Courseiva

SC-900 Describe the capabilities of Microsoft Entra Practice Question

Which TWO Microsoft Entra features can be used to enforce multifactor authentication (MFA)?

⚠ Common exam trap

Candidates often confuse Identity Protection or PIM as direct MFA enforcement features, when in reality they are risk-detection or privilege-management services that rely on Conditional Access to actually enforce MFA.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Security defaults

Security defaults (B) is correct because it is a Microsoft Entra ID setting that, when enabled, automatically enforces MFA for all users, requiring them to register for MFA and use it at sign-in. Conditional Access (E) is correct because it lets administrators create policies that require MFA based on conditions such as user, group, application, location, or risk, making it the primary policy engine for enforcing MFA. Self-Service Password Reset (A) only allows users to reset or unlock their accounts and does not enforce MFA at sign-in. Identity Protection (C) detects and reports risky sign-ins and users and can feed risk signals into Conditional Access, but by itself it does not enforce MFA. Privileged Identity Management (D) manages just-in-time role activation and approvals for privileged roles, not MFA enforcement for general sign-ins.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Self-Service Password Reset

    Why it's wrong here

    Self-Service Password Reset (SSPR) is a feature that enables users to reset their own forgotten passwords without requiring administrator intervention. While SSPR often incorporates multi-factor authentication (MFA) as a verification step during the password reset process to confirm the user's identity, its primary function is password recovery. SSPR does not, however, directly enforce MFA as a general sign-in requirement for accessing applications and resources across the tenant.

  • ✓

    Security defaults

    Why this is correct

    Security defaults are a foundational set of pre-configured identity security settings within Microsoft Entra ID designed to protect organizations from common identity-related attacks. When enabled, security defaults automatically enforce multi-factor authentication registration and usage for all users and administrators, requiring MFA for high-risk events and administrative tasks. This feature directly enforces MFA across the entire tenant, providing a strong baseline security posture.

  • ✗

    Identity Protection

    Why it's wrong here

    Identity Protection analyses sign-in risk and user risk to trigger conditional access policies, but it does not itself enforce MFA; it relies on a separate Conditional Access policy to require MFA when risk is detected. It is tempting because it is often used alongside MFA policies to block high-risk sign-ins, and would be correct if the question asked for a tool that evaluates risk to prompt MFA, rather than directly enforcing it.

  • ✗

    Privileged Identity Management

    Why it's wrong here

    Privileged Identity Management (PIM) is a feature within Microsoft Entra ID Governance that allows organizations to manage, control, and monitor access to important resources by providing just-in-time access for privileged roles. PIM focuses on elevating permissions temporarily and can be configured to require MFA as part of the activation process for a privileged role. However, PIM itself does not enforce MFA as a general sign-in requirement for all users or for accessing non-privileged resources; its scope is specifically privileged role management and activation.

  • ✓

    Conditional Access

    Why this is correct

    Conditional Access policies in Microsoft Entra ID provide granular control over how users access resources based on various conditions such as user identity, location, device state, and application. Administrators can configure these policies to explicitly require multi-factor authentication for specific user groups, applications, or scenarios. This makes Conditional Access a powerful and flexible tool for directly enforcing MFA based on defined conditions, allowing for adaptive security policies.

About these practice questions

Courseiva writes every SC-900 question from scratch — 1,279 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.