Courseiva

Microsoft Entra ID Features: Conditional Access & Identity Protection

Which THREE features are part of Microsoft Entra ID? (Select three.)

Quick Answer

The correct answers are Conditional Access and Identity Protection, as both are core features of Microsoft Entra ID. Conditional Access is the policy engine that enforces access controls based on signals like user location or device compliance, while Identity Protection uses machine learning to detect and respond to identity-based risks such as leaked credentials or suspicious sign-ins. On the SC-900 exam, this question tests your ability to distinguish Entra ID’s native security features from separate Microsoft services—a common trap is confusing Intune (a mobile device management tool) or Microsoft Sentinel (a SIEM) with Entra ID capabilities. Remember that Conditional Access and Identity Protection work together inside Entra ID to form a zero-trust foundation, whereas Intune and Sentinel are standalone products. A useful memory tip: think of “CIP” for Conditional Access, Identity Protection, and Privileged Identity Management (PIM)—all three are Entra ID features, but the question only asks for two, so focus on the first two letters of the acronym.

⚠ Common exam trap

Candidates often confuse features that integrate with Microsoft Entra ID (like Intune or Sentinel) as being part of Entra ID itself, when they are separate Azure services that only use Entra ID for authentication or data sources.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Privileged Identity Management

Privileged Identity Management (A) is a Microsoft Entra ID feature that provides just-in-time role activation, approval workflows, and access reviews for privileged directory roles, so it is correct. Conditional Access (C) is the Entra ID policy engine that evaluates signals such as user, device, location, and risk to grant or block access to resources, making it a core Entra ID capability. Identity Protection (D) is also part of Entra ID, using risk detections and machine learning to identify risky sign-ins and compromised users and to feed risk signals into Conditional Access. Microsoft Sentinel (B) is a separate cloud-native SIEM/SOAR service built on Azure Monitor/Log Analytics, and Microsoft Intune (E) is a separate cloud-based endpoint management (MDM/MAM) service, so neither is a feature of Microsoft Entra ID itself.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Privileged Identity Management

    Why this is correct

    Privileged Identity Management (PIM) is indeed a feature of Microsoft Entra ID, but it is not one of the two correct answers for this question. The intended correct options are Conditional Access and Identity Protection.

  • ✗

    Microsoft Sentinel

    Why it's wrong here

    Microsoft Sentinel is a separate cloud-native SIEM and SOAR service, not a Microsoft Entra ID feature. It tempts because both sit in the security portfolio and integrate closely, yet Sentinel is licensed and deployed independently, whereas Entra ID provides identity, access and governance capabilities.

  • ✓

    Conditional Access

    Why this is correct

    Conditional Access evaluates signals such as user, device and location, then enforces grant or session controls before access is allowed. It is a core Microsoft Entra ID policy engine, satisfying the requirement for an Entra ID feature.

  • ✓

    Identity Protection

    Why this is correct

    Identity Protection detects risky users and risky sign-ins using Microsoft's threat intelligence, then feeds those detections into risk-based Conditional Access policies. It is a native Microsoft Entra ID capability, satisfying the requirement for an Entra ID feature.

  • ✗

    Microsoft Intune

    Why it's wrong here

    Intune is a separate endpoint management service, not a component of Microsoft Entra ID, which covers identity and access capabilities such as Conditional Access and PIM. It is tempting because Intune integrates closely with Entra ID for device compliance, and would be the right answer if the question asked about device management.

About these practice questions

One of 1,279 original SC-900 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

1 more way this is tested on SC-900

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. Which TWO of the following are included in Microsoft Entra ID Protection?

easy
  • A.Data loss prevention (DLP)
  • B.Privileged Identity Management (PIM)
  • ✓ C.Risk-based Conditional Access policies
  • ✓ D.Sign-in risk detections (e.g., anonymous IP address)
  • E.Passwordless authentication support

Why C: Option C (Risk-based Conditional Access policies) is correct because Microsoft Entra ID Protection surfaces user and sign-in risk levels that can be consumed directly by Conditional Access as conditions, allowing policies to block access or require MFA/password change when risk is detected. Option D (Sign-in risk detections such as anonymous IP address) is correct because ID Protection natively detects and reports sign-in risks like anonymous IP, atypical travel, malware-linked IP, and unfamiliar sign-in properties, and these detections feed the risk evaluations used by the service. Options A, B, and E are not part of ID Protection: DLP is a Microsoft Purview/Defender for Cloud Apps capability, PIM is a separate Microsoft Entra ID Governance/Privileged Identity Management service for just-in-time role activation, and passwordless authentication (FIDO2, Windows Hello, Authenticator) is a Microsoft Entra authentication method feature rather than an ID Protection component.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.