SC-900 Describe the capabilities of Microsoft Entra Practice Question
Which TWO Microsoft Entra features can be used to enforce multifactor authentication (MFA)?
⚠ Common exam trap
Candidates often confuse Identity Protection or PIM as direct MFA enforcement features, when in reality they are risk-detection or privilege-management services that rely on Conditional Access to actually enforce MFA.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Security defaults
Security defaults (B) is correct because it is a Microsoft Entra ID setting that, when enabled, automatically enforces MFA for all users, requiring them to register for MFA and use it at sign-in. Conditional Access (E) is correct because it lets administrators create policies that require MFA based on conditions such as user, group, application, location, or risk, making it the primary policy engine for enforcing MFA. Self-Service Password Reset (A) only allows users to reset or unlock their accounts and does not enforce MFA at sign-in. Identity Protection (C) detects and reports risky sign-ins and users and can feed risk signals into Conditional Access, but by itself it does not enforce MFA. Privileged Identity Management (D) manages just-in-time role activation and approvals for privileged roles, not MFA enforcement for general sign-ins.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Self-Service Password Reset
Why it's wrong here
Self-Service Password Reset (SSPR) is a feature that enables users to reset their own forgotten passwords without requiring administrator intervention. While SSPR often incorporates multi-factor authentication (MFA) as a verification step during the password reset process to confirm the user's identity, its primary function is password recovery. SSPR does not, however, directly enforce MFA as a general sign-in requirement for accessing applications and resources across the tenant.
- ✓
Security defaults
Why this is correct
Security defaults are a foundational set of pre-configured identity security settings within Microsoft Entra ID designed to protect organizations from common identity-related attacks. When enabled, security defaults automatically enforce multi-factor authentication registration and usage for all users and administrators, requiring MFA for high-risk events and administrative tasks. This feature directly enforces MFA across the entire tenant, providing a strong baseline security posture.
- ✗
Identity Protection
Why it's wrong here
Identity Protection analyses sign-in risk and user risk to trigger conditional access policies, but it does not itself enforce MFA; it relies on a separate Conditional Access policy to require MFA when risk is detected. It is tempting because it is often used alongside MFA policies to block high-risk sign-ins, and would be correct if the question asked for a tool that evaluates risk to prompt MFA, rather than directly enforcing it.
- ✗
Privileged Identity Management
Why it's wrong here
Privileged Identity Management (PIM) is a feature within Microsoft Entra ID Governance that allows organizations to manage, control, and monitor access to important resources by providing just-in-time access for privileged roles. PIM focuses on elevating permissions temporarily and can be configured to require MFA as part of the activation process for a privileged role. However, PIM itself does not enforce MFA as a general sign-in requirement for all users or for accessing non-privileged resources; its scope is specifically privileged role management and activation.
- ✓
Conditional Access
Why this is correct
Conditional Access policies in Microsoft Entra ID provide granular control over how users access resources based on various conditions such as user identity, location, device state, and application. Administrators can configure these policies to explicitly require multi-factor authentication for specific user groups, applications, or scenarios. This makes Conditional Access a powerful and flexible tool for directly enforcing MFA based on defined conditions, allowing for adaptive security policies.
Go deeper
Related to this question
Learn chapter
Authentication vs Authorisation
Key term
Identity
Identity is the unique set of attributes that defines a user, device, or service in a computer system, determining what they can access and do.
Key term
Identity protection
Identity protection is the set of policies, technologies, and practices used to secure digital identities and prevent unauthorized access to systems and data.
About these practice questions
Courseiva writes every SC-900 question from scratch — 1,279 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.