SC-900 Describe the capabilities of Microsoft Entra Practice Question
Which TWO capabilities are provided by Microsoft Entra ID?
⚠ Common exam trap
SC-900 often tests the distinction between identity management (Entra ID) and security management (Defender, Sentinel) or compliance (Purview), so candidates may incorrectly attribute device management or incident detection to Entra ID.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Multifactor authentication
Microsoft Entra ID (formerly Azure AD) is a cloud-based identity and access management service, and it provides Multifactor Authentication (A) by letting administrators enforce a second verification factor such as the Microsoft Authenticator app, SMS, or a FIDO2 key through Conditional Access policies. It also provides Single sign-on (D), allowing users to authenticate once with their Entra ID account and access federated applications via protocols like SAML 2.0, WS-Federation, or OpenID Connect. Device management (B) is not an Entra ID capability itself; it is delivered by Microsoft Intune (or Configuration Manager) through MDM/MAM, even though Entra ID can register or join devices for identity purposes. Security incident detection (C) belongs to Microsoft Defender XDR / Microsoft Sentinel, not Entra ID, which only surfaces identity-related signals like risky sign-ins. Data classification (E) is provided by Microsoft Purview (sensitivity labels, DLP), not by Entra ID.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Multifactor authentication
Why this is correct
Microsoft Entra ID natively provides robust multifactor authentication (MFA) capabilities, allowing organizations to enforce an additional layer of security beyond just a password. Users can verify their identity through various methods like authenticator apps, biometrics, or security keys, significantly reducing the risk of unauthorized access from compromised credentials. This capability is central to a strong identity and access management strategy within the Microsoft cloud ecosystem.
- ✗
Device management
Why it's wrong here
While Microsoft Entra ID registers devices and manages their identities for conditional access and single sign-on, it does not provide comprehensive device management capabilities such as configuration deployment, application management, or compliance policy enforcement. These advanced functionalities, including mobile device management (MDM) and mobile application management (MAM), are primarily delivered through Microsoft Intune, which integrates with Entra ID for identity-driven controls.
- ✗
Security incident detection
Why it's wrong here
Microsoft Entra ID provides identity-specific security insights and risk detections, such as unusual sign-in activity or leaked credentials, which contribute to overall security posture. However, its primary role is not broad security incident detection across an entire IT estate, which involves collecting and analyzing logs from diverse sources, correlating events, and orchestrating responses. That comprehensive security information and event management (SIEM) and security orchestration, automation, and response (SOAR) functionality is provided by Microsoft Sentinel, often leveraging signals from Microsoft Defender for Identity.
- ✓
Single sign-on
Why this is correct
Single sign-on (SSO) is a foundational capability of Microsoft Entra ID, enabling users to access multiple applications and services with a single set of credentials after authenticating just once. Entra ID acts as the identity provider, facilitating seamless and secure access to thousands of pre-integrated SaaS applications, on-premises applications via Application Proxy, and custom line-of-business applications. This significantly enhances user experience and reduces password fatigue while maintaining strong security controls.
- ✗
Data classification
Why it's wrong here
Microsoft Entra ID is an identity and access management service, focusing on who can access what resources, not on the content or sensitivity of the data itself. Data classification, which involves identifying, labeling, and protecting sensitive information across an organization's digital estate, is a core capability of Microsoft Purview. Purview provides tools for automated and manual classification, data loss prevention (DLP), and information protection policies, ensuring data governance and compliance.
Go deeper
Related to this question
Learn chapter
Microsoft Defender Portal Overview
Key term
Single sign-on
Single sign-on (SSO) is an authentication method that allows a user to log in once and gain access to multiple applications or systems without re-entering credentials.
Key term
MDM
MDM stands for Mobile Device Management, a technology that allows IT administrators to securely manage, monitor, and enforce policies on mobile devices like smartphones and tablets from a central console.
About these practice questions
One of 1,279 original SC-900 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.