SC-900 Describe the capabilities of Microsoft Entra Practice Question
Which TWO of the following are capabilities of Microsoft Entra ID? (Select two.)
⚠ Common exam trap
Candidates often confuse Microsoft Entra ID with broader security suites like Microsoft 365 Defender or Azure security services, mistakenly attributing endpoint protection or network firewall capabilities to identity management.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Identity as a Service (IDaaS) for cloud applications
Microsoft Entra ID is a cloud-based identity and access management service, providing Identity as a Service (IDaaS) for cloud applications. It enables organizations to manage user identities and control access to resources, including thousands of pre-integrated SaaS applications through single sign-on (SSO). This makes option B correct because Entra ID's core function is identity management, not endpoint security or network infrastructure.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Antivirus and antimalware protection
Why it's wrong here
Microsoft Entra ID (formerly Azure Active Directory) is fundamentally an identity and access management (IAM) service, focusing on user authentication and authorization. It does not provide antivirus or antimalware protection for endpoints. These critical security functions are instead delivered by Microsoft Defender for Endpoint, a component of the broader Microsoft Defender XDR suite, which specializes in endpoint detection and response (EDR) and threat prevention.
- ✓
Identity as a Service (IDaaS) for cloud applications
Why this is correct
Microsoft Entra ID serves as a comprehensive Identity as a Service (IDaaS) solution, providing a cloud-based platform for managing digital identities and controlling access to various cloud applications. It enables organizations to centralize user accounts, enforce authentication policies, and provision users to Software as a Service (SaaS) applications and custom cloud applications. This capability streamlines identity management operations and enhances security across diverse cloud environments.
- ✗
Provide network firewall services
Why it's wrong here
Microsoft Entra ID is an identity and access management service, not a network security appliance or service designed to filter network traffic. Network firewall capabilities, such as stateful packet inspection, URL filtering, and threat intelligence-based blocking, are provided by dedicated Azure networking services. Examples include Azure Firewall for centralized network security and Network Security Groups (NSGs) for granular traffic control at the virtual network interface or subnet level within Azure.
- ✗
Manage mobile devices and applications
Why it's wrong here
While Microsoft Entra ID provides the identity foundation for users accessing mobile resources, it does not directly manage mobile devices or applications themselves. The comprehensive management of mobile devices, including configuration, compliance policies, and application deployment, is a core capability of Microsoft Intune. Intune, often integrated with Entra ID for user authentication, functions as a Mobile Device Management (MDM) and Mobile Application Management (MAM) solution.
- ✓
Single sign-on (SSO) to thousands of SaaS applications
Why this is correct
Microsoft Entra ID is a cornerstone for enabling Single Sign-On (SSO) across a vast ecosystem of Software as a Service (SaaS) applications. By integrating with Entra ID, users can authenticate once with their corporate credentials and gain seamless access to thousands of pre-integrated SaaS applications, eliminating the need to remember multiple usernames and passwords. This significantly improves user experience, reduces password fatigue, and enhances security by centralizing authentication and enforcing consistent access policies.
Go deeper
Related to this question
Learn chapter
Core Security Concepts
Key term
Security
Security in IT is the practice of protecting systems, networks, and data from unauthorized access, damage, or theft.
Key term
Single sign-on
Single sign-on (SSO) is an authentication method that allows a user to log in once and gain access to multiple applications or systems without re-entering credentials.
About these practice questions
One of 1,250 original SC-900 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.