SC-900 Describe the capabilities of Microsoft Entra Practice Question
Which THREE are benefits of using Microsoft Entra ID as an identity provider? (Choose three.)
⚠ Common exam trap
Candidates often confuse the identity provider's capabilities (like SSO, MFA, and Conditional Access) with unrelated Azure services (like App Service for hosting or Azure SQL for database management), leading them to select options that are not identity-specific.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Conditional Access policies
Option B (Conditional Access policies) is correct because Microsoft Entra ID provides a policy engine that evaluates signals such as user, device, location, and risk to enforce access controls like requiring MFA or blocking access, which is a core identity-provider benefit. Option D (Multifactor authentication) is correct because Entra ID natively supports MFA methods (Microsoft Authenticator, FIDO2 keys, SMS/voice, OATH tokens) and can enforce them through security defaults or Conditional Access. Option E (Single sign-on to thousands of cloud apps) is correct because Entra ID acts as an IdP using protocols like SAML 2.0, WS-Federation, OpenID Connect, and OAuth 2.0, with a gallery of thousands of pre-integrated SaaS applications for SSO. Option A (Web application hosting) is not a benefit of an identity provider, since hosting compute and web content is the role of services like Azure App Service or IIS, not Entra ID. Option C (Centralized database management) is also unrelated, as Entra ID stores identity objects (users, groups, app registrations) but does not provide general-purpose database management like Azure SQL Database or SQL Server.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Web application hosting
Why it's wrong here
Microsoft Entra ID is fundamentally an Identity and Access Management (IAM) service, not an application hosting platform. Its primary function is to manage user identities, authenticate users, and authorize their access to applications and resources, whether cloud-based or on-premises. It does not provide the compute, storage, or networking infrastructure required to run web applications themselves; those services are typically offered by platforms like Azure App Service, Azure Virtual Machines, or other cloud providers.
- ✓
Conditional Access policies
Why this is correct
Microsoft Entra Conditional Access is a powerful policy engine that enables organizations to enforce granular, risk-based access controls for their resources. By evaluating various signals such as user location, device compliance, sign-in risk, and application sensitivity, Conditional Access policies can dynamically determine whether to grant, block, or require additional authentication steps like multifactor authentication. This capability significantly enhances security by adapting access decisions to the context of each sign-in attempt.
- ✗
Centralized database management
Why it's wrong here
Microsoft Entra ID is an identity directory service designed specifically for managing user, group, and device identities, along with their associated attributes and access permissions. It is not a general-purpose database management system (DBMS) for storing and managing arbitrary application data or relational databases. While it stores identity-related data, its architecture and functionalities are optimized for authentication, authorization, and identity synchronization, distinct from managing transactional or analytical databases.
- ✓
Multifactor authentication
Why this is correct
Microsoft Entra ID provides robust, integrated multifactor authentication (MFA) capabilities, allowing organizations to significantly strengthen identity security. MFA requires users to provide two or more verification methods to prove their identity, such as a password combined with a code from an authenticator app, a biometric scan, or a hardware token. Entra ID seamlessly enforces these additional verification steps during sign-in, making it much harder for unauthorized users to gain access even if a password is compromised.
- ✓
Single sign-on to thousands of cloud apps
Why this is correct
Microsoft Entra ID excels at providing single sign-on (SSO) functionality, enabling users to access numerous cloud-based applications and services with a single set of credentials after authenticating once. It integrates with thousands of pre-configured SaaS applications, custom line-of-business applications, and on-premises resources, leveraging standards like SAML, OAuth, and OpenID Connect. This streamlines the user experience, reduces password fatigue, and simplifies identity management for administrators across a diverse application portfolio.
Go deeper
Related to this question
Learn chapter
Azure NSG and Application Security Groups
Key term
OAuth
OAuth is an open standard for access delegation that allows users to grant third-party applications limited access to their resources without sharing their credentials.
Key term
SQL
SQL is a standardized programming language used to manage and manipulate relational databases, enabling querying, updating, and data retrieval.
About these practice questions
This SC-900 question is part of Courseiva's 1,279-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.