SC-900 Describe the capabilities of Microsoft Entra Practice Question
Which THREE of the following are capabilities of Microsoft Entra ID Governance?
⚠ Common exam trap
Watch out — candidates often confuse security features like Conditional Access or SSPR with governance capabilities, but Microsoft Entra ID Governance specifically focuses on identity lifecycle management, access reviews, entitlement management, and privileged identity management, not on authentication or policy enforcement.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Access reviews
Entitlement management (D) is a core Entra ID Governance capability that lets organizations manage the lifecycle of access through access packages, catalogs, and policies, automating granting, revoking, and expiration of access for internal and external users. Access reviews (B) are also part of Entra ID Governance, enabling periodic recertification of group memberships, application assignments, and privileged role assignments to ensure users retain only the access they need. Privileged Identity Management (C) is included in Entra ID Governance, providing just-in-time privileged access, approval workflows, access reviews, and audit history for Microsoft Entra roles, Azure resources, and other workloads. Self-service password reset (A) is an Entra ID authentication feature, not a governance capability, and Conditional Access (E) is an Entra ID access-control policy engine, so neither belongs to the Entra ID Governance feature set.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Self-service password reset
Why it's wrong here
Self-service password reset (SSPR) allows users to reset their own passwords without administrator intervention, improving user experience and reducing help desk calls. While it enhances security by enabling quick password changes, its primary function is user convenience and operational efficiency, not managing or auditing access rights or lifecycle. It falls under identity protection and user experience, rather than the structured oversight and enforcement mechanisms of identity governance.
- ✓
Access reviews
Why this is correct
Access reviews are a capability within Microsoft Entra Identity Governance that allows organizations to efficiently manage group memberships, access to enterprise applications, and roles. They enable administrators, or even resource owners, to periodically review who has access to what resources, ensuring that only authorized users maintain appropriate permissions and helping to prevent privilege creep. This systematic validation of access rights is a core component of maintaining a strong security posture and meeting compliance requirements.
- ✓
Privileged Identity Management
Why this is correct
Microsoft Entra Privileged Identity Management (PIM) is a service that enables you to manage, control, and monitor access to important resources in your organization. It provides just-in-time and just-enough access to privileged roles, reducing the window of opportunity for malicious actors. By requiring activation for privileged roles and providing time-bound access, PIM significantly enhances the security of administrative accounts and is a critical component of identity governance.
- ✓
Entitlement management
Why this is correct
Microsoft Entra entitlement management is an identity governance feature that enables organizations to manage identity and access lifecycle at scale, by automating access request workflows, access assignments, reviews, and expiration. It allows organizations to control who has access to what resources (groups, applications, SharePoint sites) and for how long, including access for external users. This structured approach ensures that users have the necessary access when needed and that access is automatically removed when no longer required, aligning perfectly with governance principles.
- ✗
Conditional access
Why it's wrong here
Conditional Access is a security feature that evaluates various signals, suchs as user, location, device, and application, to make real-time decisions about whether to grant or block access, or to enforce additional authentication requirements. While it is crucial for enforcing security policies and protecting resources, its primary role is access enforcement and risk mitigation, not the lifecycle management, auditing, or periodic review of access rights that define identity governance. It acts as a policy enforcement engine rather than a governance framework for access lifecycle.
Go deeper
Related to this question
Learn chapter
Terms of Use and Authentication Strengths
Key term
Privileged Identity Management
Privileged Identity Management is a security system that controls, monitors, and audits access to sensitive systems by granting elevated permissions only when needed and for a limited time.
Key term
Group
A group is a collection of users, devices, or other objects that are assigned permissions and policies together for simplified management in identity and governance systems like Microsoft Entra ID.
About these practice questions
One of 1,279 original SC-900 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.