SC-900 Describe the capabilities of Microsoft Entra Practice Question
A company has discovered that many account compromise attacks are using legacy authentication protocols (e.g., IMAP, POP3, SMTP) which do not support multi-factor authentication. They want to block all sign-ins that use these protocols to reduce risk. Which Microsoft Entra ID feature should they use to enforce this block?
⚠ Common exam trap
Watch out — candidates often confuse Identity Protection's risk-based policies with Conditional Access's protocol-level controls, assuming that blocking legacy authentication is a risk-detection feature rather than a conditional access rule.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Conditional Access
Conditional Access policies in Microsoft Entra ID can be configured to block access from legacy authentication protocols (such as IMAP, POP3, and SMTP) by targeting the 'Client apps' condition. Since these protocols do not support modern authentication methods like MFA, blocking them directly reduces the attack surface for account compromise. This is the correct feature to enforce the block.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Conditional Access
Why this is correct
Conditional Access policies are the primary mechanism in Azure AD for enforcing specific access controls based on various conditions, including user attributes, device state, location, and client applications. To effectively block legacy authentication, a Conditional Access policy can be configured to target 'Other clients' or 'Exchange ActiveSync clients' and then apply a 'Block access' grant control. This prevents older protocols such as POP, IMAP, and SMTP from authenticating, thereby mitigating associated security risks by forcing the use of modern authentication.
- ✗
Identity Protection
Why it's wrong here
Azure AD Identity Protection is a robust tool designed to detect, investigate, and remediate identity-based risks, such as suspicious sign-ins, leaked credentials, or impossible travel scenarios. While it can identify risky sign-ins that might originate from legacy protocols, its core function is risk detection and automated remediation (e.g., requiring MFA or password reset) based on identified threats. Identity Protection does not proactively block specific authentication protocols across the tenant; it reacts to risk rather than preventing the use of a protocol itself.
When this WOULD be correct
Identity Protection would be correct in a question asking: 'Which feature should an administrator use to automatically block sign-ins when a user's credentials are found to be leaked on the dark web?'
- ✗
Azure AD Application Proxy
Why it's wrong here
Azure AD Application Proxy enables secure remote access to on-premises web applications from anywhere, without requiring a VPN or opening inbound firewall ports. It functions as a reverse proxy, bridging the gap between external users and internal applications, and integrates with Azure AD for authentication and authorization. Its purpose is application publishing and secure access to internal resources, not the enforcement of authentication protocol policies for the entire tenant or the blocking of legacy authentication methods.
When this WOULD be correct
A company needs to provide secure remote access to an internal web application for external users without a VPN. Azure AD Application Proxy would be the correct solution to publish the app and apply pre-authentication and conditional access policies.
- ✗
Privileged Identity Management (PIM)
Why it's wrong here
Privileged Identity Management (PIM) is a feature within Azure AD that focuses on managing, controlling, and monitoring access to important resources by providing just-in-time (JIT) and just-enough-access (JEA) to privileged roles. Its primary function is to mitigate risks associated with excessive or misused access permissions by requiring activation for roles and providing time-bound access. PIM does not, however, directly enforce or block specific authentication protocols like legacy authentication; its scope is privilege management, not authentication policy enforcement.
Option-by-option analysis
Why each answer is right or wrong
Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The SC-900 exam frequently reuses these exact scenarios with slightly different constraints.
✓Conditional AccessCorrect answer▾
Why this is correct
Conditional Access policies are the primary mechanism in Azure AD for enforcing specific access controls based on various conditions, including user attributes, device state, location, and client applications. To effectively block legacy authentication, a Conditional Access policy can be configured to target 'Other clients' or 'Exchange ActiveSync clients' and then apply a 'Block access' grant control. This prevents older protocols such as POP, IMAP, and SMTP from authenticating, thereby mitigating associated security risks by forcing the use of modern authentication.
✗Identity ProtectionWrong answer — click to see why▾
Why this is wrong here
Identity Protection detects and remediates risks like leaked credentials or anomalous sign-ins, but it does not block legacy authentication protocols. Blocking specific protocols is done via Conditional Access policies.
★ When this WOULD be the correct answer
Identity Protection would be correct in a question asking: 'Which feature should an administrator use to automatically block sign-ins when a user's credentials are found to be leaked on the dark web?'
Why candidates choose this
Candidates may confuse Identity Protection's risk-based policies with the ability to block legacy authentication, as both involve security controls for sign-ins.
✗Azure AD Application ProxyWrong answer — click to see why▾
Why this is wrong here
Azure AD Application Proxy is used to provide secure remote access to on-premises web applications, not to block legacy authentication protocols. It does not enforce authentication policies or block specific sign-in methods.
★ When this WOULD be the correct answer
A company needs to provide secure remote access to an internal web application for external users without a VPN. Azure AD Application Proxy would be the correct solution to publish the app and apply pre-authentication and conditional access policies.
Why candidates choose this
Candidates may confuse Application Proxy with a security feature that controls access, but it is actually a reverse proxy for publishing apps, not a policy engine for blocking authentication protocols.
Analysis generated from the official SC-900blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”
Go deeper
Related to this question
Learn chapter
Microsoft Entra ID
Key term
Risk
Risk is the possibility that an event or action will negatively affect an organization's ability to achieve its goals, often measured in terms of likelihood and impact.
Key term
MFA
Multi-Factor Authentication (MFA) is a security method that requires a user to verify their identity using two or more different types of evidence, such as a password plus a code from a phone, before they can access an account or system.
About these practice questions
This SC-900 question is part of Courseiva's 1,250-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.