SC-900 Describe the capabilities of Microsoft Entra Practice Question
A company wants to reduce help desk calls by allowing users to reset their own passwords. The security team requires that users verify their identity using a registered mobile phone or alternative email before resetting. Additionally, the company policy states that passwords cannot be reused until at least five new passwords have been used. Which Microsoft Entra ID features should they configure to meet these requirements?
⚠ Common exam trap
A common mix-up: candidates confuse Conditional Access with password policies, thinking that Conditional Access can enforce password history, when in fact password history is a separate setting under password protection policies, not a Conditional Access control.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Self-Service Password Reset (SSPR) and password protection policies (password history enforcement)
Self-Service Password Reset (SSPR) allows users to reset their own passwords, reducing help desk calls. The security requirement for identity verification via registered mobile phone or alternative email is met by SSPR's authentication methods. The password history enforcement (preventing reuse until at least five new passwords have been used) is configured through password protection policies, specifically the 'password history' setting that enforces a minimum of 5 unique passwords before reuse.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Self-Service Password Reset (SSPR) and password protection policies (password history enforcement)
Why this is correct
Self-Service Password Reset (SSPR) directly enables users to reset their forgotten or expired passwords independently, significantly reducing help desk calls. When combined with password protection policies, which are a feature of Microsoft Entra ID, the system enforces rules such as preventing the reuse of a specified number of previous passwords. This combination effectively addresses both requirements: empowering users for self-service and maintaining strong password hygiene through history enforcement.
- ✗
Self-Service Password Reset (SSPR) and Conditional Access policies
Why it's wrong here
While Self-Service Password Reset (SSPR) correctly allows users to reset their own passwords, Conditional Access policies do not enforce password history or reuse rules. Conditional Access is designed to control access to resources based on various conditions like user location, device compliance, or application. It can require SSPR registration or specific authentication methods, but it does not manage the historical uniqueness of a user's password.
When this WOULD be correct
A scenario where the company needs to require MFA during password reset or block password reset from untrusted locations would make Conditional Access policies correct. For example, 'Users must reset passwords only from corporate devices or trusted IPs.'
- ✗
Multi-Factor Authentication (MFA) and password protection policies
Why it's wrong here
Multi-Factor Authentication (MFA) enhances sign-in security by requiring a second verification factor, but it does not provide a mechanism for users to reset their own forgotten passwords. While password protection policies effectively enforce password history, MFA alone does not empower users with self-service password reset capabilities. Users would still need help desk assistance to regain access if they forget their password, even with MFA enabled for sign-in.
When this WOULD be correct
A question where the requirements are: users must use MFA for all sign-ins, and passwords must be blocked if they appear on a banned list (e.g., common passwords). No self-service reset or password history is needed.
- ✗
Identity Protection and Authentication Strengths
Why it's wrong here
Identity Protection focuses on detecting and responding to identity-based risks, such as compromised credentials or unusual sign-in patterns, by blocking or challenging risky users. Authentication Strengths, a component of Conditional Access, define the specific authentication methods required for accessing resources. Neither of these features provides the functionality for users to self-service reset their passwords, nor do they directly enforce password history rules.
When this WOULD be correct
A company needs to detect and block risky sign-ins (e.g., from anonymous IPs or leaked credentials) and enforce phishing-resistant authentication methods (e.g., FIDO2 keys) for privileged roles. Identity Protection would detect risks, and Authentication Strengths would require specific MFA methods.
Option-by-option analysis
Why each answer is right or wrong
Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The SC-900 exam frequently reuses these exact scenarios with slightly different constraints.
✓Self-Service Password Reset (SSPR) and password protection policies (password history enforcement)Correct answer▾
Why this is correct
Self-Service Password Reset (SSPR) directly enables users to reset their forgotten or expired passwords independently, significantly reducing help desk calls. When combined with password protection policies, which are a feature of Microsoft Entra ID, the system enforces rules such as preventing the reuse of a specified number of previous passwords. This combination effectively addresses both requirements: empowering users for self-service and maintaining strong password hygiene through history enforcement.
✗Self-Service Password Reset (SSPR) and Conditional Access policiesWrong answer — click to see why▾
Why this is wrong here
Conditional Access policies control access based on conditions like location or device state, but they do not enforce password history rules. The requirement to prevent password reuse until five new passwords are used is a password protection policy, not a Conditional Access policy.
★ When this WOULD be the correct answer
A scenario where the company needs to require MFA during password reset or block password reset from untrusted locations would make Conditional Access policies correct. For example, 'Users must reset passwords only from corporate devices or trusted IPs.'
Why candidates choose this
Candidates may confuse Conditional Access with password policies, thinking it can enforce password history, or they may overestimate the scope of Conditional Access in identity management scenarios.
✗Multi-Factor Authentication (MFA) and password protection policiesWrong answer — click to see why▾
Why this is wrong here
MFA provides identity verification but does not include password history enforcement; password protection policies alone do not enforce password history. The question requires both self-service reset with verification and password history, which SSPR and password protection policies together fulfill.
★ When this WOULD be the correct answer
A question where the requirements are: users must use MFA for all sign-ins, and passwords must be blocked if they appear on a banned list (e.g., common passwords). No self-service reset or password history is needed.
Why candidates choose this
Candidates may think MFA is required for identity verification during password reset, but SSPR already includes its own verification methods. They also confuse password protection policies (banning weak passwords) with password history enforcement.
✗Identity Protection and Authentication StrengthsWrong answer — click to see why▾
Why this is wrong here
Identity Protection and Authentication Strengths do not include password history enforcement to prevent password reuse, which is explicitly required by the policy.
★ When this WOULD be the correct answer
A company needs to detect and block risky sign-ins (e.g., from anonymous IPs or leaked credentials) and enforce phishing-resistant authentication methods (e.g., FIDO2 keys) for privileged roles. Identity Protection would detect risks, and Authentication Strengths would require specific MFA methods.
Why candidates choose this
Candidates may confuse identity protection features with password management, or think that authentication strengths (like requiring MFA) cover password history, but they do not enforce password reuse rules.
Analysis generated from the official SC-900blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”
Go deeper
Related to this question
Learn chapter
Core Security Concepts
Key term
Identity
Identity is the unique set of attributes that defines a user, device, or service in a computer system, determining what they can access and do.
Key term
Security
Security in IT is the practice of protecting systems, networks, and data from unauthorized access, damage, or theft.
About these practice questions
This SC-900 question is part of Courseiva's 1,250-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.