Courseiva
Describe the capabilities of Microsoft EntramediumMultiple ChoiceObjective-mapped

SC-900 Describe the capabilities of Microsoft Entra Practice Question

An organization uses Microsoft Entra ID. They want to automatically detect when a user's sign-in shows a high risk of compromise (e.g., impossible travel, anonymous IP address) and immediately require the user to reset their password. Which Microsoft Entra capability should they use?

⚠ Common exam trap

A common mix-up: candidates confuse Conditional Access with Identity Protection, but Conditional Access is the policy enforcement layer that can use Identity Protection risk detections as a condition, not the detection and remediation engine itself.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Identity Protection

B is correct because Microsoft Entra ID Identity Protection uses machine learning to detect risk signals such as impossible travel and anonymous IP addresses. When a user's sign-in is flagged as high risk, Identity Protection can be configured to automatically trigger a password reset as a remediation action, enforcing the principle of least privilege and reducing the window of compromise.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Conditional Access

    Why it's wrong here

    Conditional Access policies evaluate conditions like user risk, device state, or location to enforce access decisions. While they can block access, require multi-factor authentication, or enforce device compliance, they do not possess the inherent capability to automatically initiate or force a password reset for a user based on a detected risk event. Their primary function is to grant or deny access, or impose additional requirements, not to remediate identity credentials.

  • Identity Protection

    Why this is correct

    Microsoft Entra ID Protection is the correct service for this scenario, as it specializes in detecting identity-based risks, including compromised credentials and suspicious sign-ins. It leverages machine learning to identify user and sign-in risks, and its risk-based policies can be configured to automatically enforce remediation actions. When a high user risk is detected, Identity Protection can be set to require a user to perform a secure password change as a self-remediation step, directly addressing the compromised identity.

  • Privileged Identity Management (PIM)

    Why it's wrong here

    Privileged Identity Management (PIM) is designed to manage, control, and monitor access to important resources within Microsoft Entra ID, Azure, and other Microsoft Online Services. Its core function is to provide just-in-time (JIT) and time-bound access to privileged roles, requiring activation and approval workflows. PIM does not include capabilities for detecting user risk or automatically enforcing password resets for standard user accounts or based on general user risk detections; its scope is focused on privileged role management.

  • Access Reviews

    Why it's wrong here

    Access Reviews are a governance feature within Microsoft Entra ID that enables organizations to manage group memberships, access to enterprise applications, and privileged role assignments efficiently. They facilitate periodic re-certification of access rights by designated reviewers to ensure only necessary access is maintained. However, Access Reviews are a manual or scheduled review process and do not possess any real-time risk detection capabilities or the ability to automatically trigger security actions like password resets based on suspicious user behavior or compromised credentials.

About these practice questions

One of 1,250 original SC-900 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.