Courseiva
Describe the capabilities of Microsoft EntramediumMultiple ChoiceObjective-mapped

SC-900 Describe the capabilities of Microsoft Entra Practice Question

An organization uses Microsoft Entra ID to manage user access. The security policy requires that membership in the 'Finance - Sensitive Data' group must be reviewed every quarter by the group owner to confirm that each member still requires access. The group owner must approve or deny each membership, and any denied memberships should be automatically removed. Which Microsoft Entra ID feature should be configured to automate this process?

⚠ Common exam trap

Test-takers frequently confuse Privileged Identity Management (PIM) with Access Reviews because both involve approvals, but PIM handles time-bound role activation for privileged roles, not recurring membership reviews for standard groups.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Microsoft Entra ID Access Reviews

Microsoft Entra ID Access Reviews is the correct feature because it enables periodic review of group memberships, where the group owner can approve or deny each member's continued access. When a member is denied, Access Reviews can be configured to automatically remove that user from the group, satisfying the security policy's requirement for quarterly reviews and automatic removal of denied memberships.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Microsoft Entra ID Access Reviews

    Why this is correct

    Microsoft Entra ID Access Reviews provide a systematic way for organizations to periodically review who has access to specific resources, such as group memberships or application assignments. Reviewers, often resource owners, can attest whether users still require their current access. This process helps enforce the principle of least privilege by automatically removing access for users whose permissions are no longer justified, enhancing security and compliance.

  • Microsoft Entra ID Privileged Identity Management (PIM)

    Why it's wrong here

    Microsoft Entra ID Privileged Identity Management (PIM) is designed to manage, control, and monitor access to important organizational resources, specifically focusing on privileged roles and groups. It enables just-in-time (JIT) access, time-bound assignments, and approval workflows for elevated permissions, reducing the window of opportunity for malicious actors. While PIM includes access reviews for privileged roles, it is not the primary service for routine, broad attestation of standard group memberships or application assignments.

    When this WOULD be correct

    An organization needs to provide time-bound access to the 'Global Administrator' role, requiring approval for activation and automatic deactivation after a set duration. PIM would be configured to manage this privileged role access.

  • Microsoft Entra ID Conditional Access

    Why it's wrong here

    Microsoft Entra ID Conditional Access policies enforce specific access controls at the point of sign-in, based on various signals such as user location, device compliance, application being accessed, or sign-in risk level. These policies determine whether a user is granted access, blocked, or required to perform additional actions like multi-factor authentication. Conditional Access is a real-time access decision engine, not a mechanism for periodic review and attestation of existing group memberships or application assignments.

    When this WOULD be correct

    A question where the security policy requires blocking access to a sensitive application unless the user is connecting from a compliant device or a trusted location. For example: 'An organization wants to ensure that only managed devices can access the HR portal. Which feature should be configured?'

  • Microsoft Entra ID Protection

    Why it's wrong here

    Microsoft Entra ID Protection is a security tool focused on detecting identity-based risks, including suspicious sign-in activities and compromised user accounts. It leverages machine learning to identify anomalies, such as sign-ins from unfamiliar locations or leaked credentials, and can trigger automated remediation actions like multi-factor authentication enforcement or password resets. However, its primary function is not to facilitate periodic attestation of group memberships or application access.

    When this WOULD be correct

    An organization wants to automatically detect and block risky sign-ins or remediate compromised user accounts based on risk levels. Which Microsoft Entra ID feature should be configured?

Option-by-option analysis

Why each answer is right or wrong

Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The SC-900 exam frequently reuses these exact scenarios with slightly different constraints.

Microsoft Entra ID Access ReviewsCorrect answer

Why this is correct

Microsoft Entra ID Access Reviews provide a systematic way for organizations to periodically review who has access to specific resources, such as group memberships or application assignments. Reviewers, often resource owners, can attest whether users still require their current access. This process helps enforce the principle of least privilege by automatically removing access for users whose permissions are no longer justified, enhancing security and compliance.

Microsoft Entra ID Privileged Identity Management (PIM)Wrong answer — click to see why

Why this is wrong here

Privileged Identity Management (PIM) manages just-in-time access and role activation for privileged roles, not periodic membership reviews with owner approval and automatic removal of denied members.

★ When this WOULD be the correct answer

An organization needs to provide time-bound access to the 'Global Administrator' role, requiring approval for activation and automatic deactivation after a set duration. PIM would be configured to manage this privileged role access.

Why candidates choose this

Candidates may confuse PIM's approval workflows and time-limited access with the review and approval process required for group membership, assuming PIM can handle any access review scenario.

Microsoft Entra ID Conditional AccessWrong answer — click to see why

Why this is wrong here

Conditional Access enforces access policies based on signals like user, device, or location, but it does not provide periodic review and approval workflows for group membership. The requirement for quarterly review and automatic removal of denied memberships is specifically addressed by Access Reviews.

★ When this WOULD be the correct answer

A question where the security policy requires blocking access to a sensitive application unless the user is connecting from a compliant device or a trusted location. For example: 'An organization wants to ensure that only managed devices can access the HR portal. Which feature should be configured?'

Why candidates choose this

Candidates may confuse the concept of reviewing access (Access Reviews) with controlling access (Conditional Access), or think that Conditional Access can automate membership reviews because it can enforce policies based on group membership changes.

Microsoft Entra ID ProtectionWrong answer — click to see why

Why this is wrong here

Microsoft Entra ID Protection focuses on detecting and responding to identity-based risks like compromised credentials or sign-ins from unusual locations, not on reviewing and certifying group membership access.

★ When this WOULD be the correct answer

An organization wants to automatically detect and block risky sign-ins or remediate compromised user accounts based on risk levels. Which Microsoft Entra ID feature should be configured?

Why candidates choose this

Candidates may confuse 'Protection' with access governance, assuming it includes reviewing and protecting sensitive group memberships, but it is actually a risk-detection tool.

Analysis generated from the official SC-900blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”

About these practice questions

One of 1,250 original SC-900 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.