SC-900 Describe the capabilities of Microsoft Entra Practice Question
Which THREE components are part of Microsoft Entra ID's identity governance? (Choose three.)
⚠ Common exam trap
It's easy for candidates to confuse Conditional Access (a security control) with identity governance, or mistake Self-Service Password Reset (a user convenience feature) for a governance tool, when in fact governance focuses on managing who has access and for how long, not on how access is authenticated or enforced.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Privileged Identity Management
Privileged Identity Management (B) is a core identity governance component in Microsoft Entra ID, providing just-in-time role activation, approval workflows, and time-bound privileged access to Microsoft Entra ID and Azure resources. Entitlement Management (C) is also part of identity governance, delivering access packages, catalogs, and automated access request/assignment workflows for internal and external users. Access Reviews (D) belongs to identity governance as well, enabling periodic recertification of group memberships, application assignments, and privileged role assignments to ensure least privilege. Self-Service Password Reset (A) is an authentication/credential management feature, not an identity governance component, and Conditional Access (E) is a policy-based access control engine for enforcing sign-in conditions, not part of identity governance.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Self-Service Password Reset
Why it's wrong here
Self-Service Password Reset (SSPR) is an identity management feature that empowers users to reset their own passwords without administrator intervention, improving productivity and reducing helpdesk calls. While SSPR is a crucial part of identity management, its primary function is user convenience and operational efficiency for password management, not the oversight, auditing, or enforcement of access policies that define identity governance. It doesn't govern who has access to what, but rather how users manage their own authentication credentials.
- ✓
Privileged Identity Management
Why this is correct
Microsoft Entra ID Privileged Identity Management (PIM) is a core component of identity governance designed to manage, control, and monitor access to important resources within Microsoft Entra ID, Azure, and other Microsoft Online Services. PIM helps mitigate the risks associated with excessive, unnecessary, or misused access permissions by providing just-in-time (JIT) access, time-bound access, and requiring approval or multi-factor authentication for role activation. It specifically governs privileged roles by enforcing principles like least privilege and zero trust, ensuring that elevated permissions are only granted when absolutely necessary and for a limited duration.
- ✓
Entitlement Management
Why this is correct
Entitlement Management is a robust identity governance feature within Microsoft Entra ID that enables organizations to manage identity and access lifecycles at scale by automating access requests, approvals, and provisioning. It allows administrators to bundle resources (such as groups, applications, and SharePoint sites) into "access packages," which users can then request. This system streamlines the process of granting and revoking access based on predefined policies, ensuring users have appropriate access for their roles and that access is automatically removed when no longer needed.
- ✓
Access Reviews
Why this is correct
Microsoft Entra ID Access Reviews are a critical identity governance tool that helps organizations efficiently manage group memberships, access to enterprise applications, and privileged role assignments. They enable administrators to periodically review who has access to specific resources and whether that access is still appropriate, ensuring compliance with organizational policies and regulatory requirements. Reviewers can approve or deny access, and the system can automatically remove access for users whose access is no longer justified, thereby reducing the risk of stale or excessive permissions.
- ✗
Conditional Access
Why it's wrong here
Conditional Access is a powerful access control policy engine within Microsoft Entra ID that enforces specific conditions before granting access to resources. It evaluates signals like user location, device compliance, and sign-in risk in real-time to make access decisions, such as requiring multi-factor authentication or blocking access. While essential for security, Conditional Access is primarily a real-time enforcement mechanism for access policies, rather than a system for managing, auditing, or reviewing the lifecycle of access entitlements themselves, which is the purview of identity governance.
Go deeper
Related to this question
Learn chapter
Threat and Vulnerability Management
Key term
Entitlement management
Entitlement management is the process of controlling who has access to what resources in an organization through automated policies, approvals, and lifecycle management.
Key term
Conditional access
Conditional access is a security framework that evaluates signals like user location, device health, and risk level to grant or block access to resources in real time.
About these practice questions
One of 1,279 original SC-900 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.