SC-900 Describe the capabilities of Microsoft Entra Practice Question
An organization uses Microsoft Entra ID. The security team wants to require multi-factor authentication (MFA) for users who sign in from sessions that Microsoft Entra ID Protection determines to have medium or high sign-in risk. Users signing in from low-risk sessions should not be prompted for MFA. Which feature should the security team configure?
⚠ Common exam trap
Candidates often confuse sign-in risk (session-level) with user risk (user-level), leading candidates to choose the user risk policy (Option B) instead of the Conditional Access policy with sign-in risk condition.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Configure a Conditional Access policy with Sign-in risk as a condition and MFA as a grant control
A Conditional Access policy can use Sign-in risk (a condition from Microsoft Entra ID Protection) to require MFA as a grant control. This allows the security team to enforce MFA only for sessions with medium or high sign-in risk, while low-risk sessions are not prompted, exactly matching the requirement.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Configure a Conditional Access policy with Sign-in risk as a condition and MFA as a grant control
Why this is correct
Configuring a Conditional Access policy with 'Sign-in risk' as a condition and 'Require multi-factor authentication' as a grant control is the correct solution. This policy leverages real-time risk detections from Microsoft Entra ID Protection, dynamically enforcing MFA only when a user's sign-in attempt is deemed risky. This approach provides adaptive security, ensuring that users are prompted for additional verification specifically when their access attempt presents a potential threat, aligning with a Zero Trust model.
- ✗
Configure a user risk policy in Microsoft Entra ID Protection
Why it's wrong here
User risk policies in Microsoft Entra ID Protection are designed to respond to an accumulated risk level associated with a user account over time, indicating potential compromise, such as leaked credentials. These policies typically trigger remediation actions like password resets or blocking access when the *user* is at risk, not for individual risky *sign-in attempts*. They do not dynamically enforce MFA for a specific session based on its real-time sign-in risk.
When this WOULD be correct
A user risk policy would be correct if the question asked to require MFA when a user account is determined to be compromised (high user risk), such as after leaked credentials are detected, regardless of individual sign-in risk.
- ✗
Assign the Global Administrator role with Privileged Identity Management (PIM) activation requiring MFA
Why it's wrong here
Privileged Identity Management (PIM) in Microsoft Entra ID Governance focuses on managing, controlling, and monitoring access to important resources by providing just-in-time access to privileged roles. While PIM can enforce MFA as a requirement for *activating* a privileged role, it does not apply to all users or all sign-ins. It specifically governs the elevation of privileges for administrative roles and does not dynamically enforce MFA based on the real-time sign-in risk of a regular user's session.
When this WOULD be correct
This would be correct if the question asked: 'An organization wants to ensure that when a user activates the Global Administrator role via Privileged Identity Management, they must pass MFA. Which feature should they configure?'
- ✗
Create an access review in Microsoft Entra ID Governance
Why it's wrong here
Access reviews, a feature within Microsoft Entra ID Governance, are used for periodically reviewing and certifying user access to resources, groups, or applications. Their primary purpose is to ensure that users maintain only necessary access over time, helping to reduce privilege creep and maintain compliance. Access reviews are a governance and auditing tool, not a real-time security enforcement mechanism for dynamically requiring MFA based on sign-in risk.
When this WOULD be correct
An organization needs to periodically review and confirm that users still require access to critical applications, and remove stale accounts or excessive permissions. In that scenario, creating an access review in Microsoft Entra ID Governance would be the correct feature to configure.
Option-by-option analysis
Why each answer is right or wrong
Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The SC-900 exam frequently reuses these exact scenarios with slightly different constraints.
✓Configure a Conditional Access policy with Sign-in risk as a condition and MFA as a grant controlCorrect answer▾
Why this is correct
Configuring a Conditional Access policy with 'Sign-in risk' as a condition and 'Require multi-factor authentication' as a grant control is the correct solution. This policy leverages real-time risk detections from Microsoft Entra ID Protection, dynamically enforcing MFA only when a user's sign-in attempt is deemed risky. This approach provides adaptive security, ensuring that users are prompted for additional verification specifically when their access attempt presents a potential threat, aligning with a Zero Trust model.
✗Configure a user risk policy in Microsoft Entra ID ProtectionWrong answer — click to see why▾
Why this is wrong here
The question requires MFA based on sign-in risk (session risk), not user risk. A user risk policy in ID Protection addresses user-level risk (e.g., compromised account), not sign-in risk from a specific session.
★ When this WOULD be the correct answer
A user risk policy would be correct if the question asked to require MFA when a user account is determined to be compromised (high user risk), such as after leaked credentials are detected, regardless of individual sign-in risk.
Why candidates choose this
Candidates confuse 'user risk' with 'sign-in risk' because both are risk-based policies in ID Protection, but they apply to different risk types and conditions.
✗Assign the Global Administrator role with Privileged Identity Management (PIM) activation requiring MFAWrong answer — click to see why▾
Why this is wrong here
This option addresses privileged role activation requiring MFA, not sign-in risk-based MFA for all users. The question specifically requires MFA based on sign-in risk level (medium/high), which is a Conditional Access policy condition, not a PIM activation setting.
★ When this WOULD be the correct answer
This would be correct if the question asked: 'An organization wants to ensure that when a user activates the Global Administrator role via Privileged Identity Management, they must pass MFA. Which feature should they configure?'
Why candidates choose this
Candidates may confuse risk-based MFA with privileged access MFA requirements, or think that PIM activation policies can enforce MFA based on sign-in risk, which they cannot.
✗Create an access review in Microsoft Entra ID GovernanceWrong answer — click to see why▾
Why this is wrong here
Access reviews are used to verify and manage user access rights periodically, not to enforce MFA based on sign-in risk. The question specifically requires MFA enforcement for medium/high risk sessions, which is done via Conditional Access policies with sign-in risk condition.
★ When this WOULD be the correct answer
An organization needs to periodically review and confirm that users still require access to critical applications, and remove stale accounts or excessive permissions. In that scenario, creating an access review in Microsoft Entra ID Governance would be the correct feature to configure.
Why candidates choose this
Candidates may confuse access reviews with risk-based policies because both are part of Microsoft Entra ID Protection and Governance, and both involve security oversight. They might think an access review can trigger MFA, but it does not enforce real-time authentication requirements.
Analysis generated from the official SC-900blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”
Go deeper
Related to this question
Learn chapter
Core Security Concepts
Key term
Organization
An Organization is a top-level container in Google Cloud that represents your company or entities and serves as the root node for all your cloud resources, policies, and access control.
Key term
Risk
Risk is the possibility that an event or action will negatively affect an organization's ability to achieve its goals, often measured in terms of likelihood and impact.
About these practice questions
This SC-900 question is part of Courseiva's 1,250-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.