Courseiva

SC-900 Describe the capabilities of Microsoft Entra Practice Question

Which TWO features are part of Microsoft Entra ID Governance? (Choose two.)

⚠ Common exam trap

Watch out — candidates often confuse security features (Conditional Access, Identity Protection) with governance features, but Entra ID Governance specifically focuses on managing the lifecycle of access—who gets access, for how long, and with periodic review—not on enforcing security controls or mitigating threats.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Entitlement Management

Entitlement Management (A) is a core Microsoft Entra ID Governance capability that lets organizations manage the lifecycle of access through access packages, catalogs, connected organizations, and policies for internal and external users, automating assignment and removal of resource access. Access Reviews (B) is also part of Entra ID Governance, enabling periodic recertification of group memberships, application assignments, and privileged role assignments so that access is reviewed and revoked when no longer needed. Conditional Access (C) is a Microsoft Entra ID access-control policy engine that enforces signals and conditions at sign-in, but it is not classified as an Entra ID Governance feature. Self-Service Password Reset (D) is an authentication/credential-management feature in Entra ID, not a governance workload. Identity Protection (E) is a risk-detection and remediation service for identity risk signals, and while related to security, it is not one of the Entra ID Governance features asked for here.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Entitlement Management

    Why this is correct

    Microsoft Entra Entitlement Management is a core component of identity governance, automating the lifecycle of access to groups, applications, and SharePoint sites. It allows organizations to define access packages, specify approval workflows, and enable self-service requests, ensuring users gain and lose access appropriately and efficiently based on their roles and projects. This capability streamlines the process of granting and revoking access, reducing manual overhead and improving compliance.

  • ✓

    Access Reviews

    Why this is correct

    Microsoft Entra Access Reviews are a critical identity governance feature designed to periodically certify that users still require access to specific resources. This capability enables resource owners or designated reviewers to attest to group memberships or application assignments, facilitating the identification and removal of stale or excessive access rights. By automating these reviews, organizations maintain a strong security posture and meet compliance requirements by ensuring access is always justified.

  • ✗

    Conditional Access

    Why it's wrong here

    Conditional Access in Microsoft Entra ID is an access control engine that enforces policies at the point of sign-in, determining *how* users can access resources based on specific conditions like device state, location, or sign-in risk. While crucial for security enforcement, it focuses on real-time access decisions and policy application rather than the lifecycle management, auditing, or certification of access entitlements, which are the hallmarks of governance. It dictates access *conditions*, not access *entitlements* themselves.

  • ✗

    Self-Service Password Reset

    Why it's wrong here

    Self-Service Password Reset (SSPR) empowers users to securely reset their own forgotten or locked passwords without requiring assistance from IT helpdesk personnel. Although SSPR significantly enhances user experience and reduces operational overhead, it primarily falls under identity management capabilities focused on user convenience and operational efficiency. It does not involve the structured oversight, lifecycle management, or periodic certification of access rights inherent to identity governance.

  • ✗

    Identity Protection

    Why it's wrong here

    Microsoft Entra Identity Protection is a security feature that leverages machine learning to detect and remediate identity-based risks, such as compromised credentials, anomalous sign-in behaviors, or suspicious user activities. While vital for safeguarding identities and can trigger Conditional Access policies, its primary function is risk detection and automated response. It does not directly manage, review, or certify who has access to what resources, which defines identity governance.

About these practice questions

One of 1,279 original SC-900 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.