Courseiva
Describe the capabilities of Microsoft EntramediumMultiple ChoiceObjective-mapped

SC-900 Describe the capabilities of Microsoft Entra Practice Question

A company has several on-premises web-based applications that need to be securely accessed by remote employees without requiring a VPN. The IT team wants to provide single sign-on (SSO) using Microsoft Entra ID. Which Microsoft Entra ID feature should they implement?

⚠ Common exam trap

Many exam-takers confuse Application Proxy with a VPN solution or think SSPR or PIM can provide remote access, but only Application Proxy specifically proxies on-premises web apps with SSO integration.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Microsoft Entra Application Proxy

Microsoft Entra Application Proxy enables secure remote access to on-premises web applications without a VPN by acting as a reverse proxy. It integrates with Microsoft Entra ID to provide single sign-on (SSO) for users, leveraging pre-authentication and conditional access policies. This directly meets the requirement for VPN-less, SSO-enabled access.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Microsoft Entra Application Proxy

    Why this is correct

    Microsoft Entra Application Proxy is the correct solution for securely publishing on-premises web applications to external users. It achieves this by deploying a lightweight connector within the on-premises network, which establishes an outbound connection to Azure, creating a secure tunnel. This allows users to access internal web apps remotely with single sign-on capabilities, leveraging Entra ID's conditional access policies without requiring a VPN or opening inbound firewall ports.

  • Microsoft Entra Self-Service Password Reset (SSPR)

    Why it's wrong here

    Microsoft Entra Self-Service Password Reset (SSPR) empowers users to reset their own forgotten or locked-out passwords without requiring administrator intervention. It leverages pre-configured authentication methods, such as mobile phone verification or security questions, to securely validate a user's identity. While crucial for user productivity and helpdesk load reduction, SSPR is exclusively a password management feature and does not provide any mechanism for remote access to on-premises applications.

    When this WOULD be correct

    A company wants to reduce helpdesk calls by enabling employees to reset their own passwords securely. The IT team needs a Microsoft Entra ID feature that supports self-service password changes with security verification. In that scenario, SSPR would be the correct answer.

  • Microsoft Entra Privileged Identity Management (PIM)

    Why it's wrong here

    Microsoft Entra Privileged Identity Management (PIM) is designed to manage, control, and monitor access to important resources within Microsoft Entra ID, Azure, and other Microsoft Online Services. Its primary function is to provide just-in-time and time-bound access to privileged roles, reducing the risk of excessive or standing administrative permissions. PIM does not facilitate external access to general on-premises web applications; it focuses solely on privilege elevation and governance.

    When this WOULD be correct

    A company needs to provide just-in-time privileged access to Azure AD roles and monitor privileged account usage. Which Microsoft Entra feature should they implement?

  • Microsoft Entra Identity Protection

    Why it's wrong here

    Microsoft Entra Identity Protection is a security module focused on detecting, investigating, and remediating identity-based risks within an organization. It utilizes machine learning and heuristics to identify suspicious activities like anomalous sign-ins, leaked credentials, or impossible travel scenarios. While vital for enhancing an organization's security posture by enforcing conditional access policies based on risk levels, Identity Protection's purpose is purely defensive and does not offer any functionality for publishing or providing remote access to applications.

    When this WOULD be correct

    A company wants to automatically detect and block risky sign-in attempts, such as those from anonymous IP addresses or unfamiliar locations, to protect user accounts. Which Microsoft Entra feature should they implement?

Option-by-option analysis

Why each answer is right or wrong

Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The SC-900 exam frequently reuses these exact scenarios with slightly different constraints.

Microsoft Entra Application ProxyCorrect answer

Why this is correct

Microsoft Entra Application Proxy is the correct solution for securely publishing on-premises web applications to external users. It achieves this by deploying a lightweight connector within the on-premises network, which establishes an outbound connection to Azure, creating a secure tunnel. This allows users to access internal web apps remotely with single sign-on capabilities, leveraging Entra ID's conditional access policies without requiring a VPN or opening inbound firewall ports.

Microsoft Entra Self-Service Password Reset (SSPR)Wrong answer — click to see why

Why this is wrong here

SSPR allows users to reset their own passwords without admin intervention, but it does not provide secure remote access to on-premises web applications or enable SSO. The question specifically requires a solution for accessing on-premises apps without a VPN, which SSPR does not address.

★ When this WOULD be the correct answer

A company wants to reduce helpdesk calls by enabling employees to reset their own passwords securely. The IT team needs a Microsoft Entra ID feature that supports self-service password changes with security verification. In that scenario, SSPR would be the correct answer.

Why candidates choose this

Candidates may confuse SSPR's authentication capabilities with access control, or think that password reset is a prerequisite for SSO, leading them to select this option without recognizing it does not solve the remote access requirement.

Microsoft Entra Privileged Identity Management (PIM)Wrong answer — click to see why

Why this is wrong here

Privileged Identity Management (PIM) manages, controls, and monitors access to privileged roles in Microsoft Entra ID, not remote access to on-premises web apps without a VPN.

★ When this WOULD be the correct answer

A company needs to provide just-in-time privileged access to Azure AD roles and monitor privileged account usage. Which Microsoft Entra feature should they implement?

Why candidates choose this

Candidates may confuse PIM's 'access management' with the access needed for remote application access, or think PIM can handle all access scenarios including application access.

Microsoft Entra Identity ProtectionWrong answer — click to see why

Why this is wrong here

Microsoft Entra Identity Protection is a tool for detecting and responding to identity-based risks, such as compromised credentials or suspicious sign-ins, not for providing secure remote access to on-premises applications without a VPN.

★ When this WOULD be the correct answer

A company wants to automatically detect and block risky sign-in attempts, such as those from anonymous IP addresses or unfamiliar locations, to protect user accounts. Which Microsoft Entra feature should they implement?

Why candidates choose this

Candidates may confuse 'protection' with 'secure access' and think Identity Protection can secure remote access, but it focuses on risk detection, not proxying applications.

Analysis generated from the official SC-900blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”

About these practice questions

Courseiva writes every SC-900 question from scratch — 1,250 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.