Courseiva
Describe the capabilities of Microsoft EntraeasyMultiple SelectObjective-mapped

SC-900 Describe the capabilities of Microsoft Entra Practice Question

Which TWO capabilities are part of Microsoft Entra ID Governance?

⚠ Common exam trap

Watch out — candidates often confuse Identity Protection or Conditional Access with governance because they involve security controls, but Microsoft Entra ID Governance specifically focuses on the lifecycle management and periodic review of access rights, not on risk detection or policy enforcement at sign-in.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Entitlement Management

Entitlement Management is a core capability of Microsoft Entra ID Governance because it enables organizations to manage the lifecycle of access for internal and external users through access packages, catalogs, and policies. It automates the request, approval, and assignment of access to groups, apps, and SharePoint sites, ensuring governance over who gets what and for how long. Access Reviews is also a key governance feature because it allows administrators to periodically review and certify user access, automatically removing stale or inappropriate permissions to maintain compliance.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Entitlement Management

    Why this is correct

    Microsoft Entra Entitlement Management is a robust identity governance feature that automates the lifecycle of access requests and approvals for internal and external users. It allows organizations to define access packages, which bundle resources and policies, enabling self-service access requests and ensuring users have appropriate permissions based on their role or project. This capability streamlines the process of granting and revoking access, reducing manual overhead and improving security posture.

  • Identity Protection

    Why it's wrong here

    Microsoft Entra Identity Protection is a security feature focused on detecting and remediating identity-based risks, such as compromised credentials, suspicious sign-ins, and anomalous user behavior. While vital for securing identities, its primary function is threat detection and response, not the systematic management, review, or certification of access entitlements. It acts as a real-time security layer rather than a governance tool for access lifecycle management.

  • Conditional Access

    Why it's wrong here

    Microsoft Entra Conditional Access is a policy engine that enforces access controls by evaluating specific conditions at the time of a sign-in attempt. It determines whether a user is granted, blocked, or challenged for access based on factors like user location, device compliance, or application sensitivity. While critical for enforcing security policies, it dictates how access is granted or denied in real-time, rather than managing who should have what access over time as part of an identity governance framework.

  • Self-Service Password Reset

    Why it's wrong here

    Self-Service Password Reset (SSPR) in Microsoft Entra ID empowers users to securely reset their forgotten or expired passwords without requiring administrator intervention. This feature significantly enhances user productivity and reduces the burden on IT help desks by automating a common support request. However, SSPR is specifically designed for managing the password lifecycle and user convenience, and it does not encompass the broader scope of identity governance, which involves managing access entitlements, roles, and resource provisioning.

  • Access Reviews

    Why this is correct

    Microsoft Entra Access Reviews provide a systematic way to regularly evaluate and certify user access to groups, applications, and resources within an organization. This governance capability ensures that access remains appropriate and necessary over time, helping to mitigate the risk of privilege creep and maintain compliance with regulatory requirements. Designated reviewers, such as resource owners or managers, are prompted to confirm or revoke access for users, ensuring accountability and security.

About these practice questions

Courseiva writes every SC-900 question from scratch — 1,250 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.