SC-900 Practice Question: Describe the concepts of security, compliance, and identity
Which TWO of the following are benefits of using Microsoft Entra ID for identity management? (Choose two.)
⚠ Common exam trap
SC-900 often tests the misconception that Entra ID includes on-premises-only or local authentication as benefits, when it actually provides cloud-based centralized identity with SSO and Conditional Access.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Conditional Access policies
Option B (Conditional Access policies) is correct because Microsoft Entra ID provides a policy engine that evaluates signals such as user/group membership, device compliance, location, and risk to grant, block, or require MFA for access to cloud and integrated apps. Option C (Single sign-on, SSO) is correct because Entra ID acts as a centralized identity provider using protocols like SAML 2.0, WS-Federation, OpenID Connect, and OAuth 2.0, letting users authenticate once and access multiple applications without re-entering credentials. Option A is wrong because storing passwords in plaintext is a severe security anti-pattern and Entra ID stores credentials as salted hashes, not plaintext. Option D is wrong because Entra ID is a cloud-based identity service, not a mechanism for local authentication of every app. Option E is wrong because Entra ID is a cloud identity provider and does not restrict authentication to on-premises only; it can integrate with on-premises AD via Entra Connect or Entra Cloud Sync.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Storing passwords in plaintext
Why it's wrong here
Storing passwords in plaintext is a severe security vulnerability, directly contradicting fundamental security principles and industry best practices. Microsoft Entra ID, like any secure identity system, never stores user passwords in an unencrypted, readable format. Instead, it employs robust hashing and salting techniques to protect credentials, ensuring that even if a data breach occurs, passwords cannot be easily compromised or reverse-engineered. This practice is essential for safeguarding user accounts and organizational data.
- ✓
Conditional Access policies
Why this is correct
Conditional Access policies are a core security feature of Microsoft Entra ID, allowing organizations to enforce granular access controls based on specific, real-time conditions. These policies evaluate factors such as user location, device compliance, application sensitivity, and sign-in risk during an authentication attempt. By dynamically requiring multi-factor authentication, blocking access, or limiting session duration, Conditional Access significantly enhances security posture and compliance without impeding legitimate user productivity.
- ✓
Single sign-on (SSO)
Why this is correct
Single sign-on (SSO) is a fundamental benefit of Microsoft Entra ID, enabling users to authenticate once with a single set of credentials and gain seamless access to numerous connected applications, both cloud-based and on-premises. This significantly enhances user experience by eliminating the need to remember multiple passwords and reduces help desk calls for password resets. Furthermore, SSO improves security by centralizing authentication, facilitating stronger credential management, and simplifying the enforcement of security policies.
- ✗
Local authentication for all apps
Why it's wrong here
Local authentication for all applications means each app manages its own user identities and authentication process independently, creating isolated identity silos. This approach significantly increases administrative overhead, complicates user experience with multiple credentials, and makes centralized security management impossible. It directly opposes the unified identity management and single sign-on (SSO) capabilities offered by Microsoft Entra ID, which aims to centralize authentication across all applications.
- ✗
On-premises authentication only
Why it's wrong here
Relying solely on on-premises authentication severely limits an organization's ability to leverage cloud-based applications and modern identity features provided by Microsoft Entra ID. This approach prevents seamless integration with SaaS applications, restricts access to advanced security capabilities like Conditional Access and identity protection, and hinders the adoption of hybrid identity scenarios. Microsoft Entra ID is designed to extend identity to the cloud, supporting both on-premises and cloud resources for a comprehensive solution.
Go deeper
Related to this question
Learn chapter
Azure Policy Effects: Audit, Deny, Modify
Key term
General Data Protection Regulation
A European Union law that gives individuals control over their personal data and sets strict rules for how organizations collect, store, and process that data.
Key term
Access token
A digital key that a computer system gives you to prove your identity and grant you permission to access specific resources or perform actions.
About these practice questions
Courseiva writes every SC-900 question from scratch — 1,279 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.