Courseiva
Describe the capabilities of Microsoft EntramediumMultiple SelectObjective-mapped

SC-900 Describe the capabilities of Microsoft Entra Practice Question

Which THREE of the following are features of Microsoft Entra ID Protection?

⚠ Common exam trap

Watch out — candidates often confuse the distinct Microsoft Entra services—Entra ID Protection (risk detection and remediation), Privileged Identity Management (PIM) for just-in-time access, and general password policy settings—leading them to select options that belong to other services.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Ability to define risk-based Conditional Access policies.

Microsoft Entra ID Protection provides risk detection signals that can be integrated into Conditional Access policies, enabling administrators to automatically enforce controls such as requiring multi-factor authentication or blocking access based on user or sign-in risk levels. This allows organizations to respond dynamically to detected threats without manual intervention.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Automatically notify users when their password is about to expire.

    Why it's wrong here

    While Microsoft Entra ID manages user accounts and enforces password policies, the automatic notification feature for password expiration is not a direct, built-in capability of Entra ID itself. Proactive alerts for password expiration typically rely on other services or custom solutions, such as Exchange Online integration, PowerShell scripts, or third-party tools, rather than being a native Entra ID security feature.

  • Ability to define risk-based Conditional Access policies.

    Why this is correct

    This is a core security feature of Microsoft Entra ID Protection, which integrates seamlessly with Conditional Access. Entra ID Protection continuously assesses sign-in and user risks in real-time, allowing administrators to define Conditional Access policies that dynamically enforce controls like multi-factor authentication, password change, or access blocking based on the perceived risk level of an authentication attempt.

  • Automated remediation of risky users by blocking sign-in.

    Why this is correct

    Microsoft Entra ID Protection identifies users exhibiting risky behaviors, such as impossible travel or leaked credentials. As part of its automated remediation capabilities, it can be configured to automatically block sign-ins for users detected with high-risk events, preventing potential attackers from gaining access. This proactive measure prompts the legitimate user to remediate the risk, often through a secure password reset or MFA challenge.

  • Just-in-time privileged role activation.

    Why it's wrong here

    While Microsoft Entra ID is the identity provider, Just-in-Time (JIT) privileged role activation is a specific advanced capability provided by Microsoft Entra Privileged Identity Management (PIM). PIM is an add-on feature designed to manage, control, and monitor access to important resources, ensuring users only have elevated permissions for a limited, defined period when they specifically need them, rather than permanent access.

  • Detection of sign-in risks from anonymous IP addresses.

    Why this is correct

    Microsoft Entra ID Protection continuously monitors sign-in attempts for various anomalies and potential threats. One crucial detection is identifying sign-ins originating from anonymous IP addresses, which are often associated with proxies, Tor browsers, or other methods used to obscure identity and location. This detection serves as a vital signal for potential malicious activity, contributing to the overall risk score of a sign-in attempt and enabling subsequent Conditional Access policies to respond appropriately.

About these practice questions

Courseiva writes every SC-900 question from scratch — 1,250 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.