SC-900 Describe the capabilities of Microsoft Entra Practice Question
Which three features are available in Microsoft Entra ID P2 but not in P1? (Choose three.)
⚠ Common exam trap
Many exam-takers confuse Conditional Access policies as a P2-only feature, but they are actually available in P1, while P2 adds Identity Protection risk-based policies and PIM, not the base Conditional Access engine.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Access reviews
Access reviews are a Microsoft Entra ID P2 feature that allows administrators to automate periodic reviews of group memberships, application access, and role assignments. This capability is not available in P1, which lacks the automated review workflows and attestation features that P2 provides for governance and compliance.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Access reviews
Why this is correct
Microsoft Entra ID P2 includes Access reviews, a critical governance feature enabling organizations to efficiently manage group memberships, application assignments, and privileged role assignments. This feature allows administrators to regularly review who has access to what resources, ensuring that only necessary permissions are maintained and reducing the risk of stale or excessive access. Without P2, these automated and recurring reviews are not available, making manual auditing cumbersome and prone to oversight.
- ✓
Privileged Identity Management (PIM)
Why this is correct
Privileged Identity Management (PIM) is a core Microsoft Entra ID P2 capability designed to manage, control, and monitor access to important resources within an organization. PIM provides just-in-time (JIT) access to privileged roles, requiring users to activate their roles for a limited time, and includes approval workflows, multi-factor authentication enforcement, and audit trails for these activations. This advanced governance helps mitigate the risks associated with excessive, unnecessary, or misused access permissions.
- ✓
Identity Protection risk-based policies
Why this is correct
Microsoft Entra ID P2 provides Identity Protection, which includes advanced risk-based policies that automatically detect, protect, and remediate identity-based risks. These policies leverage machine learning to identify suspicious user behaviors, such as impossible travel or leaked credentials, and can automatically enforce actions like requiring multi-factor authentication or blocking access based on the detected risk level. This proactive, automated security response is a hallmark feature exclusive to the P2 license.
- ✗
Conditional Access policies
Why it's wrong here
Conditional Access policies are a fundamental security feature that allows organizations to enforce specific access controls based on various conditions, such as user location, device compliance, or application being accessed. While incredibly powerful for defining "if-then" statements for access to resources, this capability is a core offering of Microsoft Entra ID P1. Therefore, it is not exclusive to or a distinguishing feature of Microsoft Entra ID P2.
- ✗
Self-service password reset (SSPR) with writeback
Why it's wrong here
Self-service password reset (SSPR) with writeback allows users to reset their forgotten passwords without administrator intervention, and then writes those new passwords back to an on-premises Active Directory environment. This feature significantly reduces help desk calls and improves user productivity by empowering users to manage their own credentials. However, SSPR with writeback is a standard feature included with Microsoft Entra ID P1, not an exclusive capability of the P2 license.
Go deeper
Related to this question
Learn chapter
Compliance Concepts
Key term
Microsoft Entra ID
Microsoft Entra ID is a cloud-based identity and access management service that lets employees sign in and access resources both inside and outside of your organization.
Key term
Governance
Governance is the framework of policies, processes, and controls that ensures IT activities align with business goals and comply with regulations.
About these practice questions
One of 1,250 original SC-900 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.