SC-900 Describe the capabilities of Microsoft Entra Practice Question
Which TWO capabilities are provided by Microsoft Entra Identity Protection?
⚠ Common exam trap
It's easy for candidates to confuse Identity Protection's risk detection and automated remediation with other Entra features like Conditional Access (session controls) or Privileged Identity Management (role assignments), leading them to select options that describe those separate services.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Detecting sign-in risks such as anonymous IP addresses
Microsoft Entra Identity Protection is a risk-detection and remediation service, so option C is correct: it detects sign-in risks such as anonymous IP addresses (along with other detections like atypical travel, malware-linked IPs, and leaked credentials) and surfaces them as risk detections and risky sign-ins. Option D is also correct because Identity Protection can automatically remediate risk by blocking sign-ins through risk-based Conditional Access policies (for example, requiring MFA or blocking when sign-in risk is Medium/High), and it can also require password changes for risky users. Option A is incorrect because session timeouts are enforced through Conditional Access session controls (such as sign-in frequency), not Identity Protection. Option B is incorrect because self-service password reset is a separate Microsoft Entra ID feature, not a capability of Identity Protection. Option E is incorrect because managing privileged role assignments is handled by Privileged Identity Management (PIM), not Identity Protection.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Enforcing session timeouts for applications
Why it's wrong here
While Microsoft Entra ID provides the framework for identity management, the enforcement of session timeouts for applications is specifically handled by Conditional Access policies. These policies leverage session controls to dictate how users can interact with applications after authentication, such as requiring reauthentication or limiting access duration, rather than being a direct, inherent capability of Entra ID's core identity service.
- ✗
Self-service password reset
Why it's wrong here
Self-service password reset (SSPR) is indeed a valuable feature offered by Microsoft Entra ID, empowering users to reset their own forgotten passwords without administrator intervention. However, SSPR is primarily a user productivity and management capability, distinct from the advanced identity protection and risk detection functionalities that the other correct options highlight as core security capabilities.
- ✓
Detecting sign-in risks such as anonymous IP addresses
Why this is correct
Microsoft Entra ID Identity Protection actively monitors and analyzes sign-in attempts and user behavior to identify potential threats. This capability includes detecting various anomalies, such as sign-ins from anonymous IP addresses, unfamiliar locations, or impossible travel scenarios, which are strong indicators of compromised credentials or malicious activity. It continuously assesses risk levels for each identity.
- ✓
Automatically remediating risk by blocking sign-ins
Why this is correct
Building upon its risk detection capabilities, Microsoft Entra ID Identity Protection can automatically take action to mitigate identified threats. When a sign-in is deemed high-risk, for instance, due to a detected anonymous IP address or a leaked credential, Identity Protection can be configured to automatically block the sign-in attempt, preventing unauthorized access and protecting user accounts proactively.
- ✗
Managing privileged role assignments
Why it's wrong here
Managing privileged role assignments is a crucial aspect of identity governance within Microsoft Entra ID, primarily facilitated by Privileged Identity Management (PIM). PIM enables just-in-time access, approval workflows, and access reviews for administrative roles, ensuring that privileged access is granted only when needed and for a limited duration, which is a distinct governance function separate from real-time risk detection.
Go deeper
Related to this question
Learn chapter
Insider Risk Management
Key term
Identity
Identity is the unique set of attributes that defines a user, device, or service in a computer system, determining what they can access and do.
Key term
PIM
Privileged Identity Management, a Microsoft Microsoft Entra ID tool that manages, monitors, and controls access to privileged roles on a just-in-time basis.
About these practice questions
This SC-900 question is part of Courseiva's 1,279-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.