SC-900 Describe the capabilities of Microsoft Entra Practice Question
Which TWO of the following are supported identity types for Microsoft Entra External ID? (Select two.)
⚠ Common exam trap
Many candidates confuse authentication methods (like biometrics or certificates) with identity provider types, or assume OAuth 2.0 tokens are an identity type rather than a protocol used to exchange identity information.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Social identities (e.g., Google, Facebook)
Microsoft Entra External ID supports social identities such as Google and Facebook (option B), allowing consumers to sign in with existing accounts from these providers via built-in identity providers. It also supports enterprise identities from SAML/WS-Federation identity providers (option D), enabling federation with external organizations' IdPs for B2B collaboration scenarios. These two identity types are core to External ID's design for customer and partner access. OAuth 2.0 token identities (A) describe a protocol flow, not a supported identity type. X.509 certificate-based identities (C) are not a native External ID identity type. Biometric identities (E) are handled by the device/authenticator, not defined as an External ID identity type.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
OAuth 2.0 token identities
Why it's wrong here
OAuth 2.0 tokens, such as access tokens or ID tokens, are mechanisms used to convey authorization grants or identity claims, respectively, within a secure transaction. They are not considered identity types themselves, but rather temporary artifacts that represent a user's authenticated session or permissions. An identity type refers to the fundamental source or nature of a user's identity, such as a social account or an enterprise directory account, which the token then references.
- ✓
Social identities (e.g., Google, Facebook)
Why this is correct
Microsoft Entra External ID (formerly Azure AD External ID) fully supports social identities, enabling users to sign in to applications using their existing credentials from popular social identity providers like Google, Facebook, and Microsoft accounts. This capability simplifies the registration and login process for external users, leveraging their familiar accounts. These identities are managed by the respective social providers, with claims securely passed to the application via standard protocols like OpenID Connect.
- ✗
X.509 certificate-based identities
Why it's wrong here
X.509 certificates are primarily a robust method for strong authentication, verifying a user's identity through cryptographic means, often in enterprise environments. However, they represent an authentication method rather than a distinct identity type that Microsoft Entra External ID directly manages for external users. External ID focuses on federating with identity providers that manage user accounts, not on directly issuing or managing certificate-based identities for guest users. The underlying identity would still originate from an enterprise or cloud directory.
- ✓
Enterprise identities from SAML/WS-Federation identity providers
Why this is correct
Microsoft Entra External ID is specifically designed to facilitate secure collaboration with other organizations by supporting federation with their existing enterprise identity providers. This includes robust support for industry-standard protocols such as SAML 2.0 and WS-Federation, allowing users from partner companies to authenticate using their own corporate credentials. This capability ensures seamless access to shared applications and resources without requiring the creation of duplicate user accounts in the host tenant.
- ✗
Biometric identities (fingerprint, face)
Why it's wrong here
Biometric data, such as fingerprints, facial scans, or voice recognition, functions as an authentication factor used to verify a user's identity, typically in conjunction with a device or a credential. It is not an identity type in itself. The underlying identity remains a social, enterprise, or cloud-based account, which is then secured and verified through the application of a biometric authentication method.
Go deeper
Related to this question
Learn chapter
Identity Concepts
Key term
Access token
A digital key that a computer system gives you to prove your identity and grant you permission to access specific resources or perform actions.
Key term
OAuth
OAuth is an open standard for access delegation that allows users to grant third-party applications limited access to their resources without sharing their credentials.
About these practice questions
This SC-900 question is part of Courseiva's 1,279-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.