SC-900 Describe the capabilities of Microsoft Entra Practice Question
You need to provide external partners with access to your organization's SharePoint site. The partners must use their own credentials. Which Microsoft Entra feature should you use?
⚠ Common exam trap
A common mix-up: candidates confuse Microsoft Entra B2B collaboration with Microsoft Entra B2C (not listed), or mistakenly think Identity Governance or PIM can handle external authentication, when in fact B2B collaboration is the only feature that allows external users to bring their own credentials for resource access.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Microsoft Entra B2B collaboration
Microsoft Entra B2B collaboration is the correct feature because it enables external users (partners) to access your organization's resources using their own identities (e.g., work, social, or other Azure AD accounts). It leverages the existing Azure AD tenant to issue guest user objects and supports SAML/WS-Federation or OIDC for authentication, allowing partners to authenticate with their own credentials without requiring a separate account or password in your tenant.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Microsoft Entra B2B collaboration
Why this is correct
Microsoft Entra B2B collaboration is the correct solution for securely providing external partners with access to your organization's resources. It enables guest users to sign in using their own existing identities, such as work, school, or social accounts, without requiring them to create new credentials in your tenant. This streamlined process facilitates collaboration by inviting external users to access specific applications or documents while maintaining administrative control over their permissions.
- ✗
Microsoft Entra Identity Governance
Why it's wrong here
Microsoft Entra Identity Governance focuses on managing and auditing identity lifecycles, access reviews, and entitlement management for both internal and external users. While it can manage *existing* external access, it is not the primary mechanism for *initially provisioning* or inviting external partners to gain access to your organization. Its core purpose is to ensure the right people have the right access for the right reasons, not to establish the initial connection.
- ✗
Privileged Identity Management
Why it's wrong here
Privileged Identity Management (PIM) is designed to manage, control, and monitor access to important resources within Microsoft Entra ID, Azure, and other Microsoft Online Services. PIM specifically focuses on just-in-time and just-enough access for *privileged roles*, such as Global Administrator or User Administrator, to mitigate the risks of excessive, unnecessary, or misused access permissions. It does not serve as the foundational service for granting general external partner access to organizational resources.
- ✗
Microsoft Entra ID Protection
Why it's wrong here
Microsoft Entra ID Protection is a security feature that detects potential vulnerabilities affecting your organization's identities, configures automated responses to detected suspicious actions, and investigates suspicious incidents. Its primary function is to enhance security by identifying and remediating identity-based risks, such as compromised credentials or unusual sign-in activities, rather than providing the initial mechanism for external partners to gain access. It acts as a protective layer, not an access provisioning tool.
Go deeper
Related to this question
Learn chapter
Microsoft Entra ID
Key term
Collaboration
Collaboration in Microsoft 365 refers to the integrated tools and services that enable people to work together in real time, share information, and coordinate tasks from anywhere.
Key term
User
A user is any person, system, or device that interacts with an IT service, resource, or identity system, typically authenticated through credentials and authorized to perform specific actions.
About these practice questions
Courseiva writes every SC-900 question from scratch — 1,250 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.