SC-900 Describe the capabilities of Microsoft Entra Practice Question
Which THREE features are part of Microsoft Entra Identity Governance?
⚠ Common exam trap
A common mix-up: candidates confuse Microsoft Entra Connect (a synchronization tool) with Identity Governance features, or mistake ID Protection (a risk-detection service) for a governance capability, when the exam specifically tests the three pillars of Identity Governance: entitlement management, access reviews, and privileged identity management.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Privileged Identity Management
Microsoft Entra Identity Governance is the suite that ensures the right people have the right access, and it specifically includes Privileged Identity Management (B), which provides just-in-time role activation, approval workflows, and time-bound assignments for privileged roles. Access reviews (C) are also a core Identity Governance capability, letting reviewers periodically recertify group memberships, application assignments, and role assignments to remove stale access. Entitlement management (E) is the third pillar, using access packages, catalogs, and connected organizations to automate the request, approval, and lifecycle of access for internal and external users. The unmarked options do not belong: Microsoft Entra Connect (A) is a synchronization tool for hybrid identity between on-premises AD and Entra ID, and ID Protection (D) is a separate risk-detection and remediation service for identity risk signals, neither of which is part of the Identity Governance feature set.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Microsoft Entra Connect
Why it's wrong here
Microsoft Entra Connect is primarily a synchronization service that integrates on-premises directories, such as Active Directory Domain Services, with Microsoft Entra ID. Its main function is to provision users, groups, and contacts from on-premises to the cloud, and optionally synchronize password hashes or enable pass-through authentication. While crucial for hybrid identity, it does not provide identity governance features like access reviews, entitlement management, or privileged access management, which focus on managing and auditing access lifecycles and permissions.
- ✓
Privileged Identity Management
Why this is correct
Microsoft Entra Privileged Identity Management (PIM) is a core component of identity governance designed to manage, control, and monitor access to important resources within an organization. It provides just-in-time (JIT) access to privileged roles and resources, requiring users to activate their elevated permissions for a limited time. PIM also enforces approval workflows, multi-factor authentication for activation, and regular access reviews for privileged role assignments, significantly reducing the risk associated with standing administrative access.
- ✓
Access reviews
Why this is correct
Microsoft Entra access reviews are a fundamental identity governance capability that enables organizations to efficiently manage group memberships, access to enterprise applications, and privileged role assignments. By automating the process of reviewing who has access to what, access reviews help ensure that only authorized individuals maintain access, preventing "access sprawl." These periodic reviews can be assigned to business owners or resource owners, who then attest to the continued need for access, ensuring compliance and security.
- ✗
ID Protection
Why it's wrong here
Microsoft Entra ID Protection is a security feature focused on detecting, investigating, and remediating identity-based risks in real-time. It leverages machine learning and heuristics to identify suspicious activities, such as impossible travel, unfamiliar sign-in properties, or leaked credentials. While critical for securing identities, ID Protection's primary role is risk detection and automated remediation (e.g., blocking sign-ins, requiring MFA), rather than the structured management and auditing of access lifecycles and permissions that define identity governance.
- ✓
Entitlement management
Why this is correct
Microsoft Entra entitlement management is an identity governance feature that automates the access lifecycle for internal and external users to various resources, including groups, applications, and SharePoint sites. It allows organizations to create "access packages" that bundle resources and define policies for requesting, approving, and reviewing access, as well as automatic expiration. This self-service capability delegates access management to business owners, ensuring users have the right access for the right amount of time without IT intervention.
Go deeper
Related to this question
Learn chapter
Cloud App Governance and App Consent
Key term
Identity Governance
Identity Governance is the policy-based framework that ensures the right people have the right access to the right resources at the right time, with oversight and control.
Key term
Risk
Risk is the possibility that an event or action will negatively affect an organization's ability to achieve its goals, often measured in terms of likelihood and impact.
About these practice questions
This SC-900 question is part of Courseiva's 1,279-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.