Courseiva
Describe the capabilities of Microsoft EntramediumMultiple ChoiceObjective-mapped

SC-900 Describe the capabilities of Microsoft Entra Practice Question

A company has several custom-developed web applications hosted on-premises. The company wants to provide employees with secure remote access to these applications without deploying a traditional VPN. Employees should be able to sign in using their existing Microsoft Entra ID credentials, and the solution should pass through multi-factor authentication policies. Which Microsoft Entra ID feature should they implement?

⚠ Common exam trap

A common mix-up: candidates confuse Microsoft Entra Application Proxy with a traditional VPN or assume that Microsoft Entra Domain Services is needed for authentication, but the key requirement is secure remote access without VPN, which only Application Proxy fulfills by acting as a reverse proxy with Entra ID integration.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Microsoft Entra Application Proxy

Microsoft Entra Application Proxy provides secure remote access to on-premises web applications by acting as a reverse proxy. It allows employees to sign in with their existing Microsoft Entra ID credentials and enforces conditional access policies, including multi-factor authentication, without requiring a traditional VPN.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Microsoft Entra Application Proxy

    Why this is correct

    Microsoft Entra Application Proxy is the correct solution because it provides secure remote access to on-premises web applications by acting as a reverse proxy. It integrates these applications with Microsoft Entra ID, allowing users to authenticate using their Entra ID credentials, including multi-factor authentication and Conditional Access policies. The Application Proxy connector, installed on the on-premises network, establishes an outbound-only connection to the Entra ID cloud service, eliminating the need for inbound firewall rules or a VPN.

  • Microsoft Entra Domain Services

    Why it's wrong here

    Microsoft Entra Domain Services provides managed domain services, such as domain join, group policy, LDAP, and Kerberos/NTLM authentication, for cloud-based virtual machines and applications. It essentially offers a managed Active Directory-compatible domain controller environment within Azure, without requiring customers to deploy and manage their own domain controllers. However, Domain Services is not designed to securely expose on-premises web applications to external users; its purpose is to provide traditional domain services for cloud workloads.

    When this WOULD be correct

    A company needs to migrate legacy on-premises applications that require LDAP or NTLM authentication to the cloud without rewriting them. They want to use Microsoft Entra ID for authentication but the apps don't support modern protocols. In this case, Entra Domain Services would provide the necessary domain services.

  • Microsoft Entra Privileged Identity Management

    Why it's wrong here

    Microsoft Entra Privileged Identity Management (PIM) is designed to manage, control, and monitor access to important resources within Microsoft Entra ID, Azure, and other Microsoft Online Services. Its primary function is to provide just-in-time (JIT) and time-bound access to privileged roles and resources, enforcing the principle of least privilege through approval workflows and access reviews. PIM does not facilitate remote access to on-premises applications; instead, it governs who can assume administrative roles or access sensitive data.

    When this WOULD be correct

    A company needs to implement just-in-time privileged access for administrators managing critical Azure resources, requiring time-bound role assignments and approval workflows. PIM would be the correct answer for managing and auditing privileged roles.

  • Microsoft Entra Identity Protection

    Why it's wrong here

    Microsoft Entra Identity Protection focuses on detecting and remediating identity-based risks within an organization. It leverages machine learning and heuristics to identify suspicious sign-in behaviors, such as impossible travel, sign-ins from infected devices, or leaked credentials, and user risk events. While crucial for overall security, Identity Protection's role is to monitor and protect user identities from compromise, not to provide a mechanism for securely publishing or accessing on-premises web applications remotely.

    When this WOULD be correct

    An exam question asks: 'A company wants to automatically detect and respond to suspicious sign-in behaviors, such as impossible travel or leaked credentials, and enforce conditional access policies based on user risk. Which Microsoft Entra feature should they implement?'

Option-by-option analysis

Why each answer is right or wrong

Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The SC-900 exam frequently reuses these exact scenarios with slightly different constraints.

Microsoft Entra Application ProxyCorrect answer

Why this is correct

Microsoft Entra Application Proxy is the correct solution because it provides secure remote access to on-premises web applications by acting as a reverse proxy. It integrates these applications with Microsoft Entra ID, allowing users to authenticate using their Entra ID credentials, including multi-factor authentication and Conditional Access policies. The Application Proxy connector, installed on the on-premises network, establishes an outbound-only connection to the Entra ID cloud service, eliminating the need for inbound firewall rules or a VPN.

Microsoft Entra Domain ServicesWrong answer — click to see why

Why this is wrong here

Microsoft Entra Domain Services provides managed domain services like domain join and LDAP, not secure remote access to on-premises web applications with Microsoft Entra ID authentication and MFA.

★ When this WOULD be the correct answer

A company needs to migrate legacy on-premises applications that require LDAP or NTLM authentication to the cloud without rewriting them. They want to use Microsoft Entra ID for authentication but the apps don't support modern protocols. In this case, Entra Domain Services would provide the necessary domain services.

Why candidates choose this

Candidates may confuse 'Domain Services' with providing access to on-premises resources, or think that domain services are needed for authentication and MFA pass-through.

Microsoft Entra Privileged Identity ManagementWrong answer — click to see why

Why this is wrong here

Privileged Identity Management (PIM) manages, controls, and monitors access to privileged roles in Microsoft Entra ID, but it does not provide secure remote access to on-premises web applications. The question requires a solution for remote application access, not identity governance.

★ When this WOULD be the correct answer

A company needs to implement just-in-time privileged access for administrators managing critical Azure resources, requiring time-bound role assignments and approval workflows. PIM would be the correct answer for managing and auditing privileged roles.

Why candidates choose this

Candidates may confuse PIM with a security feature that controls access, but they overlook that PIM focuses on role-based access control for privileged identities, not on proxying application traffic.

Microsoft Entra Identity ProtectionWrong answer — click to see why

Why this is wrong here

Microsoft Entra Identity Protection is a risk-based detection and remediation tool, not a remote access solution. It does not provide secure access to on-premises web applications or pass through authentication to them.

★ When this WOULD be the correct answer

An exam question asks: 'A company wants to automatically detect and respond to suspicious sign-in behaviors, such as impossible travel or leaked credentials, and enforce conditional access policies based on user risk. Which Microsoft Entra feature should they implement?'

Why candidates choose this

Candidates may confuse Identity Protection's security monitoring capabilities with the secure access requirements of the question, thinking that identity protection includes remote access features.

Analysis generated from the official SC-900blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”

About these practice questions

Courseiva writes every SC-900 question from scratch — 1,250 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.