SC-900 Describe the capabilities of Microsoft Entra Practice Question
Which TWO features are part of Microsoft Entra ID Governance? (Choose two.)
⚠ Common exam trap
Watch out — candidates often confuse security features (Conditional Access, Identity Protection) with governance features, but Entra ID Governance specifically focuses on managing the lifecycle of access—who gets access, for how long, and with periodic review—not on enforcing security controls or mitigating threats.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Entitlement Management
Entitlement Management (A) is a core Microsoft Entra ID Governance capability that lets organizations manage the lifecycle of access through access packages, catalogs, connected organizations, and policies for internal and external users, automating assignment and removal of resource access. Access Reviews (B) is also part of Entra ID Governance, enabling periodic recertification of group memberships, application assignments, and privileged role assignments so that access is reviewed and revoked when no longer needed. Conditional Access (C) is a Microsoft Entra ID access-control policy engine that enforces signals and conditions at sign-in, but it is not classified as an Entra ID Governance feature. Self-Service Password Reset (D) is an authentication/credential-management feature in Entra ID, not a governance workload. Identity Protection (E) is a risk-detection and remediation service for identity risk signals, and while related to security, it is not one of the Entra ID Governance features asked for here.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Entitlement Management
Why this is correct
Microsoft Entra Entitlement Management is a core component of identity governance, automating the lifecycle of access to groups, applications, and SharePoint sites. It allows organizations to define access packages, specify approval workflows, and enable self-service requests, ensuring users gain and lose access appropriately and efficiently based on their roles and projects. This capability streamlines the process of granting and revoking access, reducing manual overhead and improving compliance.
- ✓
Access Reviews
Why this is correct
Microsoft Entra Access Reviews are a critical identity governance feature designed to periodically certify that users still require access to specific resources. This capability enables resource owners or designated reviewers to attest to group memberships or application assignments, facilitating the identification and removal of stale or excessive access rights. By automating these reviews, organizations maintain a strong security posture and meet compliance requirements by ensuring access is always justified.
- ✗
Conditional Access
Why it's wrong here
Conditional Access in Microsoft Entra ID is an access control engine that enforces policies at the point of sign-in, determining *how* users can access resources based on specific conditions like device state, location, or sign-in risk. While crucial for security enforcement, it focuses on real-time access decisions and policy application rather than the lifecycle management, auditing, or certification of access entitlements, which are the hallmarks of governance. It dictates access *conditions*, not access *entitlements* themselves.
- ✗
Self-Service Password Reset
Why it's wrong here
Self-Service Password Reset (SSPR) empowers users to securely reset their own forgotten or locked passwords without requiring assistance from IT helpdesk personnel. Although SSPR significantly enhances user experience and reduces operational overhead, it primarily falls under identity management capabilities focused on user convenience and operational efficiency. It does not involve the structured oversight, lifecycle management, or periodic certification of access rights inherent to identity governance.
- ✗
Identity Protection
Why it's wrong here
Microsoft Entra Identity Protection is a security feature that leverages machine learning to detect and remediate identity-based risks, such as compromised credentials, anomalous sign-in behaviors, or suspicious user activities. While vital for safeguarding identities and can trigger Conditional Access policies, its primary function is risk detection and automated response. It does not directly manage, review, or certify who has access to what resources, which defines identity governance.
Go deeper
Related to this question
Learn chapter
Defender for Cloud Workload Protections
Key term
Self-service password reset
Self-service password reset (SSPR) is a Microsoft identity feature that allows users to reset their own passwords without needing help from an IT helpdesk.
Key term
Conditional access
Conditional access is a security framework that evaluates signals like user location, device health, and risk level to grant or block access to resources in real time.
About these practice questions
One of 1,279 original SC-900 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.