SC-900 Describe the capabilities of Microsoft Entra Practice Question
Which THREE capabilities are provided by Microsoft Entra Identity Protection? (Choose three.)
⚠ Common exam trap
Many candidates confuse the risk-based Conditional Access integration (which is part of Identity Protection) with the password reset and JIT access features that belong to separate Microsoft Entra services like SSPR and PIM.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Detect leaked credentials
Microsoft Entra Identity Protection includes leaked credential detection (A), which scans for compromised credentials exposed in breaches or dark web dumps and surfaces them as user risk detections. It also enables risk-based Conditional Access policies (B), allowing sign-in and user risk levels to drive access decisions such as requiring MFA or password change. Its risk investigation reports (E) give administrators visibility into risky users, risky sign-ins, and detections for triage and remediation. Self-service password reset (C) is a separate Microsoft Entra ID feature, and just-in-time privileged access (D) is provided by Privileged Identity Management, not Identity Protection.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Detect leaked credentials
Why this is correct
Microsoft Entra ID Protection actively monitors public and dark web sources for compromised user credentials associated with your tenant. When a username and password pair is found to be leaked, ID Protection flags the affected user as having a "leaked credentials" risk, enabling administrators to force password resets or block sign-ins to prevent unauthorized access. This proactive monitoring is a critical defense against credential stuffing attacks.
- ✓
Enable risk-based conditional access policies
Why this is correct
Microsoft Entra ID Protection continuously evaluates sign-in and user behavior for suspicious activities, generating real-time risk scores. These dynamic risk signals are then fed directly into Microsoft Entra Conditional Access policies, allowing organizations to automatically enforce adaptive controls such as multi-factor authentication, password changes, or blocking access entirely based on the detected risk level of a specific sign-in attempt or user.
- ✗
Allow users to reset their own passwords
Why it's wrong here
While a crucial identity management feature, allowing users to reset their own passwords is provided by Microsoft Entra Self-Service Password Reset (SSPR), not Microsoft Entra ID Protection. SSPR enables users to securely reset forgotten passwords without administrator intervention, whereas ID Protection focuses on detecting and remediating identity-based risks like compromised accounts or suspicious sign-ins.
- ✗
Provide just-in-time privileged access
Why it's wrong here
Just-in-time (JIT) privileged access, which grants temporary, time-bound permissions for specific administrative tasks, is a core capability of Microsoft Entra Privileged Identity Management (PIM). Microsoft Entra ID Protection, conversely, is focused on identifying and mitigating identity-based risks associated with user accounts and sign-ins, rather than managing the lifecycle of privileged roles.
- ✓
Provide a risk investigation report
Why this is correct
Microsoft Entra ID Protection offers comprehensive reports that detail detected risks, including risky users, risky sign-ins, and detected vulnerabilities. These reports provide administrators with actionable insights into potential threats, allowing them to investigate specific risk events, understand attack patterns, and prioritize remediation efforts to enhance the overall security posture of their organization.
Go deeper
Related to this question
Learn chapter
SAML and Single Sign-On (SSO)
Key term
Conditional access
Conditional access is a security framework that evaluates signals like user location, device health, and risk level to grant or block access to resources in real time.
Key term
Risk
Risk is the possibility that an event or action will negatively affect an organization's ability to achieve its goals, often measured in terms of likelihood and impact.
About these practice questions
Courseiva writes every SC-900 question from scratch — 1,279 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.