SC-900 Describe the capabilities of Microsoft Entra Practice Question
Which TWO of the following are capabilities of Microsoft Entra ID? (Choose two.)
⚠ Common exam trap
Microsoft often tests the distinction between identity management (Entra ID) and endpoint security (Defender for Endpoint) or comprehensive device management (Intune). While Entra ID manages device *identities* and enables device-based conditional access, the broader 'Device Management' (e.g., configuration, app deployment, patching) is primarily handled by solutions like Intune.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Identity Protection
Microsoft Entra ID (formerly Azure AD) includes Identity Protection (option B), a risk-based service that detects and remediates risky sign-ins and compromised user credentials using signals like leaked credentials and atypical sign-in behavior. It also includes Privileged Identity Management (option D), which provides just-in-time privileged role activation, approval workflows, access reviews, and time-bound role assignments for administrative roles. These are both core Entra ID capabilities within the Entra suite. Device Management (option A) is primarily a Microsoft Intune capability, not Entra ID itself. Endpoint Detection and Response (option C) belongs to Microsoft Defender for Endpoint, and Information Protection (option E) is delivered by Microsoft Purview, so neither is an Entra ID capability.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Device Management
Why it's wrong here
Microsoft Entra ID plays a foundational role in device management by enabling device registration, joining, and conditional access policies based on device state. However, the comprehensive capabilities for configuring, deploying applications to, and enforcing compliance on devices (such as mobile phones, tablets, and PCs) are primarily provided by Microsoft Intune. Intune acts as the unified endpoint management solution, leveraging Entra ID for identity and access but handling the granular device configuration and lifecycle management itself.
- ✓
Identity Protection
Why this is correct
Identity Protection is a core capability within Microsoft Entra ID that focuses on detecting, investigating, and remediating identity-based risks. It leverages machine learning and heuristics to identify suspicious activities, such as anomalous sign-ins, leaked credentials, or impossible travel, across user accounts. This feature can automatically block risky sign-ins or enforce multi-factor authentication, significantly enhancing the security posture of user identities within the organization.
- ✗
Endpoint Detection and Response
Why it's wrong here
Endpoint Detection and Response (EDR) is a specialized security capability focused on monitoring, detecting, and responding to threats on endpoint devices like workstations and servers. This functionality is primarily delivered by Microsoft Defender for Endpoint, which provides advanced threat protection, vulnerability management, and automated investigation and remediation directly on the endpoints. While Entra ID secures the identities accessing these endpoints, EDR is distinctively about the security of the endpoints themselves.
- ✓
Privileged Identity Management
Why this is correct
Privileged Identity Management (PIM) is a crucial feature of Microsoft Entra ID Governance that helps organizations manage, control, and monitor access to important resources. PIM enables just-in-time (JIT) access to privileged roles, meaning users activate elevated permissions only when needed and for a limited duration. This significantly reduces the attack surface associated with standing administrative access, providing robust auditing and approval workflows for all privileged operations.
- ✗
Information Protection
Why it's wrong here
Information Protection, encompassing capabilities like data classification, labeling, and encryption, is a core component of Microsoft Purview, the unified data governance solution. Its primary function is to help organizations discover, classify, protect, and govern sensitive data across their digital estate. While Entra ID manages who can access information, the actual protection and lifecycle management of the information itself falls under the purview of data governance services like Microsoft Purview.
Go deeper
Related to this question
Learn chapter
Microsoft Entra Global Secure Access
Key term
Intune
Microsoft Intune is a cloud-based service that helps organizations manage their users' devices and applications, ensuring security and compliance without needing to own or control the physical hardware.
Key term
Identity
Identity is the unique set of attributes that defines a user, device, or service in a computer system, determining what they can access and do.
About these practice questions
One of 1,279 original SC-900 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.