Courseiva
Describe the capabilities of Microsoft EntramediumMultiple ChoiceObjective-mapped

SC-900 Describe the capabilities of Microsoft Entra Practice Question

A company wants to reduce help desk calls by allowing users to reset their own passwords. The security team requires that users verify their identity using a registered mobile phone or alternative email before resetting. Additionally, the company policy states that passwords cannot be reused until at least five new passwords have been used. Which Microsoft Entra ID features should they configure to meet these requirements?

⚠ Common exam trap

A common mix-up: candidates confuse Conditional Access with password policies, thinking that Conditional Access can enforce password history, when in fact password history is a separate setting under password protection policies, not a Conditional Access control.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Self-Service Password Reset (SSPR) and password protection policies (password history enforcement)

Self-Service Password Reset (SSPR) allows users to reset their own passwords, reducing help desk calls. The security requirement for identity verification via registered mobile phone or alternative email is met by SSPR's authentication methods. The password history enforcement (preventing reuse until at least five new passwords have been used) is configured through password protection policies, specifically the 'password history' setting that enforces a minimum of 5 unique passwords before reuse.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Self-Service Password Reset (SSPR) and password protection policies (password history enforcement)

    Why this is correct

    Self-Service Password Reset (SSPR) directly enables users to reset their forgotten or expired passwords independently, significantly reducing help desk calls. When combined with password protection policies, which are a feature of Microsoft Entra ID, the system enforces rules such as preventing the reuse of a specified number of previous passwords. This combination effectively addresses both requirements: empowering users for self-service and maintaining strong password hygiene through history enforcement.

  • Self-Service Password Reset (SSPR) and Conditional Access policies

    Why it's wrong here

    While Self-Service Password Reset (SSPR) correctly allows users to reset their own passwords, Conditional Access policies do not enforce password history or reuse rules. Conditional Access is designed to control access to resources based on various conditions like user location, device compliance, or application. It can require SSPR registration or specific authentication methods, but it does not manage the historical uniqueness of a user's password.

    When this WOULD be correct

    A scenario where the company needs to require MFA during password reset or block password reset from untrusted locations would make Conditional Access policies correct. For example, 'Users must reset passwords only from corporate devices or trusted IPs.'

  • Multi-Factor Authentication (MFA) and password protection policies

    Why it's wrong here

    Multi-Factor Authentication (MFA) enhances sign-in security by requiring a second verification factor, but it does not provide a mechanism for users to reset their own forgotten passwords. While password protection policies effectively enforce password history, MFA alone does not empower users with self-service password reset capabilities. Users would still need help desk assistance to regain access if they forget their password, even with MFA enabled for sign-in.

    When this WOULD be correct

    A question where the requirements are: users must use MFA for all sign-ins, and passwords must be blocked if they appear on a banned list (e.g., common passwords). No self-service reset or password history is needed.

  • Identity Protection and Authentication Strengths

    Why it's wrong here

    Identity Protection focuses on detecting and responding to identity-based risks, such as compromised credentials or unusual sign-in patterns, by blocking or challenging risky users. Authentication Strengths, a component of Conditional Access, define the specific authentication methods required for accessing resources. Neither of these features provides the functionality for users to self-service reset their passwords, nor do they directly enforce password history rules.

    When this WOULD be correct

    A company needs to detect and block risky sign-ins (e.g., from anonymous IPs or leaked credentials) and enforce phishing-resistant authentication methods (e.g., FIDO2 keys) for privileged roles. Identity Protection would detect risks, and Authentication Strengths would require specific MFA methods.

Option-by-option analysis

Why each answer is right or wrong

Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The SC-900 exam frequently reuses these exact scenarios with slightly different constraints.

Self-Service Password Reset (SSPR) and password protection policies (password history enforcement)Correct answer

Why this is correct

Self-Service Password Reset (SSPR) directly enables users to reset their forgotten or expired passwords independently, significantly reducing help desk calls. When combined with password protection policies, which are a feature of Microsoft Entra ID, the system enforces rules such as preventing the reuse of a specified number of previous passwords. This combination effectively addresses both requirements: empowering users for self-service and maintaining strong password hygiene through history enforcement.

Self-Service Password Reset (SSPR) and Conditional Access policiesWrong answer — click to see why

Why this is wrong here

Conditional Access policies control access based on conditions like location or device state, but they do not enforce password history rules. The requirement to prevent password reuse until five new passwords are used is a password protection policy, not a Conditional Access policy.

★ When this WOULD be the correct answer

A scenario where the company needs to require MFA during password reset or block password reset from untrusted locations would make Conditional Access policies correct. For example, 'Users must reset passwords only from corporate devices or trusted IPs.'

Why candidates choose this

Candidates may confuse Conditional Access with password policies, thinking it can enforce password history, or they may overestimate the scope of Conditional Access in identity management scenarios.

Multi-Factor Authentication (MFA) and password protection policiesWrong answer — click to see why

Why this is wrong here

MFA provides identity verification but does not include password history enforcement; password protection policies alone do not enforce password history. The question requires both self-service reset with verification and password history, which SSPR and password protection policies together fulfill.

★ When this WOULD be the correct answer

A question where the requirements are: users must use MFA for all sign-ins, and passwords must be blocked if they appear on a banned list (e.g., common passwords). No self-service reset or password history is needed.

Why candidates choose this

Candidates may think MFA is required for identity verification during password reset, but SSPR already includes its own verification methods. They also confuse password protection policies (banning weak passwords) with password history enforcement.

Identity Protection and Authentication StrengthsWrong answer — click to see why

Why this is wrong here

Identity Protection and Authentication Strengths do not include password history enforcement to prevent password reuse, which is explicitly required by the policy.

★ When this WOULD be the correct answer

A company needs to detect and block risky sign-ins (e.g., from anonymous IPs or leaked credentials) and enforce phishing-resistant authentication methods (e.g., FIDO2 keys) for privileged roles. Identity Protection would detect risks, and Authentication Strengths would require specific MFA methods.

Why candidates choose this

Candidates may confuse identity protection features with password management, or think that authentication strengths (like requiring MFA) cover password history, but they do not enforce password reuse rules.

Analysis generated from the official SC-900blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”

About these practice questions

This SC-900 question is part of Courseiva's 1,250-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.