Courseiva

SC-900 Describe the capabilities of Microsoft Entra Practice Question

Which THREE features are part of Microsoft Entra Identity Governance?

⚠ Common exam trap

A common mix-up: candidates confuse Microsoft Entra Connect (a synchronization tool) with Identity Governance features, or mistake ID Protection (a risk-detection service) for a governance capability, when the exam specifically tests the three pillars of Identity Governance: entitlement management, access reviews, and privileged identity management.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Privileged Identity Management

Microsoft Entra Identity Governance is the suite that ensures the right people have the right access, and it specifically includes Privileged Identity Management (B), which provides just-in-time role activation, approval workflows, and time-bound assignments for privileged roles. Access reviews (C) are also a core Identity Governance capability, letting reviewers periodically recertify group memberships, application assignments, and role assignments to remove stale access. Entitlement management (E) is the third pillar, using access packages, catalogs, and connected organizations to automate the request, approval, and lifecycle of access for internal and external users. The unmarked options do not belong: Microsoft Entra Connect (A) is a synchronization tool for hybrid identity between on-premises AD and Entra ID, and ID Protection (D) is a separate risk-detection and remediation service for identity risk signals, neither of which is part of the Identity Governance feature set.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Microsoft Entra Connect

    Why it's wrong here

    Microsoft Entra Connect is primarily a synchronization service that integrates on-premises directories, such as Active Directory Domain Services, with Microsoft Entra ID. Its main function is to provision users, groups, and contacts from on-premises to the cloud, and optionally synchronize password hashes or enable pass-through authentication. While crucial for hybrid identity, it does not provide identity governance features like access reviews, entitlement management, or privileged access management, which focus on managing and auditing access lifecycles and permissions.

  • ✓

    Privileged Identity Management

    Why this is correct

    Microsoft Entra Privileged Identity Management (PIM) is a core component of identity governance designed to manage, control, and monitor access to important resources within an organization. It provides just-in-time (JIT) access to privileged roles and resources, requiring users to activate their elevated permissions for a limited time. PIM also enforces approval workflows, multi-factor authentication for activation, and regular access reviews for privileged role assignments, significantly reducing the risk associated with standing administrative access.

  • ✓

    Access reviews

    Why this is correct

    Microsoft Entra access reviews are a fundamental identity governance capability that enables organizations to efficiently manage group memberships, access to enterprise applications, and privileged role assignments. By automating the process of reviewing who has access to what, access reviews help ensure that only authorized individuals maintain access, preventing "access sprawl." These periodic reviews can be assigned to business owners or resource owners, who then attest to the continued need for access, ensuring compliance and security.

  • ✗

    ID Protection

    Why it's wrong here

    Microsoft Entra ID Protection is a security feature focused on detecting, investigating, and remediating identity-based risks in real-time. It leverages machine learning and heuristics to identify suspicious activities, such as impossible travel, unfamiliar sign-in properties, or leaked credentials. While critical for securing identities, ID Protection's primary role is risk detection and automated remediation (e.g., blocking sign-ins, requiring MFA), rather than the structured management and auditing of access lifecycles and permissions that define identity governance.

  • ✓

    Entitlement management

    Why this is correct

    Microsoft Entra entitlement management is an identity governance feature that automates the access lifecycle for internal and external users to various resources, including groups, applications, and SharePoint sites. It allows organizations to create "access packages" that bundle resources and define policies for requesting, approving, and reviewing access, as well as automatic expiration. This self-service capability delegates access management to business owners, ensuring users have the right access for the right amount of time without IT intervention.

About these practice questions

This SC-900 question is part of Courseiva's 1,279-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.