SC-900 Describe the capabilities of Microsoft Entra Practice Question
A company needs to provide a developer with temporary, time-bound administrative access to Azure resources to debug a production issue. The access must require approval from the manager and automatically expire after 4 hours. Which Microsoft Entra capability should they use?
⚠ Common exam trap
A common mix-up: candidates confuse Entitlement Management (which manages access to apps/groups via access packages) with PIM (which manages time-bound role activation for Azure resources), leading candidates to pick D when the scenario explicitly requires Azure resource administrative access with automatic expiration.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Privileged Identity Management (PIM)
Privileged Identity Management (PIM) provides just-in-time (JIT) privileged access to Azure resources with time-bound activation, approval workflows, and automatic expiration. This directly matches the requirement for temporary, manager-approved administrative access that expires after 4 hours.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Privileged Identity Management (PIM)
Why this is correct
Privileged Identity Management (PIM) in Microsoft Entra ID Governance is specifically designed to manage, control, and monitor access to important resources. It enables just-in-time (JIT) activation of privileged roles, allowing users to activate administrative permissions only when needed and for a predefined, limited duration. This includes requiring approval for activation and providing comprehensive audit trails, directly addressing the requirement for temporary, time-bound administrative access.
- ✗
Conditional Access
Why it's wrong here
Conditional Access policies enforce access controls based on various conditions such as user location, device compliance, or sign-in risk. While it can block or grant access, or require multi-factor authentication, its core function is to define how users can access resources, not to manage the lifecycle of privileged role assignments. It does not provide a mechanism for activating a privileged role for a temporary, time-bound period with approval workflows.
- ✗
Identity Protection
Why it's wrong here
Microsoft Entra ID Protection is a security module focused on detecting and remediating identity-based risks, such as suspicious sign-ins, leaked credentials, or impossible travel. It generates risk detections and can trigger automated responses like requiring password resets or blocking access based on risk levels. However, Identity Protection does not offer functionality to provision or manage temporary, time-bound administrative role assignments; its scope is risk detection and remediation, not access governance.
- ✗
Entitlement Management
Why it's wrong here
Microsoft Entra Entitlement Management enables organizations to manage identity and access lifecycle at scale by creating access packages that bundle resources and define access policies. While it can grant time-limited access to resources, its primary focus is on managing broad access to groups, applications, and SharePoint sites, often for onboarding/offboarding scenarios. It is not specifically designed for the just-in-time, approval-based activation of privileged administrative roles with granular time limits.
Go deeper
Related to this question
Learn chapter
Identity Concepts
Key term
Identity
Identity is the unique set of attributes that defines a user, device, or service in a computer system, determining what they can access and do.
Key term
PIM
Privileged Identity Management, a Microsoft Azure Active Directory tool that manages, monitors, and controls access to privileged roles on a just-in-time basis.
About these practice questions
Courseiva writes every SC-900 question from scratch — 1,250 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.