SC-900 Describe the capabilities of Microsoft Entra Practice Question
An organization uses Microsoft Entra ID. The security team wants to require multi-factor authentication (MFA) for all users accessing sensitive data from outside the corporate network. Which Microsoft Entra capability should they configure?
⚠ Common exam trap
Test-takers frequently confuse Identity Protection's risk-based MFA trigger with the ability to enforce MFA based on a static network location, but Identity Protection only responds to risk events and does not allow direct configuration of location-based conditions.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Conditional Access
Conditional Access is the correct capability because it allows administrators to define policies that enforce MFA based on specific conditions, such as network location. By configuring a policy that targets all users and applies the 'Require multi-factor authentication' grant control when the location is outside the corporate network, the security team can precisely meet the requirement. This policy evaluates the user's IP address against named locations defined in Entra ID before granting access to sensitive data.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Conditional Access
Why this is correct
Conditional Access policies evaluate real-time signals such as user location and network IP address, enabling the security team to enforce MFA specifically when access originates from outside the corporate network. This satisfies the stem’s constraint of restricting MFA to external access only, without affecting internal users. Unlike baseline or per-user MFA, Conditional Access provides granular, context-aware control based on the network location condition.
- ✗
B2B Collaboration
Why it's wrong here
B2B Collaboration is a feature within Microsoft Entra ID that allows organizations to invite external users (guests) to access their applications and resources. While it facilitates external user management, B2B Collaboration itself does not provide the policy engine to enforce multi-factor authentication (MFA) based on network location for either internal or external users. MFA enforcement for B2B guests, when required, is typically managed through Conditional Access policies applied to those guest accounts.
- ✗
Privileged Identity Management
Why it's wrong here
Microsoft Entra ID Privileged Identity Management (PIM) is designed to manage, control, and monitor access to critical resources by providing just-in-time (JIT) access to privileged roles. PIM can require multi-factor authentication (MFA) as part of the role activation process to elevate privileges, but it is not a general mechanism for enforcing MFA based on network location for all user sign-ins to applications. Its scope is specifically around privileged role management and activation, not general access policy.
- ✗
Identity Protection
Why it's wrong here
Microsoft Entra ID Protection is a powerful tool focused on detecting identity-based risks, such as compromised credentials or suspicious sign-in behaviors. While Identity Protection can identify high-risk sign-ins or users and then trigger a Conditional Access policy to require multi-factor authentication (MFA), it is primarily a detection and reporting service. Identity Protection does not directly enforce MFA based on network location; instead, it feeds risk signals into Conditional Access, which then applies the configured access controls.
Go deeper
Related to this question
Learn chapter
Core Security Concepts
Key term
User
A user is any person, system, or device that interacts with an IT service, resource, or identity system, typically authenticated through credentials and authorized to perform specific actions.
Key term
Conditional access
Conditional access is a security framework that evaluates signals like user location, device health, and risk level to grant or block access to resources in real time.
About these practice questions
One of 1,250 original SC-900 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.