SC-900 Describe the capabilities of Microsoft Entra Practice Question
Which TWO features are included in Microsoft Entra ID P2 licensing?
⚠ Common exam trap
It's easy for candidates to confuse features available in Microsoft Entra ID P1 (like MFA, SSO, and passwordless) with P2-exclusive features, forgetting that P2 adds only advanced identity protection and privileged identity management on top of P1.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Microsoft Entra Privileged Identity Management
Microsoft Entra ID P2 includes Microsoft Entra Privileged Identity Management (D), which provides just-in-time privileged role activation, access reviews, and approval workflows for administrative roles, and Microsoft Entra Identity Protection (E), which delivers risk-based Conditional Access policies, user and sign-in risk detection, and automated remediation of risky identities. These two capabilities are the distinguishing features that separate Entra ID P2 from P1, since P1 already covers the baseline identity features. Passwordless authentication (A), multifactor authentication (B), and single sign-on to SaaS apps (C) are all included in Entra ID P1 (and in large part in the free tier), so they are not exclusive to or introduced by P2 licensing.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Passwordless authentication
Why it's wrong here
Passwordless authentication methods, such as FIDO2 security keys, the Microsoft Authenticator app, and Windows Hello for Business, significantly enhance security by eliminating traditional passwords. While these methods are crucial for modern identity management, the foundational capabilities to implement and manage them are fully available with a Microsoft Entra ID P1 license. Therefore, passwordless authentication is not an exclusive feature of the P2 tier.
- ✗
Multifactor authentication (MFA)
Why it's wrong here
Multifactor authentication (MFA) adds a critical layer of security by requiring users to provide two or more verification factors to gain access. The core functionality for enabling and enforcing MFA policies, including integration with various authentication methods, is a standard security feature included within Microsoft Entra ID P1 licenses. Consequently, MFA itself is not an exclusive capability of the P2 tier.
- ✗
Single sign-on (SSO) to SaaS apps
Why it's wrong here
Single sign-on (SSO) allows users to access multiple applications and services with a single set of credentials, greatly improving user experience and reducing password fatigue. This fundamental capability, which enables seamless access to thousands of pre-integrated SaaS applications, is a core feature of Microsoft Entra ID P1. Therefore, SSO to SaaS apps is not a differentiating feature of the P2 license.
- ✓
Microsoft Entra Privileged Identity Management
Why this is correct
Microsoft Entra Privileged Identity Management (PIM) is a robust feature designed to manage, control, and monitor access to critical resources within Microsoft Entra ID, Azure, and other Microsoft Online Services. It provides just-in-time (JIT) and just-enough-administration (JEA) access, significantly reducing the attack surface by limiting the duration and scope of elevated permissions. This advanced capability for privileged access governance is a cornerstone feature of Microsoft Entra ID P2.
- ✓
Microsoft Entra Identity Protection
Why this is correct
Microsoft Entra Identity Protection proactively detects, investigates, and remediates identity-based risks in an organization's environment. Utilizing machine learning, it identifies suspicious activities such as impossible travel, anomalous sign-ins, and leaked credentials, assigning risk levels to users and sign-ins. This advanced threat detection and automated remediation capability is a key differentiator and exclusive feature of Microsoft Entra ID P2.
Go deeper
Related to this question
Learn chapter
Entra Internet Access and Private Access
Key term
Passwordless authentication
Passwordless authentication is a method of verifying a user's identity without requiring them to enter a password, using alternative factors like biometrics, hardware tokens, or one-time codes.
Key term
User
A user is any person, system, or device that interacts with an IT service, resource, or identity system, typically authenticated through credentials and authorized to perform specific actions.
About these practice questions
This SC-900 question is part of Courseiva's 1,279-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.