Courseiva

SC-900 Describe the capabilities of Microsoft Entra Practice Question

Which TWO capabilities are provided by Microsoft Entra ID?

⚠ Common exam trap

SC-900 often tests the distinction between identity management (Entra ID) and security management (Defender, Sentinel) or compliance (Purview), so candidates may incorrectly attribute device management or incident detection to Entra ID.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Multifactor authentication

Microsoft Entra ID (formerly Azure AD) is a cloud-based identity and access management service, and it provides Multifactor Authentication (A) by letting administrators enforce a second verification factor such as the Microsoft Authenticator app, SMS, or a FIDO2 key through Conditional Access policies. It also provides Single sign-on (D), allowing users to authenticate once with their Entra ID account and access federated applications via protocols like SAML 2.0, WS-Federation, or OpenID Connect. Device management (B) is not an Entra ID capability itself; it is delivered by Microsoft Intune (or Configuration Manager) through MDM/MAM, even though Entra ID can register or join devices for identity purposes. Security incident detection (C) belongs to Microsoft Defender XDR / Microsoft Sentinel, not Entra ID, which only surfaces identity-related signals like risky sign-ins. Data classification (E) is provided by Microsoft Purview (sensitivity labels, DLP), not by Entra ID.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Multifactor authentication

    Why this is correct

    Microsoft Entra ID natively provides robust multifactor authentication (MFA) capabilities, allowing organizations to enforce an additional layer of security beyond just a password. Users can verify their identity through various methods like authenticator apps, biometrics, or security keys, significantly reducing the risk of unauthorized access from compromised credentials. This capability is central to a strong identity and access management strategy within the Microsoft cloud ecosystem.

  • ✗

    Device management

    Why it's wrong here

    While Microsoft Entra ID registers devices and manages their identities for conditional access and single sign-on, it does not provide comprehensive device management capabilities such as configuration deployment, application management, or compliance policy enforcement. These advanced functionalities, including mobile device management (MDM) and mobile application management (MAM), are primarily delivered through Microsoft Intune, which integrates with Entra ID for identity-driven controls.

  • ✗

    Security incident detection

    Why it's wrong here

    Microsoft Entra ID provides identity-specific security insights and risk detections, such as unusual sign-in activity or leaked credentials, which contribute to overall security posture. However, its primary role is not broad security incident detection across an entire IT estate, which involves collecting and analyzing logs from diverse sources, correlating events, and orchestrating responses. That comprehensive security information and event management (SIEM) and security orchestration, automation, and response (SOAR) functionality is provided by Microsoft Sentinel, often leveraging signals from Microsoft Defender for Identity.

  • ✓

    Single sign-on

    Why this is correct

    Single sign-on (SSO) is a foundational capability of Microsoft Entra ID, enabling users to access multiple applications and services with a single set of credentials after authenticating just once. Entra ID acts as the identity provider, facilitating seamless and secure access to thousands of pre-integrated SaaS applications, on-premises applications via Application Proxy, and custom line-of-business applications. This significantly enhances user experience and reduces password fatigue while maintaining strong security controls.

  • ✗

    Data classification

    Why it's wrong here

    Microsoft Entra ID is an identity and access management service, focusing on who can access what resources, not on the content or sensitivity of the data itself. Data classification, which involves identifying, labeling, and protecting sensitive information across an organization's digital estate, is a core capability of Microsoft Purview. Purview provides tools for automated and manual classification, data loss prevention (DLP), and information protection policies, ensuring data governance and compliance.

About these practice questions

One of 1,279 original SC-900 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Microsoft exam blueprint

This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.