcodes. This enables external users to access internal applications and resources while maintaining their original identity provider.
- ✗
Identity Protection
Why it's wrong here
Microsoft Entra ID Protection is a security feature focused on detecting and remediating identity-based risks within an organization's tenant. It analyzes sign-in and user behavior to identify potential compromises, such as leaked credentials, impossible travel, or infected devices. While crucial for security, its primary function is risk assessment and automated policy enforcement, not the provisioning or lifecycle management of external collaboration identities.
- ✗
Conditional Access
Why it's wrong here
Microsoft Entra Conditional Access acts as a policy enforcement engine, evaluating specific conditions at the time of a user's sign-in attempt to determine whether access to resources should be granted, blocked, or require additional authentication. These policies can target specific users, groups, applications, locations, or device states. Although it can enforce policies on external users, it does not create, invite, or manage the external identities themselves; it merely governs their access post-authentication.
- ✗
Privileged Identity Management
Why it's wrong here
Microsoft Entra Privileged Identity Management (PIM) is a service focused on managing, controlling, and monitoring access to important organizational resources by providing just-in-time and just-enough access. It minimizes the attack surface by requiring users to activate roles for a limited time, rather than having standing administrative permissions. PIM is designed for elevating existing users' permissions to privileged roles, not for establishing the initial framework for inviting and managing external collaborators or customer identities.
Go deeper
Related to this question
Learn chapter
Identity Concepts
Key term
OpenID Connect
OpenID Connect is an identity layer on top of OAuth 2.0 that allows applications to verify a user's identity and obtain basic profile information in a standardized way.
Key term
Federation
Federation is a system that lets you use one set of login credentials (like your work email and password) to access resources across different organizations or services without needing separate accounts for each one.
About these practice questions
One of 1,250 original SC-900 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.