SC-900 Describe the capabilities of Microsoft Entra Practice Question
Which TWO conditions can be used in a Microsoft Entra Conditional Access policy? (Choose two.)
⚠ Common exam trap
It's easy for candidates to confuse conditions (e.g., device platform, user risk) with grant controls (e.g., require MFA, sign-in frequency) or configuration settings (e.g., password complexity), leading them to select options that are not valid conditions in the Conditional Access policy editor.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Device platform
Device platform is a standard condition in Microsoft Entra Conditional Access policies, allowing administrators to target policies based on the operating system (e.g., Windows, iOS, Android). Option D is correct because User risk level is a condition derived from Microsoft Entra ID Protection, reflecting the probability that a user's identity has been compromised, and can be used to trigger step-up authentication or block access.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
MFA registration status
Why it's wrong here
MFA registration status is not a direct condition that triggers a Conditional Access policy. While a user's ability to perform MFA is critical, the policy itself typically enforces MFA as a grant control (e.g., "Require multifactor authentication") or a session control (e.g., "Require reauthentication") once other conditions are met. The policy doesn't evaluate *if* a user is registered for MFA as a primary condition to apply the policy; rather, it dictates *that* MFA must be used or registered.
- ✗
Password complexity
Why it's wrong here
Password complexity is not a configurable condition within Microsoft Entra Conditional Access policies. The enforcement of password complexity requirements, such as minimum length or character types, is managed through Microsoft Entra ID's authentication methods policies or tenant-wide settings, which apply globally to user accounts. Conditional Access policies focus on real-time attributes of a sign-in attempt, such as location or device compliance, rather than static password strength.
- ✓
Device platform
Why this is correct
Device platform is a fundamental condition in Microsoft Entra Conditional Access, enabling administrators to specify which operating systems a policy applies to. This condition allows for highly granular control, such as requiring compliant devices only for specific platforms like iOS and Android, while potentially blocking access from less secure or unsupported platforms like Linux or macOS unless they meet additional criteria. It directly evaluates the OS of the device initiating the access request.
- ✓
User risk level
Why this is correct
User risk level is a dynamic condition within Microsoft Entra Conditional Access, directly integrating with Microsoft Entra ID Protection to assess the likelihood of a user account being compromised. This condition allows policies to automatically respond to different levels of detected risk (e.g., low, medium, high) by enforcing actions such as requiring a password change, blocking access, or mandating multifactor authentication, thereby protecting against identity-based threats in real-time.
- ✗
Login frequency
Why it's wrong here
"Sign-in frequency," often referred to as login frequency, is configured as a session control within Conditional Access policies, not a condition that triggers the policy. This control dictates how often users are prompted to reauthenticate during an active session, enhancing security by regularly verifying identity. Conditions determine *when* a policy applies based on attributes of the access attempt, whereas session controls define *how* the user's session behaves *after* the policy has been applied and access granted.
Go deeper
Related to this question
Learn chapter
Identity Concepts
Key term
Conditional access
Conditional access is a security framework that evaluates signals like user location, device health, and risk level to grant or block access to resources in real time.
Key term
Policy
A policy is a set of rules or guidelines that defines how an organization manages, secures, and operates its IT systems and services.
About these practice questions
Courseiva writes every SC-900 question from scratch — 1,250 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.