SC-900 Describe the capabilities of Microsoft Entra Practice Question
Which TWO capabilities are part of Microsoft Entra ID? (Choose two.)
⚠ Common exam trap
Test-takers frequently confuse Microsoft Entra ID's identity and access management capabilities with broader security tools like Defender for Cloud (CSPM) or Sentinel (SIEM), or with device management tools like Intune (MDM), because all are part of Microsoft's security portfolio but serve distinct functions.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Application management
Application management (A) is a core Microsoft Entra ID capability, allowing administrators to register, configure, and assign enterprise applications and manage app roles, permissions, and provisioning. Single sign-on (B) is also a native Entra ID feature, enabling users to authenticate once and access integrated SaaS and on-premises applications via protocols such as SAML, OAuth 2.0, and OpenID Connect. Cloud security posture management (C) belongs to Microsoft Defender for Cloud, not Entra ID. Mobile device management (D) is provided by Microsoft Intune, and security information and event management (E) is delivered by Microsoft Sentinel, so neither is an Entra ID capability.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Application management
Why this is correct
Application management is a core Microsoft Entra ID capability, covering app registration, single sign-on configuration, provisioning and access policies for cloud and on-premises applications. It satisfies the stem's requirement by being one of the two listed capabilities genuinely delivered by the service, rather than by a separate product such as Defender or Purview.
- ✓
Single sign-on (SSO)
Why this is correct
Single sign-on is a core Microsoft Entra ID capability, letting users authenticate once and access multiple applications without re-entering credentials. It satisfies the stem's requirement for an Entra ID feature by using federated authentication and token-based access, reducing password sprawl across cloud and on-premises resources.
- ✗
Cloud security posture management
Why it's wrong here
Cloud security posture management continuously assesses resource configurations for misconfigurations, delivered by Microsoft Defender for Cloud, not Microsoft Entra ID, which governs identities, authentication and conditional access. It tempts because Entra ID contributes identity-related secure score recommendations, yet posture assessment of workloads is a separate discipline.
- ✗
Mobile device management (MDM)
Why it's wrong here
Mobile device management enrols and configures devices, handled by Microsoft Intune, whereas Microsoft Entra ID provides identity, authentication and conditional access. It tempts because Entra ID registers devices and supports compliance signals, but enrolment, configuration profiles and wipe actions belong to Intune.
- ✗
Security information and event management (SIEM)
Why it's wrong here
SIEM aggregates and correlates log data for threat detection, which Microsoft Sentinel provides, not Microsoft Entra ID, whose scope is identity and access. It tempts because Entra ID emits sign-in and audit logs into a SIEM, but the SIEM engine itself sits outside the identity service.
Go deeper
Related to this question
Learn chapter
SAML and Single Sign-On (SSO)
Key term
Single sign-on
Single sign-on (SSO) is an authentication method that allows a user to log in once and gain access to multiple applications or systems without re-entering credentials.
Key term
Microsoft Defender
Microsoft Defender is a suite of security products that protects devices, data, and identities from cyber threats like malware, phishing, and unauthorized access.
About these practice questions
Courseiva writes every SC-900 question from scratch — 1,279 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.