Courseiva
Describe the capabilities of Microsoft EntramediumMultiple ChoiceObjective-mapped

SC-900 Describe the capabilities of Microsoft Entra Practice Question

A company has discovered that many account compromise attacks are using legacy authentication protocols (e.g., IMAP, POP3, SMTP) which do not support multi-factor authentication. They want to block all sign-ins that use these protocols to reduce risk. Which Microsoft Entra ID feature should they use to enforce this block?

⚠ Common exam trap

Watch out — candidates often confuse Identity Protection's risk-based policies with Conditional Access's protocol-level controls, assuming that blocking legacy authentication is a risk-detection feature rather than a conditional access rule.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Conditional Access

Conditional Access policies in Microsoft Entra ID can be configured to block access from legacy authentication protocols (such as IMAP, POP3, and SMTP) by targeting the 'Client apps' condition. Since these protocols do not support modern authentication methods like MFA, blocking them directly reduces the attack surface for account compromise. This is the correct feature to enforce the block.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Conditional Access

    Why this is correct

    Conditional Access policies are the primary mechanism in Azure AD for enforcing specific access controls based on various conditions, including user attributes, device state, location, and client applications. To effectively block legacy authentication, a Conditional Access policy can be configured to target 'Other clients' or 'Exchange ActiveSync clients' and then apply a 'Block access' grant control. This prevents older protocols such as POP, IMAP, and SMTP from authenticating, thereby mitigating associated security risks by forcing the use of modern authentication.

  • Identity Protection

    Why it's wrong here

    Azure AD Identity Protection is a robust tool designed to detect, investigate, and remediate identity-based risks, such as suspicious sign-ins, leaked credentials, or impossible travel scenarios. While it can identify risky sign-ins that might originate from legacy protocols, its core function is risk detection and automated remediation (e.g., requiring MFA or password reset) based on identified threats. Identity Protection does not proactively block specific authentication protocols across the tenant; it reacts to risk rather than preventing the use of a protocol itself.

    When this WOULD be correct

    Identity Protection would be correct in a question asking: 'Which feature should an administrator use to automatically block sign-ins when a user's credentials are found to be leaked on the dark web?'

  • Azure AD Application Proxy

    Why it's wrong here

    Azure AD Application Proxy enables secure remote access to on-premises web applications from anywhere, without requiring a VPN or opening inbound firewall ports. It functions as a reverse proxy, bridging the gap between external users and internal applications, and integrates with Azure AD for authentication and authorization. Its purpose is application publishing and secure access to internal resources, not the enforcement of authentication protocol policies for the entire tenant or the blocking of legacy authentication methods.

    When this WOULD be correct

    A company needs to provide secure remote access to an internal web application for external users without a VPN. Azure AD Application Proxy would be the correct solution to publish the app and apply pre-authentication and conditional access policies.

  • Privileged Identity Management (PIM)

    Why it's wrong here

    Privileged Identity Management (PIM) is a feature within Azure AD that focuses on managing, controlling, and monitoring access to important resources by providing just-in-time (JIT) and just-enough-access (JEA) to privileged roles. Its primary function is to mitigate risks associated with excessive or misused access permissions by requiring activation for roles and providing time-bound access. PIM does not, however, directly enforce or block specific authentication protocols like legacy authentication; its scope is privilege management, not authentication policy enforcement.

Option-by-option analysis

Why each answer is right or wrong

Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The SC-900 exam frequently reuses these exact scenarios with slightly different constraints.

Conditional AccessCorrect answer

Why this is correct

Conditional Access policies are the primary mechanism in Azure AD for enforcing specific access controls based on various conditions, including user attributes, device state, location, and client applications. To effectively block legacy authentication, a Conditional Access policy can be configured to target 'Other clients' or 'Exchange ActiveSync clients' and then apply a 'Block access' grant control. This prevents older protocols such as POP, IMAP, and SMTP from authenticating, thereby mitigating associated security risks by forcing the use of modern authentication.

Identity ProtectionWrong answer — click to see why

Why this is wrong here

Identity Protection detects and remediates risks like leaked credentials or anomalous sign-ins, but it does not block legacy authentication protocols. Blocking specific protocols is done via Conditional Access policies.

★ When this WOULD be the correct answer

Identity Protection would be correct in a question asking: 'Which feature should an administrator use to automatically block sign-ins when a user's credentials are found to be leaked on the dark web?'

Why candidates choose this

Candidates may confuse Identity Protection's risk-based policies with the ability to block legacy authentication, as both involve security controls for sign-ins.

Azure AD Application ProxyWrong answer — click to see why

Why this is wrong here

Azure AD Application Proxy is used to provide secure remote access to on-premises web applications, not to block legacy authentication protocols. It does not enforce authentication policies or block specific sign-in methods.

★ When this WOULD be the correct answer

A company needs to provide secure remote access to an internal web application for external users without a VPN. Azure AD Application Proxy would be the correct solution to publish the app and apply pre-authentication and conditional access policies.

Why candidates choose this

Candidates may confuse Application Proxy with a security feature that controls access, but it is actually a reverse proxy for publishing apps, not a policy engine for blocking authentication protocols.

Analysis generated from the official SC-900blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”

About these practice questions

This SC-900 question is part of Courseiva's 1,250-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.