Courseiva
Describe the capabilities of Microsoft EntraeasyMultiple ChoiceObjective-mapped

SC-900 Describe the capabilities of Microsoft Entra Practice Question

An organization wants to automatically revoke access to cloud apps when an employee leaves the company. Which Microsoft Entra feature should they use?

⚠ Common exam trap

Candidates often confuse Conditional Access (which blocks new sign-ins) with full deprovisioning, not realizing that Conditional Access does not terminate existing sessions or remove the user account from the cloud app.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Automated user provisioning

Automated user provisioning (B) is the correct answer because it can automatically disable or remove a user's access to cloud apps when the user is deleted or deactivated in the HR system or on-premises directory. This feature synchronizes identity lifecycle events (e.g., termination) to connected SaaS applications, ensuring revocation of access without manual intervention.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Conditional Access

    Why it's wrong here

    Conditional Access policies enforce access decisions in real-time based on specific conditions like user, device, location, and application. While they can block access for users in a specific group (e.g., 'terminated users'), they do not automatically initiate the process of disabling an account or removing a user from groups upon termination. The revocation of access upon an employment termination event is an identity lifecycle management function, not a real-time access enforcement function.

  • Automated user provisioning

    Why this is correct

    Automated user provisioning, often managed by services like Azure AD Connect or Azure AD provisioning to SaaS apps, synchronizes identity data between authoritative sources and target applications. When a user's account is disabled or deleted in the authoritative source (e.g., HR system or on-premises AD), the provisioning service detects this change and automatically propagates it to connected applications. This process disables the user's account and revokes their access to those applications and their associated data, directly addressing the requirement for automatic access revocation upon termination.

  • Privileged Identity Management

    Why it's wrong here

    Azure AD Privileged Identity Management (PIM) focuses on managing, controlling, and monitoring access to sensitive resources by providing just-in-time and just-enough access for privileged roles. While PIM can revoke *elevated* access after a specified duration or upon request, its primary function is not the comprehensive offboarding of standard user accounts or the automatic revocation of all access for a terminated employee across various applications. It is a specialized tool for governing temporary, high-privilege access.

  • Identity Protection

    Why it's wrong here

    Azure AD Identity Protection is a tool designed to detect, investigate, and remediate identity-based risks, such as compromised credentials or suspicious sign-in activities. It uses risk signals to apply policies like requiring multi-factor authentication or blocking access if a sign-in is deemed high-risk. However, Identity Protection does not manage the lifecycle of user accounts or automatically revoke access based on an HR-driven termination event; its core focus is on real-time threat detection and response to protect identities from compromise.

About these practice questions

Courseiva writes every SC-900 question from scratch — 1,250 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.